From fd880da0577e32caca5062688a94f315b2f882b4 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Sun, 2 Feb 2014 11:32:43 +0100 Subject: [PATCH] Update vuln db --- data/plugin_vulns.xml | 48 ++++++++++++++++++++++++++++++++++++++++--- data/theme_vulns.xml | 10 +++++++++ 2 files changed, 55 insertions(+), 3 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 0ef3e902..340b2570 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -2620,13 +2620,22 @@ - Better WP Security <= 3.5.3 - Stored XSS + Better WP Security 3.5.5 - inc/admin/content.php id_specialfile Parameter Stored XSS + + 101788 + + XSS + 3.5.6 + + + Better WP Security <= 3.5.3 - inc/secure.php logevent Function URL Handling Stored XSS - https://github.com/wpscanteam/wpscan/issues/251 - http://www.securityfocus.com/archive/1/527634/30/0/threaded 95884 54299 27290 + http://packetstormsecurity.com/files/122615/ + https://github.com/wpscanteam/wpscan/issues/251 + http://www.securityfocus.com/archive/1/527634/30/0/threaded XSS 3.5.4 @@ -8208,6 +8217,7 @@ 96111 54402 27531 + http://packetstormsecurity.com/files/122761/ 2.0.11 @@ -8223,6 +8233,7 @@ 96111 54402 27531 + http://packetstormsecurity.com/files/122761/ 2.0.11 @@ -8780,6 +8791,7 @@ Booking System - events_facualty_list.php eid Parameter Reflected XSS 96740 + http://packetstormsecurity.com/files/122289/ XSS @@ -10610,4 +10622,34 @@ + + + Comment Control 0.3.0 - comment-control.php type Parameter SQL Injection + + 102581 + + SQLI + 0.3.1 + + + + + + WPtouch 1.9.8 - ajax/file_upload.php Crafted Content-Type File Upload Remote Code Execution + + 102582 + + RCE + 1.9.8.1 + + + WPtouch 1.9.8 - include/submit.php Multiple Parameter SQL Injection + + 102583 + + SQLI + 1.9.8.1 + + + diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml index 82b09d89..2b0d63dc 100644 --- a/data/theme_vulns.xml +++ b/data/theme_vulns.xml @@ -2948,4 +2948,14 @@ + + + Love It - XSS / Content Spoofing / Path Disclosure + + http://packetstormsecurity.com/files/122386/ + + MULTI + + +