Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2002-10-03   Michael Schatz Books 0.54/0.6 PostNuke Module - Cross-Site Scripting 22 WEB Pistone
2002-10-02   MySimpleNews 1.0 - Remote Readable Administrator Password 22 WEB frog
2002-10-02   MySimpleNews 1.0 - PHP Injection 21 WEB frog
2002-10-02   phpWebSite 0.8.3 - 'article.php' Cross-Site Scripting 25 WEB Sp.IC
2002-10-02   Midicart PHP - Arbitrary File Upload 25 WEB frog
2002-10-02   Jetty 3.1.6/3.1.7/4.1 Servlet Engine - Arbitrary Command Execution 23 WEB Matt Moore
2002-10-02   Midicart PHP - Information Disclosure 26 WEB frog
2002-10-02   TightAuction 3.0 - Config.INC Information Disclosure 24 WEB frog
2012-10-11   vOlk Botnet Framework 4.0 - Multiple Vulnerabilities 26 WEB Vulnerability-Lab
2012-10-11   Omnistar Document Manager 8.0 - Multiple Vulnerabilities 21 WEB Vulnerability-Lab
2002-10-02   Py-Membres 3.1 - 'index.php' Unauthorized Access 23 WEB frog
2002-09-30   Sun ONE Starter Kit 2.0 / ASTAware SearchDisc 3.1 - Search Engine Directory Traversal 22 WEB ET LoWNOISE
2002-09-29   EmuMail 5.0 Email Form - Script Injection 21 WEB FVS
2002-09-29   EmuMail 5.0 - Web Root Full Path Disclosure 23 WEB FVS
2002-09-28   Jetty 4.1 Servlet Engine - Cross-Site Scripting 21 WEB Skinnay
2002-09-27   vBulletin 2.0.3 - 'calendar.php' Command Execution 28 WEB gosper
2002-09-26   PostNuke 0.72 - 'modules.php' Cross-Site Scripting 22 WEB Mark Grimes
2012-10-10   ServersCheck Monitoring Software 9.0.12/9.0.14 - Persistent Cross-Site Scripting 23 WEB loneferret
2002-09-25   phpWebSite 0.8.3 - News Message HTML Injection 26 WEB das@hush.com
2002-09-25   Drupal 4.0 - News Message HTML Injection 23 WEB das@hush.com
2002-09-25   PHP-Nuke 6.0 - 'modules.php' SQL Injection 23 WEB Pedro Inacio
2002-09-25   DaCode 1.2 - News Message HTML Injection 25 WEB das@hush.com
2002-09-25   NPDS 4.8 - News Message HTML Injection 24 WEB das@hush.com
2002-09-25   PHP-Nuke 6.0 - News Message HTML Injection 22 WEB das@hush.com
2002-09-24   PHP-Nuke 6.0/6.5 - Search Form Cross-Site Scripting 24 WEB Mark Grimes
2012-10-10   Auxilium RateMyPet - Arbitrary File Upload (Metasploit) 25 WEB Metasploit
2012-10-10   qdPM 7.0 - Arbitrary '.PHP' File Upload (Metasploit) 22 WEB Metasploit
2012-10-10   phpMyAdmin 3.5.2.2 - 'server_sync.php' Backdoor (Metasploit) 25 WEB Metasploit
2012-10-10   PhpTax - 'pfilez' Execution Remote Code Injection (Metasploit) 26 WEB Metasploit
2002-09-24   XOOPS 1.0 RC3 - HTML Injection 23 WEB das@hush.com
2002-09-23   phpWebSite 0.8.2 - PHP File Inclusion 22 WEB Tim Vandermeersch
2012-10-09   Endpoint Protector 4.0.4.0 - Multiple Vulnerabilities 23 WEB Vulnerability-Lab
2002-09-23   Rudi Benkovic JAWMail 1.0 - Script Injection 23 WEB Ulf Harnhammar
2002-09-19   SquirrelMail 1.2.6/1.2.7 - Multiple Cross-Site Scripting Vulnerabilities 23 WEB DarC KonQuest
2012-10-08   Web Help Desk by SolarWinds - Persistent Cross-Site Scripting 25 WEB loneferret
2002-09-17   Lycos HTMLGear - guestGear CSS HTML Injection 23 WEB Matthew Murphy
2012-10-07   MyAuth3 - Blind SQL Injection 23 WEB Marcio Almeida
2012-10-07   Blog Mod 0.1.9 - 'index.php?month' SQL Injection 26 WEB WhiteCollarGroup
2002-09-09   PHPGB 1.1/1.2 - PHP Code Injection 24 WEB ppp-design
2002-09-09   phpGB 1.1 - HTML Injection 25 WEB ppp-design
2002-09-09   WoltLab Burning Board 2.0 - SQL Injection 23 WEB Cano2
2002-09-09   phpGB 1.x - SQL Injection 25 WEB ppp-design
2002-09-07   PHP 4.2.3 - Header Function Script Injection 23 WEB Matthew Murphy
2002-09-03   Aestiva HTML/OS 2.4 - Cross-Site Scripting 26 WEB eax@3xT.org
2002-09-03   Super Site Searcher - Remote Command Execution 24 WEB luca.ercoli
2002-08-31   FactoSystem Weblog 0.9/1.0/1.1 - Multiple SQL Injections 20 WEB Matthew Murphy
2002-08-24   PHPReactor 1.2.7 - Style Attribute HTML Injection 24 WEB Matthew Murphy
2002-08-22   Achievo 0.7/0.8/0.9 - Remote File Inclusion / Command Execution 23 WEB Jeroen Latour
2012-10-04   Novell Sentinel Log Manager 1.2.0.2 - Retention Policy 21 WEB Piotr Chmylkowski
2012-10-04   phpMyBitTorrent 2.04 - Multiple Vulnerabilities 24 WEB waraxe
2012-10-04   Template CMS 2.1.1 - Multiple Vulnerabilities 23 WEB High-Tech Bridge SA
2012-10-04   phpMyChat Plus 1.94 RC1 - Multiple Vulnerabilities 22 WEB L0n3ly-H34rT
2002-08-20   Mozilla Bonsai 1.3 - Full Path Disclosure 28 WEB Stan Bubrouski
2002-08-20   Mozilla Bonsai - Multiple Cross-Site Scripting Vulnerabilities 21 WEB Stan Bubrouski
2002-08-19   Kerio MailServer 5.0/5.1 Web Mail - Multiple Cross-Site Scripting Vulnerabilities 23 WEB Abraham Lincoln
2002-08-19   Mantis Bug Tracker 0.15.x/0.16/0.17.x - JPGraph Remote File Inclusion Command Execution 24 WEB Joao Gouveia
2002-08-19   Ilia Alshanetsky FUDForum 1.2.8/1.9.8/2.0.2 - File Modification 23 WEB Ulf Harnhammar
2002-08-19   Ilia Alshanetsky FUDForum 1.2.8/1.9.8/2.0.2 - File Disclosure 25 WEB Ulf Harnhammar
2012-10-03   Omnistar Mailer 7.2 - Multiple Vulnerabilities 23 WEB Vulnerability-Lab
2012-10-03   WordPress Plugin spider Calendar - Multiple Vulnerabilities 27 WEB D4NB4R
2002-08-14   Leszek Krupinski L-Forum 2.4 - Search Script SQL Injection 24 WEB Matthew Murphy
2002-08-10   Midicart ASP - Remote Customer Information Retrieval 20 WEB Dimitri Sekhniashvili
2002-07-30   Dispair 0.1/0.2 - Remote Command Execution 23 WEB anonymous
2002-08-01   Bharat Mediratta Gallery 1.x - Remote File Inclusion 24 WEB PowerTech
2002-07-29   ShoutBox 1.2 - 'Form' HTML Injection 25 WEB delusion
2012-10-02   phptax 0.8 - Remote Code Execution 22 WEB Jean Pascal Pereira
2002-07-29   dotProject 0.2.1 - User Cookie Authentication Bypass 19 WEB pokleyzz
2002-07-29   phpBB2 Gender Mod 1.1.3 - SQL Injection 25 WEB langtuhaohoa caothuvolam
2002-07-29   Ben Chivers Easy Guestbook 1.0 - Administrative Access 23 WEB Arek Suroboyo
2002-07-29   Ben Chivers Easy Homepage Creator 1.0 - File Modification 21 WEB Arek Suroboyo
2012-10-01   WordPress Theme Archin 3.2 - Configuration Access 24 WEB bwall
2002-07-24   Cobalt Qube 3.0 - Authentication Bypass 24 WEB pokley
2002-07-19   Geeklog 1.3.5 - HTML Attribute Cross-Site Scripting 24 WEB Ulf Harnhammar
2002-07-17   PHP-Wiki 1.2/1.3 - Cross-Site Scripting 27 WEB Pistone
2002-07-17   Macromedia Sitespring 1.2 - Default Error Page Cross-Site Scripting 23 WEB Peter Gründl
2002-07-15   IMHO Webmail 0.9x - Account Hijacking 23 WEB Security Bugware
2002-07-11   Sun i-Runbook 2.5.2 - Directory and File Content Disclosure 23 WEB JWC
2002-07-10   Fluid Dynamics Search Engine 2.0 - Cross-Site Scripting 23 WEB VALDEUX
2002-07-10   Apache Tomcat 4.0.3 - Denial of Service 'Device Name' / Cross-Site Scripting 24 WEB Matt Moore
2002-07-02   phpAuction 1/2 - Unauthorized Administrative Access 25 WEB ethx
2002-07-01   BlackBoard 5.0 - Cross-Site Scripting 24 WEB Berend-Jan Wever
2002-07-01   BBC Education Betsie 1.5 - Parserl.pl Cross-Site Scripting 21 WEB Mark Rowe
2002-06-21   YaBB 1 - Invalid Topic Error Page Cross-Site Scripting 25 WEB methodic
2002-06-19   BasiliX Webmail 1.1 - Message Content Script Injection 23 WEB Ulf Harnhammar
2002-06-06   WebScripts WebBBS 4.x/5.0 - Remote Command Execution 28 WEB NERF Security
2002-06-17   PHP-Address 0.2 e - Remote File Inclusion 23 WEB Tim Vandermeerch
2002-06-16   osCommerce 2.1 - Remote File Inclusion 22 WEB Tim Vandermeerch
2002-06-17   Wolfram Research webMathematica 4.0 - File Disclosure 22 WEB Andrew Badr
2002-06-15   My Postcards 6.0 - 'MagicCard.cgi' Arbitrary File Disclosure 24 WEB cult
2002-06-15   ZeroBoard 4.1 - PHP Include File Arbitrary Command Execution 24 WEB onlooker
2002-06-14   Mewsoft NetAuction 3.0 - Cross-Site Scripting 24 WEB windows-1256
2002-06-14   PHP Classifieds 6.0.5 - Cross-Site Scripting 24 WEB windows-1256
2012-09-27   Trend Micro Control Manager 5.5/6.0 AdHocQuery - (Authenticated) Blind SQL Injection 27 WEB otoy
2012-09-27   JAMF Casper Suite MDM - Cross-Site Request Forgery 26 WEB Jacob Holcomb
2002-06-13   Ruslan Communications Builder - Authentication Bypass 22 WEB Alexander Korchagin
2002-06-12   MakeBook 2.2 - Form Field Input Validation 25 WEB b0iler
2002-06-11   CGIScript.net csNews 1.0 - Header File Type Restriction Bypass 22 WEB Steve Gustin
2002-06-11   CGIScript.net csNews 1.0 - Double URL Encoding Unauthorized Administrative Access 22 WEB Steve Gustin
2002-06-10   W-Agora 4.1.x - Remote File Inclusion 22 WEB frog
2002-06-10   Geeklog 1.3.5 - Calendar Event Form Script Injection 24 WEB Ahmet Sabri ALPER
2002-06-10   MyHelpDesk 20020509 - SQL Injection 22 WEB Ahmet Sabri ALPER
2002-06-10   MyHelpDesk 20020509 - Cross-Site Scripting 23 WEB Ahmet Sabri ALPER
2002-06-10   Geeklog 1.3.5 - Multiple Cross-Site Scripting Vulnerabilities 23 WEB Ahmet Sabri ALPER
2012-09-26   ViArt Shop Evaluation 4.1 - Multiple Remote File Inclusions 21 WEB L0n3ly-H34rT
2012-09-25   ViArt Shop Enterprise 4.1 - Arbitrary Command Execution 23 WEB LiquidWorm
2002-06-10   MyHelpDesk 20020509 - HTML Injection 26 WEB Ahmet Sabri ALPER
2002-06-06   Voxel Dot Net CBms 0.x - Multiple Code Injection Vulnerabilities 24 WEB Ulf Harnhammar
2002-06-06   Splatt Forum 3.0 - Image Tag HTML Injection 27 WEB MegaHz
2002-06-03   Teekai Tracking Online 1.0 - Cross-Site Scripting 24 WEB frog
2002-05-30   CGIScript.net - 'csPassword.cgi' 1.0 HTAccess File Modification 25 WEB Steve Gustin
2002-05-30   CGIScript.net - 'csPassword.cgi' 1.0 Information Disclosure 23 WEB Steve Gustin
2002-05-29   Gafware CFXImage 1.6.4/1.6.6 - ShowTemp File Disclosure 23 WEB Richard Brain
2002-05-28   Image Display System 0.8.1 - Directory Existence Disclosure 23 WEB isox
2002-05-26   PHPBB2 - Image Tag HTML Injection 27 WEB Martijn Boerwinkel
2002-05-20   GNU Mailman 2.0.x - Admin Login Cross-Site Scripting 23 WEB office
2002-05-24   OpenBB 1.0.0 RC3 - Cross-Site Scripting 23 WEB frog
2002-05-24   OpenBB 1.0 - Unauthorized Moderator Access 20 WEB frog
2002-05-24   OpenBB 1.0.0 RC3 - BBCode Cross Agent HTML Injection 24 WEB frog
2002-05-24   ViewCVS 0.9.2 - Cross-Site Scripting 23 WEB office
2002-05-19   Hosting Controller 1.x - 'Browse.asp' File Disclosure 21 WEB Bao Dai Nhan
2002-05-17   mcNews 1.x - File Disclosure 28 WEB frog
2002-05-18   Phorum 3.3.2 - Cross-Site Scripting 23 WEB markus arndt
2002-05-17   CGIScript.net 1.0 - Information Disclosure 22 WEB Steve Gustin
2002-05-17   Phorum 3.3.2a - Remote Command Execution 24 WEB markus arndt
2002-05-17   Hosting Controller 1.4 - Import Root Directory Command Execution 23 WEB hdlkha