Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2013-11-01   pdirl PHP Directory Listing 1.0.4 - Cross-Site Scripting 21 WEB Vulnerability-Lab
2006-12-26   phpCMS 1.1.7 - 'class.layout_PHPcms.php' Remote File Inclusion 22 WEB Federico Fazzi
2006-12-26   phpCMS 1.1.7 - 'class.lib_indexer_universal_PHPcms.php' Remote File Inclusion 22 WEB Federico Fazzi
2006-12-26   phpCMS 1.1.7 - 'class.search_PHPcms.php' Remote File Inclusion 23 WEB Federico Fazzi
2006-12-26   phpCMS 1.1.7 - 'class.cache_PHPcms.php' Remote File Inclusion 18 WEB Federico Fazzi
2006-12-26   phpCMS 1.1.7 - 'class.http_indexer_PHPcms.php' Remote File Inclusion 21 WEB Federico Fazzi
2006-12-26   phpCMS 1.1.7 - 'class.edit_PHPcms.php' Remote File Inclusion 16 WEB Federico Fazzi
2006-12-26   phpCMS 1.1.7 - 'class.session_PHPcms.php' Remote File Inclusion 22 WEB Federico Fazzi
2006-12-26   phpCMS 1.1.7 - 'class.parser_PHPcms.php' Remote File Inclusion 19 WEB Federico Fazzi
2006-12-26   phpCMS 1.1.7 - 'parser.php' Remote File Inclusion 20 WEB Federico Fazzi
2006-12-26   phpCMS 1.1.7 - 'counter.php' Remote File Inclusion 22 WEB Federico Fazzi
2006-12-26   Luckybot 3 - 'DIR' Multiple Remote File Inclusions 21 WEB Red_Casper
2006-12-25   vBulletin 3.5.x/3.6.x - SWF Script Injection 18 WEB Ashraf Morad
2006-12-24   TimberWolf 1.2.2 - 'shownews.php' Cross-Site Scripting 17 WEB CorryL
2006-12-24   Chatwm 1.0 - 'SelGruFra.asp' SQL Injection 19 WEB ShaFuq31
2006-12-23   Future Internet - 'index.cfm?categoryId' Cross-Site Scripting 20 WEB Linux_Drox
2006-12-23   Future Internet - 'index.cfm' Multiple SQL Injections 24 WEB Linux_Drox
2006-12-22   Efkan Forum 1.0 - 'Grup' SQL Injection 19 WEB ShaFuq31
2013-11-01   WordPress Theme Think Responsive 1.0 - Arbitrary File Upload 19 WEB Byakuya Kouta
2013-11-01   ImpressPages CMS 3.6 - 'manage()' Remote Code Execution 19 WEB LiquidWorm
2013-11-01   WordPress Theme Switchblade 1.3 - Arbitrary File Upload 18 WEB Byakuya Kouta
2013-11-01   ImpressPages CMS 3.6 - Arbitrary File Deletion 17 WEB LiquidWorm
2013-10-31   Opsview pre 4.4.1 - Blind SQL Injection 23 WEB J. Oquendo
2013-10-31   ImpressPages CMS 3.6 - Multiple Cross-Site Scripting / SQL Injection Vulnerabilities 21 WEB LiquidWorm
2006-12-22   Xt-News 0.1 - 'show_news.php?id_news' SQL Injection 26 WEB Mr_KaLiMaN
2006-12-22   Xt-News 0.1 - 'show_news.php?id_news' Cross-Site Scripting 25 WEB Mr_KaLiMaN
2013-10-30   Unicorn Router WB-3300NR - Cross-Site Request Forgery (Factory Reset/DNS Change) 21 WEB absane
2006-12-22   Xt-News 0.1 - 'add_comment.php?id_news' Cross-Site Scripting 23 WEB Mr_KaLiMaN
2006-12-22   Oracle Portal 9i/10g - Container_Tabs.jsp Cross-Site Scripting 19 WEB putosoft softputo
2006-12-22   A-Blog 1.0 - Cross-Site Scripting 19 WEB Fukumori
2006-12-20   Calacode @Mail Webmail 4.51 - Filtering Engine HTML Injection 22 WEB Philippe C. Caturegli
2006-11-08   PHPBuilder 0.0.2 - 'HTM2PHP.php' Directory Traversal 20 WEB the master
2006-12-20   Oracle Portal 9.0.2 - Calendar.jsp Multiple HTTP Response Splitting Vulnerabilities 26 WEB putosoft softputo
2006-12-20   Typo3 3.7/3.8/4.0 - 'Class.TX_RTEHTMLArea_PI1.php' Multiple Remote Command Execution Vulnerabilities 21 WEB D. Fabian
2006-12-19   Mini Web Shop 2.1.c - 'view.php?Viewcategory.php' Cross-Site Scripting 20 WEB Linux_Drox
2006-12-19   osTicket 1.2/1.3 Support Cards - 'view.php' Cross-Site Scripting 18 WEB Hacker CooL
2006-12-18   Knusperleicht Shoutbox 2.6 - 'Shout.php' HTML Injection 21 WEB IMHOT3B
2006-12-16   Contra Haber Sistemi 1.0 - 'Haber.asp' SQL Injection 20 WEB ShaFuck31
2013-10-29   XAMPP for Windows 1.8.2 - Blind SQL Injection 24 WEB Sebastián Magof
2006-12-16   eXtreme-fusion 4.02 - 'Fusion_Forum_View.php' Local File Inclusion 18 WEB Kacper
2006-12-16   Omniture SiteCatalyst - Multiple Cross-Site Scripting Vulnerabilities 22 WEB Hackers Center Security
2006-12-14   Moodle 1.5/1.6 - '/mod/forum/discuss.php?navtail' Cross-Site Scripting 19 WEB Jose Miguel Yanez Venegas
2006-12-14   GenesisTrader 1.0 - 'form.php' Multiple Cross-Site Scripting Vulnerabilities 21 WEB Mr_KaLiMaN
2006-12-14   GenesisTrader 1.0 - 'form.php' Arbitrary File Source Disclosure 20 WEB Mr_KaLiMaN
2013-10-29   GTX CMS 2013 Optima - SQL Injection 24 WEB Vulnerability-Lab
2013-10-29   Olat CMS 7.8.0.1 - Persistent Cross-Site Scripting 24 WEB Vulnerability-Lab
2006-12-13   Work System eCommerce 3.0.3/3.0.4 - 'forum.php' Remote File Inclusion 22 WEB the_Edit0r
2006-12-11   Lotfian Request For Travel 1.0 - 'ProductDetails.asp' SQL Injection 21 WEB ajann
2006-12-11   Netwin SurgeFTP 2.3a1 - 'SurgeFTPMGR.cgi' Multiple Input Validation Vulnerabilities 23 WEB Umesh Wanve
2013-10-29   Horde Groupware Web Mail Edition 5.1.2 - Cross-Site Request Forgery (1) 19 WEB Marcela Benetrix
2006-12-11   CMS Made Simple 1.0.2 - 'SearchInput' Cross-Site Scripting 18 WEB Nicokiller
2006-12-09   AppIntellect SpotLight CRM - 'login.asp' SQL Injection 22 WEB ajann
2006-12-09   MXBB Profile Control Panel 0.91c - Module Remote File Inclusion 23 WEB bd0rk
2006-12-09   ProNews 1.5 - 'lire-avis.php?aa' Cross-Site Scripting 21 WEB Mr_KaLiMaN
2006-12-09   ProNews 1.5 - 'lire-avis.php?aa' SQL Injection 20 WEB Mr_KaLiMaN
2006-12-09   ProNews 1.5 - '/admin/change.php' Multiple Cross-Site Scripting Vulnerabilities 20 WEB Mr_KaLiMaN
2013-10-29   Stem Innovation - 'IZON' Hard-Coded Credentials 18 WEB Mark Stanislav
2013-10-29   ILIAS eLearning CMS 4.3.4 < 4.4 - Persistent Cross-Site Scripting 19 WEB Vulnerability-Lab
2013-10-28   Onpub CMS 1.4/1.5 - Multiple SQL Injections 27 WEB Vulnerability-Lab
2013-10-28   Pirelli Discus DRG A125g - Password Disclosure 19 WEB Sebastián Magof
2013-10-28   PHP RSS Reader 2010 - SQL Injection 19 WEB mishal abdullah
2006-12-09   KDPics 1.11/1.16 - 'galeries.inc.php3?categories' Cross-Site Scripting 20 WEB Mr_KaLiMaN
2006-12-09   KDPics 1.11/1.16 - 'index.php3?categories' Cross-Site Scripting 22 WEB Mr_KaLiMaN
2006-12-09   AnnonceScriptHP 2.0 - 'voirannonce.php?no' SQL Injection 20 WEB Mr_KaLiMaN
2006-12-09   AnnonceScriptHP 2.0 - 'email.php?id' SQL Injection 20 WEB Mr_KaLiMaN
2006-12-09   AnnonceScriptHP 2.0 - '/admin/admin_config/Aide.php?email' Cross-Site Scripting 18 WEB Mr_KaLiMaN
2006-12-09   AnnonceScriptHP 2.0 - 'membre.dwt.php?email' Cross-Site Scripting 18 WEB Mr_KaLiMaN
2006-12-09   AnnonceScriptHP 2.0 - '/Templates/commun.dwt.php?email' Cross-Site Scripting 20 WEB Mr_KaLiMaN
2006-12-09   AnnonceScriptHP 2.0 - '/Templates/admin.dwt.php?email' Cross-Site Scripting 20 WEB Mr_KaLiMaN
2006-12-09   AnnonceScriptHP 2.0 - 'erreurinscription.php?email' Cross-Site Scripting 23 WEB Mr_KaLiMaN
2006-12-09   AnnonceScriptHP 2.0 - '/admin/admin_membre/fiche_membre.php?idmembre' SQL Injection 19 WEB Mr_KaLiMaN
2006-12-09   Messageriescripthp 2.0 - '/Contact/contact.php' Multiple Cross-Site Scripting Vulnerabilities 22 WEB Mr_KaLiMaN
2006-12-09   Messageriescripthp 2.0 - 'existeemail.php?email' Cross-Site Scripting 20 WEB Mr_KaLiMaN
2006-12-09   Messageriescripthp 2.0 - 'existepseudo.php?pseudo' Cross-Site Scripting 24 WEB Mr_KaLiMaN
2006-12-09   Messageriescripthp 2.0 - 'lire-avis.php?aa' SQL Injection 23 WEB Mr_KaLiMaN
2006-12-09   MaviPortal - 'Arama.asp' Cross-Site Scripting 21 WEB St@rExT
2006-12-08   Cilem Haber Free Edition - 'hata.asp?hata' Cross-Site Scripting 23 WEB ShaFuck31
2006-12-08   cPanel Web Hosting Manager 3.1 - Multiple Cross-Site Scripting Vulnerabilities 23 WEB Aria-Security Team
2006-12-08   cPanel 11 BoxTrapper - Manage.HTML Cross-Site Scripting 24 WEB Aria-Security Team
2006-11-18   Link CMS - 'prikazInformacije.php?IDStranicaPodaci' SQL Injection 24 WEB Ivan Markovic
2006-11-18   Link CMS - 'navigacija.php?IDMeniGlavni' SQL Injection 20 WEB Ivan Markovic
2006-12-06   Dol Storye - 'Dettaglio.asp' Multiple SQL Injections 21 WEB WarGame
2006-12-04   Vt-Forum Lite 1.3 - 'vf_newtopic.asp' IFRAME Element Cross-Site Scripting 23 WEB St@rExT
2006-12-04   Vt-Forum Lite 1.3 - 'vf_info.asp?StrMes' Cross-Site Scripting 21 WEB St@rExT
2006-12-04   ac4p Mobile - 'polls.php' Multiple Cross-Site Scripting Vulnerabilities (2) 21 WEB SwEET-DeViL
2006-12-04   ac4p Mobile - 'up.php?Taaa' Cross-Site Scripting 20 WEB SwEET-DeViL
2006-12-04   UApplication Uguestbook 1.0 - 'index.asp' SQL Injection 24 WEB Aria-Security Team
2006-12-04   Inside Systems Mail 2.0 - 'error.php' Cross-Site Scripting 22 WEB Vicente Aguilera Diaz
2006-12-04   Cerberus Helpdesk 2.x - 'Spellwin.php' Cross-Site Scripting 21 WEB En Douli
2006-12-04   BlueSocket BSC 2100 5.0/5.1 - Admin.pl Cross-Site Scripting 20 WEB Jesus Olmos Gonzalez
2006-12-04   Metyus Okul Yonetim 1.0 - 'Sistemi Uye_giris_islem.asp' SQL Injection 33 WEB ShaFuck31
2006-12-02   DUdownload 1.0/1.1 - 'detail.asp' Multiple SQL Injections 22 WEB Aria-Security Team
2006-12-02   PHPNews 1.3 - 'Link_Temp.php' Cross-Site Scripting 23 WEB Detefix
2006-12-02   CuteNews 1.3.6 - 'result' Cross-Site Scripting 24 WEB Detefix
2006-12-01   Aspee Ziyaretci Defteri - 'giris.asp' Multiple Field SQL Injections 26 WEB ShaFuq31
2006-12-27   FreeQBoard 1.0/1.1 - 'QB_Path' Multiple Remote File Inclusions 24 WEB Shell
2013-10-26   WordPress Theme Curvo - Cross-Site Request Forgery / Arbitrary File Upload 21 WEB Byakuya Kouta
2006-12-01   DZCP (deV!L_z Clanportal) 1.3.6 - 'Show' SQL Injection 19 WEB Tim Weber
2006-12-01   Invision Gallery 2.0.7 - 'index.php?IMG' SQL Injection 22 WEB infection
2006-11-30   Woltlab Burning Board 2.3.x - 'register.php' Cross-Site Scripting 21 WEB blueshisha
2006-11-30   Seditio1.10 / Land Down 8.0 Under - 'polls.php' SQL Injection 20 WEB ajann
2006-11-16   b2evolution 1.8.2/1.9 - '_referer_spam.page.php' Multiple Cross-Site Scripting Vulnerabilities 23 WEB lotto fischer
2006-11-16   b2evolution 1.8.2/1.9 - '_410_stats_gone.page.php?app_name' Cross-Site Scripting 26 WEB lotto fischer
2006-11-16   b2evolution 1.8.2/1.9 - '_404_not_found.page.php' Multiple Cross-Site Scripting Vulnerabilities 23 WEB lotto fischer
2006-11-27   Evolve Shopping Cart - 'products.asp' SQL Injection 25 WEB Aria-Security Team
2006-11-27   uPhotoGallery 1.1 - 'thumbnails.asp?ci' SQL Injection 18 WEB Aria-Security Team
2006-11-27   uPhotoGallery 1.1 - 'Slideshow.asp?ci' SQL Injection 21 WEB Aria-Security Team
2006-11-27   Click Gallery - Multiple Input Validation Vulnerabilities 23 WEB Aria-Security Team
2006-11-27   Clickblog - 'Displaycalendar.asp' SQL Injection 22 WEB Aria-Security Team
2006-11-27   ClickContact - 'default.asp' Multiple SQL Injections 31 WEB Aria-Security Team
2006-11-25   fipsShop - Multiple SQL Injections 25 WEB Aria-Security Team
2006-11-25   cPanel WebHost Manager 3.1 - 'park?ndomain' Cross-Site Scripting 19 WEB Aria-Security Team
2006-11-25   cPanel WebHost Manager 3.1 - 'dofeaturemanager?feature' Cross-Site Scripting 22 WEB Aria-Security Team
2006-11-25   cPanel WebHost Manager 3.1 - 'editzone?domain' Cross-Site Scripting 24 WEB Aria-Security Team
2006-11-25   cPanel WebHost Manager 3.1 - 'domts2?domain' Cross-Site Scripting 19 WEB Aria-Security Team
2006-11-25   cPanel WebHost Manager 3.1 - 'editpkg?pkg' Cross-Site Scripting 19 WEB Aria-Security Team
2006-11-25   cPanel WebHost Manager 3.1 - 'addon_configsupport.cgi?supporturl' Cross-Site Scripting 22 WEB Aria-Security Team
2006-11-25   cPanel WebHost Manager 3.1 - 'dochangeemail?email' Cross-Site Scripting 21 WEB Aria-Security Team
2006-11-25   cPanel 11 Beta - Multiple Cross-Site Scripting Vulnerabilities 20 WEB Aria-Security Team
2006-11-25   SIAP CMS - 'login.asp' SQL Injection 23 WEB nagazakig74
2006-11-24   Fixit iDms Pro Image Gallery - 'showfile.asp?fid' SQL Injection 26 WEB Aria-Security Team
2006-11-24   Fixit iDms Pro Image Gallery - 'filelist.asp' Multiple SQL Injections 26 WEB Aria-Security Team
2006-11-24   MMGallery 1.55 - 'Thumbs.php' Cross-Site Scripting 19 WEB Al7ejaz Hacker
2006-11-24   ASP ListPics 5.0 - 'Listpics.asp' SQL Injection 18 WEB Aria-Security Team
2006-11-24   Simple PHP Gallery 1.1 - 'System SP_Index.php' Cross-Site Scripting 19 WEB Al7ejaz Hacker