|
2012-08-08
|
|
WordPress Plugin postie 1.4.3 - Persistent Cross-Site Scripting
|
9 |
WEB
|
loneferret
|
|
2012-08-08
|
|
OTRS Open Technology Real Services 3.1.4 - Persistent Cross-Site Scripting
|
9 |
WEB
|
loneferret
|
|
2012-08-08
|
|
WordPress Plugin mini mail Dashboard widget 1.42 - Persistent Cross-Site Scripting
|
8 |
WEB
|
loneferret
|
|
2012-08-08
|
|
Alt-N MDaemon free 12.5.4 - Persistent Cross-Site Scripting
|
9 |
WEB
|
loneferret
|
|
2012-08-08
|
|
ManageEngine ServiceDesk Plus 8.1 - Persistent Cross-Site Scripting
|
8 |
WEB
|
loneferret
|
|
2012-08-08
|
|
mailtraq 2.17.3.3150 - Persistent Cross-Site Scripting
|
8 |
WEB
|
loneferret
|
|
2012-08-08
|
|
afterlogic mailsuite pro (VMware Appliance) 6.3 - Persistent Cross-Site Scripting
|
9 |
WEB
|
loneferret
|
|
2012-08-08
|
|
mailenable enterprise 6.5 - Persistent Cross-Site Scripting
|
9 |
WEB
|
loneferret
|
|
2012-08-08
|
|
escon supportportal pro 3.0 - Persistent Cross-Site Scripting
|
9 |
WEB
|
loneferret
|
|
2012-08-08
|
|
emailarchitect enterprise email server 10.0 - Persistent Cross-Site Scripting
|
8 |
WEB
|
loneferret
|
|
2012-08-08
|
|
Axigen Mail Server 8.0.1 - Persistent Cross-Site Scripting
|
9 |
WEB
|
loneferret
|
|
2012-08-08
|
|
Openconstructor CMS 3.12.0 - 'id' Multiple SQL Injections
|
8 |
WEB
|
Lorenzo Cantoni
|
|
2012-08-08
|
|
Inout Mobile Webmail APP - Persistent Cross-Site Scripting
|
9 |
WEB
|
Vulnerability-Lab
|
|
2012-08-08
|
|
iauto mobile Application 2012 - Multiple Vulnerabilities
|
8 |
WEB
|
Vulnerability-Lab
|
|
2012-08-08
|
|
AraDown - Blind SQL Injection
|
9 |
WEB
|
G-B
|
|
2012-08-08
|
|
Joomla! Component com_enmasse 1.2.0.4 - SQL Injection
|
9 |
WEB
|
D4NB4R
|
|
2012-08-08
|
|
WespaJuris 3.0 - Multiple Vulnerabilities
|
9 |
WEB
|
WhiteCollarGroup
|
|
2012-08-07
|
|
Zoho BugTracker - Multiple Persistent Cross-Site Scripting Vulnerabilities
|
11 |
WEB
|
LiquidWorm
|
|
2000-10-07
|
|
phpix 1.0 - Directory Traversal
|
9 |
WEB
|
Synnergy.net
|
|
2012-08-05
|
|
WordPress Plugin Effective Lead Management 3.0.0 - Persistent Cross-Site Scripting
|
8 |
WEB
|
Chris Kellum
|
|
2012-08-05
|
|
Tickets CAD 2.20G - Multiple Vulnerabilities
|
10 |
WEB
|
chap0
|
|
2012-08-05
|
|
Islamnt Islam Forum Script 1.2 - Blind SQL Injection
|
9 |
WEB
|
s3n4t00r
|
|
2000-09-07
|
|
nathan purciful phpphotoalbum 0.9.9 - Directory Traversal
|
9 |
WEB
|
pestilence
|
|
2012-08-02
|
|
am4ss Support System 1.2 - PHP Code Injection
|
9 |
WEB
|
i-Hmx
|
|
2012-08-02
|
|
am4ss 1.2 - Multiple Vulnerabilities
|
8 |
WEB
|
s3n4t00r
|
|
2012-08-02
|
|
Joomla! Component com_joomgalaxy 1.2.0.4 - Multiple Vulnerabilities
|
8 |
WEB
|
D4NB4R
|
|
2012-08-02
|
|
WebPageTest - Arbitrary '.PHP' File Upload (Metasploit)
|
10 |
WEB
|
Metasploit
|
|
2012-08-01
|
|
ManageEngine Mobile Application Manager 10 - SQL Injection
|
10 |
WEB
|
Vulnerability-Lab
|
|
2012-08-01
|
|
ManageEngine Application Manager 10 - Multiple Vulnerabilities
|
10 |
WEB
|
Vulnerability-Lab
|
|
2012-08-01
|
|
Joomla! Component com_movm - SQL Injection
|
10 |
WEB
|
D4NB4R
|
|
2012-08-01
|
|
Joomla! Component com_niceajaxpoll 1.3.0 - SQL Injection
|
10 |
WEB
|
Patrick de Brouwer
|
|
2000-08-21
|
|
PHP-Nuke 1.0/2.5 - Administrative Privileges
|
11 |
WEB
|
bruj0
|
|
2012-07-31
|
|
Dr. Web Control Center 6.00.3.201111300 - Cross-Site Scripting
|
9 |
WEB
|
Oliver Karow
|
|
2012-07-30
|
|
Symantec Web Gateway 5.0.3.18 - 'deptUploads_data.php?groupid' Blind SQL Injection
|
8 |
WEB
|
Kc57
|
|
2012-07-27
|
|
CuteFlow 2.11.2 - Arbitrary File Upload (Metasploit)
|
11 |
WEB
|
Metasploit
|
|
2012-07-24
|
|
Zabbix 2.0.1 - Session Extractor
|
11 |
WEB
|
muts
|
|
2012-07-24
|
|
WordPress Plugin Front End Upload 0.5.4.4 - Arbitrary '.PHP' File Upload
|
12 |
WEB
|
Chris Kellum
|
|
2012-07-24
|
|
Symantec Web Gateway 5.0.3.18 - Local/Remote File Inclusion / Remote Command Execution
|
9 |
WEB
|
muts
|
|
2012-07-23
|
|
SpiceWorks 5.3.75941 - Persistent Cross-Site Scripting / (Authenticated) SQL Injection
|
10 |
WEB
|
dookie
|
|
2012-07-23
|
|
Alienvault Open Source SIEM (OSSIM) 3.1 - Reflected Cross-Site Scripting / Blind SQL Injection
|
10 |
WEB
|
muts
|
|
2012-07-23
|
|
MySQL Squid Access Report 2.1.4 - HTML Injection
|
9 |
WEB
|
Daniel Godoy
|
|
2012-07-23
|
|
Symantec Web Gateway 5.0.3.18 - Blind SQL Injection Backdoor via MySQL Triggers
|
11 |
WEB
|
muts
|
|
2012-07-23
|
|
Symantec Web Gateway 5.0.2 - 'blocked.php?id' Blind SQL Injection
|
10 |
WEB
|
muts
|
|
2012-07-23
|
|
Atmail WebAdmin and Webmail Control Panel - SQL Root Password Disclosure
|
9 |
WEB
|
Ciph3r
|
|
2012-07-22
|
|
ipswitch whatsup gold 15.02 - Persistent Cross-Site Scripting / Blind SQL Injection / Remote Code Ex
|
10 |
WEB
|
muts
|
|
2012-07-22
|
|
Dell SonicWALL Scrutinizer 9.0.1 - 'statusFilter.php?q' SQL Injection
|
10 |
WEB
|
muts
|
|
2012-07-23
|
|
EGallery - Arbitrary '.PHP' File Upload (Metasploit)
|
10 |
WEB
|
Metasploit
|
|
2012-07-21
|
|
SolarWinds Orion Network Performance Monitor 10.2.2 - Multiple Vulnerabilities
|
11 |
WEB
|
muts
|
|
2012-07-21
|
|
X-Cart Gold 4.5 - 'products_map.php?symb' Cross-Site Scripting
|
9 |
WEB
|
muts
|
|
2012-07-20
|
|
iBoutique 4.0 - 'key' SQL Injection
|
10 |
WEB
|
SecPod Research
|
|
2012-07-20
|
|
PHP-Nuke module (SPChat) - SQL Injection
|
10 |
WEB
|
Yakir Wizman
|
|
2012-07-18
|
|
Nwahy Articles 2.2 - Cross-Site Request Forgery (Add Admin)
|
9 |
WEB
|
DaOne
|
|
2012-07-17
|
|
Forum Oxalis 0.1.2 - SQL Injection
|
9 |
WEB
|
Jean Pascal Pereira
|
|
2012-07-16
|
|
PBBoard CMS 2.1.4 - Multiple Vulnerabilities
|
9 |
WEB
|
Vulnerability-Lab
|
|
2012-07-16
|
|
VamCart CMS 0.9 - Multiple Vulnerabilities
|
9 |
WEB
|
Vulnerability-Lab
|
|
2012-07-16
|
|
CakePHP 2.x < 2.2.0-RC2 - XML External Entity Injection
|
9 |
WEB
|
Pawel Wylecial
|
|
2012-07-16
|
|
WordPress Theme Diary/Notebook Site5 - Email Spoofing
|
10 |
WEB
|
bwall
|
|
2012-07-16
|
|
Vivotek Cameras - Sensitive Information Disclosure
|
10 |
WEB
|
GothicX
|
|
2012-07-14
|
|
Joomla! Component com_osproperty 2.0.2 - Unrestricted Arbitrary File Upload
|
11 |
WEB
|
D4NB4R
|
|
2012-07-14
|
|
Shopware 3.5 - SQL Injection
|
10 |
WEB
|
Kataklysmos
|
|
2012-07-13
|
|
Magento eCommerce - Local File Disclosure
|
12 |
WEB
|
SEC Consult
|
|
2012-07-13
|
|
Joomla! Component com_ksadvertiser - Remote File / Bypass Upload
|
10 |
WEB
|
D4NB4R
|
|
2012-07-13
|
|
WordPress Plugin Resume Submissions & Job Postings 2.5.1 - Unrestricted Arbitrary File Upload
|
8 |
WEB
|
Chris Kellum
|
|
2012-07-13
|
|
webpagetest 2.6 - Multiple Vulnerabilities
|
13 |
WEB
|
dun
|
|
2012-07-12
|
|
Reserve Logic 1.2 Booking CMS - Multiple Vulnerabilities
|
9 |
WEB
|
Vulnerability-Lab
|
|
2012-07-12
|
|
TP-Link Gateway 3.12.4 - Multiple Vulnerabilities
|
9 |
WEB
|
Vulnerability-Lab
|
|
2012-07-12
|
|
Lc Flickr Carousel 1.0 - Local File Disclosure
|
8 |
WEB
|
GoLd_M
|
|
2012-07-12
|
|
eCan 0.1 - Local File Disclosure
|
9 |
WEB
|
GoLd_M
|
|
2012-07-12
|
|
House Style 0.1.2 - 'readfile()' Local File Disclosure
|
8 |
WEB
|
GoLd_M
|
|
2012-07-12
|
|
Hastymail 2.1.1 RC1 - Command Injection (Metasploit)
|
10 |
WEB
|
Metasploit
|
|
2012-07-10
|
|
WordPress Plugin WP-Predict 1.0 - Blind SQL Injection
|
11 |
WEB
|
Chris Kellum
|
|
2012-07-09
|
|
Umbraco CMS - Remote Command Execution (Metasploit)
|
9 |
WEB
|
Metasploit
|
|
2012-07-09
|
|
Basilic 1.5.14 - 'diff.php' Arbitrary Command Execution (Metasploit)
|
11 |
WEB
|
Metasploit
|
|
2012-07-09
|
|
Tiki Wiki CMS Groupware 8.3 - 'Unserialize()' PHP Code Execution (Metasploit)
|
10 |
WEB
|
Metasploit
|
|
2012-07-06
|
|
Webmatic 3.1.1 - Blind SQL Injection
|
10 |
WEB
|
High-Tech Bridge SA
|
|
2012-07-06
|
|
Event Script PHP 1.1 CMS - Multiple Vulnerabilities
|
9 |
WEB
|
Vulnerability-Lab
|
|
2012-07-06
|
|
sflog! 1.00 - Multiple Vulnerabilities
|
9 |
WEB
|
dun
|
|
2012-07-05
|
|
CLscript CMS 3.0 - Multiple Vulnerabilities
|
9 |
WEB
|
Vulnerability-Lab
|
|
2012-07-05
|
|
Freeside SelfService CGI/API 2.3.3 - Multiple Vulnerabilities
|
9 |
WEB
|
Vulnerability-Lab
|
|
2012-07-05
|
|
Guestbook Scripts PHP 1.5 - Multiple Vulnerabilities
|
10 |
WEB
|
Vulnerability-Lab
|
|
2012-07-04
|
|
Webify Link Directory - SQL Injection
|
9 |
WEB
|
Daniel Godoy
|
|
2012-07-04
|
|
Tiki Wiki CMS Groupware 8.3 - 'Unserialize()' PHP Code Execution
|
9 |
WEB
|
EgiX
|
|
2012-07-04
|
|
WordPress Plugin MoodThingy Widget 0.8.7 - Blind SQL Injection
|
11 |
WEB
|
Chris Kellum
|
|
2012-07-03
|
|
phpMyBackupPro 2.2 - Local File Inclusion
|
10 |
WEB
|
dun
|
|
2012-07-03
|
|
CLscript Classified Script 3.0 - SQL Injection
|
10 |
WEB
|
Daniel Godoy
|
|
2012-07-03
|
|
gpEasy CMS Minishop 1.5 Plugin - Persistent Cross-Site Scripting
|
10 |
WEB
|
Carlos Mario Penagos Hollmann
|
|
2012-07-02
|
|
WANGKONGBAO CNS-1000 UTM IPS-FW - Directory Traversal (Metasploit)
|
11 |
WEB
|
Dillon Beresford
|
|
2012-07-02
|
|
Microsoft IIS - Short File/Folder Name Disclosure
|
11 |
WEB
|
Soroush Dalili
|
|
2012-07-02
|
|
WordPress Plugin Backup 2.0.1 - Information Disclosure
|
11 |
WEB
|
Stephan Knauss
|
|
2012-06-30
|
|
WordPress Plugin Paid Business Listings 1.0.2 - Blind SQL Injection
|
11 |
WEB
|
Chris Kellum
|
|
2012-06-29
|
|
specview 2.5 build 853 - Directory Traversal
|
10 |
WEB
|
Luigi Auriemma
|
|
2012-06-29
|
|
phpmoneybooks 1.03 - Persistent Cross-Site Scripting
|
11 |
WEB
|
chap0
|
|
2012-06-28
|
|
Openfire Server 3.6.0a - Admin Console Authentication Bypass (Metasploit)
|
10 |
WEB
|
Metasploit
|
|
2012-06-28
|
|
webERP 4.08.1 - Local/Remote File Inclusion
|
11 |
WEB
|
dun
|
|
2012-06-27
|
|
Zend Framework < 2.0.0 beta4 < 1.12 RC1 < 1.11.11 - Local File Disclosure
|
12 |
WEB
|
SEC Consult
|
|
2012-06-27
|
|
symantec Web gateway 5.0.2.8 - Multiple Vulnerabilities
|
11 |
WEB
|
S2 Crew
|
|
2012-06-26
|
|
SugarCRM CE 6.3.1 - 'Unserialize()' PHP Code Execution (Metasploit)
|
10 |
WEB
|
Metasploit
|
|
2012-06-26
|
|
WordPress Plugin Website FAQ 1.0 - SQL Injection
|
11 |
WEB
|
Chris Kellum
|
|
2012-06-25
|
|
WordPress Plugin Fancy Gallery 1.2.4 - Arbitrary File Upload
|
10 |
WEB
|
Sammy FORGIT
|
|
2012-06-25
|
|
Parodia 6.8 - 'employer-profile.asp' SQL Injection
|
9 |
WEB
|
Carlos Mario Penagos Hollmann
|
|
2012-06-24
|
|
UCCASS 1.8.1 - Blind SQL Injection
|
10 |
WEB
|
dun
|
|
2012-06-23
|
|
SugarCRM CE 6.3.1 - 'Unserialize()' PHP Code Execution
|
9 |
WEB
|
EgiX
|
|
2012-06-22
|
|
SoftPerfect Bandwidth Manager 2.9.10 - Authentication Bypass
|
9 |
WEB
|
Gitsnik
|
|
2012-06-22
|
|
LimeSurvey 1.92+ build120620 - Multiple Vulnerabilities
|
9 |
WEB
|
dun
|
|
2012-06-22
|
|
agora project 2.13.1 - Multiple Vulnerabilities
|
9 |
WEB
|
Chris Russell
|
|
2012-06-21
|
|
Commentics 2.0 - Multiple Vulnerabilities
|
10 |
WEB
|
Jean Pascal Pereira
|
|
2012-06-21
|
|
traq 2.3.5 - Multiple Vulnerabilities
|
10 |
WEB
|
AkaStep
|
|
2012-06-21
|
|
IBM System Storage DS Storage Manager Profiler - Multiple Vulnerabilities
|
11 |
WEB
|
LiquidWorm
|
|
2012-06-20
|
|
WordPress Plugin Schreikasten 0.14.13 - Cross-Site Scripting
|
11 |
WEB
|
Henry Hoggard
|
|
2012-06-19
|
|
iBoutique eCommerce 4.0 - Multiple Web Vulnerabilities
|
11 |
WEB
|
Vulnerability-Lab
|
|
2012-06-18
|
|
MyTickets 1.x < 2.0.8 - Blind SQL Injection
|
9 |
WEB
|
al-swisre
|
|
2012-06-18
|
|
QNAP Turbo NAS 3.6.1 Build 0302T - Multiple Vulnerabilities
|
9 |
WEB
|
Sense of Security
|
|
2012-06-16
|
|
iScripts EasyCreate 2.0 - Multiple Vulnerabilities
|
10 |
WEB
|
Vulnerability-Lab
|
|
2012-06-16
|
|
Nuked Klan SP CMS 4.5 - SQL Injection
|
10 |
WEB
|
Vulnerability-Lab
|
|
2012-06-16
|
|
WordPress Plugin Automatic 2.0.3 - SQL Injection
|
9 |
WEB
|
nick58
|
|
2012-06-16
|
|
Huawei HG866 - Authentication Bypass
|
10 |
WEB
|
hkm
|
|
2012-06-16
|
|
News Script PHP 1.2 - Multiple Vulnerabilities
|
10 |
WEB
|
Vulnerability-Lab
|
|
2012-06-16
|
|
PHP Decoda 3.3.1 - Local File Inclusion
|
9 |
WEB
|
Number 7
|
|
2012-06-16
|
|
webo site speedup 1.6.1 - Multiple Vulnerabilities
|
9 |
WEB
|
dun
|
|
2012-06-15
|
|
Useresponse 1.0.2 - Privilege Escalation / Remote Code Execution
|
9 |
WEB
|
mr_me
|
|
2012-06-14
|
|
qdPM 7 - Arbitrary File upload
|
10 |
WEB
|
loneferret
|
|
2012-06-14
|
|
Squirrelcart Cart Shop 3.3.4 - Multiple Web Vulnerabilities
|
10 |
WEB
|
Vulnerability-Lab
|
|
2012-06-14
|
|
Swoopo Gold Shop CMS 8.4.56 - Multiple Web Vulnerabilities
|
9 |
WEB
|
Vulnerability-Lab
|
|
2012-06-14
|
|
Cells Blog CMS 1.1 - Multiple Web Vulnerabilities
|
11 |
WEB
|
Vulnerability-Lab
|
|
2012-06-14
|
|
Myre Real Estate Mobile 2012 - Multiple Vulnerabilities
|
10 |
WEB
|
Vulnerability-Lab
|