Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2010-10-27   MyBB 1.6 - Full Path Disclosure 4 WEB High-Tech Bridge SA
2010-10-27   Novaboard 1.1.4 - Local File Inclusion 4 WEB High-Tech Bridge SA
2010-10-27   DZCP (deV!L_z Clanportal) 1.5.4 - Local File Inclusion 4 WEB High-Tech Bridge SA
2010-10-27   phpLiterAdmin 1.0 RC1 - Authentication Bypass 3 WEB High-Tech Bridge SA
2010-10-27   DBHcms 1.1.4 - 'dbhcms_user/SearchString' SQL Injection 3 WEB High-Tech Bridge SA
2010-10-26   BigACE 2.7.3 - Cross-Site Request Forgery (Change Admin Password) 4 WEB Sweet
2010-10-25   Plesk Small Business Manager 10.2.0 and Site Editor - Multiple Vulnerabilities 5 WEB David Hoyt
2010-10-25   Jamb - Cross-Site Request Forgery (Add a Post) 3 WEB Stoke
2010-10-24   DBHcms 1.1.4 - 'dbhcms_pid' SQL Injection 5 WEB ZonTa
2010-10-24   Pulse Pro 1.4.3 - Persistent Cross-Site Scripting 5 WEB Th3 RDX
2010-10-21   Squirrelcart PRO 3.0.0 - Blind SQL Injection 4 WEB Salvatore Fresta
2010-10-21   sNews CMS - Multiple Cross-Site Scripting Vulnerabilities 4 WEB High-Tech Bridge SA
2010-10-20   Oracle Sun Java System Web Server - HTTP Response Splitting 4 WEB Roberto Suggi Liverani
2010-10-19   phpCheckZ 1.1.0 - Blind SQL Injection 5 WEB Salvatore Fresta
2010-10-19   Event Ticket Portal Script Admin Password Change - Cross-Site Request Forgery 4 WEB KnocKout
2010-10-19   Travel Portal Script - Cross-Site Request Forgery (Admin Password Change) 5 WEB KnocKout
2010-10-18   Brooky CubeCart 2.0.1 - SQL Injection 5 WEB X_AviaTique_X
2010-10-18   GeekLog 1.7.0 - 'FCKeditor' Arbitrary File Upload 4 WEB Kubanezi AHG
2010-10-18   411cc - Multiple SQL Injections 5 WEB KnocKout
2010-10-17   Kisisel Radyo Script - Multiple Vulnerabilities 5 WEB FuRty
2010-10-17   Tastydir 1.2 (1216) - Multiple Vulnerabilities 4 WEB R
2010-10-17   WikiWebHelp 0.3.3 - Insecure Cookie Handling 4 WEB FuRty
2010-10-15   KCFinder 2.2 - Arbitrary File Upload 4 WEB saudi0hacker
2010-10-14   Xlrstats 2.0.1 - SQL Injection 4 WEB Sky4
2010-10-14   Data/File - upload and Management Arbitrary File Upload 4 WEB saudi0hacker
2010-10-13   Exponent CMS 0.97 - Multiple Vulnerabilities 4 WEB LiquidWorm
2010-10-12   Collabtive 0.65 - Multiple Vulnerabilities 4 WEB Anatolia Security
2010-10-12   WikiWebHelp 0.3.3 - Cross-Site Request Forgery 4 WEB Yoyahack
2010-10-12   AdaptCMS 2.0.1 Beta - Remote File Inclusion (Metasploit) 4 WEB v3n0m
2010-10-11   BaconMap 1.0 - Local File Disclosure 4 WEB John Leitch
2010-10-11   BaconMap 1.0 - SQL Injection 4 WEB John Leitch
2010-10-11   OrangeHRM 2.6.0.1 - Local File Inclusion 4 WEB ZonTa
2010-10-10   Site2Nite Auto e-Manager - SQL Injection 4 WEB KnocKout
2010-10-10   PHP-Fusion Mod Mg User Fotoalbum 1.0.1 - SQL Injection 4 WEB Easy Laster
2010-10-09   VideoDB 3.0.3 - Multiple Vulnerabilities 4 WEB Valentin
2010-10-09   Joomla! Component JS Calendar 1.5.1 - Multiple Vulnerabilities 4 WEB Salvatore Fresta
2010-10-09   Chipmunk Pwngame - Multiple SQL Injections 4 WEB KnocKout
2010-10-09   Joomla! Component Community Builder Enhanced (CBE) 1.4.8/1.4.9/1.4.10 - Local File Inclusion / Remot 4 WEB Delf Tonder
2010-10-08   Flex Timesheet - Authentication Bypass 4 WEB KnocKout
2010-10-08   xWeblog 2.2 - 'arsiv.asp?tarih' SQL Injection 4 WEB ZoRLu
2010-10-07   xWeblog 2.2 - 'oku.asp?makale_id' SQL Injection 4 WEB KnocKout
2010-10-07   Feindura File Manager 1.0(rc) - Arbitrary File Upload 4 WEB KnocKout
2010-10-05   Cag CMS 0.2 - Cross-Site Scripting / Blind SQL Injection 4 WEB Shamus
2010-10-05   SPAW Editor 2.0.8.1 - Local File Inclusion 5 WEB soorakh kos
2010-10-05   CuteNews - 'page' Local File Inclusion 3 WEB eidelweiss
2010-10-04   Uebimiau Webmail 3.2.0-2.0 - Local File Inclusion 6 WEB blake
2010-10-04   Aspect Ratio CMS - Blind SQL Injection 6 WEB Stephan Sattler
2010-10-04   DNET Live-Stats 0.8 - Local File Inclusion 5 WEB blake
2010-10-04   FAQMasterFlex 1.2 - SQL Injection 3 WEB cyb3r.anbu
2010-10-04   Cilem Haber 1.4.4 (Tr) - Database Disclosure 4 WEB ZoRLu
2010-10-03   Aprox CMS Engine 6.0 - Multiple Vulnerabilities 4 WEB Stephan Sattler
2010-10-03   TinyMCE MCFileManager 2.1.2 - Arbitrary File Upload 3 WEB Hackeri-AL
2010-10-02   TradeMC E-Ticaret - SQL Injection / Cross-Site Scripting 4 WEB KnocKout
2010-10-02   SmarterMail < 7.2.3925 - LDAP Injection 4 WEB sqlhacker
2010-10-02   SmarterMail < 7.2.3925 - Persistent Cross-Site Scripting 4 WEB sqlhacker
2010-10-02   Bka Haber 1.0 (Tr) - File Disclosure 4 WEB ZoRLu
2010-10-01   iGaming CMS 1.5 - Blind SQL Injection 4 WEB plucky
2010-10-01   Chipmunk Board 1.3 - 'index.php?forumID' SQL Injection 4 WEB Shamus
2010-10-01   Tiki Wiki CMS Groupware 5.2 - Multiple Vulnerabilities 4 WEB John Leitch
2010-10-01   phpMyShopping 1.0.1505 - Multiple Vulnerabilities 4 WEB Metropolis
2010-10-01   jCart 1.1 - Multiple Cross-Site Scripting / Cross-Site Request Forgery/Open Redirect Vulnerabilities 4 WEB p0deje
2010-10-01   Evaria Content Management System 1.1 - File Disclosure 4 WEB khayeye shotor
2010-10-01   Zen Cart 1.3.9f - 'typefilter' Local File Inclusion 4 WEB LiquidWorm
2010-10-01   zen cart 1.3.9f - Multiple Vulnerabilities 4 WEB LiquidWorm
2010-09-30   JomSocial 1.8.8 - Arbitrary File Upload 4 WEB Jeff Channell
2010-09-30   Joomla! Component JE Directory 1.0 - SQL Injection 4 WEB Easy Laster
2010-09-30   Joomla! Component JE Job - SQL Injection 4 WEB Easy Laster
2010-09-30   ASPMass Shopping Cart - Arbitrary File Upload / Cross-Site Request Forgery 4 WEB Abysssec
2010-09-30   Joomla! Component JE Guestbook 1.0 - Multiple Vulnerabilities 4 WEB Salvatore Fresta
2010-09-29   MyPhpAuction 2010 - 'id' SQL Injection 4 WEB h4ck3r
2010-09-29   Webspell 4.x - safe_query Bypass 4 WEB silent vapor
2010-09-29   Webspell wCMS-Clanscript4.01.02net - static Blind SQL Injection 4 WEB Easy Laster
2010-09-29   Webspell 4.2.1 - 'asearch.php' SQL Injection 4 WEB silent vapor
2010-09-28   Micro CMS 1.0 b1 - Persistent Cross-Site Scripting 4 WEB SecPod Research
2010-09-28   Achievo 1.4.3 - Cross-Site Request Forgery 4 WEB Pablo Milano
2010-09-28   Achievo 1.4.3 - Multiple Authorisation Vulnerabilities 4 WEB Pablo Milano
2010-09-28   Aleza Portal 1.6 - Insecure SQL Injection / Cookie Handling 3 WEB KnocKout
2010-09-28   e107 0.7.23 - SQL Injection 4 WEB High-Tech Bridge SA
2010-09-28   JE CMS 1.0.0 - Authentication Bypass 4 WEB Abysssec
2010-09-28   AtomatiCMS - Upload Arbitrary File 4 WEB Abysssec
2010-09-27   Car Portal 2.0 - Blind SQL Injection 5 WEB **RoAd_KiLlEr**
2010-09-27   Barracuda Networks Spam & Virus Firewall 4.1.1.021 - Remote Configuration Retrieval 4 WEB ShadowHatesYou
2010-09-27   Allpc 2.5 osCommerce - SQL Injection / Cross-Site Scripting 4 WEB **RoAd_KiLlEr**
2010-09-27   Entrans - SQL Injection 4 WEB keracker
2010-09-27   ndCMS - SQL Injection 5 WEB Abysssec
2010-09-27   pbboard 2.1.1 - Multiple Vulnerabilities 5 WEB JIKO
2010-09-26   Blue River Mura CMS - Directory Traversal 4 WEB mr_me
2010-09-26   PEEL Premium 5.71 - SQL Injection 4 WEB KnocKout
2010-09-26   gokhun asp stok 1.0 - Multiple Vulnerabilities 4 WEB KnocKout
2010-09-26   ZenPhoto - Config Update / Command Execution 3 WEB Abysssec
2010-09-25   E-Xoopport Samsara 3.1 (eCal Module) - Blind SQL Injection 4 WEB _mRkZ_
2010-09-25   VisualSite CMS 1.3 - Multiple Vulnerabilities 3 WEB Abysssec
2010-09-24   Traidnt UP - Cross-Site Request Forgery (Add Admin) 5 WEB John Johnz
2010-09-24   Joomla! Component Elite Experts - SQL Injection 4 WEB **RoAd_KiLlEr**
2010-09-24   FreePBX 2.8.0 - Recordings Interface Allows Remote Code Execution 3 WEB Trustwave's SpiderLabs
2010-09-24   Collaborative Passwords Manager 1.07 - Multiple Local File Inclusions 4 WEB sh00t0ut
2010-09-23   OvBB 0.16a - Multiple Local File Inclusions 4 WEB cOndemned
2010-09-23   GeekLog 1.3.8 (filemgmt) - SQL Injection 4 WEB Gamoscu
2010-09-23   WAnewsletter 2.1.2 - SQL Injection 3 WEB BrOx-Dz
2010-09-22   Joomla! Component Joostina - SQL Injection 4 WEB Gamoscu
2010-09-22   Joomla! Component TimeTrack 1.2.4 - Multiple SQL Injections 4 WEB Salvatore Fresta
2010-09-22   BSI Hotel Booking System Admin 1.4/2.0 - Authentication Bypass 4 WEB K-159
2010-09-22   Skybluecanvas 1.1-r248 - Cross-Site Request Forgery 5 WEB Sweet
2010-09-22   gausCMS - Multiple Vulnerabilities 4 WEB Abysssec
2010-09-21   wpQuiz 2.7 - Authentication Bypass 4 WEB KnocKout
2010-09-21   ibPhotohost 1.1.2 - SQL Injection 5 WEB fred777
2010-09-21   Personal.Net Portal - Multiple Vulnerabilities 6 WEB Abysssec
2010-09-20   primitive CMS 1.0.9 - Multiple Vulnerabilities 5 WEB Stephan Sattler
2010-09-20   LightNEasy CMS 3.2.1 - Blind SQL Injection 4 WEB Solidmedia
2010-09-20   VWD-CMS - Cross-Site Request Forgery 4 WEB Abysssec
2010-09-19   Opencart 1.4.9.1 - Arbitrary File Upload 4 WEB Net.Edit0r
2010-09-19   BoutikOne 1.0 - SQL Injection 6 WEB BrOx-Dz
2010-09-19   Fashione E-Commerce Webshop - Multiple SQL Injections 4 WEB secret
2010-09-19   jmd-cms - Multiple Vulnerabilities 4 WEB Abysssec
2010-09-18   Maian Gallery 2 - Local File Download 4 WEB mr_me
2010-09-18   Joomla! Component Restaurant Guide 1.0.0 - Multiple Vulnerabilities 4 WEB Valentin
2010-09-18   xt:Commerce Gambio 2008 < 2010 - 'reviews.php' Error-Based SQL Injection 4 WEB secret
2010-09-18   CMSimple - Cross-Site Request Forgery 4 WEB Abysssec
2010-09-17   phpMyFamily - Multiple Vulnerabilities 4 WEB Abysssec
2010-09-16   mojoportal - Multiple Vulnerabilities 4 WEB Abysssec
2010-09-15   PixelPost 1.7.3 - Multiple Vulnerabilities 4 WEB Sweet
2010-09-15   PHP microcms 1.0.1 - Multiple Vulnerabilities 3 WEB Abysssec
2010-09-15   eNdonesia 8.4 - SQL Injection 4 WEB vYc0d
2010-09-14   E-Xoopport Samsara 3.1 (Sections Module) - Blind SQL Injection 4 WEB _mRkZ_
2010-09-14   freediscussionforums 1.0 - Multiple Vulnerabilities 4 WEB Abysssec