|
2011-04-04
|
|
TP-Link TL-PS110U / TL-PS110P - Cross-Site Scripting
|
18 |
WEB
|
b0telh0
|
|
2011-04-04
|
|
Encore ENPS-2012 - Cross-Site Scripting
|
16 |
WEB
|
b0telh0
|
|
2011-04-04
|
|
Yaws-Wiki 1.88-1 (Erlang) - Persistent / Reflective Cross-Site Scripting
|
22 |
WEB
|
Michael Brooks
|
|
2011-04-04
|
|
DoceboLms 4.0.4 - Multiple Persistent Cross-Site Scripting Vulnerabilities
|
17 |
WEB
|
LiquidWorm
|
|
2011-04-03
|
|
OpenCart 1.4.9 - Multiple Local File Inclusions
|
16 |
WEB
|
KedAns-Dz
|
|
2011-04-03
|
|
Banner Ad Management Script - SQL Injection
|
19 |
WEB
|
Egyptian.H4x0rz
|
|
2011-04-03
|
|
Rash CMS - SQL Injection
|
16 |
WEB
|
keracker
|
|
2011-04-03
|
|
Advanced Image Hosting 2.2 - 'index.php' SQL Injection
|
15 |
WEB
|
keracker
|
|
2011-04-02
|
|
Anzeigenmarkt 2011 - 'index.php' SQL Injection
|
19 |
WEB
|
Easy Laster
|
|
2011-04-02
|
|
ilchClan 1.0.5 - 'regist.php' SQL Injection
|
18 |
WEB
|
Easy Laster
|
|
2011-04-02
|
|
spidaNews 1.0 - 'news.php?id' SQL Injection
|
16 |
WEB
|
Easy Laster
|
|
2011-04-01
|
|
Feng Office 1.7.3.3 - Cross-Site Request Forgery
|
16 |
WEB
|
High-Tech Bridge SA
|
|
2011-04-01
|
|
InTerra Blog Machine 1.84 - Cross-Site Scripting
|
17 |
WEB
|
High-Tech Bridge SA
|
|
2011-04-01
|
|
Allomani Super MultiMedia Library 2.5.0 - Cross-Site Request Forgery (Add Admin)
|
16 |
WEB
|
AtT4CKxT3rR0r1ST
|
|
2011-04-01
|
|
Allomani Audio and Video Library 2.7.0 - Cross-Site Request Forgery (Add Admin)
|
15 |
WEB
|
AtT4CKxT3rR0r1ST
|
|
2011-04-01
|
|
Allomani Web Links 1.0 - Cross-Site Request Forgery (Add Admin)
|
16 |
WEB
|
AtT4CKxT3rR0r1ST
|
|
2011-04-01
|
|
Allomani Movies Library 2.0 - Cross-Site Request Forgery (Add Admin)
|
17 |
WEB
|
AtT4CKxT3rR0r1ST
|
|
2011-04-01
|
|
Allomani News 1.0 - Cross-Site Request Forgery (Add Admin)
|
18 |
WEB
|
AtT4CKxT3rR0r1ST
|
|
2011-04-01
|
|
Allomani E-Store 1.0 - Cross-Site Request Forgery (Add Admin) (2)
|
17 |
WEB
|
AtT4CKxT3rR0r1ST
|
|
2011-03-31
|
|
PHPBoost 3.0 - Remote Download Backup
|
15 |
WEB
|
KedAns-Dz
|
|
2011-03-30
|
|
Andy's PHP KnowledgeBase 0.95.2 - 'viewusers.php' SQL Injection
|
18 |
WEB
|
Mark Stanislav
|
|
2011-03-30
|
|
CosmoQuest - Authentication Bypass
|
16 |
WEB
|
Net.Edit0r
|
|
2011-03-30
|
|
BigACE 2.7.5 - Arbitrary File Upload
|
17 |
WEB
|
Net.Edit0r
|
|
2011-03-30
|
|
IrIran Shoping Script - SQL Injection
|
19 |
WEB
|
Net.Edit0r
|
|
2011-03-30
|
|
Pligg CMS 1.1.3 - Multiple Vulnerabilities
|
16 |
WEB
|
Jelmer de Hen
|
|
2011-03-30
|
|
YaCOMAS 0.3.6 Alpha - Multiple Vulnerabilities
|
17 |
WEB
|
Pr@fesOr X
|
|
2011-03-29
|
|
oscss2 2.1.0 rc12 - Multiple Vulnerabilities
|
17 |
WEB
|
AutoSec Tools
|
|
2011-03-29
|
|
Claroline 1.10 - Persistent Cross-Site Scripting
|
18 |
WEB
|
AutoSec Tools
|
|
2011-03-29
|
|
Andy's PHP KnowledgeBase 0.95.4 - SQL Injection
|
17 |
WEB
|
AutoSec Tools
|
|
2011-03-28
|
|
webEdition CMS - Local File Inclusion
|
18 |
WEB
|
eidelweiss
|
|
2011-03-28
|
|
WordPress Plugin BackWPup - Remote Code Execution / Local Code Execution
|
19 |
WEB
|
Sense of Security
|
|
2011-03-28
|
|
Honey Soft Web Solution - Multiple Vulnerabilities
|
17 |
WEB
|
**RoAd_KiLlEr**
|
|
2011-03-27
|
|
webEdition CMS 6.1.0.2 - Multiple Vulnerabilities
|
19 |
WEB
|
AutoSec Tools
|
|
2011-03-27
|
|
SimplisCMS 1.0.3.0 - Multiple Vulnerabilities
|
19 |
WEB
|
NassRawI
|
|
2011-03-26
|
|
Family Connections CMS 2.3.2 - Persistent Cross-Site Scripting / XML Injection
|
20 |
WEB
|
LiquidWorm
|
|
2011-03-24
|
|
SyndeoCMS 2.8.02 - Multiple Vulnerabilities (2)
|
16 |
WEB
|
High-Tech Bridge SA
|
|
2011-03-23
|
|
Web Wiz Forum - Injection
|
17 |
WEB
|
eXeSoul
|
|
2011-03-23
|
|
Constructr CMS 3.03 - Arbitrary File Upload
|
20 |
WEB
|
plucky
|
|
2011-03-23
|
|
Symantec LiveUpdate Administrator Management GUI - HTML Injection
|
17 |
WEB
|
Nikolas Sotiriu
|
|
2011-03-21
|
|
Shimbi CMS - Multiple SQL Injections
|
15 |
WEB
|
p0pc0rn
|
|
2011-03-21
|
|
EAFlashUpload 2.5 - Arbitrary File Upload
|
20 |
WEB
|
Daniel Godoy
|
|
2011-03-21
|
|
Element-IT PowUpload 1.3 - Arbitrary File Upload
|
19 |
WEB
|
Daniel Godoy
|
|
2011-03-21
|
|
CMS Lokomedia 1.5 - Arbitrary File Upload
|
17 |
WEB
|
eidelweiss
|
|
2011-03-20
|
|
Douran 3.9.7.8 - File Download/Source Code Disclosure
|
20 |
WEB
|
AJAX Security Team
|
|
2011-03-19
|
|
CMS Balitbang 3.3 - Arbitrary File Upload
|
21 |
WEB
|
eidelweiss
|
|
2011-03-19
|
|
Phpbuddies - Arbitrary File Upload
|
19 |
WEB
|
Xr0b0t
|
|
2011-03-19
|
|
Balitbang CMS 3.3 - Multiple Vulnerabilities
|
18 |
WEB
|
Xr0b0t
|
|
2011-03-19
|
|
Kleophatra 0.1.4 - Arbitrary File Upload
|
16 |
WEB
|
Xr0b0t
|
|
2011-03-18
|
|
iCMS 1.1 - Admin SQL Injection / Brute Force
|
21 |
WEB
|
TecR0c
|
|
2011-03-18
|
|
CMS Loko Media - Local File Download
|
20 |
WEB
|
Xr0b0t
|
|
2011-03-18
|
|
Tugux CMS - 'nid' Blind SQL Injection
|
17 |
WEB
|
eidelweiss
|
|
2011-03-17
|
|
Tugux CMS 1.0_final - Multiple Vulnerabilities
|
20 |
WEB
|
Aodrulez
|
|
2011-03-17
|
|
Joomla! Component com_booklibrary - SQL Injection
|
16 |
WEB
|
Marc Doudiet
|
|
2011-03-17
|
|
Joomla! 1.6 - Multiple SQL Injections
|
18 |
WEB
|
Aung Khant
|
|
2011-03-16
|
|
b2evolution 4.0.3 - Persistent Cross-Site Scripting
|
17 |
WEB
|
AutoSec Tools
|
|
2011-03-16
|
|
WikiWig 5.01 - Multiple Cross-Site Scripting Vulnerabilities
|
19 |
WEB
|
AutoSec Tools
|
|
2011-03-16
|
|
pointter PHP content management system 1.2 - Multiple Vulnerabilities
|
21 |
WEB
|
LiquidWorm
|
|
2011-03-16
|
|
LotusCMS 3.0.3 - Multiple Vulnerabilities
|
19 |
WEB
|
High-Tech Bridge SA
|
|
2011-03-15
|
|
IF-CMS 2.07 - Local File Inclusion (1)
|
18 |
WEB
|
TecR0c
|
|
2011-03-14
|
|
SmarterMail 8.0 - Multiple Cross-Site Scripting Vulnerabilities
|
20 |
WEB
|
Hoyt LLC Research
|
|
2011-03-14
|
|
Log1 CMS 2.0 - Multiple Vulnerabilities
|
20 |
WEB
|
Aodrulez
|
|
2011-03-13
|
|
Cover Vision - SQL Injection
|
18 |
WEB
|
Egyptian.H4x0rz
|
|
2011-03-11
|
|
Constructr CMS 3.03 - Multiple Remote Vulnerabilities
|
19 |
WEB
|
LiquidWorm
|
|
2011-03-11
|
|
SmarterStats 6.0 - Multiple Vulnerabilities
|
18 |
WEB
|
Hoyt LLC Research
|
|
2011-03-11
|
|
N_CMS 1.1E - Local File Inclusion / Remote Code
|
16 |
WEB
|
TecR0c
|
|
2011-03-11
|
|
Oracle WebLogic - POST Session Fixation
|
18 |
WEB
|
Roberto Suggi Liverani
|
|
2011-03-10
|
|
SmarterMail 7.3/7.4 - Multiple Vulnerabilities
|
16 |
WEB
|
Hoyt LLC Research
|
|
2011-03-10
|
|
Keynect eCommerce - SQL Injection
|
21 |
WEB
|
Arturo Zamora
|
|
2011-03-10
|
|
Luch Web Designer - Multiple SQL Injections
|
15 |
WEB
|
p0pc0rn
|
|
2011-03-09
|
|
recordpress 0.3.1 - Multiple Vulnerabilities
|
16 |
WEB
|
Khashayar Fereidani
|
|
2011-03-09
|
|
Maian Weblog 4.0 - Blind SQL Injection
|
13 |
WEB
|
mr_me
|
|
2011-03-09
|
|
Esselbach Storyteller CMS System 1.8 - SQL Injection
|
17 |
WEB
|
Shamus
|
|
2011-03-08
|
|
WordPress Plugin GRAND Flash Album Gallery 0.55 - Multiple Vulnerabilities
|
18 |
WEB
|
High-Tech Bridge SA
|
|
2011-03-08
|
|
Ruubikcms 1.0.3 - Multiple Vulnerabilities
|
17 |
WEB
|
Khashayar Fereidani
|
|
2011-03-08
|
|
EzPub Simple Classic ASP CMS - SQL Injection
|
20 |
WEB
|
p0pc0rn
|
|
2011-03-07
|
|
BMForum Myna 6.0 - SQL Injection
|
15 |
WEB
|
Stephan Sattler
|
|
2011-03-07
|
|
EggAvatar 2.3.2 for vBulletin 3.8.x - Local File Read
|
17 |
WEB
|
DSecurity
|
|
2011-03-07
|
|
Bacula-Web 1.3.x < 5.0.3 - Multiple Vulnerabilities
|
17 |
WEB
|
b0telh0
|
|
2011-03-06
|
|
EggAvatar for vBulletin 3.8.x - SQL Injection
|
22 |
WEB
|
DSecurity
|
|
2011-03-06
|
|
Quick Polls - Local File Inclusion / Deletion
|
18 |
WEB
|
Mark Stanislav
|
|
2011-03-06
|
|
N-13 News 4.0 - Cross-Site Request Forgery (Add Admin)
|
15 |
WEB
|
AtT4CKxT3rR0r1ST
|
|
2010-10-09
|
|
ContentKeeper Web - Remote Command Execution (Metasploit)
|
14 |
WEB
|
Metasploit
|
|
2010-07-03
|
|
Dogfood CRM - 'spell.php' Remote Command Execution (Metasploit)
|
18 |
WEB
|
Metasploit
|
|
2010-07-03
|
|
The Matt Wright Guestbook.pl - Arbitrary Command Execution (Metasploit)
|
20 |
WEB
|
Metasploit
|
|
2010-07-03
|
|
phpMyAdmin - Config File Code Injection (Metasploit)
|
20 |
WEB
|
Metasploit
|
|
2010-11-24
|
|
Mambo - Cache_Lite Class MosConfig_absolute_path Remote File Inclusion (Metasploit)
|
17 |
WEB
|
Metasploit
|
|
2010-09-20
|
|
TikiWiki tiki-graph_formula - PHP Remote Code Execution (Metasploit)
|
19 |
WEB
|
Metasploit
|
|
2010-07-03
|
|
Coppermine Photo Gallery 1.4.14 - 'picEditor.php' Command Execution (Metasploit)
|
15 |
WEB
|
Metasploit
|
|
2010-07-14
|
|
Nagios3 - 'statuswml.cgi' 'Ping' Command Execution (Metasploit)
|
17 |
WEB
|
Metasploit
|
|
2010-07-01
|
|
Google Appliance ProxyStyleSheet - Command Execution (Metasploit)
|
18 |
WEB
|
Metasploit
|
|
2010-06-15
|
|
Joomla! Plugin tinybrowser 1.5.12 - Arbitrary File Upload / Code Execution (Metasploit)
|
19 |
WEB
|
Metasploit
|
|
2009-12-26
|
|
AWStats 6.1 < 6.2 - 'configdir' Remote Command Execution (Metasploit)
|
18 |
WEB
|
Metasploit
|
|
2011-01-08
|
|
Fonality trixbox CE 2.6.1 - 'langChoice' Local File Inclusion (Metasploit)
|
18 |
WEB
|
Metasploit
|
|
2011-01-14
|
|
CakePHP 1.3.5/1.2.8 - Cache Corruption (Metasploit)
|
18 |
WEB
|
Metasploit
|
|
2010-04-30
|
|
PAJAX - Remote Command Execution (Metasploit)
|
19 |
WEB
|
Metasploit
|
|
2010-07-03
|
|
osCommerce 2.2 - Arbitrary PHP Code Execution (Metasploit)
|
16 |
WEB
|
Metasploit
|
|
2010-11-24
|
|
BASE - 'base_qry_common' Remote File Inclusion (Metasploit)
|
17 |
WEB
|
Metasploit
|
|
2010-07-25
|
|
vBulletin - 'misc.php' Template Name Arbitrary Code Execution (Metasploit)
|
19 |
WEB
|
Metasploit
|
|
2010-07-03
|
|
WordPress Core 1.5.1.3 - 'cache_lastpostdate' Arbitrary Code Execution (Metasploit)
|
20 |
WEB
|
Metasploit
|
|
2010-07-03
|
|
TWiki - Search Function Arbitrary Command Execution (Metasploit)
|
18 |
WEB
|
Metasploit
|
|
2010-04-30
|
|
Barracuda - IMG.pl Remote Command Execution (Metasploit)
|
15 |
WEB
|
Metasploit
|
|
2010-07-03
|
|
TWiki History TWikiUsers - 'rev' Command Execution (Metasploit)
|
18 |
WEB
|
Metasploit
|
|
2010-07-03
|
|
QuickTime Streaming Server - 'parse_xml.cgi' Remote Execution (Metasploit)
|
18 |
WEB
|
Metasploit
|
|
2010-07-03
|
|
phpBB - 'viewtopic.php' Arbitrary Code Execution (Metasploit)
|
18 |
WEB
|
Metasploit
|
|
2011-01-08
|
|
Redmine SCM Repository 0.9.x/1.0.x - Arbitrary Command Execution (Metasploit)
|
17 |
WEB
|
Metasploit
|
|
2010-07-03
|
|
AWStats 6.4 < 6.5 - migrate Remote Command Execution (Metasploit)
|
17 |
WEB
|
Metasploit
|
|
2010-07-25
|
|
TikiWiki jhot - Remote Command Execution (Metasploit)
|
19 |
WEB
|
Metasploit
|
|
2010-07-25
|
|
Simple PHP Blog 0.4.0 - Remote Command Execution (Metasploit)
|
20 |
WEB
|
Metasploit
|
|
2010-07-25
|
|
XML-RPC Library 1.3.0 - 'xmlrpc.php' Arbitrary Code Execution (Metasploit)
|
19 |
WEB
|
Metasploit
|
|
2010-07-03
|
|
Cacti - 'graph_view.php' Remote Command Execution (Metasploit)
|
21 |
WEB
|
Metasploit
|
|
2010-10-18
|
|
RedHat Piranha Virtual Server Package - 'passwd.php3' Arbitrary Command Execution (Metasploit)
|
17 |
WEB
|
Metasploit
|
|
2010-10-05
|
|
Alcatel-Lucent OmniPCX Enterprise - masterCGI Arbitrary Command Execution (Metasploit)
|
17 |
WEB
|
Metasploit
|
|
2010-07-07
|
|
DD-WRT HTTPd Daemon/Service - Arbitrary Command Execution (Metasploit)
|
21 |
WEB
|
Metasploit
|
|
2010-11-24
|
|
ColdFusion 8.0.1 - Arbitrary File Upload / Execution (Metasploit)
|
20 |
WEB
|
Metasploit
|
|
2010-11-24
|
|
FreeNAS - 'exec_raw.php' Arbitrary Command Execution (Metasploit)
|
17 |
WEB
|
Metasploit
|
|
2011-03-05
|
|
BoutikOne - 'description.php' SQL Injection
|
25 |
WEB
|
IRAQ_JAGUAR
|
|
2011-03-05
|
|
vTiger CRM 5.0.4 - Local File Inclusion
|
18 |
WEB
|
TecR0c
|
|
2011-03-05
|
|
MySms 1.0 - Multiple Vulnerabilities
|
19 |
WEB
|
AtT4CKxT3rR0r1ST
|
|
2011-03-04
|
|
ADAN Neuronlabs - 'view.php' SQL Injection
|
19 |
WEB
|
IRAQ_JAGUAR
|
|
2011-03-04
|
|
JBoss Application Server 4.2 < 4.2.0.CP09 / 4.3 < 4.3.0.CP08 - Remote Command Execution
|
18 |
WEB
|
kingcope
|
|
2011-03-04
|
|
WordPress Plugin PHP Speedy 0.5.2 - 'admin_container.php' Remote Code Execution
|
19 |
WEB
|
mr_me
|
|
2011-03-04
|
|
Limelight Software - 'article.php' SQL Injection
|
17 |
WEB
|
eXeSoul
|
|
2011-03-02
|
|
cChatBox for vBulletin 3.6.8/3.7.x - SQL Injection
|
20 |
WEB
|
DSecurity
|
|
2011-03-02
|
|
Bitweaver 2.8.0 - Multiple Vulnerabilities
|
22 |
WEB
|
lemlajt
|
|
2011-03-02
|
|
Quicktech - SQL Injection
|
21 |
WEB
|
eXeSoul
|