Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2012-06-07   WordPress Plugin Front End Upload 0.5.3 - Arbitrary File Upload 3 WEB Adrien Thierry
2012-06-07   PHPNet 1.8 - 'ler.php' SQL Injection 4 WEB WhiteCollarGroup
2012-06-07   SN News 1.2 - '/admin/loger.php' Authentication Bypass 4 WEB Yakir Wizman
2012-06-06   vanilla kpoll plugin 1.2 - Persistent Cross-Site Scripting 4 WEB Henry Hoggard
2012-06-06   SN News 1.2 - 'visualiza.php' SQL Injection 4 WEB WhiteCollarGroup
2012-06-06   WordPress Plugin Gallery 3.06 - Arbitrary File Upload 4 WEB Sammy FORGIT
2012-06-06   WordPress Plugin MM Forms Community 2.2.6 - Arbitrary File Upload 4 WEB Sammy FORGIT
2012-06-06   WordPress Plugin Font Uploader 1.2.4 - Arbitrary File Upload 4 WEB Sammy FORGIT
2012-06-05   WordPress Plugin Asset Manager 0.2 - Arbitrary File Upload 4 WEB Sammy FORGIT
2012-06-05   WordPress Plugin Foxypress 0.4.1.1 < 0.4.2.1 - Arbitrary File Upload 4 WEB Sammy FORGIT
2012-06-05   WordPress Plugin HTML5 AV Manager 0.2.7 - Arbitrary File Upload 4 WEB Sammy FORGIT
2012-06-05   WordPress Plugin Google Maps via Store Locator 2.7.1 < 3.0.1 - Multiple Vulnerabilities 4 WEB Sammy FORGIT
2012-06-05   WordPress Plugin Marketplace Plugin 1.5.0 < 1.6.1 - Arbitrary File Upload 3 WEB Sammy FORGIT
2012-06-05   WordPress Plugin WP-Property 1.35.0 - Arbitrary File Upload 4 WEB Sammy FORGIT
2012-06-05   pyrocms 2.1.1 - Multiple Vulnerabilities 5 WEB LiquidWorm
2012-06-04   Mnews 1.1 - 'view.php' SQL Injection 3 WEB WhiteCollarGroup
2012-06-04   Hexamail Server 4.4.5 - Persistent Cross-Site Scripting 5 WEB modpr0be
2012-06-03   Vanilla Forums 2.0.18.4 - Tagging Persistent Cross-Site Scripting 5 WEB Henry Hoggard
2012-06-03   vanilla forums poll plugin 0.9 - Persistent Cross-Site Scripting 5 WEB Henry Hoggard
2012-06-03   Log1 CMS - 'writeInfo()' PHP Code Injection (Metasploit) 4 WEB Metasploit
2012-06-02   Vanilla Forum Tagging Plugin Enchanced 1.0.1 - Persistent Cross-Site Scripting 4 WEB Henry Hoggard
2012-06-01   Membris 2.0.1 - Multiple Vulnerabilities 4 WEB Dr.abolalh
2012-06-01   4PSA VoIPNow Professional 2.5.3 - Multiple Vulnerabilities 4 WEB Aboud-el
2012-05-31   Supernews 2.6.1 - 'noticias.php?cat' SQL Injection 4 WEB Yakir Wizman
2012-05-31   NewsAdd 1.0 - 'lerNoticia.php?id' SQL Injection 4 WEB Yakir Wizman
2012-05-31   PHP Volunteer Management System 1.0.2 - Arbitrary File Upload (Metasploit) 4 WEB Metasploit
2012-05-30   Simple Web Content Management System 1.1 < 1.3 - Multiple SQL Injections 4 WEB loneferret
2012-05-30   Ganesha Digital Library 4.0 - Multiple Vulnerabilities 4 WEB X-Cisadane
2012-05-30   NewsAdd 1.0 - Multiple SQL Injections 4 WEB WhiteCollarGroup
2012-05-29   PBBoard 2.1.4 - Multiple SQL Injections 5 WEB loneferret
2012-05-28   PHP Volunteer Management System 1.0.2 - Multiple SQL Injections 4 WEB loneferret
2012-05-28   PHP Volunteer Management System 1.0.2 - Multiple Vulnerabilities 4 WEB Ashoo
2012-05-28   PBBoard 2.1.4 - Local File Inclusion 4 WEB n4ss1m
2012-05-27   b2ePms 1.0 - Multiple SQL Injection Vulnerabilities 4 WEB loneferret
2012-05-27   WeBid - 'converter.php' Remote PHP Code Injection (Metasploit) 4 WEB Metasploit
2012-05-26   Symantec Web Gateway 5.0.2 - Local/Remote File Inclusion / Remote Code Execution 4 WEB muts
2012-05-25   SocialEngine 4.2.2 - Multiple Vulnerabilities 5 WEB i4k
2012-05-25   appRain CMF - Arbitrary '.PHP' File Upload (Metasploit) 3 WEB Metasploit
2012-05-24   Jaow 2.4.5 - Blind SQL Injection 4 WEB kallimero
2012-05-21   Supernews 2.6.1 - SQL Injection 5 WEB WhiteCollarGroup
2012-05-21   Vanilla FirstLastNames 1.3.2 Plugin - Persistent Cross-Site Scripting 4 WEB Henry Hoggard
2012-05-21   Vanilla Forums About Me Plugin - Persistent Cross-Site Scripting 4 WEB Henry Hoggard
2012-05-18   Vanilla Forums LatestComment 1.1 Plugin - Persistent Cross-Site Scripting 5 WEB Henry Hoggard
2012-05-19   FreeNAC 3.02 - SQL Injection / Cross-Site Scripting 4 WEB blake
2012-05-19   PHP Address Book 7.0.0 - Multiple Vulnerabilities 4 WEB Stefan Schurtz
2012-05-16   Artiphp CMS 5.5.0 - Database Backup Disclosure 4 WEB LiquidWorm
2012-01-03   OpenKM Document Management System 5.1.7 - Command Execution 4 WEB Cyrill Brunschwiler
2012-05-16   Axous 1.1.1 - Cross-Site Request Forgery / Persistent Cross-Site Scripting 4 WEB Ivano Binetti
2012-05-08   S9Y Serendipity 1.6 - 'Backend' Cross-Site Scripting / SQL Injection 4 WEB Stefan Schurtz
2012-05-15   b2ePms 1.0 - Authentication Bypass 4 WEB Jean Pascal Pereira
2012-05-13   Liferay Portal 6.0.x < 6.1 - Privilege Escalation 3 WEB Jelmer Kuperus
2012-05-13   Galette - 'picture.php' SQL Injection 4 WEB sbz
2012-05-13   Free Realty 3.1-0.6 - Multiple Vulnerabilities 4 WEB Vulnerability-Lab
2012-05-13   Viscacha Forum CMS 0.8.1.1 - Multiple Vulnerabilities 4 WEB Vulnerability-Lab
2012-05-13   Proman Xpress 5.0.1 - Multiple Vulnerabilities 4 WEB Vulnerability-Lab
2012-05-13   Travelon Express CMS 6.2.2 - Multiple Vulnerabilities 4 WEB Vulnerability-Lab
2012-05-12   Sockso 1.51 - Persistent Cross-Site Scripting 3 WEB Ciaran McNally
2012-05-12   WikkaWiki 1.3.2 - Spam Logging PHP Injection (Metasploit) 4 WEB Metasploit
2012-05-11   Belkin N150 Wireless Router - Password Disclosure 4 WEB Avinash Tangirala
2012-05-10   eLearning server 4g - Multiple Vulnerabilities 5 WEB Andrey Komarov
2012-05-10   Kerio WinRoute Firewall Web Server < 6 - Source Code Disclosure 4 WEB Andrey Komarov
2012-05-09   X7 Chat 2.0.5.1 - Cross-Site Request Forgery (Add Admin) 4 WEB DennSpec
2012-05-07   PHP Agenda 2.2.8 - SQL Injection 4 WEB loneferret
2012-05-07   myCare2x CMS - Multiple Vulnerabilities 4 WEB Vulnerability-Lab
2012-05-07   Myre Real Estate Mobile 2012/2 - Multiple Vulnerabilities 4 WEB Vulnerability-Lab
2012-05-07   Genium CMS 2012/Q2 - Multiple Vulnerabilities 4 WEB Vulnerability-Lab
2012-05-07   Lynx Message Server - Multiple Vulnerabilities 3 WEB Mark Lachniet
2012-05-07   Fortinet FortiWeb Web Application Firewall - Policy Bypass 4 WEB Geffrey Velasquez
2012-05-04   Symantec Web Gateway - Cross-Site Scripting 4 WEB B00y@
2012-05-03   PluXml 5.1.5 - Local File Inclusion 5 WEB High-Tech Bridge SA
2012-05-03   Baby Gekko CMS 1.1.5c - Multiple Persistent Cross-Site Scripting Vulnerabilities 4 WEB LiquidWorm
2012-05-02   Websense Triton - Multiple Vulnerabilities 5 WEB Ben Williams
2012-05-02   PHP-decoda - 'Video Tag' Cross-Site Scripting 4 WEB RedTeam Pentesting
2012-05-02   OpenConf 4.11 - '/author/edit.php' Blind SQL Injection 4 WEB EgiX
2012-05-01   STRATO NewsLetter Manager - Directory Traversal 4 WEB Zero X
2012-05-01   MyClientBase 0.12 - Multiple Vulnerabilities 4 WEB Vulnerability-Lab
2012-05-01   opencart 1.5.2.1 - Multiple Vulnerabilities 4 WEB waraxe
2012-05-01   GENU CMS 2012.3 - Multiple SQL Injections 4 WEB Vulnerability-Lab
2012-05-01   WordPress Plugin Zingiri Web Shop 2.4.2 - Persistent Cross-Site Scripting 5 WEB Mehmet Ince
2012-04-30   DIY CMS 1.0 Poll - Multiple Vulnerabilities 4 WEB Vulnerability-Lab
2012-04-30   Opial CMS 2.0 - Multiple Vulnerabilities 5 WEB Vulnerability-Lab
2012-04-30   C4B XPhone UC Web 4.1.890S R1 - Cross-Site Scripting 3 WEB Vulnerability-Lab
2012-04-30   Car Portal CMS 3.0 - Multiple Vulnerabilities 4 WEB Vulnerability-Lab
2012-04-29   Alienvault Open Source SIEM (OSSIM) 3.1 - Multiple Vulnerabilities 4 WEB Stefan Schurtz
2012-04-29   Soco CMS - Local File Inclusion 4 WEB BHG Security Center
2012-04-29   WebCalendar 1.2.4 - Remote Code Injection (Metasploit) 4 WEB Metasploit
2012-04-27   Axous 1.1.0 - SQL Injection 4 WEB H4ckCity Secuirty TeaM
2012-04-27   WordPress Core 3.3.1 - Multiple Cross-Site Request Forgery Vulnerabilities 4 WEB Ivano Binetti
2012-04-26   PHP Volunteer management 1.0.2 - Multiple Vulnerabilities 4 WEB G13
2012-04-26   WordPress Plugin Zingiri Web Shop 2.4.0 - Multiple Cross-Site Scripting Vulnerabilities 5 WEB Mehmet Ince
2012-04-25   piwigo 2.3.3 - Multiple Vulnerabilities 5 WEB High-Tech Bridge SA
2012-04-24   PHP Ticket System Beta 1 - 'index.php?p' SQL Injection 4 WEB G13
2012-04-23   WebCalendar 1.2.4 - Remote Code Execution 3 WEB EgiX
2012-04-23   exponentcms 2.0.5 - Multiple Vulnerabilities 4 WEB Onur Yılmaz
2012-04-23   Havalite CMS 1.0.4 - Multiple Vulnerabilities 4 WEB Vulnerability-Lab
2012-04-22   vTiger CRM 5.1.0 - Local File Inclusion 4 WEB Pi3rrot
2012-04-22   Mega File Manager - File Download 4 WEB i2sec-Min Gi Jo
2012-04-22   Oracle GlassFish Server - REST Cross-Site Request Forgery 4 WEB Roberto Suggi Liverani
2012-04-22   Oracle GlassFish Server 3.1.1 (build 12) - Multiple Cross-Site Scripting Vulnerabilities 4 WEB Roberto Suggi Liverani
2012-04-19   XOOPS 2.5.4 - Multiple Cross-Site Scripting Vulnerabilities 4 WEB High-Tech Bridge SA
2012-04-19   newscoop 3.5.3 - Multiple Vulnerabilities 4 WEB High-Tech Bridge SA
2012-04-19   Scrutinizer NetFlow & sFlow Analyzer - Multiple Vulnerabilities 4 WEB Trustwave's SpiderLabs
2012-04-15   ManageEngine Support Center Plus 7903 - Multiple Vulnerabilities 4 WEB xistence
2012-04-15   MediaXxx Adult Video / Media Script - SQL Injection 4 WEB Daniel Godoy
2012-04-15   NetworX CMS - Cross-Site Request Forgery (Add Admin) 4 WEB N3t.Crack3r
2012-04-15   Joomla! Component com_ponygallery - SQL Injection 4 WEB xDarkSton3x
2012-04-13   Ushahidi 2.2 - Multiple Vulnerabilities 4 WEB shpendk
2012-04-13   Invision Power Board 3.3.0 - Local File Inclusion 4 WEB waraxe
2012-04-12   SoftwareDEP Classified Script 2.5 - SQL Injection (2) 4 WEB hordcode security
2012-04-10   Joomla! Component com_bearleague - SQL Injection 4 WEB xDarkSton3x
2012-04-10   Joomla! Component Estate Agent - SQL Injection 4 WEB xDarkSton3x
2012-04-09   Dolibarr ERP/CRM < 3.2.0 / < 3.1.1 - OS Command Injection 5 WEB Nahuel Grisolia
2012-04-09   Dolibarr ERP/CRM 3 - (Authenticated) OS Command Injection (Metasploit) 5 WEB Metasploit
2012-04-08   ZTE - Change Admin Password 4 WEB Nuevo Asesino
2012-04-08   Utopia News Pro 1.4.0 - Cross-Site Request Forgery (Add Admin) 4 WEB Dr.NaNo
2012-04-08   Liferay XSL - Command Execution (Metasploit) 4 WEB Spencer McIntyre
2012-04-06   w-CMS 2.0.1 - Multiple Vulnerabilities 5 WEB Black-ID
2012-04-05   GENU CMS - SQL Injection 4 WEB hordcode security
2012-04-04   Hotel Booking Portal - SQL Injection 4 WEB Mark Stanislav
2012-04-04   phpPaleo - Local File Inclusion 3 WEB Mark Stanislav
2012-04-04   e-ticketing - SQL Injection 4 WEB Mark Stanislav
2012-04-04   Plume CMS 1.2.4 - Multiple Persistent Cross-Site Scripting Vulnerabilities 4 WEB Ivano Binetti
2012-04-03   Simple PHP Agenda 2.2.8 - Cross-Site Request Forgery (Add Admin / Add Event) 5 WEB Ivano Binetti
2012-03-31   WordPress Plugin BuddyPress Plugin 1.5.x < 1.5.5 - SQL Injection 4 WEB Ivan Terkin
2012-03-31   Woltlab Burning Board 2.2/2.3 [WN]KT KickTipp 3.1 - SQL Injection 4 WEB Easy Laster