|
2004-12-18
|
|
Kayako eSupport 2.x - Ticket System Multiple SQL Injections
|
9 |
WEB
|
GulfTech Security
|
|
2004-12-18
|
|
Kayako eSupport 2.x - 'index.php' Knowledgebase Cross-Site Scripting
|
9 |
WEB
|
GulfTech Security
|
|
2013-04-26
|
|
D-Link DIR-635 - Multiple Vulnerabilities
|
9 |
WEB
|
m-1-k-3
|
|
2004-12-17
|
|
WorkBoard 1.2 - Multiple Cross-Site Scripting Vulnerabilities
|
9 |
WEB
|
Lostmon
|
|
2013-04-25
|
|
phpMyAdmin 3.5.8/4.0.0-RC2 - Multiple Vulnerabilities
|
9 |
WEB
|
waraxe
|
|
2013-04-25
|
|
Hornbill Supportworks ITSM 1.0.0 - SQL Injection
|
8 |
WEB
|
Joseph Sheridan
|
|
2004-12-16
|
|
MediaWiki 1.3.x - Arbitrary Script Upload
|
8 |
WEB
|
Jeremy Bae
|
|
2004-12-16
|
|
WordPress Core 1.2.1/1.2.2 - 'moderation.php?item_approved' Cross-Site Scripting
|
7 |
WEB
|
Thomas Waldegger
|
|
2004-12-16
|
|
WordPress Core 1.2.1/1.2.2 - 'link-manager.php' Multiple Cross-Site Scripting Vulnerabilities
|
9 |
WEB
|
Thomas Waldegger
|
|
2004-12-16
|
|
WordPress Core 1.2.1/1.2.2 - 'link-categories.php?cat_id' Cross-Site Scripting
|
9 |
WEB
|
Thomas Waldegger
|
|
2004-12-16
|
|
WordPress Core 1.2.1/1.2.2 - 'link-add.php' Multiple Cross-Site Scripting Vulnerabilities
|
9 |
WEB
|
Thomas Waldegger
|
|
2004-12-16
|
|
WordPress Core 1.2.1/1.2.2 - '/wp-admin/templates.php?file' Cross-Site Scripting
|
9 |
WEB
|
Thomas Waldegger
|
|
2004-12-16
|
|
WordPress Core 1.2.1/1.2.2 - '/wp-admin/post.php?content' Cross-Site Scripting
|
9 |
WEB
|
Thomas Waldegger
|
|
2004-12-16
|
|
JSBoard 2.0.x - Arbitrary Script Upload
|
9 |
WEB
|
Jeremy Bae
|
|
2004-12-16
|
|
IkonBoard 3.x - Multiple SQL Injections
|
8 |
WEB
|
anonymous
|
|
2013-04-23
|
|
D-Link DIR-615 Rev D3 / DIR-300 Rev A - Multiple Vulnerabilities
|
9 |
WEB
|
m-1-k-3
|
|
2013-04-22
|
|
VoipNow 2.5 - Local File Inclusion
|
8 |
WEB
|
i-Hmx
|
|
2013-04-22
|
|
Joomla! Component com_civicrm 4.2.2 - Remote Code Injection
|
10 |
WEB
|
iskorpitx
|
|
2013-04-19
|
|
Nginx 0.6.x - Arbitrary Code Execution NullByte Injection
|
9 |
WEB
|
Neal Poole
|
|
2013-04-18
|
|
KrisonAV CMS 3.0.1 - Multiple Vulnerabilities
|
9 |
WEB
|
High-Tech Bridge SA
|
|
2013-04-18
|
|
Oracle WebCenter Sites Satellite Server - HTTP Header Injection
|
8 |
WEB
|
SEC Consult
|
|
2013-04-15
|
|
phpVms Virtual Airline Administration 2.1.934/2.1.935 - SQL Injection
|
9 |
WEB
|
NoGe
|
|
2013-04-15
|
|
CMSLogik 1.2.1 - Multiple Vulnerabilities
|
9 |
WEB
|
LiquidWorm
|
|
2013-04-15
|
|
Vanilla Forums Van2Shout Plugin 1.0.51 - Multiple Cross-Site Request Forgery Vulnerabilities
|
9 |
WEB
|
Henry Hoggard
|
|
2013-04-12
|
|
Simple HRM System 2.3 - Multiple Vulnerabilities
|
9 |
WEB
|
Doraemon
|
|
2013-04-12
|
|
Free Monthly Websites 2.0 - Admin Password Change
|
9 |
WEB
|
Yassin Aboukir
|
|
2013-04-09
|
|
ZAPms 1.41 - SQL Injection
|
8 |
WEB
|
NoGe
|
|
2013-04-08
|
|
WHMCompleteSolution (WHMCS) Group Pay Plugin 1.5 - 'grouppay.php?hash' SQL Injection
|
9 |
WEB
|
HJauditing Employee Tim
|
|
2013-04-08
|
|
Sophos Web Protection Appliance 3.7.8.1 - Multiple Vulnerabilities
|
9 |
WEB
|
SEC Consult
|
|
2013-04-08
|
|
TP-Link TD-8817 6.0.1 Build 111128 Rel.26763 - Cross-Site Request Forgery
|
8 |
WEB
|
Un0wn_X
|
|
2013-04-08
|
|
Vanilla Forums 2-0-18-4 - SQL Injection
|
8 |
WEB
|
bl4ckw0rm
|
|
2013-04-08
|
|
D-Link - Multiple Vulnerabilities
|
9 |
WEB
|
m-1-k-3
|
|
2013-04-08
|
|
Belkin Wemo - Arbitrary Firmware Upload
|
8 |
WEB
|
Daniel Buentello
|
|
2013-04-08
|
|
OTRS 3.x - FAQ Module Persistent Cross-Site Scripting
|
8 |
WEB
|
Luigi Vezzoso
|
|
2013-04-08
|
|
OpenCart - Cross-Site Request Forgery (Change User Password)
|
8 |
WEB
|
Saadi Siddiqui
|
|
2013-04-02
|
|
Netgear WNR1000 - Authentication Bypass
|
9 |
WEB
|
Roberto Paleari
|
|
2013-04-02
|
|
Aspen 0.8 - Directory Traversal
|
9 |
WEB
|
Daniel Ricardo dos Santos
|
|
2013-04-02
|
|
WordPress Plugin FuneralPress 1.1.6 - Persistent Cross-Site Scripting
|
9 |
WEB
|
Rob Armstrong
|
|
2013-04-02
|
|
Network Weathermap 0.97a - 'editor.php' Persistent Cross-Site Scripting
|
7 |
WEB
|
Daniel Ricardo dos Santos
|
|
2013-04-02
|
|
Pollen CMS 0.6 - 'index.php?p' Paramete' Local File Disclosure
|
8 |
WEB
|
MizoZ
|
|
2013-03-29
|
|
AWS Xms 2.5 - 'importer.php?what' Directory Traversal
|
9 |
WEB
|
High-Tech Bridge SA
|
|
2013-03-29
|
|
MailOrderWorks 5.907 - Multiple Vulnerabilities
|
9 |
WEB
|
Vulnerability-Lab
|
|
2013-03-29
|
|
SynConnect Pms - 'index.php?loginid' SQL Injection
|
9 |
WEB
|
Bhadresh Patel
|
|
2013-03-27
|
|
ClipShare 4.1.1 - Multiples Vulnerabilities
|
9 |
WEB
|
Esac
|
|
2013-03-27
|
|
PsychoStats 3.2.2b - 'awards.php' Blind SQL Injection
|
8 |
WEB
|
Mohamed from ALG
|
|
2013-03-26
|
|
WordPress Plugin Mathjax Latex 1.1 - Cross-Site Request Forgery
|
9 |
WEB
|
Junaid Hussain
|
|
2013-03-25
|
|
Ra1NX PHP Bot - pubcall Authentication Bypass Remote Code Execution (Metasploit)
|
8 |
WEB
|
bwall
|
|
2013-03-25
|
|
vBulletin 5.0.0 Beta 11 < 5.0.0 Beta 28 - SQL Injection
|
8 |
WEB
|
Orestis Kourides
|
|
2013-03-25
|
|
ClipShare 4.1.1 - 'gid' Blind SQL Injection
|
9 |
WEB
|
Esac
|
|
2013-03-25
|
|
Free Hosting Manager 2.0.2 - Multiple SQL Injections
|
9 |
WEB
|
Saadi Siddiqui
|
|
2013-03-22
|
|
OpenCart 1.5.5.1 - 'FileManager.php' Directory Traversal Arbitrary File Access
|
9 |
WEB
|
waraxe
|
|
2013-03-22
|
|
Stradus CMS 1.0beta4 - Multiple Vulnerabilities
|
9 |
WEB
|
DaOne
|
|
2013-03-22
|
|
Slash CMS - Multiple Vulnerabilities
|
9 |
WEB
|
DaOne
|
|
2013-03-22
|
|
Flatnux CMS 2013-01.17 - 'index.php' Local File Inclusion
|
9 |
WEB
|
DaOne
|
|
2013-03-22
|
|
AContent 1.3 - Local File Inclusion
|
9 |
WEB
|
DaOne
|
|
2013-03-22
|
|
WordPress Plugin IndiaNIC FAQs Manager 1.0 - Blind SQL Injection
|
10 |
WEB
|
m3tamantra
|
|
2013-03-22
|
|
WordPress Plugin IndiaNIC FAQs Manager 1.0 - Multiple Vulnerabilities
|
8 |
WEB
|
m3tamantra
|
|
2013-03-22
|
|
StarVedia IPCamera IC502w IC502w+ v020313 - 'Username'/Password Disclosure
|
9 |
WEB
|
Todor Donev
|
|
2013-03-19
|
|
ViewGit 0.0.6 - Multiple Cross-Site Scripting Vulnerabilities
|
9 |
WEB
|
Matthew R. Bucci
|
|
2013-03-19
|
|
Rebus:list - 'list.php?list_id' SQL Injection
|
7 |
WEB
|
Robert Cooper
|
|
2013-03-19
|
|
Verizon Fios Router MI424WR-GEN3I - Cross-Site Request Forgery
|
9 |
WEB
|
Jacob Holcomb
|
|
2013-03-19
|
|
WordPress Plugin Count Per Day 3.2.5 - 'counter.php' Cross-Site Scripting
|
9 |
WEB
|
m3tamantra
|
|
2013-03-19
|
|
WordPress Plugin Occasions 1.0.4 - Cross-Site Request Forgery
|
9 |
WEB
|
m3tamantra
|
|
2013-03-18
|
|
Joomla! Component com_rsfiles - 'cid' SQL Injection
|
9 |
WEB
|
ByEge
|
|
2013-03-18
|
|
WordPress Plugin Simply Poll 1.4.1 - Multiple Vulnerabilities
|
9 |
WEB
|
m3tamantra
|
|
2013-03-18
|
|
DaloRadius - Multiple Vulnerabilities
|
8 |
WEB
|
Saadi Siddiqui
|
|
2004-12-15
|
|
phpGroupWare 0.9.x - 'index.php' Multiple SQL Injections
|
9 |
WEB
|
GulfTech Security
|
|
2004-12-15
|
|
phpGroupWare 0.9.x - 'viewticket_details.php?ticket_id' SQL Injection
|
8 |
WEB
|
GulfTech Security
|
|
2004-12-15
|
|
phpGroupWare 0.9.x - 'viewticket_details.php?ticket_id' Cross-Site Scripting
|
8 |
WEB
|
GulfTech Security
|
|
2004-12-15
|
|
phpGroupWare 0.9.x - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
|
8 |
WEB
|
GulfTech Security
|
|
2004-12-15
|
|
IWebNegar - Multiple SQL Injections
|
9 |
WEB
|
Shervin Khaleghjou
|
|
2004-12-14
|
|
ASP-Rider - SQL Injection
|
9 |
WEB
|
Shervin Khaleghjou
|
|
2004-12-14
|
|
Active Server Corner ASP Calendar 1.0 - Administrative Access
|
8 |
WEB
|
ali reza AcTiOnSpIdEr
|
|
2004-01-12
|
|
PHPGedView 2.5/2.6 - 'Timeline.php' SQL Injection
|
8 |
WEB
|
JeiAr
|
|
2004-12-14
|
|
UseModWiki 1.0 - Wiki.pl Cross-Site Scripting
|
8 |
WEB
|
Jeremy Bae
|
|
2004-01-12
|
|
PHPGedView 2.5/2.6 - 'Placelist.php' SQL Injection
|
9 |
WEB
|
JeiAr
|
|
2004-01-12
|
|
PHPGedView 2.5/2.6 - 'calendar.php' Cross-Site Scripting
|
9 |
WEB
|
JeiAr
|
|
2004-01-12
|
|
PHPGedView 2.5/2.6 - 'Relationship.php' Cross-Site Scripting
|
9 |
WEB
|
JeiAr
|
|
2004-01-12
|
|
PHPGedView 2.5/2.6 - 'login.php' Newlanguage Cross-Site Scripting
|
8 |
WEB
|
JeiAr
|
|
2004-01-12
|
|
PHPGedView 2.5/2.6 - 'login.php?Username' Cross-Site Scripting
|
9 |
WEB
|
JeiAr
|
|
2004-01-12
|
|
PHPGedView 2.5/2.6 - 'login.php?URL' Cross-Site Scripting
|
9 |
WEB
|
JeiAr
|
|
2004-12-13
|
|
UBBCentral UBB.Threads 6.2.3/6.5 - 'online.php?Cat' Cross-Site Scripting
|
9 |
WEB
|
dw. & ms.
|
|
2004-12-13
|
|
UBBCentral UBB.Threads 6.2.3/6.5 - 'login.php?Cat' Cross-Site Scripting
|
9 |
WEB
|
dw. & ms.
|
|
2004-12-13
|
|
UBBCentral UBB.Threads 6.2.3/6.5 - 'calendar.php?Cat' Cross-Site Scripting
|
8 |
WEB
|
dw. & ms.
|
|
2004-12-13
|
|
UBBCentral UBB.Threads 6.2.3/6.5 - 'showflat.php?Cat' Cross-Site Scripting
|
9 |
WEB
|
dw. & ms.
|
|
2004-12-13
|
|
sugarsales 1.x/2.0 - Multiple Vulnerabilities
|
9 |
WEB
|
Daniel Fabian
|
|
2004-01-12
|
|
PHPGedView 2.5/2.6 - 'Gdbi_interface.php' Cross-Site Scripting
|
7 |
WEB
|
JeiAr
|
|
2004-01-12
|
|
PHPGedView 2.5/2.6 - 'Gedrecord.php' Cross-Site Scripting
|
8 |
WEB
|
JeiAr
|
|
2004-01-12
|
|
PHPGedView 2.5/2.6 - 'Imageview.php' Cross-Site Scripting
|
9 |
WEB
|
JeiAr
|
|
2004-01-12
|
|
PHPGedView 2.5/2.6 - 'Source.php' Cross-Site Scripting
|
8 |
WEB
|
JeiAr
|
|
2004-12-13
|
|
phpMyAdmin 2.x - External Transformations Remote Command Execution
|
8 |
WEB
|
Nicolas Gregoire
|
|
2004-01-12
|
|
PHPGedView 2.5/2.6 - 'Individual.php' Cross-Site Scripting
|
9 |
WEB
|
JeiAr
|
|
2004-01-12
|
|
PHPGedView 2.5/2.6 - 'index.php' Cross-Site Scripting
|
8 |
WEB
|
JeiAr
|
|
2004-01-19
|
|
PHPGedView 2.x - 'Descendancy.php' Cross-Site Scripting
|
9 |
WEB
|
JeiAr
|
|
2004-12-07
|
|
darryl burgdorf weblibs 1.0 - Directory Traversal
|
8 |
WEB
|
John Bissell
|
|
2004-12-07
|
|
Blog Torrent 0.80 - 'BTDownload.php' Cross-Site Scripting
|
9 |
WEB
|
Lostmon
|
|
2004-12-04
|
|
PAFileDB 3.1 - Error Message Full Path Disclosure
|
7 |
WEB
|
y3dips
|
|
2004-12-02
|
|
Advanced Guestbook 2.2/2.3 - Cross-Site Scripting
|
9 |
WEB
|
Emile van Elen
|
|
2004-12-02
|
|
Blog Torrent 0.8 - Directory Traversal
|
10 |
WEB
|
Steve Kemp
|
|
2004-11-30
|
|
IPCop 1.4.1 - Web Administration Interface Proxy Log HTML Injection
|
8 |
WEB
|
Paul Kurczaba
|
|
2013-03-15
|
|
Open-Xchange Server 6 - Multiple Vulnerabilities
|
9 |
WEB
|
Martin Braun
|
|
2013-03-15
|
|
ClipShare 4.1.4 - Multiple Vulnerabilities
|
8 |
WEB
|
AkaStep
|
|
2013-03-15
|
|
WordPress Plugin LeagueManager 3.8 - SQL Injection
|
9 |
WEB
|
Joshua Reynolds
|
|
2013-03-15
|
|
Cisco Video Surveillance Operations Manager 6.3.2 - Multiple Vulnerabilities
|
9 |
WEB
|
Bassem
|
|
2004-11-26
|
|
pntresmailer 6.0 - Directory Traversal
|
9 |
WEB
|
John Cobb
|
|
2004-11-26
|
|
phpCMS 1.1/1.2 - Cross-Site Scripting
|
9 |
WEB
|
Cyrille Barthelemy
|
|
2004-11-25
|
|
InShop and InMail - Cross-Site Scripting
|
9 |
WEB
|
Carlos Ulver
|
|
2004-11-24
|
|
JSPWiki 2.1 - Cross-Site Scripting
|
8 |
WEB
|
Jeremy Bae
|
|
2004-11-24
|
|
Zwiki 0.10/0.36.2 - Cross-Site Scripting
|
8 |
WEB
|
Jeremy Bae
|
|
2004-11-24
|
|
KorWeblog 1.6.2 - Remote Directory Listing
|
9 |
WEB
|
Jeremy Bae
|
|
2004-11-23
|
|
SugarCRM 1.x/2.0 Module - Traversal Arbitrary File Access
|
8 |
WEB
|
GulfTech Security
|
|
2004-11-23
|
|
SugarCRM 1.x/2.0 Module - 'record' SQL Injection
|
8 |
WEB
|
GulfTech Security
|
|
2004-11-23
|
|
Nuked-klaN 1.x - Submit Link Function HTML Injection
|
8 |
WEB
|
XioNoX
|
|
2004-11-22
|
|
PHPKIT 1.6 - Multiple Input Validation Vulnerabilities
|
9 |
WEB
|
Steve
|
|
2004-11-20
|
|
IPBProArcade 2.5 - SQL Injection
|
9 |
WEB
|
axl daivy
|
|
2004-11-18
|
|
Invision Power Board 2.0 - 'index.php' Post Action SQL Injection
|
9 |
WEB
|
anonymous
|
|
2004-11-17
|
|
phpBB 2.0.x - 'admin_cash.php' PHP Remote File Inclusion
|
9 |
WEB
|
Jerome Athias
|
|
2004-11-16
|
|
event Calendar - Multiple Vulnerabilities
|
8 |
WEB
|
Janek Vind
|
|
2013-03-13
|
|
Apache Rave 0.11 < 0.20 - User Information Disclosure
|
9 |
WEB
|
Andreas Guth
|
|
2013-03-13
|
|
Web Cookbook - Multiple SQL Injections
|
9 |
WEB
|
Saadat Ullah
|
|
2013-02-24
|
|
AirDrive HD 1.6 iPad iPhone - Multiple Vulnerabilities
|
8 |
WEB
|
Vulnerability-Lab
|
|
2004-11-14
|
|
PowerPortal 1.3 - SQL Injection
|
8 |
WEB
|
ruggine
|
|
2004-11-13
|
|
Mark Zuckerberg Thefacebook - Multiple Cross-Site Scripting Vulnerabilities
|
8 |
WEB
|
Alex Lanstein
|
|
2004-11-04
|
|
phpWebSite 0.7.3/0.8.x/0.9.3 - User Module HTTP Response Splitting
|
8 |
WEB
|
Maestro De-Seguridad
|
|
2004-11-12
|
|
chacmool Private Message System 1.1.3 - 'send.php' Arbitrary Message Access
|
9 |
WEB
|
digital ex
|