Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2004-06-10   BlackBoard Learning System 6.0 - Dropbox File Download 4 WEB Maarten Verbeek
2004-06-11   Invision Power Board 1.3 - 'SSI.php' SQL Injection 4 WEB JvdR
2004-06-09   AspDotNetStorefront 3.3 - 'ReturnURL' Cross-Site Scripting 4 WEB Thomas Ryan
2004-06-09   AspDotNetStorefront 3.3 - Access Validation 4 WEB Thomas Ryan
2004-06-09   cPanel 5-9 - Passwd SQL Injection 4 WEB verb0s@virtualnova.net
2013-01-17   Invision Gallery 2.0.5 - SQL Injection 4 WEB Ashiyane Digital Security Team
2004-06-07   NetWin Surgemail 1.8/1.9/2.0 / WebMail 3.1 - Login Form Cross-Site Scripting 4 WEB Donnie Werner
2004-06-07   NetWin Surgemail 1.8/1.9/2.0 / WebMail 3.1 - Error Message Full Path Disclosure 4 WEB Donnie Werner
2004-06-07   Linksys Web Camera Software 2.10 - 'Next_file' File Disclosure 4 WEB John Doe
2004-06-05   cPanel 5-9 - Killacct Script Customer Account DNS Information Deletion 4 WEB qbann targ
2004-06-04   Crafty Syntax Live Help 2.7.3 - Multiple HTML Injection Vulnerabilities 4 WEB HNK Technology Solutions
2004-06-03   Mail Manage EX 3.1.8 MMEX - 'Settings' PHP Remote File Inclusion 3 WEB The Warlock [BhQ]
2004-06-03   SquirrelMail 1.2.x - From Email Header HTML Injection 4 WEB anonymous
2004-06-01   PHP-Nuke 5.x/6.x/7.x - Direct Script Access Security Bypass 4 WEB Squid
2004-06-01   Rit Research Labs TinyWeb 1.9.2 - Unauthorized Script Disclosure 4 WEB Ziv Kamir
2013-01-16   Oracle Application Framework - Diagnostic Mode Bypass 4 WEB Trustwave's SpiderLabs
2013-01-16   Cydia Repo Manager - Cross-Site Request Forgery 4 WEB Ramdan Yantu
2004-05-29   e107 website system 0.6 - 'email article to a friend' Feature Cross-Site Scripting 5 WEB Janek Vind
2004-05-29   e107 website system 0.6 - 'usersettings.php?avmsg' Cross-Site Scripting 4 WEB Janek Vind
2004-05-29   Land Down Under - BBCode HTML Injection 4 WEB Tim De Gier
2004-05-28   jPORTAL 2.2.1 - 'print.php' SQL Injection 4 WEB Maciek Wierciski
2004-05-22   Liferay Enterprise Portal 1.x/2.x/5.0.2 - Multiple Cross-Site Scripting Vulnerabilities 4 WEB Sandeep Giri
2004-05-21   e107 Website System 0.5/0.6 - 'Log.php' HTML Injection 4 WEB Chinchilla
2013-01-15   CMS snews - SQL Injection 3 WEB By onestree
2004-05-18   dsm light Web file browser 2.0 - Directory Traversal 4 WEB Humberto
2004-05-17   PHP-Nuke 6.x/7.x - 'Modpath' File Inclusion 4 WEB waraxe
2004-05-17   osCommerce 2.x - File Manager Directory Traversal 4 WEB Rene
2004-05-17   vBulletin 1.0/2.x/3.0 - 'index.php' User Interface Spoofing 4 WEB p0rk
2004-05-17   TurboTrafficTrader C 1.0 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities 4 WEB Kaloyan Olegov Georgiev
2013-01-14   phpShop 2.0 - SQL Injection 4 WEB By onestree
2004-05-10   Tutorials Manager 1.0 - Multiple SQL Injections 4 WEB Hillel Himovich
2004-05-08   Adam Webb NukeJokes 1.7/2.0 Module - 'modules.php?jokeid' SQL Injection 4 WEB Janek Vind
2004-05-08   Adam Webb NukeJokes 1.7/2.0 Module - Multiple Cross-Site Scripting Vulnerabilities 4 WEB Janek Vind
2004-05-05   SurgeLDAP 1.0 - Web Administration Authentication Bypass 4 WEB GSS IT
2004-05-05   PHPX 3.x - '/forums.php' Cross-Site Request Forgery / Arbitrary Command Execution 5 WEB JeiAr
2004-05-05   PHPX 3.x - '/images.php' Cross-Site Request Forgery / Arbitrary Command Execution 4 WEB JeiAr
2004-05-05   PHPX 3.x - '/user.php' Cross-Site Request Forgery / Arbitrary Command Execution 3 WEB JeiAr
2004-05-05   PHPX 3.x - '/news.php' Cross-Site Request Forgery / Arbitrary Command Execution 4 WEB JeiAr
2004-05-05   PHPX 3.x - '/page.php' Cross-Site Request Forgery / Arbitrary Command Execution 4 WEB JeiAr
2013-01-13   phlyLabs phlyMail Lite 4.03.04 - Full Path Disclosure / Persistent Cross-Site Scripting 4 WEB LiquidWorm
2013-01-13   phlyLabs phlyMail Lite 4.03.04 - 'go' Open Redirect 4 WEB LiquidWorm
2004-05-05   PHPX 3.x - Multiple Cross-Site Scripting Vulnerabilities 4 WEB JeiAr
2004-05-05   Simple Machines Forum (SMF) 1.0 - Size Tag HTML Injection 4 WEB Cheng Peng Su
2004-05-05   E-Zone Media FuzeTalk 2.0 - 'AddUser.cfm' Administrator Command Execution 5 WEB Stuart Jamieson
2004-04-30   Coppermine Photo Gallery 1.2.2b - 'theme.php' Remote File Inclusion 4 WEB Janek Vind
2004-04-30   Coppermine Photo Gallery 1.2.0 RC4 - 'init.inc.php' Remote File Inclusion 4 WEB Janek Vind
2004-04-30   Coppermine Photo Gallery 1.2.0 RC4 - 'startdir' Traversal Arbitrary File Access 4 WEB Janek Vind
2004-04-30   Coppermine Photo Gallery 1.2.2b - 'menu.inc.php' Cross-Site Scripting 4 WEB Janek Vind
2004-04-30   Moodle 1.1/1.2 - Cross-Site Scripting 4 WEB Bartek Nowotarski
2004-04-30   SquirrelMail 1.4.x - Folder Name Cross-Site Scripting 4 WEB Alvin Alex
2004-04-26   OpenBB 1.0.x - Private Message Disclosure 4 WEB Manuel Lopez
2004-04-26   PHP-Nuke 7.2 Multiple Video Gallery Module - SQL Injection 4 WEB k1LL3r B0y
2004-04-26   OpenBB 1.0.x - 'post.php' Multiple SQL Injections 4 WEB JeiAr
2004-04-26   OpenBB 1.0.x - 'search.php?q' SQL Injection 4 WEB JeiAr
2004-04-26   OpenBB 1.0.x - 'member.php' Multiple SQL Injections 4 WEB JeiAr
2004-04-26   OpenBB 1.0.x - 'board.php?FID' SQL Injection 4 WEB JeiAr
2004-04-26   OpenBB 1.0.x - 'index.php?redirect' Cross-Site Scripting 4 WEB JeiAr
2004-04-26   OpenBB 1.0.x - 'post.php?TID' Cross-Site Scripting 4 WEB JeiAr
2004-04-26   OpenBB 1.0.x - 'myhome.php?to' Cross-Site Scripting 4 WEB JeiAr
2004-04-26   OpenBB 1.0.x - 'member.php?redirect' Cross-Site Scripting 4 WEB JeiAr
2004-04-23   Advanced Guestbook 2.2 - 'Password' SQL Injection 4 WEB JQ
2004-04-23   PW New Media Network Modular Site Management System 0.2.1 - 'Ver.asp' Information Disclosure 4 WEB CyberTalon
2004-04-23   Protector System 1.15 - 'blocker_query.php' Multiple Cross-Site Scripting Vulnerabilities 4 WEB waraxe
2004-04-23   Protector System 1.15 b1 - 'index.php' SQL Injection 4 WEB waraxe
2004-04-23   Fusionphp Fusion News 3.6.1 - Cross-Site Scripting 4 WEB DarkBicho
2013-01-11   PHPLiteAdmin 1.9.3 - Remote PHP Code Injection 4 WEB L@usch
2004-04-22   NewsTraXor Website Management Script 2.9 Beta - Database Disclosure 4 WEB CyberTal0n
2004-04-21   PostNuke Phoenix 0.726 - 'openwindow.php?hlpfile' Cross-Site Scripting 4 WEB Janek Vind
2004-04-23   PHProfession 2.5 - 'modules.php?jcode' Cross-Site Scripting 4 WEB Janek Vind
2004-04-23   PHProfession 2.5 - 'upload.php' Direct Request Full Path Disclosure 5 WEB Janek Vind
2004-04-23   PHProfession 2.5 - 'modules.php?offset' SQL Injection 4 WEB Janek Vind
2004-04-19   phpBB 2.0.x - 'album_portal.php' Remote File Inclusion 4 WEB Officerrr
2004-04-19   Phorum 3.4.x - Phorum_URIAuth SQL Injection 4 WEB Janek Vind
2004-04-15   Gemitel 3.50 - '/affich.php' Remote File Inclusion / Command Injection 4 WEB jaguar
2004-04-15   SCT Campus Pipeline 1.0/2.x/3.x - Email Attachment Script Injection 4 WEB spiffomatic 64
2004-04-15   phpBugTracker 0.9 - 'user.php?bugid' Cross-Site Scripting 4 WEB JeiAr
2004-04-15   phpBugTracker 0.9 - 'query.php' Multiple Cross-Site Scripting Vulnerabilities 4 WEB JeiAr
2004-04-15   phpBugTracker 0.9 - 'bug.php' Multiple Cross-Site Scripting Vulnerabilities 4 WEB JeiAr
2004-04-15   phpBugTracker 0.9 - 'bug.php' Multiple SQL Injections 4 WEB JeiAr
2004-04-15   phpBugTracker 0.9 - 'query.php' Multiple SQL Injections 4 WEB JeiAr
2004-04-14   Rhino Software Zaep AntiSpam 2.0 - Cross-Site Scripting 4 WEB Noam Rathaus
2004-04-13   PHP-Nuke 6.x/7.x - Multiple SQL Injections 4 WEB waraxe
2013-01-09   WeBid 1.0.6 - SQL Injection 4 WEB Life Wasted
2013-01-09   Watson Management Console 4.11.2.G - Directory Traversal 5 WEB Dhruv Shah
2013-01-09   Free Blog 1.0 - Multiple Vulnerabilities 3 WEB cr4wl3r
2013-01-09   WebsiteBaker Addon Concert Calendar 2.1.4 - Multiple Vulnerabilities 3 WEB Stefan Schurtz
2004-04-13   Tutos 1.1.20031017 - 'note_overview.php?id' SQL Injection 3 WEB François SORIN
2004-04-13   PHP-Nuke 6.x/7.x - CookieDecode Cross-Site Scripting 4 WEB waraxe
2004-04-12   Nuked-klaN 1.x - Multiple Vulnerabilities 4 WEB frog
2004-04-12   BlackBoard Learning System 5.x/6.0 - Multiple Cross-Site Scripting Vulnerabilities 4 WEB DarC KonQuest
2004-04-12   TikiWiki Project 1.8 - 'tiki-list_blogs.php?offset' SQL Injection 4 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-list_trackers.php?offset' SQL Injection 4 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-list_faqs.php?offset' SQL Injection 4 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-usermenu.php?offset' SQL Injection 4 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-list_blogs.php?sort_mode' SQL Injection 4 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-list_trackers.php?sort_mode' SQL Injection 3 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-list_faqs.php?sort_mode' SQL Injection 3 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-file_galleries.php?sort_mode' SQL Injection 3 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-directory_search.php?sort_mode' SQL Injection 3 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-user_tasks.php?offset & sort_mode' SQL Injections 3 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-index.php?comments_offset & offset' SQL Injections 3 WEB JeiAr
2013-01-08   WordPress Plugin Google Document Embedder - Arbitrary File Disclosure (Metasploit) 3 WEB Metasploit
2013-01-08   WordPress Plugin Google Document Embedder - Arbitrary File Disclosure (Metasploit) 4 WEB Metasploit
2013-01-08   Advantech Webaccess HMI/SCADA Software - Persistence Cross-Site Scripting 4 WEB SecPod Research
2013-01-08   E Sms Script - Multiple SQL Injections 4 WEB cr4wl3r
2004-04-12   TikiWiki Project 1.8 - 'tiki-browse_categories.php?sort_mode' SQL Injection 4 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-directory_ranking.php?sort_mode' SQL Injection 4 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-list_file_gallery.php?sort_mode' SQL Injection 3 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-usermenu.php?sort_mode' SQL Injection 4 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-view_chart.php?chartId' Cross-Site Scripting 4 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-view_faq.php?faqId' Cross-Site Scripting 4 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-upload_file.php?galleryID' Cross-Site Scripting 4 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-list_file_gallery.php?galleryID' Cross-Site Scripting 4 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-print_article.php?articleId' Cross-Site Scripting 4 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-index.php?comments_threshold' Cross-Site Scripting 4 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-browse_categories.php?parentId' Cross-Site Scripting 4 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-read_article.php?articleId' Cross-Site Scripting 4 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'messu-read.php' Multiple Cross-Site Scripting Vulnerabilities 3 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'messu-mailbox.php' Multiple Cross-Site Scripting Vulnerabilities 3 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'categorize.php' Direct Request Full Path Disclosure 4 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - Add Site Multiple Options Remote Code Injections 4 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - User Profile Multiple Option Remote Code Injections 4 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-map.phtml' Traversal Arbitrary File / Directory Enumeration 4 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'img/wiki_up' Arbitrary File Upload 4 WEB JeiAr
2004-04-12   TikiWiki Project 1.8 - 'tiki-switch_theme.php?theme' Cross-Site Scripting 4 WEB JeiAr