Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2012-01-21   ARYADAD - Multiple Vulnerabilities 4 WEB Red Security TEAM
2012-01-21   iSupport 1.x - Cross-Site Request Forgery / HTML Code Injection (Add Admin) 4 WEB Or4nG.M4N
2012-01-21   Nova CMS - Directory Traversal 4 WEB Red Security TEAM
2012-01-21   PHP iReport 1.0 - Remote Html Code Injection 4 WEB Or4nG.M4N
2012-01-20   WhatsApp - Remote Change Status 4 WEB emgent
2012-01-20   EasyPage - SQL Injection 4 WEB Red Security TEAM
2012-01-20   ICTimeAttendance - Authentication Bypass 4 WEB v3n0m
2012-01-19   appRain CMF 0.1.5 - 'Uploadify.php' Unrestricted Arbitrary File Upload 4 WEB EgiX
2012-01-19   WordPress Plugin ucan post 1.0.09 - Persistent Cross-Site Scripting 4 WEB Gianluca Brindisi
2012-01-19   Drupal Module CKEditor 3.0 < 3.6.2 - Persistent EventHandler Cross-Site Scripting 4 WEB MaXe
2012-01-18   DZCP (deV!L_z Clanportal) 1.5.5 Moviebase Addon - Blind SQL Injection 4 WEB Easy Laster
2012-01-18   DZCP (deV!L_z Clanportal) Gamebase Addon - SQL Injection 4 WEB Easy Laster
2012-01-18   PHPBridges Blog System - 'members.php' SQL Injection 3 WEB 3spi0n
2012-01-18   pGB 2.12 - 'kommentar.php' SQL Injection 4 WEB 3spi0n
2012-01-17   Joomla! Component com_discussions - SQL Injection 4 WEB Red Security TEAM
2012-01-16   PHPDomainRegister 0.4a-RC2-dev - Multiple Vulnerabilities 5 WEB Or4nG.M4N
2012-01-15   Cloupia End-to-end FlexPod Management - Directory Traversal 5 WEB Chris Rock
2012-01-14   phpMyAdmin 3.3.x/3.4.x - Local File Inclusion via XML External Entity Injection (Metasploit) 4 WEB Marco Batista
2012-01-13   Pragyan CMS 2.6.1 - Arbitrary File Upload 4 WEB Dr.KroOoZ
2012-01-13   Tine 2.0 - Maischa Multiple Cross-Site Scripting Vulnerabilities 4 WEB Vulnerability-Lab
2012-01-12   WordPress Plugin Count Per Day - Multiple Vulnerabilities 4 WEB 6Scan
2012-01-12   WordPress Plugin wp-autoyoutube - Blind SQL Injection 4 WEB longrifle0x
2012-01-12   Advanced Image Hosting Script - SQL Injection 4 WEB Robert Cooper
2012-01-10   WordPress Plugin Age Verification 0.4 - Open Redirect 5 WEB Gianluca Brindisi
2012-01-10   w-CMS 2.01 - Multiple Vulnerabilities 6 WEB th3.g4m3_0v3r
2012-01-10   Pragyan CMS 3.0 - Remote File Disclosure 4 WEB Or4nG.M4N
2012-01-10   RazorCMS 1.2 - Directory Traversal 4 WEB chap0
2012-01-09   Enigma2 Webinterface 1.5.x/1.6.x/1.7.x (Linux) - Remote File Disclosure 4 WEB Todor Donev
2012-01-09   SAPID 1.2.3 Stable - Remote File Inclusion 4 WEB Opa Yong
2012-01-09   Clipbucket 2.6 - Multiple Vulnerabilities 3 WEB YaDoY666
2012-01-09   Paddelberg Topsite Script - Authentication Bypass 4 WEB Christian Inci
2012-01-08   phpMyDirectory.com 1.3.3 - SQL Injection 4 WEB Serseri
2012-01-08   MangosWeb - SQL Injection 5 WEB Hood3dRob1n
2012-01-06   WordPress Plugin Pay with Tweet 1.1 - Multiple Vulnerabilities 3 WEB Gianluca Brindisi
2012-01-06   Apache Struts 2 < 2.3.1 - Multiple Vulnerabilities 4 WEB SEC Consult
2012-01-06   TinyWebGallery 1.8.3 - Remote Command Execution 4 WEB Expl0!Ts
2012-01-04   Posse Softball Director CMS - 'team.php' Blind SQL Injection 4 WEB Easy Laster
2012-01-04   Posse Softball Director CMS - SQL Injection 4 WEB H4ckCity Security Team
2012-01-04   Typo3 4.5 < 4.7 - Remote Code Execution / Local File Inclusion / Remote File Inclusion 4 WEB MaXe
2012-01-02   MyPHPDating 1.0 - SQL Injection 5 WEB ITTIHACK
2012-01-02   PHP-X-Links Script - SQL Injection 4 WEB H4ckCity Security Team
2012-01-02   WSN Links Script 2.3.4 - SQL Injection 4 WEB H4ckCity Security Team
2011-12-30   Akiva WebBoard 8.x - SQL Injection 4 WEB Alexander Fuchs
2011-12-30   Dede CMS - SQL Injection 3 WEB CWH & Nafsh
2011-12-29   Winn Guestbook 2.4.8c - Persistent Cross-Site Scripting 4 WEB G13
2011-12-29   DIY-CMS blog mod - SQL Injection 4 WEB snup
2011-12-28   Joomla! Component Module Simple File Upload 1.3 - Remote Code Execution 4 WEB gmda
2011-12-26   Free Image Hosting Script - Arbitrary File Upload 4 WEB ySecurity
2011-12-26   WordPress Plugin Mailing List - Arbitrary File Download 4 WEB 6Scan
2011-12-25   OpenEMR 4 - Multiple Vulnerabilities 4 WEB Level
2011-12-23   Open Conference/Journal/Harvester Systems 2.3.x - Multiple Remote Code Execution Vulnerabilities 4 WEB mr_me
2011-12-22   Tiki Wiki CMS Groupware 8.2 - 'snarf_ajax.php' Remote PHP Code Injection 4 WEB EgiX
2011-12-21   Plone and Zope - Remote Command Execution 4 WEB Nick Miles
2011-12-21   SpamTitan 5.08 - Multiple Vulnerabilities 4 WEB Vulnerability-Lab
2011-12-21   Barracuda Control Center 620 - Multiple Web Vulnerabilities 4 WEB Vulnerability-Lab
2011-12-21   Infoproject Business Hero - Multiple Vulnerabilities 4 WEB LiquidWorm
2011-12-19   Joomla! Component com_dshop - SQL Injection 4 WEB CoBRa_21
2011-12-19   DotA OpenStats 1.3.9 - SQL Injection 4 WEB HvM17
2011-12-19   appRain CMF 0.1.5 - Multiple Web Vulnerabilities 4 WEB Vulnerability-Lab
2011-12-16   mPDF 5.3 - File Disclosure 4 WEB ZadYree
2011-12-16   Capexweb 1.1 - SQL Injection 4 WEB D1rt3 Dud3
2011-12-16   Seotoaster - SQL Injection 4 WEB Stefan Schurtz
2011-12-14   PmWiki 2.2.34 - 'pagelist' Remote PHP Code Injection (2) (Metasploit) 4 WEB Metasploit
2011-12-13   Traq 2.3 - Authentication Bypass / Remote Code Execution (Metasploit) 4 WEB Metasploit
2011-12-11   Pixie 1.04 - Blog Post Cross-Site Request Forgery 3 WEB hackme
2011-12-11   Xoops 2.5.4 - Blind SQL Injection 4 WEB blkhtc0rp
2011-12-11   FCMS CMS 2.7.2 - Multiple Cross-Site Request Forgery Vulnerabilities 4 WEB Ahmed Elhady Mohamed
2011-12-11   WordPress Plugin UPM Polls 1.0.4 - Blind SQL Injection 3 WEB Saif
2011-12-10   Family CMS 2.7.2 - Multiple Persistent Cross-Site Scripting Vulnerabilities 3 WEB Ahmed Elhady Mohamed
2011-12-09   Docebo Lms 4.0.4 - 'Messages' Remote Code Execution 4 WEB mr_me
2011-12-09   SePortal 2.5 - SQL Injection (1) 4 WEB Don
2011-12-08   Joomla! Component com_qcontacts 1.0.6 - SQL Injection 4 WEB Don
2011-12-08   SantriaCMS - SQL Injection 4 WEB Troy
2011-12-07   SourceBans 1.4.8 - SQL Injection / Local File Inclusion Injection 4 WEB Havok
2011-12-07   SMF 2.0.1 - SQL Injection / Privilege Escalation 3 WEB The:Paradox
2011-12-07   Traq 2.3 - Authentication Bypass / Remote Code Execution 4 WEB EgiX
2011-12-07   phpBB MyPage Plugin - SQL Injection 4 WEB CrazyMouse
2011-12-07   PHP City Portal Script Software - SQL Injection 4 WEB Don
2011-12-07   Family Connections CMS 2.7.1 - 'less.php' Remote Command Execution (Metasploit) 3 WEB Metasploit
2011-12-06   Alstrasoft EPay Enterprise 4.0 - Blind SQL Injection 4 WEB Don
2011-12-05   Meditate Web Content Editor 'username_input' - SQL Injection 5 WEB Stefan Schurtz
2011-12-04   Family Connections CMS 2.5.0/2.7.1 - 'less.php' Remote Command Execution 4 WEB mr_me
2011-12-02   WSN Classifieds 6.2.12/6.2.18 - Multiple Vulnerabilities 5 WEB d3v1l
2011-12-02   Joomla! Component com_jobprofile - SQL Injection 4 WEB kaMtiEz
2011-12-01   Muster Render Farm Management System - Arbitrary File Download 4 WEB Nick Freeman
2011-11-30   WikkaWiki 1.3.2 - Multiple Vulnerabilities 6 WEB EgiX
2011-11-28   JQuery-Real-Person plugin - Bypass Captcha 4 WEB Alberto_García_Illera
2011-11-28   Google Android - 'content://' URI Multiple Information Disclosure Vulnerabilities 4 WEB Thomas Cannon
2011-11-25   PHP video script - SQL Injection 4 WEB longrifle0x
2011-11-24   Zabbix 1.8.4 - 'popup.php' SQL Injection 4 WEB Marcio Almeida
2011-11-24   LibLime Koha 4.2 - Local File Inclusion 4 WEB Akin Tosunlar
2011-11-24   Log1 CMS 2.0 - 'ajax_create_folder.php' Remote Code Execution 4 WEB Adel SBM
2011-11-23   PmWiki 2.2.34 - 'pagelist' Remote PHP Code Injection (1) 4 WEB EgiX
2011-11-23   PHP-Nuke 8.1.0.3.5b - 'Downloads' Blind SQL Injection 4 WEB Dante90
2011-11-19   Support Incident Tracker 3.65 - 'translate.php' Remote Code Execution 5 WEB EgiX
2011-11-19   ARASTAR - SQL Injection 4 WEB TH3_N3RD
2011-11-19   Blogs manager 1.101 - SQL Injection 4 WEB muuratsalo
2011-11-19   Valid tiny-erp 1.6 - SQL Injection 4 WEB muuratsalo
2011-11-19   Freelancer Calendar 1.01 - SQL Injection 4 WEB muuratsalo
2011-11-19   WordPress Plugin jetpack - 'sharedaddy.php' ID SQL Injection 4 WEB longrifle0x
2011-11-16   SonicWALL Aventail SSL-VPN - SQL Injection 3 WEB Asheesh kumar
2011-11-16   FreeWebShop 2.2.9 R2 - 'ajax_save_name.php' Remote Code Execution 4 WEB EgiX
2011-11-15   QuiXplorer 2.3 - Bugtraq Arbitrary File Upload 3 WEB PCA
2011-11-15   Authenex A-Key/ASAS Web Management Control 3.1.0.2 - Blind SQL Injection 4 WEB Jose Carlos de Arriba
2011-11-14   Pixie CMS 1.01 < 1.04 - Blind SQL Injections 4 WEB Piranha
2011-11-14   WordPress Plugin AdRotate 3.6.6 - SQL Injection 4 WEB Miroslav Stampar
2011-11-13   WordPress Plugin Zingiri 2.2.3 - 'ajax_save_name.php' Remote Code Execution 4 WEB EgiX
2011-11-13   Mambo 4.x - 'Zorder' SQL Injection 4 WEB KraL BeNiM
2011-11-13   Support Incident Tracker 3.65 - Remote Command Execution (Metasploit) 4 WEB Metasploit
2011-11-09   COMTREND CT-5624 Router - Root/Support Password Disclosure/Change 3 WEB Todor Donev
2011-11-09   labwiki 1.1 - Multiple Vulnerabilities 3 WEB muuratsalo
2011-11-09   osCSS2 - '_ID' Local file Inclusion 5 WEB Stefan Schurtz
2011-11-08   11in1 CMS 1.0.1 - 'do.php' CRLF Injection 5 WEB LiquidWorm
2011-11-07   OrderSys 1.6.4 - SQL Injection 4 WEB muuratsalo
2011-11-07   LabStoRe 1.5.4 - SQL Injection 4 WEB muuratsalo
2011-11-07   WHMCompleteSolution 3.x/4.x - Multiple Vulnerabilities 5 WEB ZxH-Labs
2011-11-05   aidiCMS 3.55 - 'ajax_create_folder.php' Remote Code Execution 4 WEB EgiX
2011-11-05   PHPMyFAQ 2.7.0 - 'ajax_create_folder.php' Remote Code Execution 4 WEB EgiX
2011-11-05   ZenPhoto 1.4.1.4 - 'ajax_create_folder.php' Remote Code Execution 3 WEB EgiX
2011-11-04   WHMCompleteSolution (WHMCS) 3.x - 'clientarea.php' Local File Disclosure 5 WEB red virus
2011-11-04   HP Data Protector Media Operations 6.20 - Directory Traversal 4 WEB Luigi Auriemma
2011-11-04   Advanced Poll 2.02 - SQL Injection 4 WEB Yassin Aboukir
2011-11-04   Ajax File and Image Manager 1.0 Final - Remote Code Execution 4 WEB EgiX
2011-11-03   Web File Browser 0.4b14 - File Download 4 WEB Sangyun YOO
2011-11-03   Jara 1.6 - Multiple Vulnerabilities 5 WEB Or4nG.M4N