Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2005-10-20   Chipmunk Forum - 'recommend.php?ID' Cross-Site Scripting 25 WEB Alireza Hassani
2005-10-20   Chipmunk Forum - 'quote.php?forumID' Cross-Site Scripting 23 WEB Alireza Hassani
2005-10-20   Chipmunk Forum - 'newtopic.php?forumID' Cross-Site Scripting 23 WEB Alireza Hassani
2005-10-19   PHP-Nuke Search Module - 'modules.php' Directory Traversal 23 WEB sp3x@securityreason.com
2005-10-18   MySource 2.14 - 'mime.php?PEAR_PATH' Remote File Inclusion 21 WEB Secunia Research
2005-10-18   MySource 2.14 - 'mimeDecode.php?PEAR_PATH' Remote File Inclusion 22 WEB Secunia Research
2005-10-18   MySource 2.14 - 'Span.php?PEAR_PATH' Remote File Inclusion 21 WEB Secunia Research
2005-10-18   MySource 2.14 - 'Date.php?PEAR_PATH' Remote File Inclusion 19 WEB Secunia Research
2005-10-18   MySource 2.14 - 'mail.php?PEAR_PATH' Remote File Inclusion 26 WEB Secunia Research
2013-06-21   GLPI 0.83.8 - Multiple Vulnerabilities 17 WEB LiquidWorm
2005-10-18   MySource 2.14 - 'Request.php?PEAR_PATH' Remote File Inclusion 25 WEB Secunia Research
2005-10-18   MySource 2.14 - 'Socket.php?PEAR_PATH' Remote File Inclusion 23 WEB Secunia Research
2005-10-18   MySource 2.14 - 'init_mysource.php?INCLUDE_PATH' Remote File Inclusion 21 WEB Secunia Research
2005-10-18   MySource 2.14 - 'new_upgrade_functions.php' Multiple Remote File Inclusions 25 WEB Secunia Research
2005-10-18   MySource 2.14 - 'edit_table_cell_type_wysiwyg.php?Stylesheet' Cross-Site Scripting 20 WEB Secunia Research
2005-10-18   MySource 2.14 - 'edit_table_props.php?bgcolor' Cross-Site Scripting 22 WEB Secunia Research
2005-10-18   MySource 2.14 - 'edit_table_row_props.php?bgcolor' Cross-Site Scripting 24 WEB Secunia Research
2005-10-18   MySource 2.14 - 'header.php?bgcolor' Cross-Site Scripting 21 WEB Secunia Research
2005-10-18   MySource 2.14 - 'edit_table_cell_props.php?bgcolor' Cross-Site Scripting 21 WEB Secunia Research
2005-10-18   MySource 2.14 - 'insert_table.php?bgcolor' Cross-Site Scripting 21 WEB Secunia Research
2005-10-18   MySource 2.14 - 'upgrade_in_progress_backend.php?target_url' Cross-Site Scripting 24 WEB Secunia Research
2005-10-18   NetFlow Analyzer 4 - Cross-Site Scripting 22 WEB why@nsfocus.com
2005-10-17   Comersus Backoffice Plus - Multiple Cross-Site Scripting Vulnerabilities 25 WEB Lostmon
2005-10-15   PunBB 1.2.x - 'search.php' SQL Injection 23 WEB Devil_box
2005-10-14   Complete PHP - Counter Cross-Site Scripting 22 WEB BiPi_HaCk
2005-10-14   Complete PHP Counter - SQL Injection 26 WEB BiPi_HaCk
2005-10-14   Gallery 2.0 - 'main.php' Directory Traversal 24 WEB Michael Dipper
2005-10-13   Accelerated Mortgage Manager - 'Password' SQL Injection 21 WEB imready4chillin
2005-10-13   YaPiG 0.95b - 'view.php?img_size' Cross-Site Scripting 23 WEB enji@infosys.tuwien.ac.at
2005-10-12   WebGUI 6.x - Arbitrary Command Execution 21 WEB David Maciejak
2005-10-11   Accelerated E Solutions - SQL Injection 23 WEB Andysheh Soltani
2005-10-08   Cyphor 0.19 - 'footer.php?t_login' Cross-Site Scripting 21 WEB retrogod@aliceposta.it
2005-10-08   Cyphor 0.19 - 'newmsg.php?fid' SQL Injection 22 WEB retrogod@aliceposta.it
2005-10-08   Cyphor 0.19 - 'lostpwd.php?nick' SQL Injection 22 WEB rgod
2005-10-07   Aenovo - Multiple Cross-Site Scripting Vulnerabilities 24 WEB farhad koosha
2005-10-07   Aenovo - '/incs/searchdisplay.asp?strSQL' SQL Injection 21 WEB farhad koosha
2005-10-07   Aenovo - '/Password/default.asp?Password' SQL Injection 23 WEB farhad koosha
2005-10-07   Utopia News Pro 1.1.3 - 'footer.php' Multiple Cross-Site Scripting Vulnerabilities 22 WEB rgod
2005-10-07   Utopia News Pro 1.1.3 - 'header.php?sitetitle' Cross-Site Scripting 21 WEB rgod
2005-10-05   TellMe 1.2 - Multiple Cross-Site Scripting Vulnerabilities 28 WEB Donnie Werner
2013-06-19   Monkey CMS - Multiple Vulnerabilities 25 WEB Yashar shahinzadeh_ Mormoroth
2013-06-19   imacs CMS 0.3.0 - Unrestricted Arbitrary File Upload 23 WEB CWH Underground
2005-09-30   Merak Mail Server 8.2.4 r - Arbitrary File Deletion 24 WEB ShineShadow
2005-09-30   EasyGuppy 4.5.4/4.5.5 - 'Printfaq.php' Directory Traversal 22 WEB Josh Zlatin-Amishav
2005-09-30   IceWarp Web Mail 5.5.1 - 'calendar_w.html?createdataCX' Cross-Site Scripting 23 WEB ss_contacts
2005-09-30   IceWarp Web Mail 5.5.1 - 'calendar_m.html?createdataCX' Cross-Site Scripting 21 WEB ss_contacts
2005-09-30   IceWarp Web Mail 5.5.1 - 'calendar_d.html?createdataCX' Cross-Site Scripting 20 WEB ss_contacts
2005-09-30   IceWarp Web Mail 5.5.1 - 'blank.html?id' Cross-Site Scripting 22 WEB ss_contacts
2005-09-29   LucidCMS 2.0 - Login SQL Injection 24 WEB rgod
2005-09-29   SquirrelMail 1.4.2 Address Add Plugin - 'add.php' Cross-Site Scripting 23 WEB anonymous
2005-09-28   CubeCart 3.0.3 - 'cart.php?redir' Cross-Site Scripting 21 WEB Lostmon
2005-09-28   CubeCart 3.0.3 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 24 WEB Lostmon
2005-09-28   TWiki TWikiUsers - INCLUDE Function Arbitrary Command Execution 26 WEB JChristophFuchs
2005-09-27   LucidCMS 2.0 - 'index.php' Cross-Site Scripting 23 WEB X1ngBox
2005-09-26   CMS Made Simple 0.10 - 'index.php' Cross-Site Scripting 24 WEB X1ngBox
2005-08-23   PHPMyFAQ 1.5.1 - Logs Unauthorized Access 22 WEB rgod
2005-08-23   PHPMyFAQ 1.5.1 - Local File Inclusion 25 WEB rgod
2005-09-23   PHPMyFAQ 1.5.1 - Multiple Cross-Site Scripting Vulnerabilities 21 WEB rgod
2005-08-23   PHPMyFAQ 1.5.1 - 'Password.php' SQL Injection 22 WEB retrogod@aliceposta.it
2005-08-21   jPORTAL 2.2.1/2.3.1 - 'download.php' SQL Injection 21 WEB krasza
2005-08-21   Mall23 - 'AddItem.asp' SQL Injection 21 WEB SmOk3
2005-08-21   PerlDiver 2.31 - 'Perldiver.cgi' Cross-Site Scripting 25 WEB Donnie Werner
2005-08-21   Alkalay.Net (Multiple Scripts) - Remote Command Execution 23 WEB sullo@cirt.net
2005-09-20   PHP Advanced Transfer Manager 1.30 - Multiple Cross-Site Scripting Vulnerabilities 23 WEB rgod
2005-09-20   PHP Advanced Transfer Manager 1.30 - Multiple Directory Traversal Vulnerabilities 22 WEB rgod
2005-09-20   Hesk 0.92/0.93 - Session ID Authentication Bypass 26 WEB Rajesh Sethumadhavan
2005-09-19   MX Shop 3.2 - 'index.php' Multiple SQL Injections 21 WEB David Sopas Ferreira
2005-09-19   vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/template.php' Multiple Cross-Site Scripting Vulnerabilities 22 WEB deluxe@security-project.org
2005-09-19   vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/modlog.php?orderby' Cross-Site Scripting 23 WEB deluxe@security-project.org
2005-09-19   vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/language.php?goto' Cross-Site Scripting 22 WEB deluxe@security-project.org
2005-09-19   vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/user.php?email' Cross-Site Scripting 26 WEB deluxe@security-project.org
2005-09-19   vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/index.php' Multiple Cross-Site Scripting Vulnerabilities 22 WEB deluxe@security-project.org
2005-09-19   vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/css.php?group' Cross-Site Scripting 21 WEB deluxe@security-project.org
2005-09-19   NooToplist 1.0 - 'index.php' Multiple SQL Injections 24 WEB David Sopas Ferreira
2005-09-19   vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/usertools.php?ids' SQL Injection 26 WEB deluxe@security-project.org
2005-09-19   vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/usertitle.php?usertitleid' SQL Injection 21 WEB deluxe@security-project.org
2005-09-19   vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/user.php' Multiple SQL Injections 20 WEB deluxe@security-project.org
2005-09-19   vBulletin 1.0.1 lite/2.x/3.0 - 'joinrequests.php?request' SQL Injection 21 WEB deluxe@security-project.org
2005-09-19   EPay Pro 2.0 - 'index.php' Directory Traversal 22 WEB h4cky0u
2005-09-16   Content2Web 1.0.1 - Multiple Input Validation Vulnerabilities 23 WEB Security Tester
2005-09-15   DeluxeBB 1.0 - 'newpost.php' SQL Injection 21 WEB abducter
2005-09-15   DeluxeBB 1.0 - 'pm.php' SQL Injection 24 WEB abducter
2005-09-15   DeluxeBB 1.0 - 'forums.php' SQL Injection 18 WEB abducter
2005-09-15   DeluxeBB 1.0 - 'misc.php' SQL Injection 21 WEB abducter
2005-09-15   DeluxeBB 1.0 - 'topic.php' SQL Injection 23 WEB abducter
2005-09-15   AEwebworks aeDating 3.2/4.0 - 'search_result.php' SQL Injection 21 WEB alexsrb
2005-09-15   Digital Scribe 1.4 - Login SQL Injection 22 WEB rgod
2005-09-14   Noah's Classifieds 1.3 - 'index.php' Cross-Site Scripting 20 WEB trueend5
2005-09-14   TWiki TWikiUsers - Arbitrary Command Execution 23 WEB B4dP4nd4
2005-09-14   Noah's Classifieds 1.2/1.3 - 'index.php' SQL Injection 20 WEB trueend5
2005-09-14   ATutor 1.5.1 - Chat Logs Remote Information Disclosure 28 WEB rgod
2005-09-14   ATutor 1.5.1 - 'password_reminder.php' SQL Injection 19 WEB rgod
2005-09-14   MIVA Merchant 5 - Merchant.MVC Cross-Site Scripting 19 WEB admin@hyperconx.com
2005-09-13   Mail-it Now! Upload2Server 1.5 - Arbitrary File Upload 22 WEB rgod
2005-09-13   Land Down Under 800/801 - 'plug.php?e' SQL Injection 21 WEB GroundZero Security Research
2005-09-13   Land Down Under 800/801 - 'auth.php?m' SQL Injection 24 WEB GroundZero Security Research
2005-09-13   Subscribe Me Pro 2.44 - S.pl Directory Traversal 26 WEB h4cky0u
2005-09-09   MyBulletinBoard (MyBB) 1.0 - 'RateThread.php' SQL Injection 21 WEB stranger-killer
2013-06-17   Simple File Manager 024 - Authentication Bypass 23 WEB Chako
2013-06-17   SPBAS Business Automation Software 2012 - Multiple Vulnerabilities 21 WEB Christy Philip Mathew
2013-06-17   Havalite CMS 1.1.7 - Unrestricted Arbitrary File Upload 19 WEB CWH Underground
2013-06-17   Fly-High CMS 2012-07-08 - Unrestricted Arbitrary File Upload 20 WEB CWH Underground
2013-06-17   WordPress Plugin Ultimate WordPress Auction Plugin 1.0 - Cross-Site Request Forgery 23 WEB expl0i13r
2005-09-08   AMember Pro 2.3.4 - Remote File Inclusion 22 WEB NewAngels Team
2005-09-08   Stylemotion WEB//NEWS 1.4 - 'print.php?id' SQL Injection 24 WEB onkel_fisch
2005-09-08   Stylemotion WEB//NEWS 1.4 - 'news.php' Multiple SQL Injections 21 WEB onkel_fisch
2005-09-08   Stylemotion WEB//NEWS 1.4 - 'startup.php' Cookie SQL Injection 21 WEB onkel_fisch
2005-09-07   phpCommunityCalendar 4.0 - Multiple Cross-Site Scripting Vulnerabilities 24 WEB rgod
2005-09-07   PBLang 4.65 Bulletin Board System - 'SetCookie.php' Directory Traversal 21 WEB rgod
2005-09-07   phpCommunityCalendar 4.0 - Multiple SQL Injections 24 WEB rgod
2005-09-06   MyBulletinBoard (MyBB) 1.0 - Multiple SQL Injections 23 WEB stranger-killer
2005-09-06   MAXdev MD-Pro 1.0.73 - Multiple Cross-Site Scripting Vulnerabilities 19 WEB rgod
2005-09-06   MAXdev MD-Pro 1.0.73 - Arbitrary File Upload 26 WEB rgod
2005-09-06   Unclassified NewsBoard 1.5.3 - 'Description' HTML Injection 21 WEB retrogod@aliceposta.it
2005-09-06   Land Down Under 601/602/700/701/800/801 - 'events.php' HTML Injection 26 WEB conor.e.buckley
2005-08-31   CMS Made Simple 0.10 - 'Lang.php' Remote File Inclusion 22 WEB groszynskif
2005-08-31   FlatNuke 2.5.6 - 'USR' Cross-Site Scripting 22 WEB rgod
2013-06-14   LibrettoCMS 2.2.2 - Arbitrary File Upload 21 WEB CWH Underground
2005-08-31   FlatNuke 2.5.6 - 'ID' Directory Traversal 22 WEB rgod
2005-08-30   phpLDAPadmin 0.9.6/0.9.7 - 'welcome.php' Arbitrary File Inclusion 23 WEB rgod
2005-08-29   PHP-Fusion 4.0/5.0/6.0 - BBCode URL Tag Script Injection 26 WEB slacker4ever_1
2005-08-29   Autolinks 2.1 Pro - 'Al_initialize.php' Remote File Inclusion 24 WEB 4Degrees
2005-08-29   Land Down Under 700/701/800/801 - 'list.php' Multiple SQL Injections 22 WEB matrix_killer
2005-08-29   Land Down Under 700/701/800/801 - 'events.php?c' SQL Injection 21 WEB matrix_killer
2005-08-29   Land Down Under 700/701/800/801 - 'index.php?c' SQL Injection 23 WEB matrix_killer