2009-12-07
|
|
SiSplet CMS 2008-01-24 - Multiple Remote File Inclusions
|
4 |
WEB
|
cr4wl3r
|
2009-12-07
|
|
Chipmunk NewsLetter - Persistent Cross-Site Scripting
|
4 |
WEB
|
mr_me
|
2009-12-06
|
|
iWeb HTTP Server - Directory Traversal
|
4 |
WEB
|
mr_me
|
2009-12-06
|
|
Elkagroup - SQL Injection
|
4 |
WEB
|
SadHaCkEr
|
2009-12-06
|
|
AROUNDMe 1.1 - 'language_path' Remote File Inclusion
|
4 |
WEB
|
cr4wl3r
|
2009-12-05
|
|
WordPress Plugin Image Manager - Arbitrary File Upload
|
4 |
WEB
|
DigitALL
|
2009-12-05
|
|
phpShop 0.8.1 - Multiple Vulnerabilities
|
4 |
WEB
|
Andrea Fabrizi
|
2009-12-04
|
|
Joomla! Component yt_color YOOOtheme - Cross-Site Scripting / Cookie Stealing
|
4 |
WEB
|
andresg888
|
2009-12-04
|
|
BM Classifieds Ads - SQL Injection
|
3 |
WEB
|
Dr.0rYX & Cr3W-DZ
|
2009-12-04
|
|
Joomla! Component com_joomgallery 1.5.x - &func Incorrect Flood Filter
|
4 |
WEB
|
Jbyte
|
2009-12-04
|
|
Achievo 1.4.2 - Persistent Cross-Site Scripting
|
4 |
WEB
|
Nahuel Grisolia
|
2009-12-04
|
|
Achievo 1.4.2 - Arbitrary File Upload
|
4 |
WEB
|
Nahuel Grisolia
|
2009-12-04
|
|
UBBCentral UBB.Threads 7.5.4 2 - Multiple File Inclusions
|
4 |
WEB
|
R3VAN_BASTARD
|
2009-12-04
|
|
Invision Power Board 2.3.6/3.0.4 - Local File Inclusion / SQL Injection
|
4 |
WEB
|
Dawid Golunski
|
2009-12-04
|
|
427BB 2.3.2 - SQL Injection
|
4 |
WEB
|
cr4wl3r
|
2009-12-04
|
|
GeN3 forum 1.3 - SQL Injection
|
5 |
WEB
|
Dr.0rYX & Cr3W-DZ
|
2009-12-03
|
|
Vivid Ads Shopping Cart - 'prodid' SQL Injection
|
4 |
WEB
|
Yakir Wizman
|
2009-11-24
|
|
OSI Codes PHP Live! Support 3.1 - Remote File Inclusion
|
4 |
WEB
|
Don Tukulesto
|
2009-11-27
|
|
PHP-Nuke 8.0 - News Module Cross-Site Scripting / HTML Code Injection
|
4 |
WEB
|
K053
|
2009-12-01
|
|
Apache Tomcat 3.2.1 - 404 Error Page Cross-Site Scripting
|
4 |
WEB
|
MustLive
|
2009-12-01
|
|
Joomla! Component ProofReader 1.0 RC6 - Cross-Site Scripting
|
4 |
WEB
|
MustLive
|
2009-12-03
|
|
Theeta CMS - Multiple Vulnerabilities
|
4 |
WEB
|
c0dy
|
2009-11-25
|
|
Power BB 1.8.3 - Remote File Inclusions
|
4 |
WEB
|
DigitALL
|
2009-12-03
|
|
SAPID SHOP 1.3 - Remote File Inclusion
|
4 |
WEB
|
cr4wl3r
|
2009-09-07
|
|
MundiMail 0.8.2 - Remote Code Execution
|
4 |
WEB
|
Dedalo
|
2009-11-25
|
|
OpenCSP - Multiple Remote File Inclusions
|
4 |
WEB
|
EANgel
|
2009-12-01
|
|
Public Media Manager - Remote File Inclusion
|
3 |
WEB
|
cr4wl3r
|
2009-11-30
|
|
ita-forum 5.1.32 - SQL Injection
|
4 |
WEB
|
BAYBORA
|
2009-12-03
|
|
Thatware 0.5.3 - Multiple Remote File Inclusions
|
4 |
WEB
|
cr4wl3r
|
2009-12-03
|
|
Huawei MT882 Modem/Router - Multiple Vulnerabilities
|
4 |
WEB
|
DecodeX01
|
2009-12-02
|
|
Kide Shoutbox 0.4.6 - Cross-Site Scripting / AXFR
|
3 |
WEB
|
andresg888
|
2009-12-02
|
|
Simple Machines Forum (SMF) 1.1.10/2.0 RC2 - Multiple Vulnerabilities
|
4 |
WEB
|
SimpleAudit Team
|
2009-12-01
|
|
Joomla! Component MojoBlog 0.15 - Multiple Remote File Inclusions
|
4 |
WEB
|
kaMtiEz
|
2009-12-01
|
|
Joomla! Component Joaktree 1.0 - SQL Injection
|
4 |
WEB
|
Don Tukulesto
|
2009-12-01
|
|
Quate CMS 0.3.5 - Local/Remote File Inclusion
|
3 |
WEB
|
cr4wl3r
|
2009-12-01
|
|
ISPworker 1.23 - Remote File Disclosure
|
4 |
WEB
|
cr4wl3r
|
2009-12-01
|
|
dotDefender 3.8-5 - Remote Command Execution
|
4 |
WEB
|
John Dos
|
2009-12-01
|
|
Robert Zimmerman PHP / MySQL Scripts - Authentication Bypass
|
4 |
WEB
|
DUNDEE
|
2009-12-01
|
|
Ciamos CMS 0.9.5 - 'module_path' Remote File Inclusion
|
4 |
WEB
|
cr4wl3r
|
2009-11-30
|
|
WordPress Plugin WP-Polls 2.x - Incorrect Flood Filter
|
4 |
WEB
|
Jbyte
|
2009-11-30
|
|
Xxasp 3.3.2 - SQL Injection
|
5 |
WEB
|
Secu_lab_ir
|
2009-11-30
|
|
Eshopbuilde CMS - SQL Injection
|
4 |
WEB
|
Isfahan
|
2009-11-30
|
|
Joomla! Component Quick News - SQL Injection
|
4 |
WEB
|
Don Tukulesto
|
2009-11-30
|
|
Joomla! Component MusicGallery - SQL Injection
|
4 |
WEB
|
Don Tukulesto
|
2009-11-29
|
|
AdaptCMS Lite 1.5 - Remote File Inclusion
|
4 |
WEB
|
v3n0m
|
2009-11-29
|
|
Sugar CRM 5.5.0.rc2/5.2.0j - Multiple Vulnerabilities
|
5 |
WEB
|
waraxe
|
2009-11-27
|
|
Micronet SP1910 Data Access Controller UI - Cross-Site Scripting / HTML Code Injection
|
4 |
WEB
|
K053
|
2009-11-29
|
|
SweetRice 0.5.3 - Remote File Inclusion
|
4 |
WEB
|
cr4wl3r
|
2009-11-28
|
|
phpBazar 2.1.1fix - 'cid' SQL Injection
|
4 |
WEB
|
MizoZ
|
2009-11-28
|
|
Uploaderr 1.0 File Hosting Script - Arbitrary File Upload
|
4 |
WEB
|
DigitALL
|
2009-11-28
|
|
Joomla! Component com_lyftenbloggie 1.04 - SQL Injection
|
4 |
WEB
|
kaMtiEz
|
2009-11-26
|
|
Flashden - Multiple Arbitrary File Uploads
|
3 |
WEB
|
DigitALL
|
2009-11-26
|
|
Cacti 0.8.7e - Multiple Vulnerabilities
|
4 |
WEB
|
Moritz Naumann
|
2009-11-25
|
|
phpBazar-2.1.1fix - Remote Administration-Panel
|
4 |
WEB
|
kurdish hackers team
|
2009-11-25
|
|
Joomla! Component com_gcalendar 1.1.2 - 'gcid' SQL Injection
|
4 |
WEB
|
Yogyacarderlink Crew
|
2009-11-25
|
|
Radio istek scripti 2.5 - Remote Configuration Disclosure
|
3 |
WEB
|
kurdish hackers team
|
2009-11-25
|
|
Fake Hit Generator 2.2 - Arbitrary File Upload
|
4 |
WEB
|
DigitALL
|
2009-11-25
|
|
WordPress Plugin WP-Cumulus 1.20 - Full Path Disclosure / Cross-Site Scripting
|
4 |
WEB
|
MustLive
|
2009-11-25
|
|
Joomla! Component com_mygallery - 'cid' SQL Injection
|
4 |
WEB
|
S@BUN
|
2006-05-26
|
|
MDaemon WebAdmin 2.0.x - SQL Injection
|
4 |
WEB
|
KOUSULIN
|
2009-11-24
|
|
Quick.Cart 3.4 / Quick.CMS 2.4 - Cross-Site Request Forgery
|
4 |
WEB
|
Alice Kaerast
|
2009-11-24
|
|
W3infotech - Authentication Bypass
|
4 |
WEB
|
ViRuS_HiMa
|
2009-11-24
|
|
pointcomma 3.8b2 - Remote File Inclusion
|
4 |
WEB
|
cr4wl3r
|
2009-11-24
|
|
phptraverse 0.8.0 - Remote File Inclusion
|
3 |
WEB
|
cr4wl3r
|
2009-11-24
|
|
outreach project tool 1.2.6 - Remote File Inclusion
|
4 |
WEB
|
cr4wl3r
|
2009-11-24
|
|
NukeHall 0.3 - Multiple Remote File Inclusions
|
4 |
WEB
|
cr4wl3r
|
2009-11-24
|
|
kr-web 1.1b2 - Remote File Inclusion
|
4 |
WEB
|
cr4wl3r
|
2009-11-23
|
|
Joomla! Component mygallery - 'farbinform_krell' SQL Injection
|
5 |
WEB
|
Manas58 BAYBORA
|
2009-10-14
|
|
Everfocus 1.4 - EDSR Remote Authentication Bypass
|
4 |
WEB
|
Andrea Fabrizi
|
2009-11-21
|
|
Joomla! Component Com_Joomclip - 'cat' SQL Injection
|
4 |
WEB
|
599eme Man
|
2009-11-21
|
|
Betsy CMS versions 3.5 - Local File Inclusion
|
3 |
WEB
|
MizoZ
|
2009-11-19
|
|
Joomla! 1.5.12 TinyMCE - Remote Code Execution (via Arbitrary File Upload)
|
4 |
WEB
|
daath
|
2005-06-15
|
|
Bitrix Site Manager 4.0.5 - Remote File Inclusion
|
4 |
WEB
|
Don Tukulesto
|
2009-11-16
|
|
Simplog 0.9.3.2 - Multiple Vulnerabilities
|
4 |
WEB
|
Amol Naik
|
2009-10-20
|
|
Joomla! / Mambo Component D4J eZine 2.1 - Remote File Inclusion
|
4 |
WEB
|
kaMtiEz
|
2009-11-18
|
|
Joomla! Extension iF Portfolio Nexus - SQL Injection
|
3 |
WEB
|
599eme Man
|
2009-11-18
|
|
Xerver 4.31/4.32 - HTTP Response Splitting
|
4 |
WEB
|
s4squatch
|
2009-11-16
|
|
phpMyBackupPro - Arbitrary File Download
|
4 |
WEB
|
Amol Naik
|
2009-11-18
|
|
Shoutbox 1.0 - HTML / Cross-Site Scripting Injection
|
4 |
WEB
|
SkuLL-HackeR
|
2009-11-17
|
|
ActiveBids - 'default.asp' Blind SQL Injection
|
4 |
WEB
|
Hussin X
|
2009-11-17
|
|
ActiveTrade 2.0 - 'default.asp' Blind SQL Injection
|
4 |
WEB
|
Hussin X
|
2009-11-17
|
|
TelebidAuctionScript - 'aid' Blind SQL Injection
|
5 |
WEB
|
Hussin X
|
2009-11-17
|
|
JBS 2.0 / JBSX - Administration Panel Bypass / Arbitrary File Upload
|
4 |
WEB
|
blackenedsecurity
|
2009-11-16
|
|
Cifshanghai - 'chanpin_info.php' CMS SQL Injection
|
4 |
WEB
|
ProF.Code
|
2009-11-16
|
|
telepark wiki 2.4.23 - Multiple Vulnerabilities
|
4 |
WEB
|
Abysssec
|
2009-11-13
|
|
OS Commerce 2.2r2 - Authentication Bypass
|
4 |
WEB
|
Stuart Udall
|
2009-10-15
|
|
IBM Rational RequisitePro 7.10 / ReqWebHelp - Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
IBM
|
2009-11-10
|
|
WordPress MU 1.2.2 < 1.3.1 - '/wp-includes/wpmu-functions.php' Cross-Site Scripting
|
4 |
WEB
|
Juan Galiana Lara
|
2009-11-11
|
|
WordPress Core < 2.8.5 - Unrestricted Arbitrary File Upload / Arbitrary PHP Code Execution
|
3 |
WEB
|
Dawid Golunski
|
2009-11-10
|
|
WordPress Core 2.0 < 2.7.1 - 'admin.php' Module Configuration Security Bypass
|
4 |
WEB
|
Fernando Arnaboldi
|
2009-11-07
|
|
toutvirtual virtualiq pro 3.2 - Multiple Vulnerabilities
|
4 |
WEB
|
Alberto Trivero
|
2009-10-06
|
|
PBBoard 2.0.2 - Full Path Disclosure
|
4 |
WEB
|
rUnViRuS
|
2009-09-23
|
|
Novell Edirectory 8.8 SP5 - Cross-Site Scripting
|
4 |
WEB
|
Francis Provencher
|
2009-10-01
|
|
Novell eDirectory 8.8 SP5 - 'dconserv.dlm' Cross-Site Scripting
|
4 |
WEB
|
Francis Provencher
|
2009-10-05
|
|
Empire CMS 47 - SQL Injection
|
4 |
WEB
|
Securitylab Security Research
|
2009-10-05
|
|
Joomla! Component Soundset 1.0 - SQL Injection
|
4 |
WEB
|
kaMtiEz
|
2009-10-05
|
|
Joomla! Component CB Resume Builder - SQL Injection
|
5 |
WEB
|
kaMtiEz
|
2009-11-12
|
|
McAfee Network Security Manager < 5.1.11.8.1 - Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Daniel King
|
2009-11-12
|
|
McAfee Network Security Manager < 5.1.11.8.1 - Information Disclosure
|
4 |
WEB
|
Daniel King
|
2009-10-07
|
|
Joomla! Component Recerca - SQL Injection
|
4 |
WEB
|
Don Tukulesto
|
2009-10-07
|
|
AIOCP 1.4.001 - Remote File Inclusion
|
4 |
WEB
|
Hadi Kiamarsi
|
2009-10-08
|
|
The BMW - 'inventory.php' SQL Injection
|
3 |
WEB
|
Dazz
|
2009-10-08
|
|
QuickCart 3.x - Cross-Site Scripting / Cross-Site Request Forgery / Local File Inclusion / Directory
|
3 |
WEB
|
kl3ryk
|
2009-10-12
|
|
EZRecipeZee CMS 91 - Remote File Inclusion
|
4 |
WEB
|
kaMtiEz
|
2009-10-12
|
|
EZsneezyCal CMS 95.1-95.2 - Remote File Inclusion
|
4 |
WEB
|
kaMtiEz
|
2009-10-12
|
|
Dazzle Blast - Remote File Inclusion
|
4 |
WEB
|
NoGe
|
2009-10-12
|
|
Community Translate - Remote File Inclusion
|
4 |
WEB
|
NoGe
|
2009-10-02
|
|
redcat media - SQL Injection
|
4 |
WEB
|
s4va
|
2009-10-14
|
|
Achievo 1.3.4 - SQL Injection
|
4 |
WEB
|
Ryan Dewhurst
|
2007-09-17
|
|
Alcatel-Lucent OmniPCX Enterprise Communication Server 7.1 - masterCGI Command Injection (Metasploit
|
4 |
WEB
|
patrick
|
2009-11-10
|
|
Joomla! Component JForJoomla! Jreservation 1.5 - 'pid' SQL Injection
|
4 |
WEB
|
Chip d3 bi0s
|
2009-10-02
|
|
Hyperic HQ 3.2 < 4.2-beta1 - Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
CoreLabs
|
2009-09-25
|
|
html2ps - 'include file' Server-Side Include Directive Directory Traversal
|
4 |
WEB
|
epiphant
|
2009-10-08
|
|
DreamPoll 3.1 - SQL Injection
|
4 |
WEB
|
Mark from infosecstuff
|
2009-10-09
|
|
Docebo 3.6.0.3 - Multiple SQL Injections
|
4 |
WEB
|
Andrea Fabrizi
|
2009-11-10
|
|
CuteNews and UTF-8 CuteNews - Multiple Vulnerabilities
|
4 |
WEB
|
Andrew Horton
|
2009-10-20
|
|
Websense Email Security - Cross-Site Scripting
|
4 |
WEB
|
Nikolas Sotiriu
|
2009-10-22
|
|
Vivvo CMS 4.1.5.1 - file Disclosure
|
4 |
WEB
|
Janek Vind
|
2009-10-23
|
|
TwonkyMedia Server 4.4.17/5.0.65 - Cross-Site Scripting
|
4 |
WEB
|
Davide Canali
|
2009-11-16
|
|
Alteon OS BBI (Nortell) - Cross-Site Scripting / Cross-Site Request Forgery
|
3 |
WEB
|
Alexey Sintsov
|
2009-10-26
|
|
SharePoint 2007 - Team Services Source Code Disclosure
|
4 |
WEB
|
Daniel Martin
|
2009-10-26
|
|
RunCMS 2ma - 'post.php' SQL Injection
|
4 |
WEB
|
bookoo
|
2009-10-26
|
|
RunCMS 2m1 - 'store()' SQL Injection
|
4 |
WEB
|
bookoo
|
2009-10-14
|
|
QuickTeam 2.2 - SQL Injection
|
4 |
WEB
|
drunken danish rednecks
|
2009-10-19
|
|
Piwik 1357 2009-08-02 - Arbitrary File Upload / Code Execution
|
4 |
WEB
|
boecke
|