Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2010-02-11   vBulletin 2.3.x - SQL Injection 23 WEB ROOT_EGY
2010-02-11   vBulletin 3.0.0 - Cross-Site Scripting 25 WEB ROOT_EGY
2010-02-11   vBulletin 3.5.2 - Cross-Site Scripting 22 WEB ROOT_EGY
2010-02-11   Omnidocs - SQL Injection 21 WEB thebluegenius
2010-02-10   ULoki Community Forum 2.1 - 'usercp.php' Cross-Site Scripting 21 WEB Sioma Labs
2010-02-10   HASHE! Solutions - Multiple SQL Injections 23 WEB AtT4CKxT3rR0r1ST
2010-02-10   eSmile Script - 'index.php' SQL Injection 24 WEB AtT4CKxT3rR0r1ST
2010-02-09   osTicket 1.6 RC5 - Multiple Vulnerabilities 19 WEB Nahuel Grisolia
2010-02-09   NewsLetter Tailor 0.2.0 - Remote File Inclusion 26 WEB snakespc
2010-02-09   Limny 1.01 - Arbitrary File Upload 22 WEB JIKO
2010-02-09   Fonts Site Script - Remote File Disclosure 23 WEB JIKO
2010-02-09   Zomorrod CMS - SQL Injection 26 WEB Pouya Daneshmand
2010-02-09   MOJO's IWms 7 - SQL Injection / Cross-Site Scripting 25 WEB cp77fk4r
2010-02-09   Yes Solutions - Webapp SQL Injection 24 WEB HackXBack
2010-02-09   NewsLetter Tailor - Authentication Bypass 24 WEB ViRuSMaN
2010-02-09   NewsLetter Tailor - Database Backup Dump 23 WEB ViRuSMaN
2010-02-09   CPA Site Solutions - Arbitrary File Upload 24 WEB R3VAN_BASTARD
2010-02-09   fipsForum 2.6 - Remote Database Disclosure 23 WEB ViRuSMaN
2010-02-08   Blue Dove - SQL Injection 28 WEB HackXBack
2010-02-08   JaxCMS 1.0 - Local File Inclusion 24 WEB Hamza 'MizoZ' N.
2010-02-07   TinyMCE WYSIWYG Editor - Multiple Vulnerabilities 25 WEB mc2_s3lector
2010-02-07   Uiga Business Portal - SQL Injection / Cross-Site Scripting 23 WEB Sioma Labs
2010-02-07   Rostermain 1.1 - Authentication Bypass 23 WEB cr4wl3r
2010-02-07   EncapsCMS 0.3.6 - 'config[path]' Remote File Inclusion 26 WEB cr4wl3r
2010-02-07   Killmonster 2.1 - Authentication Bypass 22 WEB cr4wl3r
2010-02-07   Croogo 1.2.1 - Multiple Cross-Site Request Forgery Vulnerabilities 23 WEB Milos Zivanovic
2010-02-07   Joomla! Component com_productbook - SQL Injection 23 WEB snakespc
2010-02-07   Belkatalog CMS - SQL Injection 21 WEB anonymous
2010-02-07   Exponent CMS 0.96.3 - 'articlemodule' SQL Injection 24 WEB T u R c O
2010-02-07   DA Mailing List System 2 - Multiple Vulnerabilities 23 WEB Phenom
2010-02-07   Baal Systems 3.8 - Authentication Bypass 24 WEB cr4wl3r
2010-02-07   Zen Tracking 2.2 - Authentication Bypass 26 WEB cr4wl3r
2010-02-07   WSN Guest - Database Disclosure 25 WEB HackXBack
2010-02-06   ShopEx Single 4.5.1 - Multiple Vulnerabilities 21 WEB cp77fk4r
2010-02-06   odlican.net CMS 1.5 - Arbitrary File Upload 24 WEB anonymous
2010-02-06   Arab Network Tech. (ANT) CMS - SQL Injection 26 WEB Tr0y-x
2010-02-06   Joomla! Component com_photoblog - Blind SQL Injection 24 WEB ALTBTA
2010-02-06   Open Bulletin Board - Multiple Blind SQL Injections 24 WEB AtT4CKxT3rR0r1ST
2010-02-05   Audistats 1.3 - SQL Injection 21 WEB kaMtiEz
2010-02-04   ManageEngine OpUtils 5 - 'Login.DO' SQL Injection 22 WEB Asheesh Anaconda
2010-02-04   MASA2EL Music City 1.0 - SQL Injection 24 WEB alnjm33
2010-02-03   myBusinessAdmin - 'content.php' Blind SQL Injection 20 WEB AtT4CKxT3rR0r1ST
2010-02-03   cityadmin - 'links.php' Blind SQL Injection 22 WEB AtT4CKxT3rR0r1ST
2010-02-03   RealAdmin - 'detail.php' Blind SQL Injection 23 WEB AtT4CKxT3rR0r1ST
2010-02-03   Hipergate 4.0.12 - Multiple Vulnerabilities 23 WEB Nahuel Grisolia
2010-02-03   PHP Car Rental-Script - Authentication Bypass 24 WEB Hamza 'MizoZ' N.
2010-02-03   KubeLance 1.7.6 - Cross-Site Request Forgery (Add Admin) 23 WEB Milos Zivanovic
2010-02-02   MobPartner Chat - Multiple SQL Injections 24 WEB AtT4CKxT3rR0r1ST
2010-02-02   MYRE Classified - 'cat' SQL Injection 25 WEB kaMtiEz
2010-02-02   Dlili Script - SQL Injection 24 WEB Dr.DaShEr
2010-02-02   GCP 2.0 datasets provided as BioCASE Web services - Local File Inclusion 23 WEB R3VAN_BASTARD
2010-02-01   Home Of AlegroCart 1.1 - Cross-Site Request Forgery (Change Administrator Password) 24 WEB The.Morpheus
2010-02-01   RaakCMS - Multiple Vulnerabilities 23 WEB Pouya Daneshmand
2010-02-01   Snif 1.5.2 - Any Filetype Download 24 WEB Aodrulez
2010-02-01   Joomla! Component Yelp - SQL Injection 19 WEB B-HUNT3|2
2010-02-01   Joomla! Component Job - SQL Injection 23 WEB B-HUNT3|2
2010-02-01   Evernew Free Joke Script - 'viewjokes.php' SQL Injection 26 WEB Hamza 'MizoZ' N.
2010-02-01   ShoutCMS - 'content.php' Blind SQL Injection 26 WEB Zero Cold
2010-01-31   Saman Portal - SQL Injection 24 WEB Pouya Daneshmand
2010-01-31   Maian Greetings 2.1 - Arbitrary File Upload 25 WEB indoushka
2010-01-31   Creative SplashWorks-SplashSite - 'page.php' Blind SQL Injection 26 WEB AtT4CKxT3rR0r1ST
2010-01-31   crownweb - 'page.cfm' SQL Injection 24 WEB AtT4CKxT3rR0r1ST
2010-01-30   dotProject 2.1.3 - Cross-Site Scripting / Improper Permissions 21 WEB h00die
2010-01-30   IPB (nv2) Awards < 1.1.0 - SQL Injection 25 WEB fred777
2010-01-30   ThinkAdmin - 'page.php' SQL Injection 23 WEB AtT4CKxT3rR0r1ST
2010-01-29   eWebeditor ASP Version - Multiple Vulnerabilities 24 WEB anonymous
2010-01-30   Joomla! Component com_simplefaq - 'catid' Blind SQL Injection 24 WEB AtT4CKxT3rR0r1ST
2010-01-30   Joomla! Component JE Event Calendar - SQL Injection 25 WEB B-HUNT3|2
2010-01-30   phpunity.newsmanager - Local File Inclusion 22 WEB kaMtiEz
2010-01-30   Joomla! Component com_dms 2.5.1 - SQL Injection 22 WEB kaMtiEz
2010-01-29   Joomla! Component JE Quiz - 'eid' Blind SQL Injection 21 WEB B-HUNT3|2
2010-01-29   Joomla! Component Jreservation - Blind SQL Injection 25 WEB B-HUNT3|2
2010-01-29   PHP Product Catalog - Cross-Site Request Forgery (Change Administrator Password) 24 WEB bi0
2010-01-28   Joomla! Component CCNewsLetter - Local File Inclusion 24 WEB AtT4CKxT3rR0r1ST
2010-01-28   Joomla! Component jVideoDirect - Blind SQL Injection 23 WEB B-HUNT3|2
2010-01-28   Joomla! Component com_kunena - Blind SQL Injection 21 WEB B-HUNT3|2
2010-01-28   Novaboard 1.1.2 - SQL Injection 20 WEB Delibey
2010-01-28   Joomla! Component CCNewsLetter - Directory Traversal 23 WEB B-HUNT3|2
2009-12-21   Woltlab Burningboard Addon Kleinanzeigenmarkt - SQL Injection 25 WEB fred777
2010-01-27   Joomla! Component com_virtuemart - order_status_id SQL Injection 22 WEB B-HUNT3|2
2010-01-27   Joomla! Component VirtueMart Module Customers_who_bought - SQL Injection 23 WEB B-HUNT3|2
2010-01-26   Joomla! 1.5.12 - read/exec Remote files 26 WEB Nikoal Petrov
2010-01-26   Joomla! 1.5.12 - Connect Back 24 WEB Nikola Petrov
2010-01-26   UGiA PHP UPLOADER 0.2 - Arbitrary File Upload 25 WEB indoushka
2010-01-25   Status2k - Remote Add Admin 22 WEB alnjm33
2010-01-24   BoastMachine 3.1 - Arbitrary File Upload 24 WEB alnjm33
2010-01-24   SilverStripe CMS 2.3.5 - Cross-Site Request Forgery / Open Redirection 22 WEB cp77fk4r
2010-01-24   Joomla! Component com_mochigames - SQL Injection 26 WEB B-HUNT3|2
2010-01-23   OpenDb 1.5.0.4 - Multiple Local File Inclusions 25 WEB ViRuSMaN
2010-01-23   Joomla! Component JBDiary - Blind SQL Injection 23 WEB B-HUNT3|2
2010-01-23   Joomla! Component com_jbpublishdownfp - SQL Injection 22 WEB B-HUNT3|2
2010-01-23   Joomla! Component com_casino - SQL Injection 24 WEB B-HUNT3|2
2010-01-23   Joomla! Component com_ContentBlogList - SQL Injection 25 WEB B-HUNT3|2
2010-01-23   magic-portal 2.1 - SQL Injection 26 WEB alnjm33
2010-01-22   Joomla! Component com_biographies - SQL Injection 22 WEB snakespc
2010-01-22   Joomla! Component com_gurujibook - SQL Injection 21 WEB snakespc
2010-01-22   KosmosBlog 0.9.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery 24 WEB Milos Zivanovic
2010-01-22   Joomla! Component com_avosbillets - SQL Injection 26 WEB snakespc
2010-01-22   Joomla! Component com_gameserver - SQL Injection 22 WEB B-HUNT3|2
2010-01-21   jQuery Uploadify 2.1.0 - Arbitrary File Upload 27 WEB k4cp3r/Ablus
2010-01-21   Blog System 1.x - 'note' SQL Injection 21 WEB h4ck3r
2010-01-21   SHOUTcast Server 1.9.8/Win32 - Cross-Site Request Forgery 23 WEB cp77fk4r
2010-01-21   Joomla! Component com_book - SQL Injection 22 WEB Evil-Cod3r
2010-01-21   eWebeditor - Directory Traversal 23 WEB anonymous
2010-01-21   cPanel - HTTP Response Splitting 26 WEB Trancer
2010-01-19   al3jeb script - Remote Authentication Bypass 23 WEB cr4wl3r
2010-01-18   Soft Direct 1.05 - Multiple Vulnerabilities 24 WEB indoushka
2010-01-18   Fatwiki (fwiki) 1.0 - Remote File Inclusion 23 WEB kaMtiEz
2010-01-18   FreePBX 2.5.x - Information Disclosure 27 WEB Ivan Huertas
2010-01-18   FreePBX 2.5.1 - SQL Injection 24 WEB Ivan Huertas
2010-01-18   al3jeb script - Remote Change Password 24 WEB alnjm33
2010-01-18   FreePBX 2.5.x < 2.6.0 - Persistent Cross-Site Scripting 26 WEB Ivan Huertas
2010-01-18   Testlink TestManagement and Execution System 1.8.5 - Multiple Directory Traversal Vulnerabilities 24 WEB Prashant Khandelwal
2010-01-17   Joomla! Component com_libros - SQL Injection 22 WEB FL0RiX
2010-01-17   Joomla! Component com_prime - Directory Traversal 27 WEB FL0RiX
2010-01-17   Max's Image Uploader - Arbitrary File Upload 24 WEB indoushka
2010-01-17   Joomla! Component com_pc - Local File Inclusion 23 WEB Pyske
2010-01-17   Uploader by CeleronDude 5.3.0 - Arbitrary File Upload (2) 26 WEB Stink'
2010-01-16   Ebay Clone from clone2009 - SQL Injection 23 WEB Hamza 'MizoZ' N.
2010-01-16   ITechSctipts Alibaba Clone - Multiple Vulnerabilities 24 WEB Hamza 'MizoZ' N.
2010-01-16   CLONEBID B2B Marketplace - Multiple Vulnerabilities 25 WEB Hamza 'MizoZ' N.
2010-01-16   DasForum - 'layout' Local File Inclusion 23 WEB cr4wl3r
2010-01-16   RoseOnlineCMS 3 B1 - Remote Authentication Bypass 25 WEB cr4wl3r
2010-01-16   MoME CMS 0.8.5 - Remote Authentication Bypass 25 WEB cr4wl3r
2010-01-16   PHP-RESIDENCE 0.7.2 - Multiple Local File Inclusions 26 WEB cr4wl3r