Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2006-03-13   Vegas Forum 1.0 - 'Forumlib.php' SQL Injection 11 WEB Aliaksandr Hartsuyeu
2006-03-10   WMNews - 'wmcomments.php?ArtID' Cross-Site Scripting 16 WEB R00T3RR0R
2006-03-10   WMNews - 'footer.php?ctrrowcol' Cross-Site Scripting 12 WEB R00T3RR0R
2006-03-10   WMNews - 'wmview.php?ArtCat' Cross-Site Scripting 11 WEB R00T3RR0R
2006-03-11   vCard 2.8/2.9 - 'create.php' Multiple Cross-Site Scripting Vulnerabilities 14 WEB Linux_Drox
2006-03-10   Core News 2.0.1 - 'index.php' Remote Code Execution 12 WEB botan
2006-03-10   QwikiWiki 1.4/1.5 - 'recentchanges.php?help' Cross-Site Scripting 11 WEB Kiki
2006-03-10   QwikiWiki 1.4/1.5 - 'pageindex.php?help' Cross-Site Scripting 11 WEB Kiki
2006-03-10   QwikiWiki 1.4/1.5 - 'login.php' Multiple Cross-Site Scripting Vulnerabilities 13 WEB Kiki
2006-03-10   QwikiWiki 1.4/1.5 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 13 WEB Kiki
2006-03-09   txtForum 1.0.3/1.0.4 - Remote PHP Script Code Injection 12 WEB enji@infosys.tuwien.ac.at
2013-08-07   McAfee SuperScan 4.0 - Cross-Site Scripting 14 WEB Trustwave's SpiderLabs
2013-08-07   Joomla! Component com_sectionex 2.5.96 - SQL Injection 15 WEB Matias Fontanini
2013-08-07   WordPress Plugin Usernoise 3.7.8 - Persistent Cross-Site Scripting 12 WEB RogueCoder
2013-08-07   Hikvision IP Cameras 4.1.0 b130111 - Multiple Vulnerabilities 11 WEB Core Security
2013-08-07   WordPress Plugin Booking Calendar 4.1.4 - Cross-Site Request Forgery 13 WEB Dylan Irzi
2013-08-07   Pluck CMS 4.7 - HTML Code Injection 11 WEB Yashar shahinzadeh
2006-03-09   txtForum 1.0.3/1.0.4 - Multiple Cross-Site Scripting Vulnerabilities 14 WEB Nenad Jovanovic
2006-03-09   DCP-Portal 3.7/4.x/5.x/6.x - 'mycontents.php' Multiple Cross-Site Scripting Vulnerabilities 13 WEB Nenad Jovanovic
2006-03-09   DCP-Portal 3.7/4.x/5.x/6.x - 'lostpassword.php' Multiple Cross-Site Scripting Vulnerabilities 10 WEB Nenad Jovanovic
2006-03-09   DCP-Portal 3.7/4.x/5.x/6.x - 'inbox.php' Multiple Cross-Site Scripting Vulnerabilities 10 WEB Nenad Jovanovic
2006-03-09   DCP-Portal 3.7/4.x/5.x/6.x - 'forums.php' Multiple Cross-Site Scripting Vulnerabilities 11 WEB Nenad Jovanovic
2006-03-09   DCP-Portal 3.7/4.x/5.x/6.x - 'calendar.php' Multiple Cross-Site Scripting Vulnerabilities 11 WEB Nenad Jovanovic
2006-03-09   DCP-Portal 3.7/4.x/5.x/6.x - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 9 WEB Nenad Jovanovic
2006-03-09   MyBloggie 2.1.2/2.1.3 - 'del.php' Cross-Site Scripting 14 WEB enji@infosys.tuwien.ac.at
2006-03-09   MyBloggie 2.1.2/2.1.3 - 'delcat.php' Cross-Site Scripting 13 WEB enji@infosys.tuwien.ac.at
2006-03-09   MyBloggie 2.1.2/2.1.3 - 'trackback_url' Cross-Site Scripting 12 WEB enji@infosys.tuwien.ac.at
2006-03-09   MyBloggie 2.1.2/2.1.3 - 'editcat.php' Cross-Site Scripting 10 WEB enji@infosys.tuwien.ac.at
2006-03-09   MyBloggie 2.1.2/2.1.3 - 'adduser.php' Cross-Site Scripting 15 WEB enji@infosys.tuwien.ac.at
2006-03-09   MyBloggie 2.1.2/2.1.3 - 'edituser.php' Cross-Site Scripting 11 WEB enji@infosys.tuwien.ac.at
2006-03-09   MyBloggie 2.1.2/2.1.3 - 'addcat.php' Cross-Site Scripting 13 WEB enji@infosys.tuwien.ac.at
2006-03-09   MyBloggie 2.1.2/2.1.3 - 'deluser.php' Cross-Site Scripting 11 WEB enji@infosys.tuwien.ac.at
2006-03-09   MyBloggie 2.1.2/2.1.3 - 'delcomment.php' Cross-Site Scripting 10 WEB enji@infosys.tuwien.ac.at
2006-03-09   MyBloggie 2.1.2/2.1.3 - 'upload.php' Cross-Site Scripting 10 WEB enji@infosys.tuwien.ac.at
2006-03-09   ADP Forum 2.0.x - 'Subject' HTML Injection 14 WEB liz0
2013-08-07   FTP OnConnect 1.4.11 iOS - Multiple Vulnerabilities 11 WEB Vulnerability-Lab
2006-03-09   sBlog 0.7.2 - 'comments_do.php' Multiple POST Cross-Site Scripting Vulnerabilities 14 WEB Kiki
2006-03-09   sBlog 0.7.2 - 'search.php?keyword' POST Method Cross-Site Scripting 14 WEB Kiki
2006-03-08   TextFileBB 1.0 - Multiple Cross-Site Scripting Vulnerabilities 14 WEB Retard
2006-03-06   HitHost 1.0 - 'viewuser.php?hits' Cross-Site Scripting 12 WEB Retard
2006-03-06   HitHost 1.0 - 'deleteuser.php?user' Cross-Site Scripting 10 WEB Retard
2006-03-07   LoudBlog 0.41 - 'backend_settings.php' Traversal Arbitrary File Access 12 WEB tzitaroth
2006-03-07   LoudBlog 0.41 - 'index.php?template' Traversal Arbitrary File Access 12 WEB tzitaroth
2006-03-07   LoudBlog 0.41 - 'podcast.php' SQL Injection 9 WEB tzitaroth
2006-03-07   Link Bank - 'Iframe.php' Cross-Site Scripting 10 WEB Retard
2006-03-06   Game-Panel 2.6 - 'login.php' Cross-Site Scripting 11 WEB Retard
2006-03-06   PHORUM 3.x/5.x - 'Common.php' Remote File Inclusion 12 WEB ERNE
2006-03-06   Bitweaver 1.1/1.2 - 'Title' HTML Injection 12 WEB Kiki
2006-03-06   Invision Power Board 2.1.5 - showtopic SQL Injection 12 WEB Mr.SNAKE
2006-03-06   RunCMS 1.x - 'Bigshow.php' Cross-Site Scripting 11 WEB Roozbeh Afrasiabi
2006-03-06   DVGuestbook 1.0/1.2.2 - 'dv_gbook.php?f' Cross-Site Scripting 18 WEB Liz0ziM
2006-03-06   DVGuestbook 1.0/1.2.2 - 'index.php?page' Cross-Site Scripting 14 WEB Liz0ziM
2006-03-04   Simplog 1.0.2 - Information Disclosure 11 WEB Retard
2006-03-04   CutePHP CuteNews 1.4.1 - 'index.php' Cross-Site Scripting 10 WEB Roozbeh Afrasiabi
2006-03-04   Woltlab Burning Board 2.3.4 - 'misc.php' Cross-Site Scripting 12 WEB r57shell
2006-03-04   Easy Forum 2.5 - New User Image File HTML Injection 13 WEB Aliaksandr Hartsuyeu
2006-03-04   VBZooM Forum 1.11 - 'contact.php?UserID' Cross-Site Scripting 13 WEB Mr.SNAKE
2006-03-04   VBZooM Forum 1.11 - 'comment.php?UserID' Cross-Site Scripting 11 WEB Mr.SNAKE
2006-03-04   VBZoom Forum 1.11 - 'show.php' MainID SQL Injection 12 WEB Mr.SNAKE
2006-03-02   LogIT 1.3/1.4 - Remote File Inclusion 9 WEB botan
2006-03-02   NZ eCommerce System - 'index.php' Multiple SQL Injections 10 WEB r0t
2006-03-02   vBulletin 3.0/3.5 - 'profile.php?Email' HTML Injection 13 WEB imei
2006-03-02   PluggedOut Nexus 0.1 - 'forgotten_password.php' SQL Injection 12 WEB Hamid Ebadi
2006-03-02   DCI-Designs Dawaween 1.03 - 'Poems.php' SQL Injection 12 WEB sherba
2006-03-01   SMBlog 1.2 - Arbitrary PHP Command Execution 11 WEB botan
2006-02-28   PEHEPE Membership Management System 3.0 - Remote PHP Script Code Injection 11 WEB Yunus Emre Yilmaz
2006-02-26   PEHEPE Membership Management System 3.0 - 'Sol_menu.php' Cross-Site Scripting 11 WEB Yunus Emre Yilmaz
2006-02-28   Mozilla Thunderbird 1.5 - Multiple Remote Information Disclosure Vulnerabilities 11 WEB Crashfr
2006-02-28   EJ3 TOPo 2.2.178 - 'Inc_header.php' Cross-Site Scripting 11 WEB Yunus Emre Yilmaz
2006-02-28   QwikiWiki 1.4 - 'index.php' Cross-Site Scripting 14 WEB Dr^Death
2006-02-27   n8cms 1.1/1.2 - 'mailto.php?userid' Cross-Site Scripting 10 WEB Liz0ziM
2006-02-27   n8cms 1.1/1.2 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 11 WEB Liz0ziM
2006-02-27   n8cms 1.1/1.2 - 'index.php' Multiple SQL Injections 12 WEB Liz0ziM
2006-02-25   D3Jeeb Pro 3 - 'catogary.php?catid' SQL Injection 10 WEB SAUDI
2006-02-25   D3Jeeb Pro 3 - 'fastlinks.php?catid' SQL Injection 11 WEB SAUDI
2006-02-27   Archangel Weblog 0.90.2 - Authentication Bypass 14 WEB KingOfSka
2006-02-27   Woltlab Burning Board 1.1.1/2.x - 'galerie_onfly.php' Cross-Site Scripting 12 WEB botan
2006-02-27   Woltlab Burning Board 1.1.1/2.x - 'galerie_index.php?Username' Cross-Site Scripting 11 WEB botan
2006-02-27   Fantastic News 2.1.1 - SQL Injection 10 WEB SAUDI
2006-02-25   Thomson SpeedTouch 500 Series - LocalNetwork Page 'name' Cross-Site Scripting 10 WEB Preben Nylokken
2006-02-25   PHP-Nuke 7.8 - 'Mainfile.php' SQL Injection 14 WEB waraxe
2013-08-03   RiteCMS 1.0.0 - Multiple Vulnerabilities 11 WEB Yashar shahinzadeh
2006-02-25   DCI-Taskeen 1.03 - 'cat.php' Multiple SQL Injections 13 WEB Linux_Drox
2006-02-25   DCI-Taskeen 1.03 - 'basket.php' Multiple SQL Injections 12 WEB Linux_Drox
2006-02-25   FreeHostShop Website Generator 3.3 - Arbitrary File Upload 12 WEB NSA Group
2006-02-25   SPiD 1.3.1 - 'Scan_Lang_Insert.php' Local File Inclusion 10 WEB NSA Group
2006-02-25   Battleaxe Software BttlxeForum 2.0 - 'Failure.asp' Cross-Site Scripting 10 WEB rUnViRuS
2006-02-22   myPHPNuke 1.8.8 - 'download.php' Cross-Site Scripting 11 WEB Mustafa Can Bjorn
2006-02-22   myPHPNuke 1.8.8 - 'reviews.php' Cross-Site Scripting 10 WEB Mustafa Can Bjorn
2006-02-23   JGS-Gallery 4.0 - 'Board jgs_galerie_scroll.php?userid' Cross-Site Scripting 11 WEB nuker
2006-02-23   JGS-Gallery 4.0 - 'jgs_galerie_slideshow.php' Multiple Cross-Site Scripting Vulnerabilities 12 WEB nuker
2006-02-23   PHPX 3.5.9 - XCode Tag HTML Injection 13 WEB Thomas Pollet
2006-02-23   CubeCart 3.0.x - Arbitrary File Upload 10 WEB NSA Group
2006-02-23   Oi! Email Marketing System 3.0 - 'index.php' SQL Injection 12 WEB h4cky0u
2006-02-23   NOCC 1.0 - 'html_bottom_table.php' Multiple Cross-Site Scripting Vulnerabilities 12 WEB rgod
2006-02-23   NOCC 1.0 - 'no_mail.php?html_no_mail' Cross-Site Scripting 11 WEB rgod
2006-02-23   NOCC 1.0 - 'filter_prefs.php?html_filter_select' Cross-Site Scripting 12 WEB rgod
2006-02-23   NOCC 1.0 - 'error.php?html_error_occurred' Cross-Site Scripting 11 WEB rgod
2006-02-23   Web Calendar Pro - 'Dropbase.php' SQL Injection 13 WEB ReZEN
2013-08-02   Oracle Hyperion 11 - Directory Traversal 11 WEB Richard Warren
2013-08-02   WordPress Plugin Better WP Security 3.4.8/3.4.9/3.4.10/3.5.2/3.5.3 - Persistent Cross-Site Scripting 12 WEB Richard Warren
2013-08-02   TP-Link TL-SC3171 IP Cameras - Multiple Vulnerabilities 11 WEB Core Security
2013-08-02   Western Digital My Net Wireless Routers - Password Disclosure 13 WEB Kyle Lovett
2013-08-02   Cotonti 0.9.13 - SQL Injection 12 WEB High-Tech Bridge SA
2013-08-02   MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities 12 WEB Trustwave's SpiderLabs
2013-08-02   INSTEON Hub 2242-222 - Lack of Web and API Authentication 11 WEB Trustwave's SpiderLabs
2013-08-02   D-Link DIR-645 1.03B08 - Multiple Vulnerabilities 14 WEB Roberto Paleari
2013-08-02   Telmanik CMS Press 1.01b - 'pages.php?page_name' SQL Injection 13 WEB Anarchy Angel
2013-08-02   vTiger CRM 5.4.0 SOAP - Multiple Vulnerabilities 12 WEB EgiX
2013-08-02   BigACE 2.7.8 - Cross-Site Request Forgery (Add Admin) 10 WEB Yashar shahinzadeh
2013-08-02   FunGamez - Arbitrary File Upload 11 WEB cr4wl3r
2013-08-02   Ginkgo CMS - 'index.php?rang' SQL Injection 13 WEB Raw-x
2013-08-02   SocialEngine Timeline Plugin 4.2.5p9 - Arbitrary File Upload 11 WEB spyk2r
2006-02-22   Dragonfly CMS 9.0.6.1 Coppermine Module - 'album' Cross-Site Scripting 13 WEB Lostmon
2006-02-22   Dragonfly CMS 9.0.6.1 Downloads Module - 'c' Cross-Site Scripting 11 WEB Lostmon
2006-02-22   Dragonfly CMS 9.0.6.1 Surveys Module - Multiple Cross-Site Scripting Vulnerabilities 10 WEB Lostmon
2006-02-22   Dragonfly CMS 9.0.6.1 Web_Links Module - Multiple Cross-Site Scripting Vulnerabilities 12 WEB Lostmon
2006-02-22   Dragonfly CMS 9.0.6.1 Stories_Archive Module - Multiple Cross-Site Scripting Vulnerabilities 11 WEB Lostmon
2006-02-22   Dragonfly CMS 9.0.6 1 News Module - Multiple Cross-Site Scripting Vulnerabilities 11 WEB Lostmon
2006-02-22   Dragonfly CMS 9.0.6 1 Your_Account Module - Multiple Cross-Site Scripting Vulnerabilities 12 WEB Lostmon
2006-02-22   Noah's Classifieds 1.0/1.3 - 'index.php' Remote File Inclusion 10 WEB trueend5
2006-02-22   Noah's Classifieds 1.0/1.3 - Local File Inclusion 9 WEB trueend5
2006-02-22   Noah's Classifieds 1.0/1.3 - Search Page SQL Injection 11 WEB trueend5
2006-02-22   Noah's Classifieds 1.0/1.3 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 12 WEB trueend5
2006-02-22   RunCMS 1.x - 'Ratefile.php' Cross-Site Scripting 12 WEB Roozbeh Afrasiabi