From 5b1a8b03b75fe04360f0f874f8a487b1edd04e50 Mon Sep 17 00:00:00 2001 From: cervoise Date: Tue, 11 Jun 2013 10:31:10 +0200 Subject: [PATCH] Update plugin_vulns.xml Add vulnerabilites for wp125, wp-symposium, wp-download-manager, digg-digg, ssquiz, funcapatcha, wili-language, wordpress-seo. Correct fixed_in version for a vulnerability in easy-adsense-lite. Correct indent. --- data/plugin_vulns.xml | 86 +++++++++++++++++++++++++++++++++++++++---- 1 file changed, 78 insertions(+), 8 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 0f9c1f33..af6b8e6b 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -80,6 +80,12 @@ http://secunia.com/advisories/50976/ XSS + + WordPress WP125 Plugin CSRF + http://www.securityfocus.com/bid/58934 + CSRF + 1.5.0 + @@ -1831,6 +1837,17 @@ http://ceriksen.com/2013/02/18/wp-symposium-multiple-sql-injection/ SQLI + + WordPress WP Symposium Plugin "u" XSS + http://secunia.com/advisories/52864/ + XSS + 13.04 + + + WordPress WP Symposium Plugin "u" Redirection Weakness + http://secunia.com/advisories/52925/ + REDIRECT + @@ -4428,7 +4445,7 @@ https://secunia.com/advisories/52953/ http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2702 CSRF - 6.20 + 6.10 @@ -4528,24 +4545,77 @@ XSS 1.9 - + - - + WordPress WP-Print Plugin CSRF http://www.securityfocus.com/bid/58900 CSRF 2.52 - + - + WordPress WP-Print Plugin CSRF http://packetstorm.wowhacker.com/1304-exploits/wptrafficanalyzer-xss.txt XSS - - + + + + + WordPress WP-DownloadManager Plugin CSRF + http://www.securityfocus.com/bid/58937 + CSRF + 1.61 + + + + + + Digg Digg CSRF + http://wordpress.org/plugins/digg-digg/changelog/ + CSRF + 5.3.5 + + + + + + Vulneratbility in SS Quiz + http://wordpress.org/plugins/ssquiz/changelog/ + UNKNOWN + 2.0 + + + + + + FunCaptcha CSRF + http://wordpress.org/extend/plugins/funcaptcha/changelog/ + UNKNOWN + 0.33 + + + + + + xili-language XSS + http://wordpress.org/plugins/xili-language/changelog/ + XSS + 2.8.6 + + + + + + Security issue which allowed any user to reset settings + http://wordpress.org/plugins/wordpress-seo/changelog/ + UNKOWN + 1.4.5 + + +