diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index a49e0d75..c4aa3510 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -2926,11 +2926,38 @@ - Buddypress <= 1.5.5 - SQL Injection + Buddypress <= 1.9.1 - Privilege Escalation + http://packetstormsecurity.com/files/125213/ + + UNKNOWN + 1.9.2 + + + Buddypress <= 1.9.1 - Cross Site Scripting + + http://packetstormsecurity.com/files/125212/ + + XSS + 1.9.2 + + + Buddypress - player.swf / jwplayer.swf playerready Parameter XSS + + 88886 + http://packetstormsecurity.com/files/119020/ + http://xforce.iss.net/xforce/xfdb/80840 + + XSS + + + Buddypress <= 1.5.4 - wp-load.php exclude Parameter SQL Injection + + 80763 18690 SQLI + 1.5.5 @@ -7713,7 +7740,6 @@ Advanced XML Reader 0.1.1 - XML External Entity (XXE) Data Parsing Arbitrary File Disclosure 92904 - http://packetstormsecurity.com/files/121492/ http://seclists.org/bugtraq/2013/May/5 XXE @@ -9923,6 +9949,15 @@ + + DZS Video Gallery - ajax.php source Parameter Reflected XSS + + 103283 + 56904 + http://packetstormsecurity.com/files/125179/ + + RCE + DZS Video Gallery - upload.php File Upload Remote Code Execution