Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2012-12-19   SonicWALL SonicOS 5.8.1.8 WAF - Cross-Site Scripting 17 WEB Vulnerability-Lab
2012-12-19   WordPress Theme Clockstone (and other CMSMasters Themes) - Arbitrary File Upload 17 WEB DigiP
2003-12-29   BulletScript MailList - bsml.pl Information Disclosure 19 WEB M0rf
2003-12-29   PHP-ping - 'Count' Command Execution 18 WEB ppp-design
2003-12-27   Private Message System 2.x - 'index.php?Page' Cross-Site Scripting 17 WEB David S. Ferreira
2003-12-26   L-Soft 1.8 - Listserv Multiple Cross-Site Scripting Vulnerabilities 16 WEB http-equiv
2003-12-27   PHP-Nuke 6.x/7.0 Survey Module - SQL Injection 20 WEB idtwolf@pisem.net
2003-12-27   OpenBB 1.0 - 'board.php' Cross-Site Scripting 17 WEB gr00vy
2003-12-24   Psychoblogger PB-beta1 - errormessage Cross-Site Scripting 19 WEB Andrew Smith
2003-12-24   Psychoblogger PB-beta1 - 'desc' Cross-Site Scripting 21 WEB Andrew Smith
2003-12-24   KnowledgeBuilder 2.0/2.1/3.0 - Remote File Inclusion 15 WEB Zero X
2003-12-23   phpBB 2.0.6 - 'privmsg.php' Cross-Site Scripting 16 WEB Ben Drysdale
2003-12-23   Webfroot Shoutbox 2.32 - 'Viewshoutbox.php' Cross-Site Scripting 17 WEB Ben Drysdale
2003-12-23   My Little Forum 1.3 - 'email.php' Cross-Site Scripting 19 WEB David S. Ferreira
2003-12-23   iSoft-Solutions QuikStore Shopping Cart 2.12 - 'template' Directory Traversal 18 WEB Dr Ponidi Haryanto
2003-12-23   iSoft-Solutions QuikStore Shopping Cart 2.12 - 'store' Full Path Disclosure 18 WEB Dr Ponidi Haryanto
2003-12-22   osCommerce 2.2 - 'manufacturers_id' Cross-Site Scripting 19 WEB JeiAr
2003-12-22   osCommerce 2.2 - 'products_id' SQL Injection 17 WEB JeiAr
2003-12-21   Xoops 2.0.5.1 - 'MyLinks Myheader.php' Cross-Site Scripting 16 WEB Chintan Trivedi
2003-12-20   BES-CMS 0.4/0.5 - 'hacking.php' File Inclusion 18 WEB frog
2003-12-20   BES-CMS 0.4/0.5 - 'folder.php' File Inclusion 21 WEB frog
2003-12-20   BES-CMS 0.4/0.5 - 'start.php' File Inclusion 18 WEB frog
2003-12-20   BES-CMS 0.4/0.5 - 'message.php' File Inclusion 20 WEB frog
2003-12-20   BES-CMS 0.4/0.5 - '/members/index.inc.php' File Inclusion 18 WEB frog
2003-12-20   BES-CMS 0.4/0.5 - 'index.inc.php' File Inclusion 17 WEB frog
2012-12-17   PHPWCMS 1.5.4.6 - 'preg_replace' Multiple Vulnerabilities 18 WEB aeon
2003-12-18   SiteInteractive Subscribe Me - 'Setup.pl' Arbitrary Command Execution 20 WEB Paul Craig
2003-12-17   osCommerce 2.2 - 'osCsid' Cross-Site Scripting 19 WEB JeiAr
2003-12-16   Aardvark Topsites 4.1 PHP - Multiple Vulnerabilities 19 WEB JeiAr
2003-12-15   elektropost episerver 3/4 - Multiple Vulnerabilities 17 WEB babbelbubbel
2003-12-13   osCommerce 2.2 - SQL Injection 20 WEB GulfTech Security
2003-12-11   RemotelyAnywhere - Default.HTML Logout Message Injection 18 WEB Oliver Karow
2003-12-10   Mambo Open Source 4.0.14 - 'PollBooth.php' Multiple SQL Injections 17 WEB frog
2003-12-10   Mambo Open Source 4.0.14 Server - SQL Injection 20 WEB Chintan Trivedi
2003-12-10   Mambo 4.5 Server - 'user.php' Script Unauthorized Access 17 WEB frog
2012-12-16   MyBB User Profile Skype ID Plugin 1.0 - Persistent Cross-Site Scripting 15 WEB limb0
2003-12-09   calacode @mail webmail system 3.52 - Multiple Vulnerabilities 16 WEB Nick Gudov
2003-12-09   Bitfolge Snif 1.2.6 - 'index.php' Path Cross-Site Scripting 15 WEB Justin Hagstrom
2003-12-08   Webgate WebEye - Information Disclosure 18 WEB datapath
2003-12-06   Xoops 1.3.x/2.0.x - Multiple Vulnerabilities 18 WEB frog
2003-12-05   Virtual Programming VP-ASP 4/5 - 'shopdisplayproducts.asp' Cross-Site Scripting 17 WEB Xnuxer Research
2003-12-02   IBM Directory Server 4.1 - Web Administration Interface Cross-Site Scripting 16 WEB Oliver Karow
2003-12-01   Jason Maloney's Guestbook 3.0 - Remote Command Execution 15 WEB shaun2k2
2003-12-01   Virtual Programming VP-ASP 4.00/5.00 - 'shopdisplayproducts.asp' SQL Injection 17 WEB Nick Gudov
2003-12-01   Virtual Programming VP-ASP 4.00/5.00 - 'shopsearch.asp' SQL Injection 18 WEB Nick Gudov
2003-12-01   CuteNews 1.3 - Debug Query Information Disclosure 18 WEB scrap
2003-11-26   My_eGallery Module 3.1.1 - Remote File Inclusion Command Injection 16 WEB Bojan Zdrnja
2003-11-26   Macromedia JRun 4.0 build 61650 - Administrative Interface Multiple Cross-Site Scripting Vulnerabili 17 WEB dr_insane
2003-11-24   CommerceSQL Shopping Cart 2.2 - 'index.cgi' Directory Traversal 18 WEB Mariusz Ciesla
2003-11-17   Justin Hagstrom Auto Directory Index 1.2.3 - Cross-Site Scripting 18 WEB David Sopas Ferreira
2003-11-17   Koch Roland Rolis Guestbook 1.0 - '$path' Remote File Inclusion 17 WEB RusH security team
2012-12-14   Social Sites MyBB Plugin 0.2.2 - Cross-Site Scripting 20 WEB s3m00t
2003-11-17   PHPWebFileManager 2.0 - 'index.php' Directory Traversal 19 WEB RusH security team
2003-11-11   PHP-Coolfile 1.4 - Unauthorized Administrative Access 17 WEB r00t@rsteam.ru
2003-11-10   ncube server manager 1.0 - Directory Traversal 16 WEB Beck Mr.R
2003-11-10   OnlineArts DailyDose 1.1 - 'dose.pl' Remote Command Execution 21 WEB Don_Huan
2003-11-08   phpBB 2.0.x - 'profile.php' SQL Injection 21 WEB JOCANOR
2012-12-13   Centreon Enterprise Server 2.3.3 < 2.3.9-4 - Blind SQL Injection 19 WEB modpr0be
2012-12-13   MyBB DyMy User Agent Plugin - 'newreply.php' SQL Injection 18 WEB JoinSe7en
2012-12-13   WordPress Plugin Portable phpMyAdmin - Authentication Bypass 19 WEB Mark Stanislav
2012-12-13   Facebook Profile MyBB Plugin 2.4 - Persistent Cross-Site Scripting 17 WEB limb0
2012-12-13   MyBB AJAX Chat - Persistent Cross-Site Scripting 18 WEB Mr. P-teo
2012-12-13   MyYoutube MyBB Plugin 1.0 - SQL Injection 19 WEB Zixem
2003-11-04   John Beatty Easy PHP Photo Album 1.0 - 'dir' HTML Injection 20 WEB nimber@designer.ru
2003-11-04   OpenAutoClassifieds 1.0 - 'Listing' Cross-Site Scripting 18 WEB David Sopas Ferreira
2003-11-03   VieNuke VieBoard 2.6 - SQL Injection 18 WEB ekerazha@yahoo.it
2003-11-02   PHPKit 1.6 - 'Include.php' Cross-Site Scripting 18 WEB ben.moeckel@badwebmasters.net
2003-11-03   MPM Guestbook 1.2 - Cross-Site Scripting 16 WEB David Ferreira
2003-11-03   Web Wiz Forum 6.34/7.0/7.5 - Unauthorized Private Forum Access 15 WEB Alexander Antipov
2003-11-03   Synthetic Reality SymPoll 1.5 - Cross-Site Scripting 21 WEB Michael Frame
2003-11-01   http commander 4.0 - Directory Traversal 18 WEB Zero X
2012-12-12   Axway Secure Transport 5.1 SP2 - Directory Traversal 17 WEB Sebastian Perez
2012-12-12   TipsOfTheDay MyBB Plugin - Multiple Vulnerabilities 26 WEB VipVince
2003-10-31   Tritanium Scripts Tritanium Bulletin Board 1.2.3 - Unauthorized Access 21 WEB Virginity Security
2003-10-31   BEA WebLogic 6/7/8 - InteractiveQuery.jsp Cross-Site Scripting 19 WEB Corsaire Limited
2003-10-30   Ledscripts LedForums - Multiple HTML Injections 18 WEB ProXy
2003-10-27   Les Visiteurs 2.0 - Remote File Inclusion 18 WEB Matthieu Peschaud
2003-10-27   Chi Kien Uong Guestbook 1.51 - Cross-Site Scripting 19 WEB Joshua P. Miller
2012-12-11   PHP-Nuke 8.2.4 - Cross-Site Request Forgery 16 WEB sajith
2012-12-11   MyBB Profile Blogs Plugin 1.2 - Multiple Vulnerabilities 18 WEB Zixem
2012-12-11   Joomla! Component com_jooproperty 1.13.0 - Multiple Vulnerabilities 16 WEB D4NB4R
2012-12-11   MyBB Bank- 3 Plugin - SQL Injection 21 WEB Red_Hat
2003-10-22   DansGuardian 2.2.x - Denied URL Cross-Site Scripting 15 WEB Richard Maudsley
2003-10-21   FuzzyMonkey 2.11 - MyClassifieds Email Variable SQL Injection 20 WEB Ezhilan
2003-10-21   Vivisimo Clustering Engine - Search Script Cross-Site Scripting 19 WEB ComSec
2003-10-20   Dansie Shopping Cart - Server Error Message Installation Full Path Disclosure 18 WEB Dr_Ponidi
2003-10-20   DeskPro 1.1 - Multiple SQL Injections 16 WEB Aviram Jenik
2003-10-20   Caucho Resin 2.0/2.1 - Multiple HTML Injection / Cross-Site Scripting Vulnerabilities 19 WEB Donnie Werner
2003-10-20   Bytehoard 0.7 - File Disclosure 18 WEB Ezhilan
2003-10-19   Geeklog 1.3.8 - Forgot Password SQL Injection 17 WEB Jouko Pynnonen
2003-10-18   GoldLink 3.0 - Cookie SQL Injection 18 WEB Weke
2003-10-15   Macromedia ColdFusion MX 6.0 - SQL Error Message Cross-Site Scripting 21 WEB Lorenzo Hernandez Garcia-Hierro
2012-12-09   Achievo 1.4.5 - Multiple Vulnerabilities (2) 16 WEB High-Tech Bridge SA
2012-12-09   Clipbucket 2.6 Revision 738 - Multiple SQL Injections 16 WEB High-Tech Bridge SA
2012-12-09   Cisco DPC2420 - Multiples Vulnerabilities 21 WEB Facundo M. de la Cruz
2012-12-09   MyBB KingChat Plugin - Persistent Cross-Site Scripting 21 WEB VipVince
2003-10-14   WrenSoft Zoom Search Engine 2.0 Build: 1018 - Cross-Site Scripting 17 WEB Ezhilan
2003-10-11   Gallery 1.4 - 'index.php' Remote File Inclusion 17 WEB peter
2003-10-08   PHP-Nuke 6.6 - 'admin.php' SQL Injection 19 WEB 1dt.w0lf
2003-10-08   GeekLog 1.3.x - HTML Injection 16 WEB Jelmer
2003-10-08   PayPal Store Front 3.0 - 'index.php' Remote File Inclusion 22 WEB Zone-h Security Team
2003-10-05   GuppY 2.4 - Remote File Access 22 WEB frog
2003-10-05   GuppY 2.4 - Cross-Site Scripting 20 WEB frog
2003-10-04   EternalMart Mailing List Manager 1.32 - Remote File Inclusion 24 WEB frog
2003-10-03   Divine Content Server 5.0 - Error Page Cross-Site Scripting 21 WEB valgasu
2003-10-03   Sun Cobalt RaQ 1.1/2.0/3.0/4.0 - 'Message.cgi' Cross-Site Scripting 22 WEB Lorenzo Hernandez Garcia-Hierro
2003-10-03   WordPress Core 0.6/0.7 - 'Blog.header.php' SQL Injection 20 WEB Seth Woolley
2003-10-01   mpnews pro 2.1.0.18 - Directory Traversal Information Disclosure 17 WEB Gama Sec
2003-10-01   Atrise Everyfind 5.0.2 - search Cross-Site Scripting 20 WEB Ezhilan
2003-10-01   DCP-Portal 5.5 - 'lostpassword.php?email' SQL Injection 21 WEB Lifo Fifo
2003-10-01   DCP-Portal 5.5 - 'advertiser.php?Password' SQL Injection 23 WEB Lifo Fifo
2012-12-07   m0n0wall 1.33 - Multiple Cross-Site Request Forgery Vulnerabilities 19 WEB Yann CAM
2003-09-29   Alan Ward A-Cart 2.0 - MSG Cross-Site Scripting 20 WEB G00db0y
2003-09-29   Geeklog 1.3.x - Cross-Site Scripting 19 WEB Lorenzo Hernandez Garcia-Hierro
2003-09-29   Geeklog 1.3.x - SQL Injection 21 WEB Lorenzo Hernandez Garcia-Hierro
2003-09-29   GuppY 2.4 - HTML Injection 21 WEB David Suzanne
2003-09-25   Software602 602Pro LAN SUITE 2003 - Sensitive User Information Storage 22 WEB Phuong Nguyen
2012-12-06   Kordil EDms 2.2.60rc3 - SQL Injection 24 WEB Woody Hughes
2003-09-24   yMonda Thread-IT 1.6 - Multiple HTML Injections 21 WEB Bahaa Naamneh
2003-09-20   myPHPNuke 1.8.8 - 'auth.inc.php' SQL Injection 21 WEB Lifo Fifo
2003-09-19   Flying Dog Software Powerslave 4.3 Portalmanager - 'sql_id' Information Disclosure 24 WEB H Zero Seven
2003-09-18   Mambo Site Server 4.0.14 - 'contact.php' Unauthorized Mail Relay 17 WEB Lifo Fifo
2003-09-18   Mambo Site Server 4.0.14 - 'emailarticle.php?id' SQL Injection 21 WEB Lifo Fifo
2003-09-18   Mambo Site Server 4.0.14 - 'banners.php?bid' SQL Injection 19 WEB Lifo Fifo
2003-09-16   NetWin DBabble 2.5 i - Cross-Site Scripting 17 WEB dr_insane