diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index fe9a4c36..b4a5dadb 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -11814,13 +11814,122 @@ - CSRF vulnerability in WP HTML Sitemap 1.2 + WP HTML Sitemap 1.2 - wp-html-sitemap.html Sitemap Deletion CSRF + 105084 + http://seclists.org/fulldisclosure/2014/Mar/400 https://security.dxw.com/advisories/csrf-vulnerability-in-wp-html-sitemap-1-2/ CSRF + + + Groups 1.4.5 - Negated Role Capability Handling Elevated Privilege Issue + + 104940 + + AUTHBYPASS + 1.4.6 + + + + + + HTML5 jQuery Audio Player 2.3 - playlist/add_playlist.php Multiple Parameter Stored XSS Weakness + + 104951 + + XSS + 2.4 + + + HTML5 jQuery Audio Player 2.3 - playlist/add_playlist.php id Parameter SQL Injection + + 104952 + + SQLI + 2.4 + + + + + + ShrimpTest 1.0b2 - plugins/metric-conversion.php Multiple Unspecified XSS + + 104956 + + XSS + 1.0b3 + + + ShrimpTest 1.0b2 - plugins/plugin-notification.php Unspecified XSS + + 104957 + + XSS + 1.0b3 + + + ShrimpTest 1.0b2 - plugins/variant-shortcode.php Unspecified XSS + + 104958 + + XSS + 1.0b3 + + + ShrimpTest 1.0b2 - admin/experiments.php Multiple Unspecified XSS + + 104959 + + XSS + 1.0b3 + + + ShrimpTest 1.0b2 - admin/experiment-new.php Multiple Unspecified XSS + + 104960 + + XSS + 1.0b3 + + + + + + ActiveHelper LiveHelp Server 3.2.2 - server/import/status.php Multiple Parameter SQL Injection + + 104990 + + SQLI + 3.4.0 + + + ActiveHelper LiveHelp Server 3.2.2 - server/import/tracker.php Multiple Parameter SQL Injection + + 104991 + + SQLI + 3.4.0 + + + ActiveHelper LiveHelp Server 3.2.2 - server/import/javascript.php Multiple Vector SQL Injection + + 104992 + + SQLI + 3.4.0 + + + ActiveHelper LiveHelp Server 3.2.2 - server/frames.php DEPARTMENT Parameter SQL Injection + + 104993 + + SQLI + 3.4.0 + + diff --git a/data/wp_vulns.xml b/data/wp_vulns.xml index 32a312b5..cd8355c2 100644 --- a/data/wp_vulns.xml +++ b/data/wp_vulns.xml @@ -1658,6 +1658,7 @@ wp-includes/comment.php bypass intended spam restrictions via a crafted URL + 104693 2010-5293 UNKNOWN @@ -1792,10 +1793,11 @@ When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + 104691 2010-5297 AUTHBYPASS - 3.0 + 3.0.1 Crafted String URL Redirect Restriction Bypass @@ -1838,6 +1840,7 @@ wp-includes/comment.php bypass intended spam restrictions via a crafted URL + 104693 2010-5293 UNKNOWN