Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2011-03-27   webEdition CMS 6.1.0.2 - Multiple Vulnerabilities 8 WEB AutoSec Tools
2011-03-27   SimplisCMS 1.0.3.0 - Multiple Vulnerabilities 8 WEB NassRawI
2011-03-26   Family Connections CMS 2.3.2 - Persistent Cross-Site Scripting / XML Injection 8 WEB LiquidWorm
2011-03-24   SyndeoCMS 2.8.02 - Multiple Vulnerabilities (2) 8 WEB High-Tech Bridge SA
2011-03-23   Web Wiz Forum - Injection 8 WEB eXeSoul
2011-03-23   Constructr CMS 3.03 - Arbitrary File Upload 8 WEB plucky
2011-03-23   Symantec LiveUpdate Administrator Management GUI - HTML Injection 8 WEB Nikolas Sotiriu
2011-03-21   Shimbi CMS - Multiple SQL Injections 7 WEB p0pc0rn
2011-03-21   EAFlashUpload 2.5 - Arbitrary File Upload 8 WEB Daniel Godoy
2011-03-21   Element-IT PowUpload 1.3 - Arbitrary File Upload 7 WEB Daniel Godoy
2011-03-21   CMS Lokomedia 1.5 - Arbitrary File Upload 7 WEB eidelweiss
2011-03-20   Douran 3.9.7.8 - File Download/Source Code Disclosure 7 WEB AJAX Security Team
2011-03-19   CMS Balitbang 3.3 - Arbitrary File Upload 8 WEB eidelweiss
2011-03-19   Phpbuddies - Arbitrary File Upload 8 WEB Xr0b0t
2011-03-19   Balitbang CMS 3.3 - Multiple Vulnerabilities 8 WEB Xr0b0t
2011-03-19   Kleophatra 0.1.4 - Arbitrary File Upload 8 WEB Xr0b0t
2011-03-18   iCMS 1.1 - Admin SQL Injection / Brute Force 8 WEB TecR0c
2011-03-18   CMS Loko Media - Local File Download 8 WEB Xr0b0t
2011-03-18   Tugux CMS - 'nid' Blind SQL Injection 8 WEB eidelweiss
2011-03-17   Tugux CMS 1.0_final - Multiple Vulnerabilities 8 WEB Aodrulez
2011-03-17   Joomla! Component com_booklibrary - SQL Injection 8 WEB Marc Doudiet
2011-03-17   Joomla! 1.6 - Multiple SQL Injections 8 WEB Aung Khant
2011-03-16   b2evolution 4.0.3 - Persistent Cross-Site Scripting 8 WEB AutoSec Tools
2011-03-16   WikiWig 5.01 - Multiple Cross-Site Scripting Vulnerabilities 8 WEB AutoSec Tools
2011-03-16   pointter PHP content management system 1.2 - Multiple Vulnerabilities 8 WEB LiquidWorm
2011-03-16   LotusCMS 3.0.3 - Multiple Vulnerabilities 8 WEB High-Tech Bridge SA
2011-03-15   IF-CMS 2.07 - Local File Inclusion (1) 9 WEB TecR0c
2011-03-14   SmarterMail 8.0 - Multiple Cross-Site Scripting Vulnerabilities 8 WEB Hoyt LLC Research
2011-03-14   Log1 CMS 2.0 - Multiple Vulnerabilities 8 WEB Aodrulez
2011-03-13   Cover Vision - SQL Injection 9 WEB Egyptian.H4x0rz
2011-03-11   Constructr CMS 3.03 - Multiple Remote Vulnerabilities 8 WEB LiquidWorm
2011-03-11   SmarterStats 6.0 - Multiple Vulnerabilities 8 WEB Hoyt LLC Research
2011-03-11   N_CMS 1.1E - Local File Inclusion / Remote Code 8 WEB TecR0c
2011-03-11   Oracle WebLogic - POST Session Fixation 8 WEB Roberto Suggi Liverani
2011-03-10   SmarterMail 7.3/7.4 - Multiple Vulnerabilities 8 WEB Hoyt LLC Research
2011-03-10   Keynect eCommerce - SQL Injection 8 WEB Arturo Zamora
2011-03-10   Luch Web Designer - Multiple SQL Injections 7 WEB p0pc0rn
2011-03-09   recordpress 0.3.1 - Multiple Vulnerabilities 7 WEB Khashayar Fereidani
2011-03-09   Maian Weblog 4.0 - Blind SQL Injection 6 WEB mr_me
2011-03-09   Esselbach Storyteller CMS System 1.8 - SQL Injection 7 WEB Shamus
2011-03-08   WordPress Plugin GRAND Flash Album Gallery 0.55 - Multiple Vulnerabilities 7 WEB High-Tech Bridge SA
2011-03-08   Ruubikcms 1.0.3 - Multiple Vulnerabilities 7 WEB Khashayar Fereidani
2011-03-08   EzPub Simple Classic ASP CMS - SQL Injection 9 WEB p0pc0rn
2011-03-07   BMForum Myna 6.0 - SQL Injection 8 WEB Stephan Sattler
2011-03-07   EggAvatar 2.3.2 for vBulletin 3.8.x - Local File Read 8 WEB DSecurity
2011-03-07   Bacula-Web 1.3.x < 5.0.3 - Multiple Vulnerabilities 8 WEB b0telh0
2011-03-06   EggAvatar for vBulletin 3.8.x - SQL Injection 8 WEB DSecurity
2011-03-06   Quick Polls - Local File Inclusion / Deletion 8 WEB Mark Stanislav
2011-03-06   N-13 News 4.0 - Cross-Site Request Forgery (Add Admin) 8 WEB AtT4CKxT3rR0r1ST
2010-10-09   ContentKeeper Web - Remote Command Execution (Metasploit) 8 WEB Metasploit
2010-07-03   Dogfood CRM - 'spell.php' Remote Command Execution (Metasploit) 8 WEB Metasploit
2010-07-03   The Matt Wright Guestbook.pl - Arbitrary Command Execution (Metasploit) 7 WEB Metasploit
2010-07-03   phpMyAdmin - Config File Code Injection (Metasploit) 7 WEB Metasploit
2010-11-24   Mambo - Cache_Lite Class MosConfig_absolute_path Remote File Inclusion (Metasploit) 6 WEB Metasploit
2010-09-20   TikiWiki tiki-graph_formula - PHP Remote Code Execution (Metasploit) 7 WEB Metasploit
2010-07-03   Coppermine Photo Gallery 1.4.14 - 'picEditor.php' Command Execution (Metasploit) 7 WEB Metasploit
2010-07-14   Nagios3 - 'statuswml.cgi' 'Ping' Command Execution (Metasploit) 7 WEB Metasploit
2010-07-01   Google Appliance ProxyStyleSheet - Command Execution (Metasploit) 7 WEB Metasploit
2010-06-15   Joomla! Plugin tinybrowser 1.5.12 - Arbitrary File Upload / Code Execution (Metasploit) 7 WEB Metasploit
2009-12-26   AWStats 6.1 < 6.2 - 'configdir' Remote Command Execution (Metasploit) 7 WEB Metasploit
2011-01-08   Fonality trixbox CE 2.6.1 - 'langChoice' Local File Inclusion (Metasploit) 7 WEB Metasploit
2011-01-14   CakePHP 1.3.5/1.2.8 - Cache Corruption (Metasploit) 7 WEB Metasploit
2010-04-30   PAJAX - Remote Command Execution (Metasploit) 7 WEB Metasploit
2010-07-03   osCommerce 2.2 - Arbitrary PHP Code Execution (Metasploit) 7 WEB Metasploit
2010-11-24   BASE - 'base_qry_common' Remote File Inclusion (Metasploit) 7 WEB Metasploit
2010-07-25   vBulletin - 'misc.php' Template Name Arbitrary Code Execution (Metasploit) 7 WEB Metasploit
2010-07-03   WordPress Core 1.5.1.3 - 'cache_lastpostdate' Arbitrary Code Execution (Metasploit) 7 WEB Metasploit
2010-07-03   TWiki - Search Function Arbitrary Command Execution (Metasploit) 7 WEB Metasploit
2010-04-30   Barracuda - IMG.pl Remote Command Execution (Metasploit) 7 WEB Metasploit
2010-07-03   TWiki History TWikiUsers - 'rev' Command Execution (Metasploit) 6 WEB Metasploit
2010-07-03   QuickTime Streaming Server - 'parse_xml.cgi' Remote Execution (Metasploit) 6 WEB Metasploit
2010-07-03   phpBB - 'viewtopic.php' Arbitrary Code Execution (Metasploit) 7 WEB Metasploit
2011-01-08   Redmine SCM Repository 0.9.x/1.0.x - Arbitrary Command Execution (Metasploit) 7 WEB Metasploit
2010-07-03   AWStats 6.4 < 6.5 - migrate Remote Command Execution (Metasploit) 8 WEB Metasploit
2010-07-25   TikiWiki jhot - Remote Command Execution (Metasploit) 7 WEB Metasploit
2010-07-25   Simple PHP Blog 0.4.0 - Remote Command Execution (Metasploit) 7 WEB Metasploit
2010-07-25   XML-RPC Library 1.3.0 - 'xmlrpc.php' Arbitrary Code Execution (Metasploit) 7 WEB Metasploit
2010-07-03   Cacti - 'graph_view.php' Remote Command Execution (Metasploit) 8 WEB Metasploit
2010-10-18   RedHat Piranha Virtual Server Package - 'passwd.php3' Arbitrary Command Execution (Metasploit) 7 WEB Metasploit
2010-10-05   Alcatel-Lucent OmniPCX Enterprise - masterCGI Arbitrary Command Execution (Metasploit) 7 WEB Metasploit
2010-07-07   DD-WRT HTTPd Daemon/Service - Arbitrary Command Execution (Metasploit) 8 WEB Metasploit
2010-11-24   ColdFusion 8.0.1 - Arbitrary File Upload / Execution (Metasploit) 8 WEB Metasploit
2010-11-24   FreeNAS - 'exec_raw.php' Arbitrary Command Execution (Metasploit) 8 WEB Metasploit
2011-03-05   BoutikOne - 'description.php' SQL Injection 10 WEB IRAQ_JAGUAR
2011-03-05   vTiger CRM 5.0.4 - Local File Inclusion 8 WEB TecR0c
2011-03-05   MySms 1.0 - Multiple Vulnerabilities 8 WEB AtT4CKxT3rR0r1ST
2011-03-04   ADAN Neuronlabs - 'view.php' SQL Injection 9 WEB IRAQ_JAGUAR
2011-03-04   JBoss Application Server 4.2 < 4.2.0.CP09 / 4.3 < 4.3.0.CP08 - Remote Command Execution 8 WEB kingcope
2011-03-04   WordPress Plugin PHP Speedy 0.5.2 - 'admin_container.php' Remote Code Execution 7 WEB mr_me
2011-03-04   Limelight Software - 'article.php' SQL Injection 9 WEB eXeSoul
2011-03-02   cChatBox for vBulletin 3.6.8/3.7.x - SQL Injection 9 WEB DSecurity
2011-03-02   Bitweaver 2.8.0 - Multiple Vulnerabilities 10 WEB lemlajt
2011-03-02   Quicktech - SQL Injection 10 WEB eXeSoul
2011-03-02   Readmore Systems Script - SQL Injection 11 WEB vBzone & Zooka & El3arby
2011-02-28   SnapProof - 'page.php' SQL Injection 9 WEB AtT4CKxT3rR0r1ST
2011-02-28   DO-CMS - Multiple SQL Injections 10 WEB AtT4CKxT3rR0r1ST
2011-02-26   Cisco Linksys WAG120N - Cross-Site Request Forgery 8 WEB Khashayar Fereidani
2011-02-26   WordPress Plugin OPS Old Post Spinner 2.2.1 - Local File Inclusion 8 WEB AutoSec Tools
2011-02-26   WordPress Plugin jQuery Mega Menu 1.0 - Local File Inclusion 9 WEB AutoSec Tools
2011-02-26   phreebooks r30rc4 - Multiple Vulnerabilities 9 WEB AutoSec Tools
2011-02-25   Pragyan CMS 3.0 - Multiple Vulnerabilities 9 WEB Villy & Abhishek Lyall
2011-02-25   Joomla! Component com_xcloner-backupandrestore - Remote Command Execution 10 WEB mr_me
2011-02-25   RaksoCT - Multiple SQL Injections 9 WEB p0pc0rn
2011-02-24   WordPress Plugin IWantOneButton 3.0.1 - Multiple Vulnerabilities 9 WEB High-Tech Bridge SA
2011-02-24   WordPress Plugin Forum Server 1.6.5 - SQL Injection 10 WEB High-Tech Bridge SA
2011-02-24   WordPress Plugin Relevanssi 2.7.2 - Persistent Cross-Site Scripting 10 WEB Saif El-Sherei
2011-02-24   WordPress Plugin GigPress 2.1.10 - Persistent Cross-Site Scripting 11 WEB Saif El-Sherei
2011-02-24   Alcassoft's SOPHIA CMS - SQL Injection 8 WEB p0pc0rn
2011-02-23   VidiScript - SQL Injection 10 WEB ThEtA.Nu
2011-02-23   course registration management system 2.1 - Multiple Vulnerabilities 10 WEB AutoSec Tools
2011-02-23   WordPress Plugin Comment Rating 2.9.23 - Multiple Vulnerabilities 10 WEB High-Tech Bridge SA
2011-02-23   ProQuiz 2.0.0b - Arbitrary File Upload 9 WEB AutoSec Tools
2011-02-23   WordPress Plugin Z-Vote 1.1 - SQL Injection 10 WEB High-Tech Bridge SA
2011-02-23   Bitweaver 2.8.1 - Persistent Cross-Site Scripting 9 WEB lemlajt
2011-02-23   tplSoccerStats - 'player.php' SQL Injection 9 WEB AtT4CKxT3rR0r1ST
2011-02-23   Hyena Cart - 'index.php' SQL Injection 10 WEB AtT4CKxT3rR0r1ST
2011-02-22   dotProject 2.1.5 - Multiple Vulnerabilities 10 WEB lemlajt
2011-02-22   Galilery 1.0 - Local File Inclusion 10 WEB lemlajt
2011-02-22   DIY Web CMS - Multiple Vulnerabilities 9 WEB p0pc0rn
2011-02-21   Woltlab Burning Board 2.3.6 Addon - 'hilfsmittel.php' SQL Injection 9 WEB Crazyball
2011-02-20   JAKCMS 2.01 RC1 - Blind SQL Injection 9 WEB mr_me
2011-02-20   JAKCMS 2.01 - Code Execution 10 WEB mr_me
2011-02-20   Icy Phoenix 1.3.0.53a - HTTP Referer Persistent Cross-Site Scripting 9 WEB Saif El-Sherei
2011-02-19   Independent Escort CMS - Blind SQL Injection 9 WEB NoNameMT
2011-02-19   Escort Directory CMS - SQL Injection 8 WEB NoNameMT