Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2003-09-12   vbPortal 2.0 alpha 8.1 - (Authenticated) SQL Injection 21 WEB frog
2012-12-04   Advantech Studio 7.0 - SCADA/HMI Directory Traversal 20 WEB Nin3
2003-09-09   Invision Power Board (IP.Board) 1.x - 'index.php' showtopic Cross-Site Scripting 23 WEB Boy Bear
2003-09-09   Escapade 0.2.1 Beta Scripting Engine - 'PAGE' Full Path Disclosure 20 WEB Bahaa Naamneh
2003-09-09   Escapade 0.2.1 Beta Scripting Engine - 'PAGE' Cross-Site Scripting 24 WEB Bahaa Naamneh
2003-09-08   phpBB 2.0.6 - URL BBCode HTML Injection 22 WEB keupon_ps2
2003-09-08   ICQ 2003 - Webfront Guestbook Cross-Site Scripting 19 WEB Donnie Werner
2012-12-03   FirePass SSL VPN - Local File Inclusion 20 WEB SEC Consult
2012-12-03   Symantec Messaging Gateway 9.5.3-3 - Arbitrary File Download 19 WEB Ben Williams
2012-12-03   Symantec Messaging Gateway 9.5.3-3 - Cross-Site Request Forgery 20 WEB Ben Williams
2012-12-03   SchoolCMS - Persistent Cross-Site Scripting 21 WEB VipVince
2012-12-03   MyBB KingChat Plugin - SQL Injection 21 WEB Red_Hat
2003-09-05   Digital Scribe 1.x - Error Function Cross-Site Scripting 23 WEB Secunia
2003-09-03   WebCalendar 0.9.x (Multiple Modules) - SQL Injection 20 WEB noconflic
2003-09-01   Sitebuilder 1.4 - 'sitebuilder.cgi' Directory Traversal 19 WEB Zero X
2003-09-01   TSguestbook 2.1 - 'Message' HTML Injection 18 WEB Trash-80
2003-09-01   Ezboard - 'invitefriends.php3' Cross-Site Scripting 19 WEB David F. Madrid
2003-08-27   eNdonesia 8.2/8.3 - 'Mod' Cross-Site Scripting 21 WEB Bahaa Naamneh
2003-08-27   AldWeb MiniPortail 1.9/2.x - 'LNG' Cross-Site Scripting 20 WEB Bahaa Naamneh
2003-08-26   Attila PHP 3.0 - SQL Injection Unauthorized Privileged Access 24 WEB frog
2003-08-26   Py-Membres 4.x - 'Pass_done.php' SQL Injection 22 WEB frog
2003-08-26   Py-Membres 4.x - 'Secure.php' Unauthorized Access 24 WEB frog
2003-08-25   Netbula Anyboard 9.9.5 6 - Information Disclosure 22 WEB cyber talon
2003-08-25   newsPHP 216 - Authentication Bypass 23 WEB Officerrr
2003-08-25   newsPHP 216 - Remote File Inclusion 20 WEB Officerrr
2003-08-23   IdealBB 1.4.9 Beta - HTML Injection 22 WEB Scott M
2003-08-18   Fusion News 3.3 - Unauthorized Account Addition 20 WEB DarkKnight
2003-08-16   MatrikzGB Guestbook 2.0 - Administrative Privilege Escalation 20 WEB Stephan Sattler
2003-08-15   Poster 2.0 - Unauthorized Privileged User Access 21 WEB DarkKnight
2003-08-13   Clickcess ChitChat.NET - topic title Cross-Site Scripting 23 WEB G00db0y
2003-08-13   Clickcess ChitChat.NET - name Cross-Site Scripting 19 WEB G00db0y
2012-11-30   SilverStripe CMS 3.0.2 - (Multiple Vulnerabilities) Cross-Site Scripting / Cross-Site Request Forger 20 WEB Sense of Security
2012-11-30   SmartCMS - '/index.php?menuitem' SQL Injection / Cross-Site Scripting 20 WEB Yakir Wizman
2012-11-30   Free Hosting Manager 2.0 - 'id' SQL Injection 23 WEB Yakir Wizman
2003-08-13   HolaCMS 1.2.x - 'HTMLtags.php' Local File Inclusion 21 WEB Virginity Security
2003-08-13   Xoops 1.0/1.3.x - BBCode HTML Injection 24 WEB frog
2003-08-13   SurgeLDAP 1.0 d - 'User.cgi' Cross-Site Scripting 25 WEB Ziv Kamir
2003-08-12   Eudora WorldMail 2.0 - Search Cross-Site Scripting 27 WEB Donnie Werner
2003-08-12   HostAdmin - Full Path Disclosure 20 WEB G00db0y
2003-08-11   PHPOutsourcing Zorum 3.4 - Full Path Disclosure 20 WEB Zone-h Security Team
2003-08-11   phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 earch Module - 'PDA_limit' Cross-Site Scripting 24 WEB Lorenzo Hernandez Garcia-Hierro
2003-08-11   phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 pagemaster Module - 'PAGE_id' Cross-Site Scripting 25 WEB Lorenzo Hernandez Garcia-Hierro
2003-08-11   phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 fatcat Module - 'fatcat_id' Cross-Site Scripting 23 WEB Lorenzo Hernandez Garcia-Hierro
2003-08-11   phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 Calendar Module - 'day' Cross-Site Scripting 24 WEB Lorenzo Hernandez Garcia-Hierro
2003-08-11   PHP Website 0.7.3/0.8.2/0.8.3/0.9.2 Calendar Module - SQL Injection 27 WEB Lorenzo Hernandez Garcia-Hierro
2003-08-11   News Wizard 2.0 - Full Path Disclosure 26 WEB G00db0y
2003-08-11   PHPOutSourcing Zorum 3.x - Cross-Site Scripting 22 WEB G00db0y
2003-08-11   Better Basket Pro 3.0 Store Builder - Full Path Disclosure 23 WEB G00db0y
2003-08-11   Stellar Docs 1.2 - Full Path Disclosure 24 WEB G00db0y
2003-08-11   DCForum+ 1.2 - 'Subject' HTML Injection 21 WEB G00db0y
2012-11-29   FCKEditor Core ASP 2.6.8 - Arbitrary File Upload Protection Bypass 17 WEB Soroush Dalili
2012-11-29   Oracle OpenSSO 8.0 - Multiple Cross-Site Scripting POST Injection Vulnerabilities 20 WEB LiquidWorm
2003-08-09   Invision Power Board (IP.Board) 1.0/1.1/1.2 - 'admin.php' Cross-Site Scripting 21 WEB Boy Bear
2003-08-09   geeeekShop 1.4 - Information Disclosure 23 WEB G00db0y
2003-08-08   PostNuke 0.6/0.7 web_links Module - TTitle Cross-Site Scripting 22 WEB Lorenzo Hernandez Garcia-Hierro
2003-08-08   PostNuke 0.6/0.7 Downloads Module - TTitle Cross-Site Scripting 23 WEB Lorenzo Hernandez Garcia-Hierro
2003-08-08   C-Cart 1.0 - Full Path Disclosure 22 WEB G00db0y
2003-08-07   IdealBB 1.4.9 - 'error.asp' Cross-Site Scripting 20 WEB G00db0y
2003-08-06   vBulletin 3.0 - 'register.php' HTML Injection 19 WEB Ferruh Mavituna
2003-08-04   Macromedia Dreamweaver MX 6.0 - PHP User Authentication Suite Cross-Site Scripting 23 WEB Lorenzo Hernandez Garcia-Hierro
2003-07-31   MOD Guthabenhack 1.3 For Woltlab Burning Board - SQL Injection 20 WEB ben.moeckel@badwebmasters.net
2012-11-28   gleamtech filevista/fileultimate 4.6 - Directory Traversal 20 WEB Soroush Dalili
2003-07-28   Softshoe - Parse-file Cross-Site Scripting 24 WEB Bahaa Naamneh
2003-07-27   Gallery 1.2/1.3.x - Search Engine Cross-Site Scripting 23 WEB Larry Nguyen
2003-07-28   PBLang 4.0/4.56 Bulletin Board System - IMG Tag HTML Injection 19 WEB Quan Van Truong
2003-07-25   e107 Website System 0.554 - HTML Injection 19 WEB Pete Foster
2003-07-24   e107 Website System 0.555 - 'db.php' Information Disclosure 18 WEB Artoor Petrovich
2003-07-24   PHP Arena paFileDB 1.1.3/2.1.1/3.0/3.1 - Arbitrary File Upload / Execution 19 WEB Martin Eiszner
2003-07-24   PHP-Gastebuch 1.60 - Information Disclosure 21 WEB Jim Pangalos
2003-07-21   MoreGroupWare 0.6.8 - WEBMAIL2_INC_DIR Remote File Inclusion 25 WEB phil dunn
2003-07-21   WebCalendar 0.9.x - Local File Inclusion Information Disclosure 21 WEB noconflic
2003-07-21   atomicboard 0.6.2 - Directory Traversal 21 WEB gr00vy
2003-07-21   Drupal 4.1/4.2 - Cross-Site Scripting 21 WEB Ferruh Mavituna
2012-11-26   PRADO PHP Framework 3.2.0 - Arbitrary File Read 18 WEB LiquidWorm
2012-11-26   SmartCMS - 'index.php?idx' SQL Injection 21 WEB NoGe
2012-11-26   BuyClassifiedScript - PHP Code Injection 19 WEB d3b4g
2003-07-18   SimpNews 2.0.1/2.13 - 'path_simpnews' Remote File Inclusion 21 WEB PUPET
2003-07-17   eStore 1.0.1/1.0.2 - 'Settings.inc.php' Full Path Disclosure 22 WEB Bosen
2003-07-16   Ultimate Bulletin Board 6.0/6.2 - UBBER Cookie HTML Injection 21 WEB anti_acid
2003-07-16   .netCART Settings.XML - Information Disclosure 20 WEB G00db0y
2003-07-15   Splatt Forum 3/4 - Post Icon HTML Injection 23 WEB Lethalman
2012-11-25   ES CmS 0.1 - SQL Injection 23 WEB hossein beizaee
2012-11-25   jBilling 3.0.2 - Cross-Site Scripting 19 WEB Woody Hughes
2003-07-14   BlazeBoard 1.0 - Information Disclosure 20 WEB JackDaniels
2003-07-13   HTMLToNuke - Cross-Site Scripting 19 WEB JOCANOR
2003-07-13   ASP-DEV Discussion Forum 2.0 - Admin Directory Weak Default Permissions 27 WEB G00db0y
2003-07-10   Virtual Programming VP-ASP 5.00 - 'shopexd.asp' SQL Injection (2) 23 WEB Bosen & TioEuy
2003-07-10   Virtual Programming VP-ASP 5.00 - 'shopexd.asp' SQL Injection (1) 19 WEB TioEuy & AresU
2003-07-10   PHPForum 2.0 RC1 - 'Mainfile.php' Remote File Inclusion 19 WEB theblacksheep
2003-07-09   ChangshinSoft EZTrans Server - 'download.php' Directory Traversal 22 WEB SSR Team
2003-07-09   QuadComm Q-Shop 2.5 - Failure To Validate Credentials 22 WEB G00db0y
2012-11-21   PHP Server Monitor - Persistent Cross-Site Scripting 21 WEB loneferret
2012-11-21   ManageEngine ServiceDesk 8.0 - Multiple Vulnerabilities 22 WEB Vulnerability-Lab
2012-11-21   Yii Framework 1.1.8 - Search SQL Injection 25 WEB Juno_okyo
2003-07-07   CPanel 5.0/5.3/6.x - Admin Interface HTML Injection 23 WEB Ory Segal
2003-07-05   ProductCart 1.5/1.6/2.0 - File Disclosure 23 WEB Tri Huynh
2003-07-05   ProductCart 1.5/1.6/2.0 - 'MSG.asp' Cross-Site Scripting 21 WEB atomix
2003-07-04   ProductCart 1.5/1.6/2.0 - 'login.asp' SQL Injection 21 WEB Bosen
2003-07-04   ProductCart 1.5/1.6/2.0 - 'Custva.asp' SQL Injection 24 WEB Bosen
2003-07-02   Verity K2 Toolkit 2.20 Query Builder Search Script - Cross-Site Scripting 20 WEB SSR Team
2012-11-20   WordPress Plugin Facebook Survey 1.0 - SQL Injection 22 WEB Vulnerability Research Laboratory
2012-11-20   SonicWALL CDP 5040 6.x - Multiple Vulnerabilities 21 WEB Vulnerability-Lab
2003-07-02   Verity K2 Toolkit 2.20 - Cross-Site Scripting 19 WEB SSR Team
2003-06-30   PABox 1.6 - Password Reset 22 WEB silentscripter
2003-06-29   MegaBook 1.1/2.0/2.1 - Multiple HTML Injection Vulnerabilities 34 WEB Morning Wood
2003-06-29   CutePHP CuteNews 1.3 - HTML Injection 23 WEB Peter Winter-Smith
2003-06-26   iXmail 0.2/0.3 - 'iXmail_NetAttach.php' File Deletion 23 WEB leseulfrog
2012-11-19   weBid 1.0.5 - Directory Traversal 20 WEB loneferret
2012-11-19   WeBid 1.0.5 - Cross-Site Scripting 25 WEB Woody Hughes
2003-06-23   VisNetic WebMail 5.8.6 .6 - Information Disclosure 22 WEB posidron
2003-06-23   XMB Forum 1.8 - 'buddy.php?action' Cross-Site Scripting 23 WEB Knight Commander
2003-06-23   XMB Forum 1.8 - 'member.php?member' Cross-Site Scripting 19 WEB Knight Commander
2003-06-20   Tutos 1.1 - File_New Arbitrary File Upload 22 WEB François SORIN
2003-06-20   Tutos 1.1 - 'File_Select.php' Cross-Site Scripting 22 WEB François SORIN
2003-06-20   WebJeff FileManager 1.6 - File Disclosure 20 WEB Adam Stephens
2003-06-19   pMachine 1.0/2.x - Search Module Cross-Site Scripting 19 WEB Lorenzo Hernandez Garcia-Hierro
2003-06-19   pMachine 1.0/2.x - Multiple Script 'sfx' Full Path Disclosures 21 WEB Lorenzo Hernandez Garcia-Hierro
2003-06-19   pMachine 1.0/2.x - '/lib/' Multiple Script Direct Request Full Path Disclosures 27 WEB Lorenzo Hernandez Garcia-Hierro
2003-06-17   Tmax Soft JEUS 3.1.4 p1 - URL.jsp Cross-Site Scripting 21 WEB Jeremy Bae
2003-06-18   Kerio MailServer 5.6.3 - Web Mail DO_MAP Module Cross-Site Scripting 18 WEB David F.Madrid
2003-06-18   Kerio MailServer 5.6.3 - Web Mail ADD_ACL Module Cross-Site Scripting 19 WEB David F.Madrid
2003-06-18   phpMyAdmin 2.x - Information Disclosure 23 WEB Lorenzo Manuel Hernandez Garcia-Hierro
2003-06-17   SquirrelMail 1.2.11 - Multiple Vulnerabilities 21 WEB dr_insane
2003-06-17   SquirrelMail 1.2.11 Administrator Plugin - 'options.php' Arbitrary Admin Account Creation 25 WEB dr_insane
2003-06-17   SquirrelMail 1.2.11 - 'move_messages.php' Arbitrary File Moving 24 WEB dr_insane