2003-07-28
|
|
Softshoe - Parse-file Cross-Site Scripting
|
5 |
WEB
|
Bahaa Naamneh
|
2003-07-27
|
|
Gallery 1.2/1.3.x - Search Engine Cross-Site Scripting
|
4 |
WEB
|
Larry Nguyen
|
2003-07-28
|
|
PBLang 4.0/4.56 Bulletin Board System - IMG Tag HTML Injection
|
4 |
WEB
|
Quan Van Truong
|
2003-07-25
|
|
e107 Website System 0.554 - HTML Injection
|
4 |
WEB
|
Pete Foster
|
2003-07-24
|
|
e107 Website System 0.555 - 'db.php' Information Disclosure
|
4 |
WEB
|
Artoor Petrovich
|
2003-07-24
|
|
PHP Arena paFileDB 1.1.3/2.1.1/3.0/3.1 - Arbitrary File Upload / Execution
|
4 |
WEB
|
Martin Eiszner
|
2003-07-24
|
|
PHP-Gastebuch 1.60 - Information Disclosure
|
4 |
WEB
|
Jim Pangalos
|
2003-07-21
|
|
MoreGroupWare 0.6.8 - WEBMAIL2_INC_DIR Remote File Inclusion
|
4 |
WEB
|
phil dunn
|
2003-07-21
|
|
WebCalendar 0.9.x - Local File Inclusion Information Disclosure
|
4 |
WEB
|
noconflic
|
2003-07-21
|
|
atomicboard 0.6.2 - Directory Traversal
|
4 |
WEB
|
gr00vy
|
2003-07-21
|
|
Drupal 4.1/4.2 - Cross-Site Scripting
|
4 |
WEB
|
Ferruh Mavituna
|
2012-11-26
|
|
PRADO PHP Framework 3.2.0 - Arbitrary File Read
|
4 |
WEB
|
LiquidWorm
|
2012-11-26
|
|
SmartCMS - 'index.php?idx' SQL Injection
|
4 |
WEB
|
NoGe
|
2012-11-26
|
|
BuyClassifiedScript - PHP Code Injection
|
5 |
WEB
|
d3b4g
|
2003-07-18
|
|
SimpNews 2.0.1/2.13 - 'path_simpnews' Remote File Inclusion
|
5 |
WEB
|
PUPET
|
2003-07-17
|
|
eStore 1.0.1/1.0.2 - 'Settings.inc.php' Full Path Disclosure
|
4 |
WEB
|
Bosen
|
2003-07-16
|
|
Ultimate Bulletin Board 6.0/6.2 - UBBER Cookie HTML Injection
|
5 |
WEB
|
anti_acid
|
2003-07-16
|
|
.netCART Settings.XML - Information Disclosure
|
4 |
WEB
|
G00db0y
|
2003-07-15
|
|
Splatt Forum 3/4 - Post Icon HTML Injection
|
5 |
WEB
|
Lethalman
|
2012-11-25
|
|
ES CmS 0.1 - SQL Injection
|
4 |
WEB
|
hossein beizaee
|
2012-11-25
|
|
jBilling 3.0.2 - Cross-Site Scripting
|
4 |
WEB
|
Woody Hughes
|
2003-07-14
|
|
BlazeBoard 1.0 - Information Disclosure
|
4 |
WEB
|
JackDaniels
|
2003-07-13
|
|
HTMLToNuke - Cross-Site Scripting
|
3 |
WEB
|
JOCANOR
|
2003-07-13
|
|
ASP-DEV Discussion Forum 2.0 - Admin Directory Weak Default Permissions
|
4 |
WEB
|
G00db0y
|
2003-07-10
|
|
Virtual Programming VP-ASP 5.00 - 'shopexd.asp' SQL Injection (2)
|
4 |
WEB
|
Bosen & TioEuy
|
2003-07-10
|
|
Virtual Programming VP-ASP 5.00 - 'shopexd.asp' SQL Injection (1)
|
4 |
WEB
|
TioEuy & AresU
|
2003-07-10
|
|
PHPForum 2.0 RC1 - 'Mainfile.php' Remote File Inclusion
|
3 |
WEB
|
theblacksheep
|
2003-07-09
|
|
ChangshinSoft EZTrans Server - 'download.php' Directory Traversal
|
3 |
WEB
|
SSR Team
|
2003-07-09
|
|
QuadComm Q-Shop 2.5 - Failure To Validate Credentials
|
4 |
WEB
|
G00db0y
|
2012-11-21
|
|
PHP Server Monitor - Persistent Cross-Site Scripting
|
4 |
WEB
|
loneferret
|
2012-11-21
|
|
ManageEngine ServiceDesk 8.0 - Multiple Vulnerabilities
|
5 |
WEB
|
Vulnerability-Lab
|
2012-11-21
|
|
Yii Framework 1.1.8 - Search SQL Injection
|
4 |
WEB
|
Juno_okyo
|
2003-07-07
|
|
CPanel 5.0/5.3/6.x - Admin Interface HTML Injection
|
4 |
WEB
|
Ory Segal
|
2003-07-05
|
|
ProductCart 1.5/1.6/2.0 - File Disclosure
|
4 |
WEB
|
Tri Huynh
|
2003-07-05
|
|
ProductCart 1.5/1.6/2.0 - 'MSG.asp' Cross-Site Scripting
|
5 |
WEB
|
atomix
|
2003-07-04
|
|
ProductCart 1.5/1.6/2.0 - 'login.asp' SQL Injection
|
5 |
WEB
|
Bosen
|
2003-07-04
|
|
ProductCart 1.5/1.6/2.0 - 'Custva.asp' SQL Injection
|
5 |
WEB
|
Bosen
|
2003-07-02
|
|
Verity K2 Toolkit 2.20 Query Builder Search Script - Cross-Site Scripting
|
4 |
WEB
|
SSR Team
|
2012-11-20
|
|
WordPress Plugin Facebook Survey 1.0 - SQL Injection
|
4 |
WEB
|
Vulnerability Research Laboratory
|
2012-11-20
|
|
SonicWALL CDP 5040 6.x - Multiple Vulnerabilities
|
4 |
WEB
|
Vulnerability-Lab
|
2003-07-02
|
|
Verity K2 Toolkit 2.20 - Cross-Site Scripting
|
4 |
WEB
|
SSR Team
|
2003-06-30
|
|
PABox 1.6 - Password Reset
|
4 |
WEB
|
silentscripter
|
2003-06-29
|
|
MegaBook 1.1/2.0/2.1 - Multiple HTML Injection Vulnerabilities
|
5 |
WEB
|
Morning Wood
|
2003-06-29
|
|
CutePHP CuteNews 1.3 - HTML Injection
|
4 |
WEB
|
Peter Winter-Smith
|
2003-06-26
|
|
iXmail 0.2/0.3 - 'iXmail_NetAttach.php' File Deletion
|
4 |
WEB
|
leseulfrog
|
2012-11-19
|
|
weBid 1.0.5 - Directory Traversal
|
4 |
WEB
|
loneferret
|
2012-11-19
|
|
WeBid 1.0.5 - Cross-Site Scripting
|
4 |
WEB
|
Woody Hughes
|
2003-06-23
|
|
VisNetic WebMail 5.8.6 .6 - Information Disclosure
|
4 |
WEB
|
posidron
|
2003-06-23
|
|
XMB Forum 1.8 - 'buddy.php?action' Cross-Site Scripting
|
4 |
WEB
|
Knight Commander
|
2003-06-23
|
|
XMB Forum 1.8 - 'member.php?member' Cross-Site Scripting
|
4 |
WEB
|
Knight Commander
|
2003-06-20
|
|
Tutos 1.1 - File_New Arbitrary File Upload
|
4 |
WEB
|
François SORIN
|
2003-06-20
|
|
Tutos 1.1 - 'File_Select.php' Cross-Site Scripting
|
5 |
WEB
|
François SORIN
|
2003-06-20
|
|
WebJeff FileManager 1.6 - File Disclosure
|
4 |
WEB
|
Adam Stephens
|
2003-06-19
|
|
pMachine 1.0/2.x - Search Module Cross-Site Scripting
|
4 |
WEB
|
Lorenzo Hernandez Garcia-Hierro
|
2003-06-19
|
|
pMachine 1.0/2.x - Multiple Script 'sfx' Full Path Disclosures
|
4 |
WEB
|
Lorenzo Hernandez Garcia-Hierro
|
2003-06-19
|
|
pMachine 1.0/2.x - '/lib/' Multiple Script Direct Request Full Path Disclosures
|
4 |
WEB
|
Lorenzo Hernandez Garcia-Hierro
|
2003-06-17
|
|
Tmax Soft JEUS 3.1.4 p1 - URL.jsp Cross-Site Scripting
|
5 |
WEB
|
Jeremy Bae
|
2003-06-18
|
|
Kerio MailServer 5.6.3 - Web Mail DO_MAP Module Cross-Site Scripting
|
4 |
WEB
|
David F.Madrid
|
2003-06-18
|
|
Kerio MailServer 5.6.3 - Web Mail ADD_ACL Module Cross-Site Scripting
|
4 |
WEB
|
David F.Madrid
|
2003-06-18
|
|
phpMyAdmin 2.x - Information Disclosure
|
4 |
WEB
|
Lorenzo Manuel Hernandez Garcia-Hierro
|
2003-06-17
|
|
SquirrelMail 1.2.11 - Multiple Vulnerabilities
|
4 |
WEB
|
dr_insane
|
2003-06-17
|
|
SquirrelMail 1.2.11 Administrator Plugin - 'options.php' Arbitrary Admin Account Creation
|
4 |
WEB
|
dr_insane
|
2003-06-17
|
|
SquirrelMail 1.2.11 - 'move_messages.php' Arbitrary File Moving
|
4 |
WEB
|
dr_insane
|
2003-06-16
|
|
Snitz Forums 2000 3.4.03 - 'search.asp' Cross-Site Scripting
|
4 |
WEB
|
JeiAr
|
2003-06-16
|
|
LedNews 0.7 Post Script - Code Injection
|
4 |
WEB
|
gilbert vilvoorde
|
2003-06-15
|
|
PMachine 2.2.1 - '/Lib.Inc.php' Remote File Inclusion / Command Execution
|
5 |
WEB
|
frog
|
2003-06-12
|
|
Infinity CGI Exploit Scanner 3.11 - Remote Command Execution
|
5 |
WEB
|
badpack3t
|
2003-06-12
|
|
Infinity CGI Exploit Scanner 3.11 - Cross-Site Scripting
|
4 |
WEB
|
badpack3t
|
2003-06-13
|
|
PostNuke 0.723 - 'user.php' UNAME Cross-Site Scripting
|
4 |
WEB
|
David F. Madrid
|
2012-11-16
|
|
friendsinwar FAQ Manager - 'view_faq.php?question' SQL Injection
|
4 |
WEB
|
unsuprise
|
2003-06-13
|
|
Sphera HostingDirector 1.0/2.0/3.0 VDS Control Panel - Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Lorenzo Hernandez Garcia-Hierro
|
2003-06-13
|
|
PostNuke 0.723 - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
David F. Madrid
|
2003-06-13
|
|
Sphera HostingDirector 1.0/2.0/3.0 - VDS Control Panel Account Configuration Modification
|
4 |
WEB
|
Lorenzo Hernandez Garcia-Hierro
|
2003-06-09
|
|
H-Sphere 2.x - HTML Template Inclusion Cross-Site Scripting
|
4 |
WEB
|
Lorenzo Hernandez Garcia-Hierro
|
2003-06-06
|
|
Zentrack 2.2/2.3/2.4 - 'index.php' Remote File Inclusion
|
4 |
WEB
|
farking
|
2003-06-06
|
|
Maxwebportal 1.30 - Remote Database Disclosure
|
4 |
WEB
|
JeiAr
|
2003-06-06
|
|
Maxwebportal 1.30 - 'search.asp?Search' Cross-Site Scripting
|
4 |
WEB
|
JeiAr
|
2003-06-06
|
|
Synkron.Web 3.0 - HTML Injection
|
3 |
WEB
|
Gyrniff
|
2003-06-05
|
|
ImageFolio 2.2x/3.0/3.1 - 'Admin.cgi' Directory Traversal
|
3 |
WEB
|
Paul Craig
|
2012-11-15
|
|
ReciPHP 1.1 - SQL Injection
|
4 |
WEB
|
cr4wl3r
|
2012-11-15
|
|
BabyGekko 1.2.2e - Multiple Vulnerabilities
|
4 |
WEB
|
High-Tech Bridge SA
|
2012-11-15
|
|
Friends in War Make or Break 1.3 - Authentication Bypass
|
6 |
WEB
|
d3b4g
|
2012-11-15
|
|
iDev Rentals 1.0 - Multiple Vulnerabilities
|
4 |
WEB
|
Vulnerability-Lab
|
2003-06-04
|
|
Mailtraq 2.2 - Webmail Utility Full Path Disclosure
|
5 |
WEB
|
Ziv Kamir
|
2003-06-04
|
|
Mailtraq 2.2 - 'Browse.asp' Cross-Site Scripting
|
4 |
WEB
|
Ziv Kamir
|
2002-10-12
|
|
PHP 4 - 'PHPInfo()' Cross-Site Scripting
|
4 |
WEB
|
Matthew Murphy
|
2003-06-04
|
|
Xpressions Interactive - Multiple SQL Injections
|
4 |
WEB
|
Paul Craig
|
2003-06-02
|
|
SPChat 0.8 Module - Remote File Inclusion
|
4 |
WEB
|
Rynho Zeros Web
|
2003-06-02
|
|
WebChat 2.0 - 'users.php' Cross-Site Scripting
|
4 |
WEB
|
Rynho Zeros Web
|
2003-06-02
|
|
WebChat 2.0 - 'users.php?Database Username Disclosure
|
4 |
WEB
|
Rynho Zeros Web
|
2012-11-14
|
|
MYRE Realty Manager - Multiple Vulnerabilities
|
4 |
WEB
|
d3b4g
|
2012-11-14
|
|
MYREphp Vacation Rental Software - Multiple Vulnerabilities
|
4 |
WEB
|
d3b4g
|
2012-11-14
|
|
Myrephp Business Directory - Multiple Vulnerabilities
|
4 |
WEB
|
d3b4g
|
2012-11-14
|
|
friendsinwar FAQ Manager - SQL Injection / Authentication Bypass
|
4 |
WEB
|
d3b4g
|
2012-11-14
|
|
Narcissus - Remote Command Execution
|
4 |
WEB
|
dun
|
2012-11-14
|
|
dotProject 2.1.6 - Remote File Inclusion
|
4 |
WEB
|
dun
|
2003-06-02
|
|
Webfroot Shoutbox 2.32 - 'Expanded.php' Directory Traversal
|
4 |
WEB
|
_6mO_HaCk
|
2003-06-02
|
|
Webchat 2.0 Module - Full Path Disclosure
|
4 |
WEB
|
Rynho Zeros Web
|
2003-06-02
|
|
Webfroot Shoutbox 2.32 - 'Expanded.php' Remote Command Execution
|
4 |
WEB
|
_6mO_HaCk
|
2003-05-31
|
|
WebCortex WebStores2000 - SQL Injection
|
4 |
WEB
|
Bosen
|
2003-05-31
|
|
iisCart2000 - Arbitrary File Upload
|
5 |
WEB
|
Bosen
|
2003-05-30
|
|
cPanel 5/6 / Formail-Clone - E-Mail Restriction Bypass
|
4 |
WEB
|
Chad C. Keep
|
2003-05-29
|
|
Zeus Web Server 4.x - Admin Interface 'VS_Diag.cgi' Cross-Site Scripting
|
2 |
WEB
|
Hugo Vazquez
|
2003-05-29
|
|
M-TECH P-Synch 6.2.5 - 'nph-psa.exe?css' Remote File Inclusion
|
4 |
WEB
|
JeiAr
|
2003-05-29
|
|
M-TECH P-Synch 6.2.5 - 'nph-psf.exe?css' Remote File Inclusion
|
4 |
WEB
|
JeiAr
|
2003-05-29
|
|
Webfroot Shoutbox 2.32 - Remote Command Execution
|
4 |
WEB
|
pokleyzz
|
2012-11-13
|
|
Eventy CMS 1.8 Plus - Multiple Vulnerabilities
|
5 |
WEB
|
Vulnerability-Lab
|
2003-05-29
|
|
Geeklog 1.3.x - (Authenticated) SQL Injection
|
4 |
WEB
|
pokleyzz
|
2003-05-29
|
|
philboard 1.14 - 'philboard_admin.asp' Authentication Bypass
|
4 |
WEB
|
aresu@bosen.net
|
2003-05-29
|
|
Cafelog b2 0.6 - Remote File Inclusion
|
4 |
WEB
|
pokleyzz
|
2003-05-29
|
|
Webfroot Shoutbox 2.32 - 'URI' File Disclosure
|
4 |
WEB
|
pokleyzz
|
2003-05-28
|
|
Bandmin 1.4 - Cross-Site Scripting
|
4 |
WEB
|
silent needel
|
2003-05-27
|
|
Newsscript 1.0 - Administrative Privilege Escalation
|
4 |
WEB
|
Peter Winter-Smith
|
2012-11-12
|
|
vBulletin vBay 1.1.9 - Error-Based SQL Injection
|
5 |
WEB
|
Dan UK
|
2012-11-12
|
|
Bananadance Wiki b2.2 - Multiple Vulnerabilities
|
4 |
WEB
|
Vulnerability-Lab
|
2003-05-26
|
|
PostNuke 0.72x Phoenix Glossary Module - SQL Injection
|
4 |
WEB
|
Lorenzo Manuel Hernandez Garcia-Hierro
|
2003-05-24
|
|
Ultimate PHP Board 1.9 - 'admin_iplog.php' Arbitrary PHP Execution
|
6 |
WEB
|
euronymous
|
2003-05-24
|
|
BLNews 2.1.3 - Remote File Inclusion
|
5 |
WEB
|
Over_G
|
2003-05-23
|
|
IISProtect 2.1/2.2 - Web Administration Interface SQL Injection
|
6 |
WEB
|
Gyrniff
|
2003-06-22
|
|
XMB Forum 1.8 - 'member.php' Cross-Site Scripting
|
4 |
WEB
|
Marc Ruef
|
2003-05-21
|
|
SudBox Boutique 1.2 - 'login.php' Authentication Bypass
|
5 |
WEB
|
frog
|
2003-05-20
|
|
ttCMS 2.2/2.3 / ttForum 1.1 - 'index.php' Instant-Messages Preferences SQL Injection
|
5 |
WEB
|
ScriptSlave@gmx.net
|
2003-05-17
|
|
ttCMS 2.2/2.3 - 'header.php' Remote File Inclusion
|
5 |
WEB
|
ScriptSlave@gmx.net
|
2003-05-16
|
|
EZ Publish 2.2 - 'index.php' IMG Tag Cross-Site Scripting
|
4 |
WEB
|
Ferruh Mavituna
|
2003-05-15
|
|
OneOrZero Helpdesk 1.4 - 'install.php' Administrative Access
|
4 |
WEB
|
frog
|