From fbf2d827c29e195eba5c614f2e13459dcab4959d Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Sat, 16 Nov 2013 19:33:46 +0100 Subject: [PATCH] Update theme_vulns.xml --- data/theme_vulns.xml | 56 ++++++++++++++++++++++++++++++++++++++++++-- 1 file changed, 54 insertions(+), 2 deletions(-) diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml index 16feb4c9..12ca9d64 100644 --- a/data/theme_vulns.xml +++ b/data/theme_vulns.xml @@ -1535,12 +1535,64 @@ RCE - Multiple vulnerabilities in Flash News theme for WordPress + Flash News - thumb.php src Parameter XSS + 89887 + http://packetstormsecurity.com/files/120037/ http://seclists.org/fulldisclosure/2013/Feb/8 http://cxsecurity.com/issue/WLB-2013020010 - MULTI + XSS + + + Flash News - Multiple Script Path Disclosure + + 89888 + http://packetstormsecurity.com/files/120037/ + http://seclists.org/fulldisclosure/2013/Feb/8 + http://cxsecurity.com/issue/WLB-2013020010 + + FPD + + + Flash News - includes/test.php a Parameter XSS + + 89889 + http://packetstormsecurity.com/files/120037/ + http://seclists.org/fulldisclosure/2013/Feb/8 + http://cxsecurity.com/issue/WLB-2013020010 + + XSS + + + Flash News - includes/test.php Direct Request Information Disclosure + + 89890 + http://packetstormsecurity.com/files/120037/ + http://seclists.org/fulldisclosure/2013/Feb/8 + http://cxsecurity.com/issue/WLB-2013020010 + + UNKNOWN + + + Flash News - thumb.php src Parameter File Upload Arbitrary Code Execution + + 89891 + http://packetstormsecurity.com/files/120037/ + http://seclists.org/fulldisclosure/2013/Feb/8 + http://cxsecurity.com/issue/WLB-2013020010 + + UNKNOWN + + + Flash News - thumb.php src Parameter Remote DoS + + 89892 + http://packetstormsecurity.com/files/120037/ + http://seclists.org/fulldisclosure/2013/Feb/8 + http://cxsecurity.com/issue/WLB-2013020010 + + UNKNOWN