diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml index 16feb4c9..12ca9d64 100644 --- a/data/theme_vulns.xml +++ b/data/theme_vulns.xml @@ -1535,12 +1535,64 @@ RCE - Multiple vulnerabilities in Flash News theme for WordPress + Flash News - thumb.php src Parameter XSS + 89887 + http://packetstormsecurity.com/files/120037/ http://seclists.org/fulldisclosure/2013/Feb/8 http://cxsecurity.com/issue/WLB-2013020010 - MULTI + XSS + + + Flash News - Multiple Script Path Disclosure + + 89888 + http://packetstormsecurity.com/files/120037/ + http://seclists.org/fulldisclosure/2013/Feb/8 + http://cxsecurity.com/issue/WLB-2013020010 + + FPD + + + Flash News - includes/test.php a Parameter XSS + + 89889 + http://packetstormsecurity.com/files/120037/ + http://seclists.org/fulldisclosure/2013/Feb/8 + http://cxsecurity.com/issue/WLB-2013020010 + + XSS + + + Flash News - includes/test.php Direct Request Information Disclosure + + 89890 + http://packetstormsecurity.com/files/120037/ + http://seclists.org/fulldisclosure/2013/Feb/8 + http://cxsecurity.com/issue/WLB-2013020010 + + UNKNOWN + + + Flash News - thumb.php src Parameter File Upload Arbitrary Code Execution + + 89891 + http://packetstormsecurity.com/files/120037/ + http://seclists.org/fulldisclosure/2013/Feb/8 + http://cxsecurity.com/issue/WLB-2013020010 + + UNKNOWN + + + Flash News - thumb.php src Parameter Remote DoS + + 89892 + http://packetstormsecurity.com/files/120037/ + http://seclists.org/fulldisclosure/2013/Feb/8 + http://cxsecurity.com/issue/WLB-2013020010 + + UNKNOWN