|
2012-06-13
|
|
WordPress Plugin Foxypress - 'Uploadify.php' Arbitrary Code Execution (Metasploit)
|
10 |
WEB
|
Metasploit
|
|
2012-06-13
|
|
WordPress Plugin Foxypress - 'Uploadify.php' Arbitrary Code Execution (Metasploit)
|
9 |
WEB
|
Metasploit
|
|
2012-06-12
|
|
Symantec Web Gateway 5.0.2.8 - 'ipchange.php' Command Injection (Metasploit)
|
11 |
WEB
|
Metasploit
|
|
2012-06-11
|
|
TheBlog 2.0 - Multiple Vulnerabilities
|
8 |
WEB
|
WhiteCollarGroup
|
|
2012-06-11
|
|
Agora-Project 2.12.11 - Arbitrary File Upload
|
9 |
WEB
|
Misa3l
|
|
2012-06-11
|
|
WordPress Plugin Custom Content Type Manager 0.9.5.13-pl - Arbitrary File Upload
|
8 |
WEB
|
Adrien Thierry
|
|
2012-06-11
|
|
WordPress Plugin drag and drop file upload 0.1 - Arbitrary File Upload
|
9 |
WEB
|
Adrien Thierry
|
|
2012-06-11
|
|
WordPress Plugin Mac Photo Gallery 2.7 - Arbitrary File Upload
|
9 |
WEB
|
Adrien Thierry
|
|
2012-06-11
|
|
WordPress Plugin Pica Photo Gallery 1.0 - Arbitrary File Upload
|
8 |
WEB
|
Adrien Thierry
|
|
2012-06-11
|
|
WordPress Plugin SfBrowser 1.4.5 - Arbitrary File Upload
|
9 |
WEB
|
Adrien Thierry
|
|
2012-06-11
|
|
WordPress Plugin Top Quark Architecture 2.10 - Arbitrary File Upload
|
9 |
WEB
|
Adrien Thierry
|
|
2012-06-11
|
|
WordPress Plugin User Meta 1.1.1 - Arbitrary File Upload
|
10 |
WEB
|
Adrien Thierry
|
|
2012-06-11
|
|
ClanSuite 2.9 - Arbitrary File Upload
|
9 |
WEB
|
Adrien Thierry
|
|
2012-06-11
|
|
WordPress Plugin wp-gpx-map 1.1.21 - Arbitrary File Upload
|
10 |
WEB
|
Adrien Thierry
|
|
2012-06-10
|
|
Symantec Web Gateway 5.0.2.8 - Arbitrary '.PHP' File Upload (Metasploit)
|
10 |
WEB
|
Metasploit
|
|
2012-06-10
|
|
WordPress Plugin Content Flow 3D 1.0.0 - Arbitrary File Upload
|
11 |
WEB
|
g11tch
|
|
2012-06-10
|
|
freepost 0.1 r1 - Multiple Vulnerabilities
|
9 |
WEB
|
ThE g0bL!N
|
|
2012-06-10
|
|
Webspell dailyinput Movie Addon 4.2.x - SQL Injection
|
10 |
WEB
|
Easy Laster
|
|
2012-06-08
|
|
phpAcounts 0.5.3 - SQL Injection
|
10 |
WEB
|
loneferret
|
|
2012-06-08
|
|
WordPress Plugin wpStoreCart 2.5.27-2.5.29 - Arbitrary File Upload
|
10 |
WEB
|
Sammy FORGIT
|
|
2012-06-08
|
|
WordPress Plugin TinyMCE Thumbnail Gallery 1.0.7 - Remote File Disclosure
|
10 |
WEB
|
Sammy FORGIT
|
|
2012-06-08
|
|
WordPress Plugin Thinkun Remind 1.1.3 - Remote File Disclosure
|
10 |
WEB
|
Sammy FORGIT
|
|
2012-06-08
|
|
WordPress Plugin Simple Download Button ShortCode 1.0 - Remote File Disclosure
|
9 |
WEB
|
Sammy FORGIT
|
|
2012-06-08
|
|
WordPress Plugin RBX Gallery 2.1 - Arbitrary File Upload
|
8 |
WEB
|
Sammy FORGIT
|
|
2012-06-08
|
|
WordPress Plugin NewsLetter 1.5 - Remote File Disclosure
|
9 |
WEB
|
Sammy FORGIT
|
|
2012-06-08
|
|
WordPress Plugin PICA Photo Gallery 1.0 - Remote File Disclosure
|
6 |
WEB
|
Sammy FORGIT
|
|
2012-06-08
|
|
WordPress Plugin Easy Contact Forms Export 1.1.0 - Information Disclosure
|
8 |
WEB
|
Sammy FORGIT
|
|
2012-06-08
|
|
WordPress Plugin Front File Manager 0.1 - Arbitrary File Upload
|
8 |
WEB
|
Adrien Thierry
|
|
2012-06-08
|
|
Webspell FIRSTBORN Movie-Addon - Blind SQL Injection
|
9 |
WEB
|
Easy Laster
|
|
2012-06-07
|
|
WordPress Plugin Omni Secure Files 0.1.13 - Arbitrary File Upload
|
9 |
WEB
|
Adrien Thierry
|
|
2012-06-07
|
|
WordPress Plugin Front End Upload 0.5.3 - Arbitrary File Upload
|
9 |
WEB
|
Adrien Thierry
|
|
2012-06-07
|
|
PHPNet 1.8 - 'ler.php' SQL Injection
|
8 |
WEB
|
WhiteCollarGroup
|
|
2012-06-07
|
|
SN News 1.2 - '/admin/loger.php' Authentication Bypass
|
10 |
WEB
|
Yakir Wizman
|
|
2012-06-06
|
|
vanilla kpoll plugin 1.2 - Persistent Cross-Site Scripting
|
11 |
WEB
|
Henry Hoggard
|
|
2012-06-06
|
|
SN News 1.2 - 'visualiza.php' SQL Injection
|
9 |
WEB
|
WhiteCollarGroup
|
|
2012-06-06
|
|
WordPress Plugin Gallery 3.06 - Arbitrary File Upload
|
9 |
WEB
|
Sammy FORGIT
|
|
2012-06-06
|
|
WordPress Plugin MM Forms Community 2.2.6 - Arbitrary File Upload
|
10 |
WEB
|
Sammy FORGIT
|
|
2012-06-06
|
|
WordPress Plugin Font Uploader 1.2.4 - Arbitrary File Upload
|
10 |
WEB
|
Sammy FORGIT
|
|
2012-06-05
|
|
WordPress Plugin Asset Manager 0.2 - Arbitrary File Upload
|
7 |
WEB
|
Sammy FORGIT
|
|
2012-06-05
|
|
WordPress Plugin Foxypress 0.4.1.1 < 0.4.2.1 - Arbitrary File Upload
|
9 |
WEB
|
Sammy FORGIT
|
|
2012-06-05
|
|
WordPress Plugin HTML5 AV Manager 0.2.7 - Arbitrary File Upload
|
9 |
WEB
|
Sammy FORGIT
|
|
2012-06-05
|
|
WordPress Plugin Google Maps via Store Locator 2.7.1 < 3.0.1 - Multiple Vulnerabilities
|
9 |
WEB
|
Sammy FORGIT
|
|
2012-06-05
|
|
WordPress Plugin Marketplace Plugin 1.5.0 < 1.6.1 - Arbitrary File Upload
|
8 |
WEB
|
Sammy FORGIT
|
|
2012-06-05
|
|
WordPress Plugin WP-Property 1.35.0 - Arbitrary File Upload
|
9 |
WEB
|
Sammy FORGIT
|
|
2012-06-05
|
|
pyrocms 2.1.1 - Multiple Vulnerabilities
|
11 |
WEB
|
LiquidWorm
|
|
2012-06-04
|
|
Mnews 1.1 - 'view.php' SQL Injection
|
9 |
WEB
|
WhiteCollarGroup
|
|
2012-06-04
|
|
Hexamail Server 4.4.5 - Persistent Cross-Site Scripting
|
12 |
WEB
|
modpr0be
|
|
2012-06-03
|
|
Vanilla Forums 2.0.18.4 - Tagging Persistent Cross-Site Scripting
|
10 |
WEB
|
Henry Hoggard
|
|
2012-06-03
|
|
vanilla forums poll plugin 0.9 - Persistent Cross-Site Scripting
|
10 |
WEB
|
Henry Hoggard
|
|
2012-06-03
|
|
Log1 CMS - 'writeInfo()' PHP Code Injection (Metasploit)
|
9 |
WEB
|
Metasploit
|
|
2012-06-02
|
|
Vanilla Forum Tagging Plugin Enchanced 1.0.1 - Persistent Cross-Site Scripting
|
9 |
WEB
|
Henry Hoggard
|
|
2012-06-01
|
|
Membris 2.0.1 - Multiple Vulnerabilities
|
10 |
WEB
|
Dr.abolalh
|
|
2012-06-01
|
|
4PSA VoIPNow Professional 2.5.3 - Multiple Vulnerabilities
|
10 |
WEB
|
Aboud-el
|
|
2012-05-31
|
|
Supernews 2.6.1 - 'noticias.php?cat' SQL Injection
|
9 |
WEB
|
Yakir Wizman
|
|
2012-05-31
|
|
NewsAdd 1.0 - 'lerNoticia.php?id' SQL Injection
|
9 |
WEB
|
Yakir Wizman
|
|
2012-05-31
|
|
PHP Volunteer Management System 1.0.2 - Arbitrary File Upload (Metasploit)
|
9 |
WEB
|
Metasploit
|
|
2012-05-30
|
|
Simple Web Content Management System 1.1 < 1.3 - Multiple SQL Injections
|
7 |
WEB
|
loneferret
|
|
2012-05-30
|
|
Ganesha Digital Library 4.0 - Multiple Vulnerabilities
|
8 |
WEB
|
X-Cisadane
|
|
2012-05-30
|
|
NewsAdd 1.0 - Multiple SQL Injections
|
9 |
WEB
|
WhiteCollarGroup
|
|
2012-05-29
|
|
PBBoard 2.1.4 - Multiple SQL Injections
|
11 |
WEB
|
loneferret
|
|
2012-05-28
|
|
PHP Volunteer Management System 1.0.2 - Multiple SQL Injections
|
9 |
WEB
|
loneferret
|
|
2012-05-28
|
|
PHP Volunteer Management System 1.0.2 - Multiple Vulnerabilities
|
9 |
WEB
|
Ashoo
|
|
2012-05-28
|
|
PBBoard 2.1.4 - Local File Inclusion
|
10 |
WEB
|
n4ss1m
|
|
2012-05-27
|
|
b2ePms 1.0 - Multiple SQL Injection Vulnerabilities
|
9 |
WEB
|
loneferret
|
|
2012-05-27
|
|
WeBid - 'converter.php' Remote PHP Code Injection (Metasploit)
|
9 |
WEB
|
Metasploit
|
|
2012-05-26
|
|
Symantec Web Gateway 5.0.2 - Local/Remote File Inclusion / Remote Code Execution
|
12 |
WEB
|
muts
|
|
2012-05-25
|
|
SocialEngine 4.2.2 - Multiple Vulnerabilities
|
9 |
WEB
|
i4k
|
|
2012-05-25
|
|
appRain CMF - Arbitrary '.PHP' File Upload (Metasploit)
|
7 |
WEB
|
Metasploit
|
|
2012-05-24
|
|
Jaow 2.4.5 - Blind SQL Injection
|
9 |
WEB
|
kallimero
|
|
2012-05-21
|
|
Supernews 2.6.1 - SQL Injection
|
10 |
WEB
|
WhiteCollarGroup
|
|
2012-05-21
|
|
Vanilla FirstLastNames 1.3.2 Plugin - Persistent Cross-Site Scripting
|
11 |
WEB
|
Henry Hoggard
|
|
2012-05-21
|
|
Vanilla Forums About Me Plugin - Persistent Cross-Site Scripting
|
10 |
WEB
|
Henry Hoggard
|
|
2012-05-18
|
|
Vanilla Forums LatestComment 1.1 Plugin - Persistent Cross-Site Scripting
|
9 |
WEB
|
Henry Hoggard
|
|
2012-05-19
|
|
FreeNAC 3.02 - SQL Injection / Cross-Site Scripting
|
10 |
WEB
|
blake
|
|
2012-05-19
|
|
PHP Address Book 7.0.0 - Multiple Vulnerabilities
|
9 |
WEB
|
Stefan Schurtz
|
|
2012-05-16
|
|
Artiphp CMS 5.5.0 - Database Backup Disclosure
|
8 |
WEB
|
LiquidWorm
|
|
2012-01-03
|
|
OpenKM Document Management System 5.1.7 - Command Execution
|
10 |
WEB
|
Cyrill Brunschwiler
|
|
2012-05-16
|
|
Axous 1.1.1 - Cross-Site Request Forgery / Persistent Cross-Site Scripting
|
9 |
WEB
|
Ivano Binetti
|
|
2012-05-08
|
|
S9Y Serendipity 1.6 - 'Backend' Cross-Site Scripting / SQL Injection
|
9 |
WEB
|
Stefan Schurtz
|
|
2012-05-15
|
|
b2ePms 1.0 - Authentication Bypass
|
7 |
WEB
|
Jean Pascal Pereira
|
|
2012-05-13
|
|
Liferay Portal 6.0.x < 6.1 - Privilege Escalation
|
7 |
WEB
|
Jelmer Kuperus
|
|
2012-05-13
|
|
Galette - 'picture.php' SQL Injection
|
9 |
WEB
|
sbz
|
|
2012-05-13
|
|
Free Realty 3.1-0.6 - Multiple Vulnerabilities
|
10 |
WEB
|
Vulnerability-Lab
|
|
2012-05-13
|
|
Viscacha Forum CMS 0.8.1.1 - Multiple Vulnerabilities
|
9 |
WEB
|
Vulnerability-Lab
|
|
2012-05-13
|
|
Proman Xpress 5.0.1 - Multiple Vulnerabilities
|
9 |
WEB
|
Vulnerability-Lab
|
|
2012-05-13
|
|
Travelon Express CMS 6.2.2 - Multiple Vulnerabilities
|
8 |
WEB
|
Vulnerability-Lab
|
|
2012-05-12
|
|
Sockso 1.51 - Persistent Cross-Site Scripting
|
8 |
WEB
|
Ciaran McNally
|
|
2012-05-12
|
|
WikkaWiki 1.3.2 - Spam Logging PHP Injection (Metasploit)
|
11 |
WEB
|
Metasploit
|
|
2012-05-11
|
|
Belkin N150 Wireless Router - Password Disclosure
|
10 |
WEB
|
Avinash Tangirala
|
|
2012-05-10
|
|
eLearning server 4g - Multiple Vulnerabilities
|
9 |
WEB
|
Andrey Komarov
|
|
2012-05-10
|
|
Kerio WinRoute Firewall Web Server < 6 - Source Code Disclosure
|
9 |
WEB
|
Andrey Komarov
|
|
2012-05-09
|
|
X7 Chat 2.0.5.1 - Cross-Site Request Forgery (Add Admin)
|
9 |
WEB
|
DennSpec
|
|
2012-05-07
|
|
PHP Agenda 2.2.8 - SQL Injection
|
9 |
WEB
|
loneferret
|
|
2012-05-07
|
|
myCare2x CMS - Multiple Vulnerabilities
|
8 |
WEB
|
Vulnerability-Lab
|
|
2012-05-07
|
|
Myre Real Estate Mobile 2012/2 - Multiple Vulnerabilities
|
9 |
WEB
|
Vulnerability-Lab
|
|
2012-05-07
|
|
Genium CMS 2012/Q2 - Multiple Vulnerabilities
|
9 |
WEB
|
Vulnerability-Lab
|
|
2012-05-07
|
|
Lynx Message Server - Multiple Vulnerabilities
|
8 |
WEB
|
Mark Lachniet
|
|
2012-05-07
|
|
Fortinet FortiWeb Web Application Firewall - Policy Bypass
|
9 |
WEB
|
Geffrey Velasquez
|
|
2012-05-04
|
|
Symantec Web Gateway - Cross-Site Scripting
|
9 |
WEB
|
B00y@
|
|
2012-05-03
|
|
PluXml 5.1.5 - Local File Inclusion
|
10 |
WEB
|
High-Tech Bridge SA
|
|
2012-05-03
|
|
Baby Gekko CMS 1.1.5c - Multiple Persistent Cross-Site Scripting Vulnerabilities
|
9 |
WEB
|
LiquidWorm
|
|
2012-05-02
|
|
Websense Triton - Multiple Vulnerabilities
|
10 |
WEB
|
Ben Williams
|
|
2012-05-02
|
|
PHP-decoda - 'Video Tag' Cross-Site Scripting
|
9 |
WEB
|
RedTeam Pentesting
|
|
2012-05-02
|
|
OpenConf 4.11 - '/author/edit.php' Blind SQL Injection
|
10 |
WEB
|
EgiX
|
|
2012-05-01
|
|
STRATO NewsLetter Manager - Directory Traversal
|
10 |
WEB
|
Zero X
|
|
2012-05-01
|
|
MyClientBase 0.12 - Multiple Vulnerabilities
|
10 |
WEB
|
Vulnerability-Lab
|
|
2012-05-01
|
|
opencart 1.5.2.1 - Multiple Vulnerabilities
|
10 |
WEB
|
waraxe
|
|
2012-05-01
|
|
GENU CMS 2012.3 - Multiple SQL Injections
|
9 |
WEB
|
Vulnerability-Lab
|
|
2012-05-01
|
|
WordPress Plugin Zingiri Web Shop 2.4.2 - Persistent Cross-Site Scripting
|
10 |
WEB
|
Mehmet Ince
|
|
2012-04-30
|
|
DIY CMS 1.0 Poll - Multiple Vulnerabilities
|
9 |
WEB
|
Vulnerability-Lab
|
|
2012-04-30
|
|
Opial CMS 2.0 - Multiple Vulnerabilities
|
10 |
WEB
|
Vulnerability-Lab
|
|
2012-04-30
|
|
C4B XPhone UC Web 4.1.890S R1 - Cross-Site Scripting
|
10 |
WEB
|
Vulnerability-Lab
|
|
2012-04-30
|
|
Car Portal CMS 3.0 - Multiple Vulnerabilities
|
9 |
WEB
|
Vulnerability-Lab
|
|
2012-04-29
|
|
Alienvault Open Source SIEM (OSSIM) 3.1 - Multiple Vulnerabilities
|
9 |
WEB
|
Stefan Schurtz
|
|
2012-04-29
|
|
Soco CMS - Local File Inclusion
|
8 |
WEB
|
BHG Security Center
|
|
2012-04-29
|
|
WebCalendar 1.2.4 - Remote Code Injection (Metasploit)
|
8 |
WEB
|
Metasploit
|
|
2012-04-27
|
|
Axous 1.1.0 - SQL Injection
|
9 |
WEB
|
H4ckCity Secuirty TeaM
|
|
2012-04-27
|
|
WordPress Core 3.3.1 - Multiple Cross-Site Request Forgery Vulnerabilities
|
9 |
WEB
|
Ivano Binetti
|
|
2012-04-26
|
|
PHP Volunteer management 1.0.2 - Multiple Vulnerabilities
|
9 |
WEB
|
G13
|
|
2012-04-26
|
|
WordPress Plugin Zingiri Web Shop 2.4.0 - Multiple Cross-Site Scripting Vulnerabilities
|
11 |
WEB
|
Mehmet Ince
|
|
2012-04-25
|
|
piwigo 2.3.3 - Multiple Vulnerabilities
|
11 |
WEB
|
High-Tech Bridge SA
|
|
2012-04-24
|
|
PHP Ticket System Beta 1 - 'index.php?p' SQL Injection
|
10 |
WEB
|
G13
|
|
2012-04-23
|
|
WebCalendar 1.2.4 - Remote Code Execution
|
9 |
WEB
|
EgiX
|
|
2012-04-23
|
|
exponentcms 2.0.5 - Multiple Vulnerabilities
|
9 |
WEB
|
Onur Yılmaz
|
|
2012-04-23
|
|
Havalite CMS 1.0.4 - Multiple Vulnerabilities
|
9 |
WEB
|
Vulnerability-Lab
|