|
2009-10-08
|
|
The BMW - 'inventory.php' SQL Injection
|
8 |
WEB
|
Dazz
|
|
2009-10-08
|
|
QuickCart 3.x - Cross-Site Scripting / Cross-Site Request Forgery / Local File Inclusion / Directory
|
7 |
WEB
|
kl3ryk
|
|
2009-10-12
|
|
EZRecipeZee CMS 91 - Remote File Inclusion
|
8 |
WEB
|
kaMtiEz
|
|
2009-10-12
|
|
EZsneezyCal CMS 95.1-95.2 - Remote File Inclusion
|
8 |
WEB
|
kaMtiEz
|
|
2009-10-12
|
|
Dazzle Blast - Remote File Inclusion
|
8 |
WEB
|
NoGe
|
|
2009-10-12
|
|
Community Translate - Remote File Inclusion
|
9 |
WEB
|
NoGe
|
|
2009-10-02
|
|
redcat media - SQL Injection
|
8 |
WEB
|
s4va
|
|
2009-10-14
|
|
Achievo 1.3.4 - SQL Injection
|
8 |
WEB
|
Ryan Dewhurst
|
|
2007-09-17
|
|
Alcatel-Lucent OmniPCX Enterprise Communication Server 7.1 - masterCGI Command Injection (Metasploit
|
8 |
WEB
|
patrick
|
|
2009-11-10
|
|
Joomla! Component JForJoomla! Jreservation 1.5 - 'pid' SQL Injection
|
8 |
WEB
|
Chip d3 bi0s
|
|
2009-10-02
|
|
Hyperic HQ 3.2 < 4.2-beta1 - Multiple Cross-Site Scripting Vulnerabilities
|
8 |
WEB
|
CoreLabs
|
|
2009-09-25
|
|
html2ps - 'include file' Server-Side Include Directive Directory Traversal
|
8 |
WEB
|
epiphant
|
|
2009-10-08
|
|
DreamPoll 3.1 - SQL Injection
|
8 |
WEB
|
Mark from infosecstuff
|
|
2009-10-09
|
|
Docebo 3.6.0.3 - Multiple SQL Injections
|
8 |
WEB
|
Andrea Fabrizi
|
|
2009-11-10
|
|
CuteNews and UTF-8 CuteNews - Multiple Vulnerabilities
|
8 |
WEB
|
Andrew Horton
|
|
2009-10-20
|
|
Websense Email Security - Cross-Site Scripting
|
8 |
WEB
|
Nikolas Sotiriu
|
|
2009-10-22
|
|
Vivvo CMS 4.1.5.1 - file Disclosure
|
8 |
WEB
|
Janek Vind
|
|
2009-10-23
|
|
TwonkyMedia Server 4.4.17/5.0.65 - Cross-Site Scripting
|
8 |
WEB
|
Davide Canali
|
|
2009-11-16
|
|
Alteon OS BBI (Nortell) - Cross-Site Scripting / Cross-Site Request Forgery
|
7 |
WEB
|
Alexey Sintsov
|
|
2009-10-26
|
|
SharePoint 2007 - Team Services Source Code Disclosure
|
8 |
WEB
|
Daniel Martin
|
|
2009-10-26
|
|
RunCMS 2ma - 'post.php' SQL Injection
|
8 |
WEB
|
bookoo
|
|
2009-10-26
|
|
RunCMS 2m1 - 'store()' SQL Injection
|
8 |
WEB
|
bookoo
|
|
2009-10-14
|
|
QuickTeam 2.2 - SQL Injection
|
8 |
WEB
|
drunken danish rednecks
|
|
2009-10-19
|
|
Piwik 1357 2009-08-02 - Arbitrary File Upload / Code Execution
|
8 |
WEB
|
boecke
|
|
2009-10-19
|
|
phpCMS 2008 - File Disclosure
|
8 |
WEB
|
Securitylab Security Research
|
|
2009-10-15
|
|
Pentaho 1.7.0.1062 - Cross-Site Scripting / Information Disclosure
|
8 |
WEB
|
antisnatchor
|
|
2009-10-28
|
|
PHP168 6.0 - Command Execution
|
8 |
WEB
|
Securitylab Security Research
|
|
2009-07-22
|
|
Joomla! Plugin tinybrowser 1.5.12 - Arbitrary File Upload / Execution
|
7 |
WEB
|
spinbad
|
|
2009-10-28
|
|
Oscailt CMS 3.3 - Local File Inclusion
|
7 |
WEB
|
s4r4d0
|
|
2009-02-25
|
|
ContentKeeper Web Appliance < 125.10 - Command Execution (Metasploit)
|
8 |
WEB
|
patrick
|
|
2005-01-15
|
|
AWStats 6.2 < 6.1 - configdir Command Injection (Metasploit)
|
8 |
WEB
|
Matteo Cantoni
|
|
2005-01-15
|
|
Cacti 0.8.6-d - 'graph_view.php' Command Injection (Metasploit)
|
8 |
WEB
|
David Maciejak
|
|
2006-05-04
|
|
AWStats 6.4 < 6.5 - AllowToUpdateStatsFromBrowser Command Injection (Metasploit)
|
8 |
WEB
|
patrick
|
|
2008-06-14
|
|
BASE 1.2.4 - 'base_qry_common.php' Remote File Inclusion (Metasploit)
|
8 |
WEB
|
MC
|
|
1999-11-05
|
|
The Matt Wright Guestbook.pl 2.3.1 - Server-Side Include
|
8 |
WEB
|
patrick
|
|
2008-06-14
|
|
Mambo 4.6.4 - Cache Lite Output Remote File Inclusion (Metasploit)
|
8 |
WEB
|
MC
|
|
2009-10-30
|
|
PSArt 1.2 - SQL Injection
|
8 |
WEB
|
Securitylab Research
|
|
2009-10-20
|
|
OpenDocMan 1.2.5 - Cross-Site Scripting / SQL Injection
|
8 |
WEB
|
Amol Naik
|
|
2009-10-29
|
|
Mura CMS 5.1 - Root Path Disclosure
|
8 |
WEB
|
Vladimir Vorontsov
|
|
2009-10-23
|
|
Mongoose Web Server 2.8 - Source Disclosure
|
8 |
WEB
|
Dr_IDE
|
|
2009-10-23
|
|
Joomla! Component Photo Blog alpha 3 < alpha 3a - SQL Injection
|
8 |
WEB
|
kaMtiEz
|
|
2009-10-23
|
|
Joomla! Component Jshop - SQL Injection
|
8 |
WEB
|
Don Tukulesto
|
|
2009-10-19
|
|
Joomla! Plugin JD-WordPress 2.0 RC2 - Remote File Inclusion
|
8 |
WEB
|
Don Tukulesto
|
|
2009-10-19
|
|
Joomla! Component Book Library 1.0 - Remote File Inclusion
|
8 |
WEB
|
kaMtiEz
|
|
2009-10-19
|
|
Joomla! Component Ajax Chat 1.0 - Remote File Inclusion
|
7 |
WEB
|
kaMtiEz
|
|
2009-10-26
|
|
jetty 6.x < 7.x - Cross-Site Scripting / Information Disclosure / Injection
|
9 |
WEB
|
Antonion Parata
|
|
2009-10-21
|
|
httpdx 1.4.6b - Source Disclosure
|
8 |
WEB
|
Dr_IDE
|
|
2009-11-04
|
|
eNdonesia CMS 8.4 - Local File Inclusion
|
8 |
WEB
|
s4r4d0
|
|
2009-10-17
|
|
DWebPro - Command Injection
|
8 |
WEB
|
Rafael Sousa
|
|
2009-10-14
|
|
DeDeCMS 5.1 - SQL Injection
|
9 |
WEB
|
Securitylab Security Research
|
|
2009-10-30
|
|
CubeCart 4 - Session Management Bypass
|
8 |
WEB
|
Bogdan Calin
|
|
2009-10-28
|
|
Cherokee 0.5.4 - Directory Traversal
|
8 |
WEB
|
Dr_IDE
|
|
2009-10-20
|
|
boxalino 09.05.25-0421 - Directory Traversal
|
8 |
WEB
|
Axel Neumann
|
|
2009-10-19
|
|
Amiro.CMS 5.4.0.0 - Path Disclosure
|
8 |
WEB
|
Vladimir Vorontsov
|
|
2009-10-14
|
|
Achievo 1.3.4 - Cross-Site Scripting
|
8 |
WEB
|
Ryan Dewhurst
|
|
2009-10-30
|
|
Nagios3 - 'statuswml.cgi' Command Injection (Metasploit)
|
8 |
WEB
|
H D Moore
|
|
2009-10-05
|
|
AfterLogic WebMail Pro 4.7.10 - Cross-Site Scripting
|
8 |
WEB
|
Sébastien Duquette
|
|
2009-10-15
|
|
Snitz Forums 2000 - Multiple Cross-Site Scripting Vulnerabilities
|
8 |
WEB
|
Andrea Fabrizi
|
|
2009-10-03
|
|
Geeklog 1.6.0sr2 - Arbitrary File Upload
|
8 |
WEB
|
JaL0h
|
|
2009-11-02
|
|
TFTgallery .13 - Directory Traversal
|
9 |
WEB
|
blake
|
|
2009-11-03
|
|
Xerox Fiery Webtools - SQL Injection
|
8 |
WEB
|
Bernardo Trigo
|
|
2009-11-03
|
|
PunBB Extension Attachment 1.0.2 - SQL Injection
|
8 |
WEB
|
puret_t
|
|
2009-11-04
|
|
Portili Personal and Team Wiki 1.14 - Multiple Vulnerabilities (1)
|
8 |
WEB
|
Abysssec
|
|
2009-09-22
|
|
BPHolidayLettings 1.0 - Blind SQL Injection
|
9 |
WEB
|
OoN Boy
|
|
2009-09-22
|
|
Joomla! Component GroupJive 1.8 B4 - Remote File Inclusion
|
8 |
WEB
|
M3NW5
|
|
2009-09-22
|
|
Achievo 1.3.4 - Remote File Inclusion
|
8 |
WEB
|
M3NW5
|
|
2009-09-22
|
|
BPGames 1.0 - Blind SQL Injection
|
8 |
WEB
|
OoN Boy
|
|
2009-09-22
|
|
BPStudent 1.0 - Blind SQL Injection
|
8 |
WEB
|
OoN Boy
|
|
2009-09-22
|
|
BPMusic 1.0 - Blind SQL Injection
|
8 |
WEB
|
OoN Boy
|
|
2009-09-22
|
|
HB CMS 1.7 - SQL Injection
|
8 |
WEB
|
Securitylab Security Research
|
|
2009-09-22
|
|
BPLawyerCaseDocuments - SQL Injection
|
8 |
WEB
|
OoN Boy
|
|
2009-09-22
|
|
Joomla! Component com_facebook - SQL Injection
|
8 |
WEB
|
kaMtiEz
|
|
2009-09-22
|
|
Joomla! / Mambo Component Tupinambis - SQL Injection
|
8 |
WEB
|
Don Tukulesto
|
|
2009-09-23
|
|
Cour Supreme - SQL Injection
|
9 |
WEB
|
CrAzY CrAcKeR
|
|
2009-09-23
|
|
OSSIM 2.1 - SQL Injection / Cross-Site Scripting
|
8 |
WEB
|
Alexey Sintsov
|
|
2009-09-24
|
|
MindSculpt CMS - SQL Injection
|
8 |
WEB
|
kaMitEz
|
|
2009-09-24
|
|
e107 0.7.16 - Referer header Cross-Site Scripting
|
8 |
WEB
|
MustLive
|
|
2009-09-24
|
|
Swiss Mango CMS - SQL Injection
|
8 |
WEB
|
kaMtiEz
|
|
2009-09-24
|
|
Joomla! Component Fastball 1.1.0 < 1.2 - 'league' SQL Injection
|
8 |
WEB
|
kaMtiEz
|
|
2009-09-24
|
|
FSphp 0.2.1 - Remote File Inclusion
|
8 |
WEB
|
NoGe
|
|
2009-09-24
|
|
Regental Medien - Blind SQL Injection
|
8 |
WEB
|
NoGe
|
|
2009-09-25
|
|
Engeman 6.x - SQL Injection
|
8 |
WEB
|
crashbrz
|
|
2009-09-25
|
|
Klonet E-Commerce - 'products.php' SQL Injection
|
8 |
WEB
|
S3T4N
|
|
2009-09-28
|
|
Joomla! Component IRCm Basic - SQL Injection
|
7 |
WEB
|
kaMtiEz
|
|
2009-09-28
|
|
HEAT Call Logging 8.01 - SQL Injection
|
8 |
WEB
|
0 0
|
|
2009-09-29
|
|
Flatpress 0.804 < 0.812.1 - Local File Inclusion
|
8 |
WEB
|
Giuseppe Fuggiano
|
|
2009-09-21
|
|
Joomla! Component com_mytube (user_id) 1.0 Beta - Blind SQL Injection
|
8 |
WEB
|
Chip d3 bi0s
|
|
2009-09-21
|
|
Joomla! Component com_jinc 0.2 - 'newsid' Blind SQL Injection
|
8 |
WEB
|
Chip d3 bi0s
|
|
2009-09-21
|
|
WX Guestbook 1.1.208 - SQL Injection / Persistent Cross-Site Scripting
|
8 |
WEB
|
learn3r
|
|
2009-09-21
|
|
Loggix Project 9.4.5 - Multiple Remote File Inclusions
|
8 |
WEB
|
cr4wl3r
|
|
2009-09-21
|
|
ProdLer 2.0 - Remote File Inclusion
|
8 |
WEB
|
cr4wl3r
|
|
2009-09-21
|
|
CMScontrol (Content Management Portal Solutions) - SQL Injection
|
9 |
WEB
|
ph1l1ster
|
|
2009-09-21
|
|
cP Creator 2.7.1 - SQL Injection
|
8 |
WEB
|
Sina Yazdanmehr
|
|
2009-09-21
|
|
BAnner ROtation System mini - Multiple Remote File Inclusions
|
8 |
WEB
|
EA Ngel
|
|
2009-09-21
|
|
Joomla! Component com_jbudgetsmagic 0.3.2 < 0.4.0 - 'bid' SQL Injection
|
8 |
WEB
|
kaMtiEz
|
|
2009-09-21
|
|
DDL CMS 1.0 - Multiple Remote File Inclusions
|
8 |
WEB
|
HxH
|
|
2009-09-21
|
|
Joomla! Component com_surveymanager 1.5.0 - 'stype' SQL Injection
|
8 |
WEB
|
kaMtiEz
|
|
2009-09-18
|
|
FSphp 0.2.1 - Multiple Remote File Inclusions
|
8 |
WEB
|
NoGe
|
|
2009-09-18
|
|
FanUpdate 2.2.1 - 'show-cat.php' SQL Injection
|
8 |
WEB
|
(In)Security Romania
|
|
2009-09-18
|
|
Network Management/Inventory System - 'header.php' Remote File Inclusion
|
8 |
WEB
|
EA Ngel
|
|
2009-09-18
|
|
Zainu 1.0 - SQL Injection
|
7 |
WEB
|
snakespc
|
|
2009-10-18
|
|
Mambo Component com_koesubmit 1.0.0 - Remote File Inclusion
|
8 |
WEB
|
Don Tukulesto
|
|
2009-09-17
|
|
Joomla! Component com_jreservation 1.5 - 'pid' Blind SQL Injection
|
8 |
WEB
|
Chip d3 bi0s
|
|
2009-09-17
|
|
Nephp Publisher Enterprise 4.5 - Authentication Bypass
|
9 |
WEB
|
learn3r hacker
|
|
2009-09-17
|
|
FMyClone 2.3 - Multiple SQL Injections
|
9 |
WEB
|
learn3r hacker
|
|
2009-09-17
|
|
CF Shopkart 5.3x - 'itemID' SQL Injection
|
8 |
WEB
|
learn3r hacker
|
|
2009-09-17
|
|
OpenSiteAdmin 0.9.7b - 'pageHeader.php?path' Remote File Inclusion
|
9 |
WEB
|
EA Ngel
|
|
2009-09-17
|
|
Joomla! Component com_album 1.14 - Directory Traversal
|
8 |
WEB
|
DreamTurk
|
|
2009-09-16
|
|
phpPollScript 1.3 - 'include_class' Remote File Inclusion
|
8 |
WEB
|
cr4wl3r
|
|
2009-09-16
|
|
Elite Gaming Ladders 3.2 - 'platform' SQL Injection
|
7 |
WEB
|
snakespc
|
|
2009-09-16
|
|
SaphpLesson 4.3 - Blind SQL Injection
|
8 |
WEB
|
Jafer Al Zidjali
|
|
2009-09-16
|
|
Micro CMS 3.5 - SQL Injection / Local File Inclusion
|
7 |
WEB
|
learn3r hacker
|
|
2009-09-16
|
|
Joomla! Component com_jlord_rss - 'id' Blind SQL Injection
|
8 |
WEB
|
Chip d3 bi0s
|
|
2009-09-16
|
|
Joomla! Component com_foobla_suggestions (idea_id) 1.5.11 - SQL Injection
|
8 |
WEB
|
Chip d3 bi0s
|
|
2009-09-16
|
|
AdsDX 3.05 - Authentication Bypass
|
8 |
WEB
|
snakespc
|
|
2009-09-15
|
|
Joomla! Component com_djcatalog - SQL Injection / Blind SQL Injection
|
8 |
WEB
|
Chip d3 bi0s
|
|
2009-09-15
|
|
iBoutique.MALL 1.2 - 'cat' Blind SQL Injection
|
8 |
WEB
|
InjEctOr5
|
|
2009-09-15
|
|
efront 3.5.4 - 'database.php?path' Remote File Inclusion
|
8 |
WEB
|
cr4wl3r
|
|
2009-09-15
|
|
HotWeb Rentals - 'details.asp?PropId' Blind SQL Injection
|
8 |
WEB
|
R3d-D3V!L
|
|
2009-09-15
|
|
Three Pillars Help Desk 3.0 - Authentication Bypass
|
8 |
WEB
|
snakespc
|
|
2009-09-14
|
|
Bs Counter 2.5.3 - 'page' SQL Injection
|
8 |
WEB
|
Bgh7
|
|
2009-09-14
|
|
PHP Pro Bid - Blind SQL Injection
|
8 |
WEB
|
NoGe
|
|
2009-09-14
|
|
Aurora CMS 1.0.2 - 'install.plugin.php' Remote File Inclusion
|
8 |
WEB
|
EA Ngel
|
|
2009-09-14
|
|
Joomla! Component AlphaUserPoints - SQL Injection
|
8 |
WEB
|
jdc
|
|
2009-09-14
|
|
Joomla! Component Turtushout 0.11 - 'Name' SQL Injection
|
8 |
WEB
|
jdc
|