From f688860bb27f16081fd83099f759e1819cea1acf Mon Sep 17 00:00:00 2001 From: ethicalhack3r Date: Sat, 26 Jan 2013 13:24:32 +0100 Subject: [PATCH] Added XMLRPC issues to all prev versions of WP. See issue #119. --- data/wp_vulns.xml | 480 ++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 480 insertions(+) diff --git a/data/wp_vulns.xml b/data/wp_vulns.xml index 13408bda..ead9f3c2 100644 --- a/data/wp_vulns.xml +++ b/data/wp_vulns.xml @@ -40,6 +40,16 @@ http://packetstormsecurity.org/files/116785/WordPress-3.4.2-Cross-Site-Request-Forgery.html CSRF + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -48,6 +58,16 @@ http://www.exploit-db.com/exploits/18791/ CSRF + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -61,6 +81,16 @@ http://packetstormsecurity.org/files/113254 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -79,6 +109,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -92,6 +132,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -100,6 +150,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -108,6 +168,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -116,6 +186,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -129,6 +209,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -142,6 +232,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -155,6 +255,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -163,6 +273,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -171,6 +291,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -179,6 +309,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -187,6 +327,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -205,6 +355,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -218,6 +378,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -231,6 +401,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -239,6 +419,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -247,6 +437,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -255,6 +455,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -273,6 +483,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -281,6 +501,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -294,6 +524,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -302,6 +542,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -315,6 +565,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -328,6 +588,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -336,6 +606,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -349,6 +629,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -357,6 +647,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -365,6 +665,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -373,6 +683,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -381,6 +701,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -389,6 +719,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -402,6 +742,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -410,6 +760,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -418,6 +778,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -426,6 +796,16 @@ http://seclists.org/fulldisclosure/2012/Nov/51 XSS + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -434,6 +814,16 @@ http://www.exploit-db.com/exploits/4721/ SQLI + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -447,6 +837,16 @@ http://www.exploit-db.com/exploits/4039/ SQLI + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -455,6 +855,16 @@ http://www.exploit-db.com/exploits/3960/ SQLI + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -463,6 +873,16 @@ http://www.exploit-db.com/exploits/3656/ SQLI + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -471,6 +891,16 @@ http://www.exploit-db.com/exploits/3109/ SQLI + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -479,6 +909,16 @@ http://www.exploit-db.com/exploits/3095/ SQLI + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -487,6 +927,16 @@ http://www.exploit-db.com/exploits/6/ UNKNOWN + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -495,6 +945,16 @@ http://www.exploit-db.com/exploits/1145/ SQLI + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -503,6 +963,16 @@ http://www.exploit-db.com/exploits/1077/ SQLI + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN + @@ -516,6 +986,16 @@ http://www.exploit-db.com/exploits/1033/ SQLI + + XMLRPC Pingback API Internal/External Port Scanning + https://github.com/FireFart/WordpressPingbackPortScanner + UNKNOWN + + + WordPress XMLRPC pingback additional issues + http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html + UNKNOWN +