2001-07-02
|
|
Citrix Nfuse 1.51 - Webroot Disclosure
|
4 |
WEB
|
sween
|
2012-09-01
|
|
Joomla! Component Spider Calendar - SQL Injection
|
4 |
WEB
|
D4NB4R
|
2012-09-01
|
|
SugarCRM Community Edition 6.5.2 (Build 8410) - Multiple Vulnerabilities
|
4 |
WEB
|
Brendan Coles
|
2012-08-31
|
|
OTRS Open Technology Real Services 3.1.8/3.1.9 - Cross-Site Scripting
|
5 |
WEB
|
Mike Eduard
|
2012-08-31
|
|
vBulletin Yet Another Awards System 4.0.2 - SQL Injection
|
4 |
WEB
|
Backsl@sh/Dan
|
2012-08-30
|
|
Booking System Pro - Cross-Site Request Forgery
|
4 |
WEB
|
DaOne
|
2001-06-13
|
|
SiteWare 2.5/3.0/3.1 Editor Desktop - Directory Traversal
|
4 |
WEB
|
Foundstone Labs
|
2012-08-29
|
|
WordPress Plugin HD Webplayer 1.1 - SQL Injection
|
4 |
WEB
|
JoinSe7en
|
2012-08-29
|
|
Disqus Blog Comments - Blind SQL Injection
|
4 |
WEB
|
Spy_w4r3
|
2012-08-28
|
|
Conceptronic Grab'n'Go and Sitecom Storage Center - Password Disclosure
|
4 |
WEB
|
Mattijs van Ommeren
|
2012-08-28
|
|
RV Shopping Cart - Cross-Site Request Forgery
|
4 |
WEB
|
DaOne
|
2012-08-28
|
|
RV Article Publisher - Cross-Site Request Forgery
|
4 |
WEB
|
DaOne
|
2012-08-28
|
|
mieric AddressBook 1.0 - SQL Injection
|
3 |
WEB
|
Jean Pascal Pereira
|
2012-08-28
|
|
CommPort 1.01 - Multiple Vulnerabilities
|
4 |
WEB
|
Jean Pascal Pereira
|
2012-08-27
|
|
aoop CMS 0.3.6 - Multiple Vulnerabilities
|
4 |
WEB
|
Julien Ahrens
|
2012-08-27
|
|
Elcom CMS 7.4.10 - Community Manager Insecure Arbitrary File Upload
|
4 |
WEB
|
Sense of Security
|
2012-08-27
|
|
xt:Commerce VEYTON 4.0.15 - 'products_name_de' Script Insertion
|
4 |
WEB
|
LiquidWorm
|
2012-08-27
|
|
WordPress Plugin Count Per Day 3.2.3 - Cross-Site Scripting
|
4 |
WEB
|
Crim3R
|
2012-08-27
|
|
Vlinks 2.0.3 - 'id' SQL Injection
|
4 |
WEB
|
JIKO
|
2012-08-27
|
|
web@all CMS 2.0 - Multiple Vulnerabilities
|
4 |
WEB
|
LiquidWorm
|
2012-08-27
|
|
XWiki 4.2-milestone-2 - Multiple Persistent Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Shai rod
|
2012-08-27
|
|
Wiki Web Help 0.3.9 - Multiple Persistent Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Shai rod
|
2001-04-15
|
|
PHPSlash 0.5.3 2/0.6.1 - URL Block Arbitrary File Disclosure
|
4 |
WEB
|
tobozo tagada
|
2012-08-24
|
|
businesswiki 2.5rc3 - Persistent Cross-Site Scripting / Arbitrary file upload
|
4 |
WEB
|
Shai rod
|
2012-08-24
|
|
Easy Banner Pro - 'index.php' Local File Inclusion
|
4 |
WEB
|
Yakir Wizman
|
2012-08-24
|
|
AB Banner Exchange - 'index.php' Local File Inclusion
|
4 |
WEB
|
Yakir Wizman
|
2012-08-24
|
|
Text Exchange Pro - 'index.php' Local File Inclusion
|
4 |
WEB
|
Yakir Wizman
|
2012-08-24
|
|
Ad Manager Pro - Multiple Vulnerabilities
|
4 |
WEB
|
Yakir Wizman
|
2012-08-24
|
|
webpa 1.1.0.1 - Multiple Vulnerabilities
|
4 |
WEB
|
dun
|
2012-08-23
|
|
Ad Manager Pro 4 - Local File Inclusion
|
4 |
WEB
|
CorryL
|
2012-08-23
|
|
op5 Monitoring 5.4.2 - VM Applicance Multiple Vulnerabilities
|
4 |
WEB
|
loneferret
|
2012-08-23
|
|
letodms 3.3.6 - Multiple Vulnerabilities
|
3 |
WEB
|
Shai rod
|
2001-04-02
|
|
PHP-Nuke 1.0/2.5/3.0/4.x - Remote Ad Banner URL Change
|
4 |
WEB
|
Juan Diego
|
2012-08-22
|
|
XODA 0.4.5 - Arbitrary '.PHP' File Upload (Metasploit)
|
4 |
WEB
|
Metasploit
|
2012-08-22
|
|
E-Mail Security Virtual Appliance - 'learn-msg.cgi' Command Injection (Metasploit)
|
3 |
WEB
|
Metasploit
|
2012-08-22
|
|
VamCart 0.9 - Cross-Site Request Forgery
|
4 |
WEB
|
DaOne
|
2012-08-22
|
|
OpenDocMan 1.2.6.1 - Cross-Site Request Forgery (Password Change)
|
3 |
WEB
|
Shai rod
|
2012-08-21
|
|
Clipbucket 2.5 - Blind SQL Injection
|
4 |
WEB
|
loneferret
|
2012-08-21
|
|
Symantec Web Gateway 5.0.3.18 - Arbitrary Password Change
|
4 |
WEB
|
Kc57
|
2012-08-21
|
|
Symantec Web Gateway 5.0.3.18 - Arbitrary Password Change (Metasploit)
|
3 |
WEB
|
Kc57
|
2012-08-21
|
|
Clipbucket 2.5 - Directory Traversal
|
4 |
WEB
|
loneferret
|
2012-08-21
|
|
XODA Document Management System 0.4.5 - Cross-Site Scripting / Arbitrary File Upload
|
4 |
WEB
|
Shai rod
|
2012-08-20
|
|
IOServer 1.0.18.0 - Directory Traversal
|
4 |
WEB
|
hinge
|
2012-08-20
|
|
uebimiau webmail 2.7.2 - Persistent Cross-Site Scripting
|
4 |
WEB
|
Shai rod
|
2012-08-20
|
|
YourArcadeScript 2.4 - 'index.php?id' SQL Injection
|
4 |
WEB
|
DaOne
|
2012-08-20
|
|
Hivemail Webmail - Multiple Persistent Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Shai rod
|
2012-08-20
|
|
PG Portal Pro - Cross-Site Request Forgery
|
4 |
WEB
|
Noxious
|
2012-08-20
|
|
GWebmail 0.7.3 - Cross-Site Scripting / Local File Inclusion / Remote Code Execution
|
4 |
WEB
|
Shai rod
|
2012-08-20
|
|
hupa webmail 0.0.2 - Persistent Cross-Site Scripting
|
4 |
WEB
|
Shai rod
|
2012-08-20
|
|
Alpha Networks ADSL2/2+ Wireless Router ASL-26555 - Password Disclosure
|
4 |
WEB
|
Alberto Ortega
|
2012-08-20
|
|
Clipbucket 2.5 - Cross-Site Request Forgery
|
4 |
WEB
|
DaOne
|
2012-08-20
|
|
T-dah Webmail - Cross-Site Request Forgery / Persistent Cross-Site Scripting
|
4 |
WEB
|
Yakir Wizman
|
2012-08-18
|
|
ManageEngine OpUtils 6.0 - Persistent Cross-Site Scripting
|
5 |
WEB
|
loneferret
|
2012-08-18
|
|
IlohaMail Webmail - Persistent Cross-Site Scripting
|
4 |
WEB
|
Shai rod
|
2012-08-17
|
|
Jaow CMS 2.3 - Blind SQL Injection
|
4 |
WEB
|
loneferret
|
2000-01-06
|
|
Phorum 3.0.7 - 'auth.php3' Backdoor Access
|
4 |
WEB
|
Max Vision
|
2000-01-01
|
|
Phorum 3.0.7 - 'violation.php3' Arbitrary Email Relay
|
5 |
WEB
|
Max Vision
|
2000-01-06
|
|
Phorum 3.0.7 - 'admin.php3' Unverified Administrative Password Change
|
5 |
WEB
|
Max Vision
|
2012-08-17
|
|
webid 1.0.4 - Multiple Vulnerabilities
|
4 |
WEB
|
dun
|
2012-08-17
|
|
T-dah Webmail Client - Multiple Persistent Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Shai rod
|
2012-08-17
|
|
hastymail2 webmail 1.1 rc2 - Persistent Cross-Site Scripting
|
4 |
WEB
|
Shai rod
|
2012-08-17
|
|
Inferno vBShout 2.5.2 - SQL Injection
|
4 |
WEB
|
Luit
|
2012-08-17
|
|
ManageEngine OpStor 7.4 - Multiple Vulnerabilities
|
4 |
WEB
|
Vulnerability-Lab
|
2012-08-17
|
|
Social Engine 4.2.5 - Multiple Vulnerabilities
|
4 |
WEB
|
Vulnerability-Lab
|
2012-08-17
|
|
Jaow CMS 2.3 - Cross-Site Request Forgery
|
4 |
WEB
|
DaOne
|
2012-08-16
|
|
ProQuiz 2.0.2 - Cross-Site Request Forgery
|
4 |
WEB
|
DaOne
|
2012-08-16
|
|
Roundcube Webmail 0.8.0 - Persistent Cross-Site Scripting
|
4 |
WEB
|
Shai rod
|
2012-08-15
|
|
sphpforum 0.4 - Multiple Vulnerabilities
|
4 |
WEB
|
loneferret
|
2012-08-15
|
|
Cyclope Employee Surveillance Solution 6.0 6.1.0 6.2.0 - Multiple Vulnerabilities
|
4 |
WEB
|
loneferret
|
2012-08-15
|
|
xt:Commerce 3.04 SP2.1 - Blind SQL Injection
|
4 |
WEB
|
stoffline.com
|
2012-08-15
|
|
MaxForum 1.0.0 - Local File Inclusion
|
4 |
WEB
|
ahwak2000
|
2012-08-15
|
|
MobileCartly 1.0 - Arbitrary File Upload
|
4 |
WEB
|
ICheer_No0M
|
2001-01-11
|
|
Basilix Webmail 0.9.7 - Incorrect File Permissions
|
4 |
WEB
|
Tamer Sahin
|
2012-08-13
|
|
IBM Websphere MQ File Transfer Edition Web Gateway - Insufficient Access Control
|
4 |
WEB
|
Nir Valtman
|
2012-08-13
|
|
IBM Websphere MQ File Transfer Edition Web Gateway - Cross-Site Request Forgery
|
4 |
WEB
|
Nir Valtman
|
2012-08-13
|
|
Hotel Booking Portal 0.1 - Multiple Vulnerabilities
|
4 |
WEB
|
Yakir Wizman
|
2012-08-13
|
|
WordPress Plugin RSVPMaker 2.5.4 - Persistent Cross-Site Scripting
|
4 |
WEB
|
Chris Kellum
|
2000-11-24
|
|
Phorum 3.x - Arbitrary File Read
|
4 |
WEB
|
Joao Gouveia
|
2000-11-23
|
|
Phorum 3.x - PHP Configuration Disclosure
|
4 |
WEB
|
Joao Gouveia
|
2012-08-10
|
|
MobileCartly 1.0 - Arbitrary File Write
|
3 |
WEB
|
Yakir Wizman
|
2012-08-11
|
|
ProQuiz 2.0.2 - Multiple Vulnerabilities
|
4 |
WEB
|
L0n3ly-H34rT
|
2012-08-11
|
|
Flynax General Classifieds CMS 4.0 - Multiple Vulnerabilities
|
5 |
WEB
|
Vulnerability-Lab
|
2012-08-10
|
|
WordPress Plugin Mz-jajak 2.1 - SQL Injection
|
3 |
WEB
|
StRoNiX
|
2012-08-10
|
|
MobileCartly 1.0 - Arbitrary File Deletion
|
4 |
WEB
|
GoLd_M
|
2012-08-09
|
|
Cyclope Employee Surveillance Solution 6.0/6.1.0/6.2.0/6.2.1/6.3.0 - SQL Injection
|
4 |
WEB
|
loneferret
|
2012-08-09
|
|
Kamads Classifieds 2.0 - Admin Hash Disclosure
|
4 |
WEB
|
Mr.tro0oqy
|
2012-08-09
|
|
Joomla! Component com_fireboard - SQL Injection
|
4 |
WEB
|
Vulnerability-Lab
|
2012-08-08
|
|
IBM Proventia Network Mail Security System 2.5 - POST File Read
|
4 |
WEB
|
muts
|
2012-08-08
|
|
xeams email server 4.4 build 5720 - Persistent Cross-Site Scripting
|
4 |
WEB
|
loneferret
|
2012-08-08
|
|
winwebmail server 3.8.1.6 - Persistent Cross-Site Scripting
|
4 |
WEB
|
loneferret
|
2012-08-08
|
|
WordPress Plugin ThreeWP Email Reflector 1.13 - Persistent Cross-Site Scripting
|
4 |
WEB
|
loneferret
|
2012-08-08
|
|
T-dah Webmail Client 3.2.0-2.3 - Persistent Cross-Site Scripting
|
4 |
WEB
|
loneferret
|
2012-08-08
|
|
Surgemail 6.0a4 - Persistent Cross-Site Scripting
|
4 |
WEB
|
loneferret
|
2012-08-08
|
|
smartermail free 9.2 - Persistent Cross-Site Scripting
|
4 |
WEB
|
loneferret
|
2012-08-08
|
|
WordPress Plugin simplemail 1.0.6 - Persistent Cross-Site Scripting
|
4 |
WEB
|
loneferret
|
2012-08-08
|
|
WordPress Plugin postie 1.4.3 - Persistent Cross-Site Scripting
|
4 |
WEB
|
loneferret
|
2012-08-08
|
|
OTRS Open Technology Real Services 3.1.4 - Persistent Cross-Site Scripting
|
4 |
WEB
|
loneferret
|
2012-08-08
|
|
WordPress Plugin mini mail Dashboard widget 1.42 - Persistent Cross-Site Scripting
|
3 |
WEB
|
loneferret
|
2012-08-08
|
|
Alt-N MDaemon free 12.5.4 - Persistent Cross-Site Scripting
|
4 |
WEB
|
loneferret
|
2012-08-08
|
|
ManageEngine ServiceDesk Plus 8.1 - Persistent Cross-Site Scripting
|
4 |
WEB
|
loneferret
|
2012-08-08
|
|
mailtraq 2.17.3.3150 - Persistent Cross-Site Scripting
|
4 |
WEB
|
loneferret
|
2012-08-08
|
|
afterlogic mailsuite pro (VMware Appliance) 6.3 - Persistent Cross-Site Scripting
|
4 |
WEB
|
loneferret
|
2012-08-08
|
|
mailenable enterprise 6.5 - Persistent Cross-Site Scripting
|
4 |
WEB
|
loneferret
|
2012-08-08
|
|
escon supportportal pro 3.0 - Persistent Cross-Site Scripting
|
4 |
WEB
|
loneferret
|
2012-08-08
|
|
emailarchitect enterprise email server 10.0 - Persistent Cross-Site Scripting
|
4 |
WEB
|
loneferret
|
2012-08-08
|
|
Axigen Mail Server 8.0.1 - Persistent Cross-Site Scripting
|
4 |
WEB
|
loneferret
|
2012-08-08
|
|
Openconstructor CMS 3.12.0 - 'id' Multiple SQL Injections
|
4 |
WEB
|
Lorenzo Cantoni
|
2012-08-08
|
|
Inout Mobile Webmail APP - Persistent Cross-Site Scripting
|
4 |
WEB
|
Vulnerability-Lab
|
2012-08-08
|
|
iauto mobile Application 2012 - Multiple Vulnerabilities
|
4 |
WEB
|
Vulnerability-Lab
|
2012-08-08
|
|
AraDown - Blind SQL Injection
|
4 |
WEB
|
G-B
|
2012-08-08
|
|
Joomla! Component com_enmasse 1.2.0.4 - SQL Injection
|
4 |
WEB
|
D4NB4R
|
2012-08-08
|
|
WespaJuris 3.0 - Multiple Vulnerabilities
|
4 |
WEB
|
WhiteCollarGroup
|
2012-08-07
|
|
Zoho BugTracker - Multiple Persistent Cross-Site Scripting Vulnerabilities
|
5 |
WEB
|
LiquidWorm
|
2000-10-07
|
|
phpix 1.0 - Directory Traversal
|
4 |
WEB
|
Synnergy.net
|
2012-08-05
|
|
WordPress Plugin Effective Lead Management 3.0.0 - Persistent Cross-Site Scripting
|
4 |
WEB
|
Chris Kellum
|
2012-08-05
|
|
Tickets CAD 2.20G - Multiple Vulnerabilities
|
4 |
WEB
|
chap0
|
2012-08-05
|
|
Islamnt Islam Forum Script 1.2 - Blind SQL Injection
|
4 |
WEB
|
s3n4t00r
|
2000-09-07
|
|
nathan purciful phpphotoalbum 0.9.9 - Directory Traversal
|
4 |
WEB
|
pestilence
|
2012-08-02
|
|
am4ss Support System 1.2 - PHP Code Injection
|
4 |
WEB
|
i-Hmx
|
2012-08-02
|
|
am4ss 1.2 - Multiple Vulnerabilities
|
3 |
WEB
|
s3n4t00r
|
2012-08-02
|
|
Joomla! Component com_joomgalaxy 1.2.0.4 - Multiple Vulnerabilities
|
4 |
WEB
|
D4NB4R
|
2012-08-02
|
|
WebPageTest - Arbitrary '.PHP' File Upload (Metasploit)
|
4 |
WEB
|
Metasploit
|
2012-08-01
|
|
ManageEngine Mobile Application Manager 10 - SQL Injection
|
4 |
WEB
|
Vulnerability-Lab
|
2012-08-01
|
|
ManageEngine Application Manager 10 - Multiple Vulnerabilities
|
4 |
WEB
|
Vulnerability-Lab
|
2012-08-01
|
|
Joomla! Component com_movm - SQL Injection
|
4 |
WEB
|
D4NB4R
|