2010-10-27
|
|
MyBB 1.6 - Full Path Disclosure
|
4 |
WEB
|
High-Tech Bridge SA
|
2010-10-27
|
|
Novaboard 1.1.4 - Local File Inclusion
|
4 |
WEB
|
High-Tech Bridge SA
|
2010-10-27
|
|
DZCP (deV!L_z Clanportal) 1.5.4 - Local File Inclusion
|
4 |
WEB
|
High-Tech Bridge SA
|
2010-10-27
|
|
phpLiterAdmin 1.0 RC1 - Authentication Bypass
|
3 |
WEB
|
High-Tech Bridge SA
|
2010-10-27
|
|
DBHcms 1.1.4 - 'dbhcms_user/SearchString' SQL Injection
|
3 |
WEB
|
High-Tech Bridge SA
|
2010-10-26
|
|
BigACE 2.7.3 - Cross-Site Request Forgery (Change Admin Password)
|
4 |
WEB
|
Sweet
|
2010-10-25
|
|
Plesk Small Business Manager 10.2.0 and Site Editor - Multiple Vulnerabilities
|
5 |
WEB
|
David Hoyt
|
2010-10-25
|
|
Jamb - Cross-Site Request Forgery (Add a Post)
|
3 |
WEB
|
Stoke
|
2010-10-24
|
|
DBHcms 1.1.4 - 'dbhcms_pid' SQL Injection
|
5 |
WEB
|
ZonTa
|
2010-10-24
|
|
Pulse Pro 1.4.3 - Persistent Cross-Site Scripting
|
5 |
WEB
|
Th3 RDX
|
2010-10-21
|
|
Squirrelcart PRO 3.0.0 - Blind SQL Injection
|
4 |
WEB
|
Salvatore Fresta
|
2010-10-21
|
|
sNews CMS - Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
High-Tech Bridge SA
|
2010-10-20
|
|
Oracle Sun Java System Web Server - HTTP Response Splitting
|
4 |
WEB
|
Roberto Suggi Liverani
|
2010-10-19
|
|
phpCheckZ 1.1.0 - Blind SQL Injection
|
5 |
WEB
|
Salvatore Fresta
|
2010-10-19
|
|
Event Ticket Portal Script Admin Password Change - Cross-Site Request Forgery
|
4 |
WEB
|
KnocKout
|
2010-10-19
|
|
Travel Portal Script - Cross-Site Request Forgery (Admin Password Change)
|
5 |
WEB
|
KnocKout
|
2010-10-18
|
|
Brooky CubeCart 2.0.1 - SQL Injection
|
5 |
WEB
|
X_AviaTique_X
|
2010-10-18
|
|
GeekLog 1.7.0 - 'FCKeditor' Arbitrary File Upload
|
4 |
WEB
|
Kubanezi AHG
|
2010-10-18
|
|
411cc - Multiple SQL Injections
|
5 |
WEB
|
KnocKout
|
2010-10-17
|
|
Kisisel Radyo Script - Multiple Vulnerabilities
|
5 |
WEB
|
FuRty
|
2010-10-17
|
|
Tastydir 1.2 (1216) - Multiple Vulnerabilities
|
4 |
WEB
|
R
|
2010-10-17
|
|
WikiWebHelp 0.3.3 - Insecure Cookie Handling
|
4 |
WEB
|
FuRty
|
2010-10-15
|
|
KCFinder 2.2 - Arbitrary File Upload
|
4 |
WEB
|
saudi0hacker
|
2010-10-14
|
|
Xlrstats 2.0.1 - SQL Injection
|
4 |
WEB
|
Sky4
|
2010-10-14
|
|
Data/File - upload and Management Arbitrary File Upload
|
4 |
WEB
|
saudi0hacker
|
2010-10-13
|
|
Exponent CMS 0.97 - Multiple Vulnerabilities
|
4 |
WEB
|
LiquidWorm
|
2010-10-12
|
|
Collabtive 0.65 - Multiple Vulnerabilities
|
4 |
WEB
|
Anatolia Security
|
2010-10-12
|
|
WikiWebHelp 0.3.3 - Cross-Site Request Forgery
|
4 |
WEB
|
Yoyahack
|
2010-10-12
|
|
AdaptCMS 2.0.1 Beta - Remote File Inclusion (Metasploit)
|
4 |
WEB
|
v3n0m
|
2010-10-11
|
|
BaconMap 1.0 - Local File Disclosure
|
4 |
WEB
|
John Leitch
|
2010-10-11
|
|
BaconMap 1.0 - SQL Injection
|
4 |
WEB
|
John Leitch
|
2010-10-11
|
|
OrangeHRM 2.6.0.1 - Local File Inclusion
|
4 |
WEB
|
ZonTa
|
2010-10-10
|
|
Site2Nite Auto e-Manager - SQL Injection
|
4 |
WEB
|
KnocKout
|
2010-10-10
|
|
PHP-Fusion Mod Mg User Fotoalbum 1.0.1 - SQL Injection
|
4 |
WEB
|
Easy Laster
|
2010-10-09
|
|
VideoDB 3.0.3 - Multiple Vulnerabilities
|
4 |
WEB
|
Valentin
|
2010-10-09
|
|
Joomla! Component JS Calendar 1.5.1 - Multiple Vulnerabilities
|
4 |
WEB
|
Salvatore Fresta
|
2010-10-09
|
|
Chipmunk Pwngame - Multiple SQL Injections
|
4 |
WEB
|
KnocKout
|
2010-10-09
|
|
Joomla! Component Community Builder Enhanced (CBE) 1.4.8/1.4.9/1.4.10 - Local File Inclusion / Remot
|
4 |
WEB
|
Delf Tonder
|
2010-10-08
|
|
Flex Timesheet - Authentication Bypass
|
4 |
WEB
|
KnocKout
|
2010-10-08
|
|
xWeblog 2.2 - 'arsiv.asp?tarih' SQL Injection
|
4 |
WEB
|
ZoRLu
|
2010-10-07
|
|
xWeblog 2.2 - 'oku.asp?makale_id' SQL Injection
|
4 |
WEB
|
KnocKout
|
2010-10-07
|
|
Feindura File Manager 1.0(rc) - Arbitrary File Upload
|
4 |
WEB
|
KnocKout
|
2010-10-05
|
|
Cag CMS 0.2 - Cross-Site Scripting / Blind SQL Injection
|
4 |
WEB
|
Shamus
|
2010-10-05
|
|
SPAW Editor 2.0.8.1 - Local File Inclusion
|
5 |
WEB
|
soorakh kos
|
2010-10-05
|
|
CuteNews - 'page' Local File Inclusion
|
3 |
WEB
|
eidelweiss
|
2010-10-04
|
|
Uebimiau Webmail 3.2.0-2.0 - Local File Inclusion
|
6 |
WEB
|
blake
|
2010-10-04
|
|
Aspect Ratio CMS - Blind SQL Injection
|
6 |
WEB
|
Stephan Sattler
|
2010-10-04
|
|
DNET Live-Stats 0.8 - Local File Inclusion
|
5 |
WEB
|
blake
|
2010-10-04
|
|
FAQMasterFlex 1.2 - SQL Injection
|
3 |
WEB
|
cyb3r.anbu
|
2010-10-04
|
|
Cilem Haber 1.4.4 (Tr) - Database Disclosure
|
4 |
WEB
|
ZoRLu
|
2010-10-03
|
|
Aprox CMS Engine 6.0 - Multiple Vulnerabilities
|
4 |
WEB
|
Stephan Sattler
|
2010-10-03
|
|
TinyMCE MCFileManager 2.1.2 - Arbitrary File Upload
|
3 |
WEB
|
Hackeri-AL
|
2010-10-02
|
|
TradeMC E-Ticaret - SQL Injection / Cross-Site Scripting
|
4 |
WEB
|
KnocKout
|
2010-10-02
|
|
SmarterMail < 7.2.3925 - LDAP Injection
|
4 |
WEB
|
sqlhacker
|
2010-10-02
|
|
SmarterMail < 7.2.3925 - Persistent Cross-Site Scripting
|
4 |
WEB
|
sqlhacker
|
2010-10-02
|
|
Bka Haber 1.0 (Tr) - File Disclosure
|
4 |
WEB
|
ZoRLu
|
2010-10-01
|
|
iGaming CMS 1.5 - Blind SQL Injection
|
4 |
WEB
|
plucky
|
2010-10-01
|
|
Chipmunk Board 1.3 - 'index.php?forumID' SQL Injection
|
4 |
WEB
|
Shamus
|
2010-10-01
|
|
Tiki Wiki CMS Groupware 5.2 - Multiple Vulnerabilities
|
4 |
WEB
|
John Leitch
|
2010-10-01
|
|
phpMyShopping 1.0.1505 - Multiple Vulnerabilities
|
4 |
WEB
|
Metropolis
|
2010-10-01
|
|
jCart 1.1 - Multiple Cross-Site Scripting / Cross-Site Request Forgery/Open Redirect Vulnerabilities
|
4 |
WEB
|
p0deje
|
2010-10-01
|
|
Evaria Content Management System 1.1 - File Disclosure
|
4 |
WEB
|
khayeye shotor
|
2010-10-01
|
|
Zen Cart 1.3.9f - 'typefilter' Local File Inclusion
|
4 |
WEB
|
LiquidWorm
|
2010-10-01
|
|
zen cart 1.3.9f - Multiple Vulnerabilities
|
4 |
WEB
|
LiquidWorm
|
2010-09-30
|
|
JomSocial 1.8.8 - Arbitrary File Upload
|
4 |
WEB
|
Jeff Channell
|
2010-09-30
|
|
Joomla! Component JE Directory 1.0 - SQL Injection
|
4 |
WEB
|
Easy Laster
|
2010-09-30
|
|
Joomla! Component JE Job - SQL Injection
|
4 |
WEB
|
Easy Laster
|
2010-09-30
|
|
ASPMass Shopping Cart - Arbitrary File Upload / Cross-Site Request Forgery
|
4 |
WEB
|
Abysssec
|
2010-09-30
|
|
Joomla! Component JE Guestbook 1.0 - Multiple Vulnerabilities
|
4 |
WEB
|
Salvatore Fresta
|
2010-09-29
|
|
MyPhpAuction 2010 - 'id' SQL Injection
|
4 |
WEB
|
h4ck3r
|
2010-09-29
|
|
Webspell 4.x - safe_query Bypass
|
4 |
WEB
|
silent vapor
|
2010-09-29
|
|
Webspell wCMS-Clanscript4.01.02net - static Blind SQL Injection
|
4 |
WEB
|
Easy Laster
|
2010-09-29
|
|
Webspell 4.2.1 - 'asearch.php' SQL Injection
|
4 |
WEB
|
silent vapor
|
2010-09-28
|
|
Micro CMS 1.0 b1 - Persistent Cross-Site Scripting
|
4 |
WEB
|
SecPod Research
|
2010-09-28
|
|
Achievo 1.4.3 - Cross-Site Request Forgery
|
4 |
WEB
|
Pablo Milano
|
2010-09-28
|
|
Achievo 1.4.3 - Multiple Authorisation Vulnerabilities
|
4 |
WEB
|
Pablo Milano
|
2010-09-28
|
|
Aleza Portal 1.6 - Insecure SQL Injection / Cookie Handling
|
3 |
WEB
|
KnocKout
|
2010-09-28
|
|
e107 0.7.23 - SQL Injection
|
4 |
WEB
|
High-Tech Bridge SA
|
2010-09-28
|
|
JE CMS 1.0.0 - Authentication Bypass
|
4 |
WEB
|
Abysssec
|
2010-09-28
|
|
AtomatiCMS - Upload Arbitrary File
|
4 |
WEB
|
Abysssec
|
2010-09-27
|
|
Car Portal 2.0 - Blind SQL Injection
|
5 |
WEB
|
**RoAd_KiLlEr**
|
2010-09-27
|
|
Barracuda Networks Spam & Virus Firewall 4.1.1.021 - Remote Configuration Retrieval
|
4 |
WEB
|
ShadowHatesYou
|
2010-09-27
|
|
Allpc 2.5 osCommerce - SQL Injection / Cross-Site Scripting
|
4 |
WEB
|
**RoAd_KiLlEr**
|
2010-09-27
|
|
Entrans - SQL Injection
|
4 |
WEB
|
keracker
|
2010-09-27
|
|
ndCMS - SQL Injection
|
5 |
WEB
|
Abysssec
|
2010-09-27
|
|
pbboard 2.1.1 - Multiple Vulnerabilities
|
5 |
WEB
|
JIKO
|
2010-09-26
|
|
Blue River Mura CMS - Directory Traversal
|
4 |
WEB
|
mr_me
|
2010-09-26
|
|
PEEL Premium 5.71 - SQL Injection
|
4 |
WEB
|
KnocKout
|
2010-09-26
|
|
gokhun asp stok 1.0 - Multiple Vulnerabilities
|
4 |
WEB
|
KnocKout
|
2010-09-26
|
|
ZenPhoto - Config Update / Command Execution
|
3 |
WEB
|
Abysssec
|
2010-09-25
|
|
E-Xoopport Samsara 3.1 (eCal Module) - Blind SQL Injection
|
4 |
WEB
|
_mRkZ_
|
2010-09-25
|
|
VisualSite CMS 1.3 - Multiple Vulnerabilities
|
3 |
WEB
|
Abysssec
|
2010-09-24
|
|
Traidnt UP - Cross-Site Request Forgery (Add Admin)
|
5 |
WEB
|
John Johnz
|
2010-09-24
|
|
Joomla! Component Elite Experts - SQL Injection
|
4 |
WEB
|
**RoAd_KiLlEr**
|
2010-09-24
|
|
FreePBX 2.8.0 - Recordings Interface Allows Remote Code Execution
|
3 |
WEB
|
Trustwave's SpiderLabs
|
2010-09-24
|
|
Collaborative Passwords Manager 1.07 - Multiple Local File Inclusions
|
4 |
WEB
|
sh00t0ut
|
2010-09-23
|
|
OvBB 0.16a - Multiple Local File Inclusions
|
4 |
WEB
|
cOndemned
|
2010-09-23
|
|
GeekLog 1.3.8 (filemgmt) - SQL Injection
|
4 |
WEB
|
Gamoscu
|
2010-09-23
|
|
WAnewsletter 2.1.2 - SQL Injection
|
3 |
WEB
|
BrOx-Dz
|
2010-09-22
|
|
Joomla! Component Joostina - SQL Injection
|
4 |
WEB
|
Gamoscu
|
2010-09-22
|
|
Joomla! Component TimeTrack 1.2.4 - Multiple SQL Injections
|
4 |
WEB
|
Salvatore Fresta
|
2010-09-22
|
|
BSI Hotel Booking System Admin 1.4/2.0 - Authentication Bypass
|
4 |
WEB
|
K-159
|
2010-09-22
|
|
Skybluecanvas 1.1-r248 - Cross-Site Request Forgery
|
5 |
WEB
|
Sweet
|
2010-09-22
|
|
gausCMS - Multiple Vulnerabilities
|
4 |
WEB
|
Abysssec
|
2010-09-21
|
|
wpQuiz 2.7 - Authentication Bypass
|
4 |
WEB
|
KnocKout
|
2010-09-21
|
|
ibPhotohost 1.1.2 - SQL Injection
|
5 |
WEB
|
fred777
|
2010-09-21
|
|
Personal.Net Portal - Multiple Vulnerabilities
|
6 |
WEB
|
Abysssec
|
2010-09-20
|
|
primitive CMS 1.0.9 - Multiple Vulnerabilities
|
5 |
WEB
|
Stephan Sattler
|
2010-09-20
|
|
LightNEasy CMS 3.2.1 - Blind SQL Injection
|
4 |
WEB
|
Solidmedia
|
2010-09-20
|
|
VWD-CMS - Cross-Site Request Forgery
|
4 |
WEB
|
Abysssec
|
2010-09-19
|
|
Opencart 1.4.9.1 - Arbitrary File Upload
|
4 |
WEB
|
Net.Edit0r
|
2010-09-19
|
|
BoutikOne 1.0 - SQL Injection
|
6 |
WEB
|
BrOx-Dz
|
2010-09-19
|
|
Fashione E-Commerce Webshop - Multiple SQL Injections
|
4 |
WEB
|
secret
|
2010-09-19
|
|
jmd-cms - Multiple Vulnerabilities
|
4 |
WEB
|
Abysssec
|
2010-09-18
|
|
Maian Gallery 2 - Local File Download
|
4 |
WEB
|
mr_me
|
2010-09-18
|
|
Joomla! Component Restaurant Guide 1.0.0 - Multiple Vulnerabilities
|
4 |
WEB
|
Valentin
|
2010-09-18
|
|
xt:Commerce Gambio 2008 < 2010 - 'reviews.php' Error-Based SQL Injection
|
4 |
WEB
|
secret
|
2010-09-18
|
|
CMSimple - Cross-Site Request Forgery
|
4 |
WEB
|
Abysssec
|
2010-09-17
|
|
phpMyFamily - Multiple Vulnerabilities
|
4 |
WEB
|
Abysssec
|
2010-09-16
|
|
mojoportal - Multiple Vulnerabilities
|
4 |
WEB
|
Abysssec
|
2010-09-15
|
|
PixelPost 1.7.3 - Multiple Vulnerabilities
|
4 |
WEB
|
Sweet
|
2010-09-15
|
|
PHP microcms 1.0.1 - Multiple Vulnerabilities
|
3 |
WEB
|
Abysssec
|
2010-09-15
|
|
eNdonesia 8.4 - SQL Injection
|
4 |
WEB
|
vYc0d
|
2010-09-14
|
|
E-Xoopport Samsara 3.1 (Sections Module) - Blind SQL Injection
|
4 |
WEB
|
_mRkZ_
|
2010-09-14
|
|
freediscussionforums 1.0 - Multiple Vulnerabilities
|
4 |
WEB
|
Abysssec
|