Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2005-06-07   FlatNuke 2.5.x - 'index.php?where' Full Path Disclosure 10 WEB SecWatch
2005-06-06   Early Impact ProductCart 2.6/2.7 - 'OptionFieldsEdit.asp?idccr' SQL Injection 13 WEB Dedi Dwianto
2005-06-06   Early Impact ProductCart 2.6/2.7 - 'modCustomCardPaymentOpt.asp?idc' SQL Injection 12 WEB Dedi Dwianto
2005-06-06   Early Impact ProductCart 2.6/2.7 - 'editCategories.asp?lid' SQL Injection 13 WEB Dedi Dwianto
2005-06-06   Early Impact ProductCart 2.6/2.7 - 'viewPrd.asp?idcategory' SQL Injection 10 WEB Dedi Dwianto
2005-06-06   YaPiG 0.9x - 'upload.php' Directory Traversal 15 WEB anonymous
2005-06-06   YaPiG 0.9x - 'view.php' Cross-Site Scripting 13 WEB anonymous
2005-06-06   YaPiG 0.9x - Local/Remote File Inclusion 12 WEB anonymous
2005-06-06   WWWeb Concepts Events System 1.0 - 'login.asp' SQL Injection 11 WEB Romty
2005-06-03   Popper Webmail 1.41 - 'ChildWindow.Inc.php' Remote File Inclusion 15 WEB Leon Juranic
2005-06-03   LiteWEB Web Server 2.5 - Authentication Bypass 11 WEB Ziv Kamir
2005-06-03   MWChat 6.7 - 'Start_Lobby.php' Remote File Inclusion 13 WEB Status-x
2005-06-02   Liberum Help Desk 0.97.3 - Multiple SQL Injections 10 WEB Dedi Dwianto
2005-06-01   Livingcolor Livingmailing 1.3 - 'login.asp' SQL Injection 11 WEB Dj romty
2005-06-01   NEXTWEB (i)Site - 'login.asp' SQL Injection 13 WEB Jim Pangalos
2005-06-01   JiRo's Upload System 1.0 - 'login.asp' SQL Injection 11 WEB Romty
2005-05-31   MyBulletinBoard (MyBB) RC4 - Multiple Cross-Site Scripting / SQL Injections 11 WEB Alberto Trivero
2005-05-31   Calendarix 0.8.20071118 - Multiple SQL Injections / Cross-Site Scripting Vulnerabilities 11 WEB DarkBicho
2005-05-31   PowerDownload 3.0.2/3.0.3 - IncDir Remote File Inclusion 10 WEB SoulBlack Group
2005-05-30   Qualiteam X-Cart 4.0.8 - 'giftcert.php' Multiple SQL Injections 11 WEB CENSORED Search Vulnerabilities
2005-05-30   Qualiteam X-Cart 4.0.8 - 'search.php?mode' SQL Injection 12 WEB CENSORED Search Vulnerabilities
2005-05-30   Qualiteam X-Cart 4.0.8 - 'register.php?mode' SQL Injection 10 WEB CENSORED Search Vulnerabilities
2005-05-30   Qualiteam X-Cart 4.0.8 - 'orders.php?mode' SQL Injection 10 WEB CENSORED Search Vulnerabilities
2005-05-30   Qualiteam X-Cart 4.0.8 - 'help.php?section' SQL Injection 11 WEB CENSORED Search Vulnerabilities
2005-05-30   Qualiteam X-Cart 4.0.8 - 'error_message.php?id' SQL Injection 10 WEB CENSORED Search Vulnerabilities
2005-05-30   Qualiteam X-Cart 4.0.8 - 'product.php' Multiple SQL Injections 10 WEB CENSORED Search Vulnerabilities
2005-05-30   Qualiteam X-Cart 4.0.8 - 'home.php' Multiple SQL Injections 11 WEB CENSORED Search Vulnerabilities
2005-05-30   Qualiteam X-Cart 4.0.8 - 'giftcert.php' Multiple Cross-Site Scripting Vulnerabilities 10 WEB CENSORED Search Vulnerabilities
2005-05-30   Qualiteam X-Cart 4.0.8 - 'search.php?mode' Cross-Site Scripting 12 WEB CENSORED Search Vulnerabilities
2005-05-30   Qualiteam X-Cart 4.0.8 - 'register.php?mode' Cross-Site Scripting 12 WEB CENSORED Search Vulnerabilities
2005-05-30   Qualiteam X-Cart 4.0.8 - 'orders.php?mode' Cross-Site Scripting 11 WEB CENSORED Search Vulnerabilities
2005-05-30   Qualiteam X-Cart 4.0.8 - 'help.php?section' Cross-Site Scripting 10 WEB CENSORED Search Vulnerabilities
2005-05-30   Qualiteam X-Cart 4.0.8 - 'error_message.php?id' Cross-Site Scripting 11 WEB CENSORED Search Vulnerabilities
2005-05-30   Qualiteam X-Cart 4.0.8 - 'product.php' Multiple Cross-Site Scripting Vulnerabilities 10 WEB CENSORED Search Vulnerabilities
2005-05-30   Qualiteam X-Cart 4.0.8 - 'home.php' Multiple Cross-Site Scripting Vulnerabilities 12 WEB CENSORED Search Vulnerabilities
2005-05-30   Hosting Controller 6.1 - User Profile Unauthorized Access 14 WEB GrayHatz Security Group
2005-05-28   India Software Solution Shopping Cart - SQL Injection 10 WEB Rayden
2005-05-28   Hosting Controller 6.1 - 'plandetails.asp' Information Disclosure 12 WEB GrayHatz Security Group
2005-05-28   Hosting Controller 6.1 - 'resellerresources.asp?jresourceid' SQL Injection 12 WEB GrayHatz Security Group
2005-05-28   OS4E - 'login.asp' SQL Injection 12 WEB Dj romty
2005-05-28   NPDS 4.8 < 5.0 - 'faq.php?categories' Cross-Site Scripting 13 WEB NoSP
2005-05-28   NPDS 4.8 < 5.0 - 'links.php?Query' SQL Injection 12 WEB NoSP
2005-05-28   NPDS 4.8 < 5.0 Glossaire Module - 'terme' SQL Injection 12 WEB NoSP
2005-05-28   NPDS 4.8 < 5.0 - 'reply.php?image_subject' Cross-Site Scripting 11 WEB NoSP
2005-05-28   NPDS 4.8 < 5.0 - 'reviews.php?title' Cross-Site Scripting 11 WEB NoSP
2005-05-28   NPDS 4.8 /5.0 - 'modules.php?Lettre' Cross-Site Scripting 11 WEB NoSP
2005-05-28   NPDS 4.8 < 5.0 - 'sdv_infos.php?sitename' Cross-Site Scripting 11 WEB NoSP
2005-05-28   NPDS 4.8 < 5.0 - 'powerpack_f.php?language' Cross-Site Scripting 11 WEB NoSP
2005-05-28   NPDS 4.8 < 5.0 - 'admin.php?language' Cross-Site Scripting 10 WEB NoSP
2005-05-28   Invision Power Board 1.x - Unauthorized Access 12 WEB V[i]RuS
2005-05-27   Jaws Glossary 0.4/0.5 - Cross-Site Scripting 14 WEB Nah
2005-05-27   BEA WebLogic 7.0/8.1 - Administration Console Error Page Cross-Site Scripting 12 WEB Team SHATTER
2005-05-27   BEA WebLogic 7.0/8.1 - Administration Console LoginForm.jsp Cross-Site Scripting 12 WEB Team SHATTER
2005-05-26   BookReview 1.0 - 'suggest_review.htm?node' Cross-Site Scripting 11 WEB Lostmon
2005-05-26   BookReview 1.0 - 'add_classification.htm?isbn' Cross-Site Scripting 12 WEB Lostmon
2005-05-26   BookReview 1.0 - 'search.htm?submit string' Cross-Site Scripting 12 WEB Lostmon
2005-05-26   BookReview 1.0 - 'add_url.htm?node' Cross-Site Scripting 12 WEB Lostmon
2005-05-26   BookReview 1.0 - 'add_booklist.htm?node' Cross-Site Scripting 9 WEB Lostmon
2005-05-26   BookReview 1.0 - 'contact.htm?user' Cross-Site Scripting 12 WEB Lostmon
2005-05-26   BookReview 1.0 - 'suggest_category.htm?node' Cross-Site Scripting 12 WEB Lostmon
2005-05-26   BookReview 1.0 - 'add_contents.htm' Multiple Cross-Site Scripting Vulnerabilities 10 WEB Lostmon
2005-05-26   BookReview 1.0 - 'add_review.htm' Multiple Cross-Site Scripting Vulnerabilities 12 WEB Lostmon
2013-05-26   RadioCMS 2.2 - 'menager.php?playlist_id' SQL Injection 11 WEB Rooster(XEKA)
2013-05-26   WordPress Plugin Spider Catalog 1.4.6 - Multiple Vulnerabilities 15 WEB waraxe
2013-05-26   WordPress Plugin Spider Event Calendar 1.3.0 - Multiple Vulnerabilities 13 WEB waraxe
2013-05-26   WordPress Plugin User Role Editor 3.12 - Cross-Site Request Forgery 11 WEB Henry Hoggard
2013-05-26   Vanilla Forums 2.0.18.8 - Multiple Vulnerabilities 10 WEB Henry Hoggard
2013-05-26   AVE.CMS 2.09 - 'index.php?module' Blind SQL Injection 12 WEB mr.pr0n
2013-05-26   HP LaserJet Pro P1606dn - Webadmin Password Reset 11 WEB m3tamantra
2005-05-25   FunkyASP AD Systems 1.1 - 'login.asp' SQL Injection 12 WEB Romty
2005-05-25   PHP Poll Creator 1.0.1 - 'Poll_Vote.php' Remote File Inclusion 13 WEB rash ilusion
2005-05-24   Sun JavaMail 1.x - Multiple Information Disclosure Vulnerabilities 12 WEB Ricky Latt
2005-05-24   Spread The Word - Multiple SQL Injections 11 WEB Lostmon
2005-05-24   Spread The Word - Multiple Cross-Site Scripting Vulnerabilities 9 WEB Lostmon
2005-05-24   GForge 3.x - Arbitrary Command Execution 11 WEB Filippo Spike Morelli
2005-05-23   PortailPHP 1.3 - 'ID' SQL Injection 10 WEB CENSORED Search Vulnerabilities
2003-05-20   EJ3 TOPo 2.2 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 10 WEB Lostmon
2005-05-19   PHP Advanced Transfer Manager 1.21 - Arbitrary File Inclusion 10 WEB Ingvar Gilbert
2005-05-19   Sun JavaMail 1.3 - API MimeMessage Infromation Disclosure 11 WEB Ricky Latt
2005-05-24   HelpCenter Live! 1.0/1.2.x - Multiple Input Validation Vulnerabilities 10 WEB GulfTech Security
2005-05-17   WordPress Core 1.5 - 'post.php' Cross-Site Scripting 12 WEB Thomas Waldegger
2005-05-24   Fusionphp Fusion News 3.3/3.6 - X-Forworded-For PHP Script Code Injection 12 WEB Network security team
2005-05-16   JGS-Portal 3.0.1/3.0.2 - 'jgs_portal_sponsor.php?id' SQL Injection 11 WEB deluxe@security-project.org
2005-05-16   JGS-Portal 3.0.1/3.0.2 - 'jgs_portal_mitgraf.php?year' SQL Injection 11 WEB deluxe@security-project.org
2005-05-16   JGS-Portal 3.0.1/3.0.2 - 'jgs_portal_themengraf.php?year' SQL Injection 13 WEB deluxe@security-project.org
2005-05-16   JGS-Portal 3.0.1/3.0.2 - 'jgs_portal_viewsgraf.php?tag' SQL Injection 10 WEB deluxe@security-project.org
2005-05-16   JGS-Portal 3.0.1/3.0.2 - 'jgs_portal_beitraggraf.php?year' SQL Injection 13 WEB deluxe@security-project.org
2005-05-16   JGS-Portal 3.0.1/3.0.2 - 'jgs_portal.php?anzahl_beitraege' SQL Injection 12 WEB deluxe@security-project.org
2005-05-16   JGS-Portal 3.0.1/3.0.2 - 'jgs_portal_statistik.php?year' SQL Injection 11 WEB deluxe@security-project.org
2005-05-16   NPDS 4.8/5.0 - 'pollcomments.php?thold' SQL Injection 10 WEB NoSP
2005-05-16   NPDS 4.8/5.0 - 'comments.php?thold' SQL Injection 14 WEB NoSP
2005-05-16   Sigma ISP Manager 6.6 - 'Sigmaweb.dll' SQL Injection 10 WEB mehran gashtasebi
2005-05-16   MetaCart E-Shop - 'ProductsByCategory.asp' Cross-Site Scripting 11 WEB Dedi Dwianto
2005-05-16   PServ 3.2 - Source Code Disclosure 10 WEB Claus R. F. Overbeck
2005-05-16   PostNuke 0.75/0.76 Blocks Module - Directory Traversal 10 WEB pokley
2005-05-16   Shop-Script - ProductID SQL Injection 11 WEB CENSORED Search Vulnerabilities
2005-05-16   Shop-Script - categoryId SQL Injection 10 WEB CENSORED Search Vulnerabilities
2005-05-14   Skull-Splitter Guestbook 1.0/2.0/2.2 - Multiple HTML Injection Vulnerabilities 10 WEB Morinex Eneco
2005-05-01   Keyvan1 ImageGallery - Database Disclosure 13 WEB g0rellazz G0r
2005-05-13   PHPHeaven PHPMyChat 0.14.5 - 'Style.CSS.php3' Cross-Site Scripting 12 WEB Megasky
2005-05-13   PHPHeaven PHPMyChat 0.14.5 - 'Start-Page.CSS.php3' Cross-Site Scripting 12 WEB Megasky
2005-05-13   OpenBB 1.0.8 - 'member.php' Cross-Site Scripting 11 WEB Megasky
2005-05-13   OpenBB 1.0.8 - 'Read.php' SQL Injection 11 WEB Megasky
2005-05-13   Ultimate PHP Board 1.8/1.9 - 'viewforum.php' SQL Injection 13 WEB Morinex Eneco
2005-05-13   Ultimate PHP Board 1.8/1.9 - 'viewforum.php' Cross-Site Scripting 12 WEB Morinex Eneco
2005-05-12   DirectTopics 2 - 'topic.php' SQL Injection 12 WEB Morinex Eneco
2005-05-11   Maxwebportal 1.3x - 'post.asp' Multiple Cross-Site Scripting Vulnerabilities 10 WEB Zinho
2005-05-11   Open Solution Quick.Cart 0.3 - 'index.php' Cross-Site Scripting 11 WEB Lostmon
2011-05-11   showoff! digital media software 1.5.4 - Multiple Vulnerabilities 15 WEB dr_insane
2005-05-10   e107 Website System 0.617 - 'Forum_viewforum.php' SQL Injection 12 WEB Heintz
2005-05-10   e107 Website System 0.617 - 'Request.php' Directory Traversal 10 WEB Heintz
2005-05-10   NukeET 3.0/3.1 - Base64 Codigo Variable Cross-Site Scripting 11 WEB Suko & Lostmon
2005-05-10   WowBB 1.6 - 'View_User.php' SQL Injection 14 WEB Megasky
2005-05-09   PWSPHP 1.1/1.2 - 'Profil.php' SQL Injection 10 WEB SecuBox fRoGGz
2005-05-09   PWSPHP 1.2 - Multiple Cross-Site Scripting Vulnerabilities 11 WEB SecuBox fRoGGz
2005-05-09   CodeThatShoppingCart 1.3.1 - 'catalog.php?id' SQL Injection 10 WEB Lostmon
2005-05-09   CodeThatShoppingCart 1.3.1 - 'catalog.php?id' Cross-Site Scripting 13 WEB Lostmon
2005-05-09   PHP-Nuke 0-7 - Double Hex Encoded Input Validation 10 WEB fistfuxxer@gmx.de
2005-05-09   Easy Message Board - Remote Command Execution 10 WEB SoulBlack Group
2005-05-09   Easy Message Board - Directory Traversal 11 WEB SoulBlack Group
2005-05-09   Advanced Guestbook 2.3.1/2.4 - 'index.php?Entry' SQL Injection 10 WEB Spy Hat
2005-05-09   phpBB 2.0.x - 'BBCode.php' URL Tag 11 WEB Papados
2005-05-06   CJ Ultra Plus 1.0.3/1.0.4 - 'OUT.php' SQL Injection 13 WEB Kold
2005-05-05   MegaBook 2.0/2.1 - 'Admin.cgi?EntryID' Cross-Site Scripting 13 WEB Spy Hat
2005-05-05   MidiCart PHP - 'Item_List.php?MainGroup' Cross-Site Scripting 15 WEB Exoduks