Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2002-11-25   Web Server Creator Web Portal 0.1 - Remote File Inclusion 7 WEB frog
2002-11-25   phpBB 2.0.3 - Script Injection 7 WEB Pete Foster
2002-11-25   vBulletin 2.0.x/2.2.x - 'members2.php' Cross-Site Scripting 7 WEB Sp.IC
2012-10-17   Oracle WebCenter Sites (FatWire Content Server) - Multiple Vulnerabilities 7 WEB SEC Consult
2012-10-17   ManageEngine Support Center Plus 7908 - Multiple Vulnerabilities 7 WEB xistence
2012-10-17   Symphony CMS 2.3 - Multiple Vulnerabilities 7 WEB Wireghoul
2012-10-17   Sisfokol 4.0 - Arbitrary File Upload 7 WEB cr4wl3r
2002-11-25   PHP-Nuke 5.x/6.0/6.5 Beta 1 - Multiple Cross-Site Scripting Vulnerabilities 8 WEB Matthew Murphy
2002-11-22   vBulletin 2.0/2.2.x - 'memberlist.php' Cross-Site Scripting 8 WEB Sp.IC
2002-11-13   phpBB Advanced Quick Reply Hack 1.0/1.1 - Remote File Inclusion 8 WEB Hai Nam Luke
2002-11-12   W3Mail 1.0.6 - File Disclosure 8 WEB Tim Brown
2002-11-11   EZ Systems HTTPBench 1.1 - Information Disclosure 8 WEB Tacettin Karadeniz
2012-10-16   Visual Tools DVR3.0.6.16_ vx series 4.2.19.2 - Multiple Vulnerabilities 7 WEB Andrea Fabrizi
2012-10-16   Joomla! Component com_icagenda - 'id' Multiple Vulnerabilities 7 WEB Dark-Puzzle
2012-10-16   MyBB Profile Albums Plugin 0.9 - 'albums.php?album' SQL Injection 7 WEB Zixem
2002-11-07   CuteCast 1.2 - User Credential Disclosure 8 WEB Zero-X
2012-10-15   BigPond 3G21WB - Multiple Vulnerabilities 7 WEB Roberto Paleari
2012-10-15   airVisionNVR 1.1.13 - 'readfile()' Disclosure / SQL Injection 7 WEB pennyGrit
2012-10-15   Cartweaver 3 - Local File Inclusion 7 WEB HaxOr
2002-11-01   ION Script 1.4 - Remote File Disclosure 9 WEB Zero X
2002-11-01   PHP-Nuke 5.6 - 'modules.php' SQL Injection 7 WEB kill9
2002-11-01   Jason Orcutt Prometheus 3.0/4.0/6.0 - Remote File Inclusion 7 WEB Karol Wiesek
2002-10-28   Benjamin Lefevre Dobermann Forum 0.x - 'newtopic.php?subpath' Remote File Inclusion 7 WEB frog
2002-10-28   Benjamin Lefevre Dobermann Forum 0.x - 'index.php?subpath' Remote File Inclusion 7 WEB frog
2002-10-28   Benjamin Lefevre Dobermann Forum 0.x - 'enteteacceuil.php?subpath' Remote File Inclusion 6 WEB frog
2002-10-28   Benjamin Lefevre Dobermann Forum 0.x - 'entete.php?subpath' Remote File Inclusion 7 WEB frog
2002-10-28   MailReader.com 2.3.x - 'NPH-MR.cgi' File Disclosure 7 WEB pokleyzz
2002-10-24   Mojo Mail 2.7 - Email Form Cross-Site Scripting 7 WEB Daniel Boland
2002-10-23   MyMarket 1.71 - 'Form_Header.php' Cross-Site Scripting 7 WEB qber66
2002-10-22   gBook 1.4 - Administrative Access 8 WEB frog
2002-10-21   PHP Arena PAFileDB 1.1.3/2.1.1/3.0 - 'Email To Friend' Cross-Site Scripting 14 WEB ersatz
2002-10-21   KMMail 1.0 - E-Mail HTML Injection 7 WEB Ulf Harnhammar
2002-10-18   YaBB 1.40/1.41 - Login Cross-Site Scripting 8 WEB Nir Adar
2002-10-18   vBulletin 2.0/2.2.x - Cross-Site Scripting 8 WEB Sp.IC
2002-10-10   PHPRank 1.8 - 'add.php' Cross-Site Scripting 9 WEB Jedi/Sector One
2002-10-10   PHPBBMod 1.3.3 - PHPInfo Information Disclosure 9 WEB Roland Verlander
2002-10-10   PHPReactor 1.2.7 pl1 - 'browse.php' Cross-Site Scripting 7 WEB Arab VieruZ
2012-10-16   Project Pier - Arbitrary File Upload (Metasploit) 8 WEB Metasploit
2002-10-09   Authoria HR Suite - 'AthCGI.exe' Cross-Site Scripting 8 WEB Max
2002-10-08   SurfControl SuperScout Email Filter 3.5 - User Credential Disclosure 8 WEB ken@FTU
2002-10-08   SurfControl SuperScout Email Filter 3.5 - 'MsgError.asp' Cross-Site Scripting 8 WEB ken@FTU
2002-10-09   VBZoom 1.0 - Arbitrary File Upload 8 WEB hish
2002-10-09   Microsoft Content Management Server 2001 - Cross-Site Scripting 8 WEB overclocking_a_la_abuela
2002-10-08   VBZoom 1.0 - SQL Injection 8 WEB hish
2002-10-08   SSGBook 1.0 - Image Tag HTML Injection 8 WEB frog
2002-10-07   Killer Protection 1.0 - Information Disclosure 9 WEB frog
2002-10-04   phpLinkat 0.1 - Multiple Cross-Site Scripting Vulnerabilities 7 WEB Sp.IC
2002-10-03   phpMyNewsletter 0.6.10 - Remote File Inclusion 9 WEB frog
2002-10-03   Michael Schatz Books 0.54/0.6 PostNuke Module - Cross-Site Scripting 9 WEB Pistone
2002-10-02   MySimpleNews 1.0 - Remote Readable Administrator Password 8 WEB frog
2002-10-02   MySimpleNews 1.0 - PHP Injection 7 WEB frog
2002-10-02   phpWebSite 0.8.3 - 'article.php' Cross-Site Scripting 9 WEB Sp.IC
2002-10-02   Midicart PHP - Arbitrary File Upload 9 WEB frog
2002-10-02   Jetty 3.1.6/3.1.7/4.1 Servlet Engine - Arbitrary Command Execution 9 WEB Matt Moore
2002-10-02   Midicart PHP - Information Disclosure 8 WEB frog
2002-10-02   TightAuction 3.0 - Config.INC Information Disclosure 8 WEB frog
2012-10-11   vOlk Botnet Framework 4.0 - Multiple Vulnerabilities 8 WEB Vulnerability-Lab
2012-10-11   Omnistar Document Manager 8.0 - Multiple Vulnerabilities 7 WEB Vulnerability-Lab
2002-10-02   Py-Membres 3.1 - 'index.php' Unauthorized Access 8 WEB frog
2002-09-30   Sun ONE Starter Kit 2.0 / ASTAware SearchDisc 3.1 - Search Engine Directory Traversal 9 WEB ET LoWNOISE
2002-09-29   EmuMail 5.0 Email Form - Script Injection 7 WEB FVS
2002-09-29   EmuMail 5.0 - Web Root Full Path Disclosure 8 WEB FVS
2002-09-28   Jetty 4.1 Servlet Engine - Cross-Site Scripting 7 WEB Skinnay
2002-09-27   vBulletin 2.0.3 - 'calendar.php' Command Execution 8 WEB gosper
2002-09-26   PostNuke 0.72 - 'modules.php' Cross-Site Scripting 9 WEB Mark Grimes
2012-10-10   ServersCheck Monitoring Software 9.0.12/9.0.14 - Persistent Cross-Site Scripting 8 WEB loneferret
2002-09-25   phpWebSite 0.8.3 - News Message HTML Injection 7 WEB das@hush.com
2002-09-25   Drupal 4.0 - News Message HTML Injection 7 WEB das@hush.com
2002-09-25   PHP-Nuke 6.0 - 'modules.php' SQL Injection 7 WEB Pedro Inacio
2002-09-25   DaCode 1.2 - News Message HTML Injection 7 WEB das@hush.com
2002-09-25   NPDS 4.8 - News Message HTML Injection 7 WEB das@hush.com
2002-09-25   PHP-Nuke 6.0 - News Message HTML Injection 8 WEB das@hush.com
2002-09-24   PHP-Nuke 6.0/6.5 - Search Form Cross-Site Scripting 7 WEB Mark Grimes
2012-10-10   Auxilium RateMyPet - Arbitrary File Upload (Metasploit) 8 WEB Metasploit
2012-10-10   qdPM 7.0 - Arbitrary '.PHP' File Upload (Metasploit) 8 WEB Metasploit
2012-10-10   phpMyAdmin 3.5.2.2 - 'server_sync.php' Backdoor (Metasploit) 9 WEB Metasploit
2012-10-10   PhpTax - 'pfilez' Execution Remote Code Injection (Metasploit) 9 WEB Metasploit
2002-09-24   XOOPS 1.0 RC3 - HTML Injection 6 WEB das@hush.com
2002-09-23   phpWebSite 0.8.2 - PHP File Inclusion 7 WEB Tim Vandermeersch
2012-10-09   Endpoint Protector 4.0.4.0 - Multiple Vulnerabilities 7 WEB Vulnerability-Lab
2002-09-23   Rudi Benkovic JAWMail 1.0 - Script Injection 8 WEB Ulf Harnhammar
2002-09-19   SquirrelMail 1.2.6/1.2.7 - Multiple Cross-Site Scripting Vulnerabilities 8 WEB DarC KonQuest
2012-10-08   Web Help Desk by SolarWinds - Persistent Cross-Site Scripting 8 WEB loneferret
2002-09-17   Lycos HTMLGear - guestGear CSS HTML Injection 8 WEB Matthew Murphy
2012-10-07   MyAuth3 - Blind SQL Injection 7 WEB Marcio Almeida
2012-10-07   Blog Mod 0.1.9 - 'index.php?month' SQL Injection 8 WEB WhiteCollarGroup
2002-09-09   PHPGB 1.1/1.2 - PHP Code Injection 8 WEB ppp-design
2002-09-09   phpGB 1.1 - HTML Injection 8 WEB ppp-design
2002-09-09   WoltLab Burning Board 2.0 - SQL Injection 7 WEB Cano2
2002-09-09   phpGB 1.x - SQL Injection 8 WEB ppp-design
2002-09-07   PHP 4.2.3 - Header Function Script Injection 8 WEB Matthew Murphy
2002-09-03   Aestiva HTML/OS 2.4 - Cross-Site Scripting 7 WEB eax@3xT.org
2002-09-03   Super Site Searcher - Remote Command Execution 8 WEB luca.ercoli
2002-08-31   FactoSystem Weblog 0.9/1.0/1.1 - Multiple SQL Injections 7 WEB Matthew Murphy
2002-08-24   PHPReactor 1.2.7 - Style Attribute HTML Injection 8 WEB Matthew Murphy
2002-08-22   Achievo 0.7/0.8/0.9 - Remote File Inclusion / Command Execution 8 WEB Jeroen Latour
2012-10-04   Novell Sentinel Log Manager 1.2.0.2 - Retention Policy 7 WEB Piotr Chmylkowski
2012-10-04   phpMyBitTorrent 2.04 - Multiple Vulnerabilities 8 WEB waraxe
2012-10-04   Template CMS 2.1.1 - Multiple Vulnerabilities 7 WEB High-Tech Bridge SA
2012-10-04   phpMyChat Plus 1.94 RC1 - Multiple Vulnerabilities 7 WEB L0n3ly-H34rT
2002-08-20   Mozilla Bonsai 1.3 - Full Path Disclosure 9 WEB Stan Bubrouski
2002-08-20   Mozilla Bonsai - Multiple Cross-Site Scripting Vulnerabilities 7 WEB Stan Bubrouski
2002-08-19   Kerio MailServer 5.0/5.1 Web Mail - Multiple Cross-Site Scripting Vulnerabilities 7 WEB Abraham Lincoln
2002-08-19   Mantis Bug Tracker 0.15.x/0.16/0.17.x - JPGraph Remote File Inclusion Command Execution 8 WEB Joao Gouveia
2002-08-19   Ilia Alshanetsky FUDForum 1.2.8/1.9.8/2.0.2 - File Modification 8 WEB Ulf Harnhammar
2002-08-19   Ilia Alshanetsky FUDForum 1.2.8/1.9.8/2.0.2 - File Disclosure 10 WEB Ulf Harnhammar
2012-10-03   Omnistar Mailer 7.2 - Multiple Vulnerabilities 9 WEB Vulnerability-Lab
2012-10-03   WordPress Plugin spider Calendar - Multiple Vulnerabilities 8 WEB D4NB4R
2002-08-14   Leszek Krupinski L-Forum 2.4 - Search Script SQL Injection 8 WEB Matthew Murphy
2002-08-10   Midicart ASP - Remote Customer Information Retrieval 8 WEB Dimitri Sekhniashvili
2002-07-30   Dispair 0.1/0.2 - Remote Command Execution 8 WEB anonymous
2002-08-01   Bharat Mediratta Gallery 1.x - Remote File Inclusion 9 WEB PowerTech
2002-07-29   ShoutBox 1.2 - 'Form' HTML Injection 9 WEB delusion
2012-10-02   phptax 0.8 - Remote Code Execution 8 WEB Jean Pascal Pereira
2002-07-29   dotProject 0.2.1 - User Cookie Authentication Bypass 7 WEB pokleyzz
2002-07-29   phpBB2 Gender Mod 1.1.3 - SQL Injection 7 WEB langtuhaohoa caothuvolam
2002-07-29   Ben Chivers Easy Guestbook 1.0 - Administrative Access 7 WEB Arek Suroboyo
2002-07-29   Ben Chivers Easy Homepage Creator 1.0 - File Modification 7 WEB Arek Suroboyo
2012-10-01   WordPress Theme Archin 3.2 - Configuration Access 8 WEB bwall
2002-07-24   Cobalt Qube 3.0 - Authentication Bypass 8 WEB pokley
2002-07-19   Geeklog 1.3.5 - HTML Attribute Cross-Site Scripting 10 WEB Ulf Harnhammar
2002-07-17   PHP-Wiki 1.2/1.3 - Cross-Site Scripting 9 WEB Pistone
2002-07-17   Macromedia Sitespring 1.2 - Default Error Page Cross-Site Scripting 7 WEB Peter Gründl
2002-07-15   IMHO Webmail 0.9x - Account Hijacking 8 WEB Security Bugware
2002-07-11   Sun i-Runbook 2.5.2 - Directory and File Content Disclosure 8 WEB JWC