2009-10-19
|
|
phpCMS 2008 - File Disclosure
|
4 |
WEB
|
Securitylab Security Research
|
2009-10-15
|
|
Pentaho 1.7.0.1062 - Cross-Site Scripting / Information Disclosure
|
4 |
WEB
|
antisnatchor
|
2009-10-28
|
|
PHP168 6.0 - Command Execution
|
4 |
WEB
|
Securitylab Security Research
|
2009-07-22
|
|
Joomla! Plugin tinybrowser 1.5.12 - Arbitrary File Upload / Execution
|
4 |
WEB
|
spinbad
|
2009-10-28
|
|
Oscailt CMS 3.3 - Local File Inclusion
|
4 |
WEB
|
s4r4d0
|
2009-02-25
|
|
ContentKeeper Web Appliance < 125.10 - Command Execution (Metasploit)
|
4 |
WEB
|
patrick
|
2005-01-15
|
|
AWStats 6.2 < 6.1 - configdir Command Injection (Metasploit)
|
4 |
WEB
|
Matteo Cantoni
|
2005-01-15
|
|
Cacti 0.8.6-d - 'graph_view.php' Command Injection (Metasploit)
|
4 |
WEB
|
David Maciejak
|
2006-05-04
|
|
AWStats 6.4 < 6.5 - AllowToUpdateStatsFromBrowser Command Injection (Metasploit)
|
4 |
WEB
|
patrick
|
2008-06-14
|
|
BASE 1.2.4 - 'base_qry_common.php' Remote File Inclusion (Metasploit)
|
4 |
WEB
|
MC
|
1999-11-05
|
|
The Matt Wright Guestbook.pl 2.3.1 - Server-Side Include
|
4 |
WEB
|
patrick
|
2008-06-14
|
|
Mambo 4.6.4 - Cache Lite Output Remote File Inclusion (Metasploit)
|
4 |
WEB
|
MC
|
2009-10-30
|
|
PSArt 1.2 - SQL Injection
|
4 |
WEB
|
Securitylab Research
|
2009-10-20
|
|
OpenDocMan 1.2.5 - Cross-Site Scripting / SQL Injection
|
3 |
WEB
|
Amol Naik
|
2009-10-29
|
|
Mura CMS 5.1 - Root Path Disclosure
|
4 |
WEB
|
Vladimir Vorontsov
|
2009-10-23
|
|
Mongoose Web Server 2.8 - Source Disclosure
|
4 |
WEB
|
Dr_IDE
|
2009-10-23
|
|
Joomla! Component Photo Blog alpha 3 < alpha 3a - SQL Injection
|
4 |
WEB
|
kaMtiEz
|
2009-10-23
|
|
Joomla! Component Jshop - SQL Injection
|
4 |
WEB
|
Don Tukulesto
|
2009-10-19
|
|
Joomla! Plugin JD-WordPress 2.0 RC2 - Remote File Inclusion
|
4 |
WEB
|
Don Tukulesto
|
2009-10-19
|
|
Joomla! Component Book Library 1.0 - Remote File Inclusion
|
4 |
WEB
|
kaMtiEz
|
2009-10-19
|
|
Joomla! Component Ajax Chat 1.0 - Remote File Inclusion
|
3 |
WEB
|
kaMtiEz
|
2009-10-26
|
|
jetty 6.x < 7.x - Cross-Site Scripting / Information Disclosure / Injection
|
4 |
WEB
|
Antonion Parata
|
2009-10-21
|
|
httpdx 1.4.6b - Source Disclosure
|
4 |
WEB
|
Dr_IDE
|
2009-11-04
|
|
eNdonesia CMS 8.4 - Local File Inclusion
|
4 |
WEB
|
s4r4d0
|
2009-10-17
|
|
DWebPro - Command Injection
|
4 |
WEB
|
Rafael Sousa
|
2009-10-14
|
|
DeDeCMS 5.1 - SQL Injection
|
4 |
WEB
|
Securitylab Security Research
|
2009-10-30
|
|
CubeCart 4 - Session Management Bypass
|
4 |
WEB
|
Bogdan Calin
|
2009-10-28
|
|
Cherokee 0.5.4 - Directory Traversal
|
4 |
WEB
|
Dr_IDE
|
2009-10-20
|
|
boxalino 09.05.25-0421 - Directory Traversal
|
3 |
WEB
|
Axel Neumann
|
2009-10-19
|
|
Amiro.CMS 5.4.0.0 - Path Disclosure
|
4 |
WEB
|
Vladimir Vorontsov
|
2009-10-14
|
|
Achievo 1.3.4 - Cross-Site Scripting
|
4 |
WEB
|
Ryan Dewhurst
|
2009-10-30
|
|
Nagios3 - 'statuswml.cgi' Command Injection (Metasploit)
|
4 |
WEB
|
H D Moore
|
2009-10-05
|
|
AfterLogic WebMail Pro 4.7.10 - Cross-Site Scripting
|
4 |
WEB
|
Sébastien Duquette
|
2009-10-15
|
|
Snitz Forums 2000 - Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Andrea Fabrizi
|
2009-10-03
|
|
Geeklog 1.6.0sr2 - Arbitrary File Upload
|
4 |
WEB
|
JaL0h
|
2009-11-02
|
|
TFTgallery .13 - Directory Traversal
|
4 |
WEB
|
blake
|
2009-11-03
|
|
Xerox Fiery Webtools - SQL Injection
|
4 |
WEB
|
Bernardo Trigo
|
2009-11-03
|
|
PunBB Extension Attachment 1.0.2 - SQL Injection
|
4 |
WEB
|
puret_t
|
2009-11-04
|
|
Portili Personal and Team Wiki 1.14 - Multiple Vulnerabilities (1)
|
4 |
WEB
|
Abysssec
|
2009-09-22
|
|
BPHolidayLettings 1.0 - Blind SQL Injection
|
5 |
WEB
|
OoN Boy
|
2009-09-22
|
|
Joomla! Component GroupJive 1.8 B4 - Remote File Inclusion
|
4 |
WEB
|
M3NW5
|
2009-09-22
|
|
Achievo 1.3.4 - Remote File Inclusion
|
4 |
WEB
|
M3NW5
|
2009-09-22
|
|
BPGames 1.0 - Blind SQL Injection
|
4 |
WEB
|
OoN Boy
|
2009-09-22
|
|
BPStudent 1.0 - Blind SQL Injection
|
4 |
WEB
|
OoN Boy
|
2009-09-22
|
|
BPMusic 1.0 - Blind SQL Injection
|
4 |
WEB
|
OoN Boy
|
2009-09-22
|
|
HB CMS 1.7 - SQL Injection
|
3 |
WEB
|
Securitylab Security Research
|
2009-09-22
|
|
BPLawyerCaseDocuments - SQL Injection
|
4 |
WEB
|
OoN Boy
|
2009-09-22
|
|
Joomla! Component com_facebook - SQL Injection
|
4 |
WEB
|
kaMtiEz
|
2009-09-22
|
|
Joomla! / Mambo Component Tupinambis - SQL Injection
|
4 |
WEB
|
Don Tukulesto
|
2009-09-23
|
|
Cour Supreme - SQL Injection
|
4 |
WEB
|
CrAzY CrAcKeR
|
2009-09-23
|
|
OSSIM 2.1 - SQL Injection / Cross-Site Scripting
|
4 |
WEB
|
Alexey Sintsov
|
2009-09-24
|
|
MindSculpt CMS - SQL Injection
|
4 |
WEB
|
kaMitEz
|
2009-09-24
|
|
e107 0.7.16 - Referer header Cross-Site Scripting
|
4 |
WEB
|
MustLive
|
2009-09-24
|
|
Swiss Mango CMS - SQL Injection
|
4 |
WEB
|
kaMtiEz
|
2009-09-24
|
|
Joomla! Component Fastball 1.1.0 < 1.2 - 'league' SQL Injection
|
4 |
WEB
|
kaMtiEz
|
2009-09-24
|
|
FSphp 0.2.1 - Remote File Inclusion
|
4 |
WEB
|
NoGe
|
2009-09-24
|
|
Regental Medien - Blind SQL Injection
|
4 |
WEB
|
NoGe
|
2009-09-25
|
|
Engeman 6.x - SQL Injection
|
4 |
WEB
|
crashbrz
|
2009-09-25
|
|
Klonet E-Commerce - 'products.php' SQL Injection
|
4 |
WEB
|
S3T4N
|
2009-09-28
|
|
Joomla! Component IRCm Basic - SQL Injection
|
3 |
WEB
|
kaMtiEz
|
2009-09-28
|
|
HEAT Call Logging 8.01 - SQL Injection
|
4 |
WEB
|
0 0
|
2009-09-29
|
|
Flatpress 0.804 < 0.812.1 - Local File Inclusion
|
4 |
WEB
|
Giuseppe Fuggiano
|
2009-09-21
|
|
Joomla! Component com_mytube (user_id) 1.0 Beta - Blind SQL Injection
|
4 |
WEB
|
Chip d3 bi0s
|
2009-09-21
|
|
Joomla! Component com_jinc 0.2 - 'newsid' Blind SQL Injection
|
4 |
WEB
|
Chip d3 bi0s
|
2009-09-21
|
|
WX Guestbook 1.1.208 - SQL Injection / Persistent Cross-Site Scripting
|
4 |
WEB
|
learn3r
|
2009-09-21
|
|
Loggix Project 9.4.5 - Multiple Remote File Inclusions
|
4 |
WEB
|
cr4wl3r
|
2009-09-21
|
|
ProdLer 2.0 - Remote File Inclusion
|
4 |
WEB
|
cr4wl3r
|
2009-09-21
|
|
CMScontrol (Content Management Portal Solutions) - SQL Injection
|
4 |
WEB
|
ph1l1ster
|
2009-09-21
|
|
cP Creator 2.7.1 - SQL Injection
|
4 |
WEB
|
Sina Yazdanmehr
|
2009-09-21
|
|
BAnner ROtation System mini - Multiple Remote File Inclusions
|
4 |
WEB
|
EA Ngel
|
2009-09-21
|
|
Joomla! Component com_jbudgetsmagic 0.3.2 < 0.4.0 - 'bid' SQL Injection
|
4 |
WEB
|
kaMtiEz
|
2009-09-21
|
|
DDL CMS 1.0 - Multiple Remote File Inclusions
|
4 |
WEB
|
HxH
|
2009-09-21
|
|
Joomla! Component com_surveymanager 1.5.0 - 'stype' SQL Injection
|
4 |
WEB
|
kaMtiEz
|
2009-09-18
|
|
FSphp 0.2.1 - Multiple Remote File Inclusions
|
4 |
WEB
|
NoGe
|
2009-09-18
|
|
FanUpdate 2.2.1 - 'show-cat.php' SQL Injection
|
4 |
WEB
|
(In)Security Romania
|
2009-09-18
|
|
Network Management/Inventory System - 'header.php' Remote File Inclusion
|
4 |
WEB
|
EA Ngel
|
2009-09-18
|
|
Zainu 1.0 - SQL Injection
|
3 |
WEB
|
snakespc
|
2009-10-18
|
|
Mambo Component com_koesubmit 1.0.0 - Remote File Inclusion
|
4 |
WEB
|
Don Tukulesto
|
2009-09-17
|
|
Joomla! Component com_jreservation 1.5 - 'pid' Blind SQL Injection
|
4 |
WEB
|
Chip d3 bi0s
|
2009-09-17
|
|
Nephp Publisher Enterprise 4.5 - Authentication Bypass
|
5 |
WEB
|
learn3r hacker
|
2009-09-17
|
|
FMyClone 2.3 - Multiple SQL Injections
|
5 |
WEB
|
learn3r hacker
|
2009-09-17
|
|
CF Shopkart 5.3x - 'itemID' SQL Injection
|
4 |
WEB
|
learn3r hacker
|
2009-09-17
|
|
OpenSiteAdmin 0.9.7b - 'pageHeader.php?path' Remote File Inclusion
|
5 |
WEB
|
EA Ngel
|
2009-09-17
|
|
Joomla! Component com_album 1.14 - Directory Traversal
|
4 |
WEB
|
DreamTurk
|
2009-09-16
|
|
phpPollScript 1.3 - 'include_class' Remote File Inclusion
|
4 |
WEB
|
cr4wl3r
|
2009-09-16
|
|
Elite Gaming Ladders 3.2 - 'platform' SQL Injection
|
4 |
WEB
|
snakespc
|
2009-09-16
|
|
SaphpLesson 4.3 - Blind SQL Injection
|
4 |
WEB
|
Jafer Al Zidjali
|
2009-09-16
|
|
Micro CMS 3.5 - SQL Injection / Local File Inclusion
|
4 |
WEB
|
learn3r hacker
|
2009-09-16
|
|
Joomla! Component com_jlord_rss - 'id' Blind SQL Injection
|
4 |
WEB
|
Chip d3 bi0s
|
2009-09-16
|
|
Joomla! Component com_foobla_suggestions (idea_id) 1.5.11 - SQL Injection
|
4 |
WEB
|
Chip d3 bi0s
|
2009-09-16
|
|
AdsDX 3.05 - Authentication Bypass
|
3 |
WEB
|
snakespc
|
2009-09-15
|
|
Joomla! Component com_djcatalog - SQL Injection / Blind SQL Injection
|
4 |
WEB
|
Chip d3 bi0s
|
2009-09-15
|
|
iBoutique.MALL 1.2 - 'cat' Blind SQL Injection
|
4 |
WEB
|
InjEctOr5
|
2009-09-15
|
|
efront 3.5.4 - 'database.php?path' Remote File Inclusion
|
5 |
WEB
|
cr4wl3r
|
2009-09-15
|
|
HotWeb Rentals - 'details.asp?PropId' Blind SQL Injection
|
4 |
WEB
|
R3d-D3V!L
|
2009-09-15
|
|
Three Pillars Help Desk 3.0 - Authentication Bypass
|
4 |
WEB
|
snakespc
|
2009-09-14
|
|
Bs Counter 2.5.3 - 'page' SQL Injection
|
4 |
WEB
|
Bgh7
|
2009-09-14
|
|
PHP Pro Bid - Blind SQL Injection
|
4 |
WEB
|
NoGe
|
2009-09-14
|
|
Aurora CMS 1.0.2 - 'install.plugin.php' Remote File Inclusion
|
4 |
WEB
|
EA Ngel
|
2009-09-14
|
|
Joomla! Component AlphaUserPoints - SQL Injection
|
4 |
WEB
|
jdc
|
2009-09-14
|
|
Joomla! Component Turtushout 0.11 - 'Name' SQL Injection
|
4 |
WEB
|
jdc
|
2009-09-11
|
|
Joomla! Component Hotel Booking System - Cross-Site Scripting / SQL Injection
|
4 |
WEB
|
K-159
|
2009-09-11
|
|
PHP-IPNMonitor - 'maincat_id' SQL Injection
|
4 |
WEB
|
noname
|
2009-09-11
|
|
gyro 5.0 - SQL Injection / Cross-Site Scripting
|
4 |
WEB
|
OoN_Boy
|
2009-09-11
|
|
Image voting 1.0 - 'index.php?show' SQL Injection
|
4 |
WEB
|
SkuLL-HackeR
|
2009-09-10
|
|
T-HTB Manager 0.5 - Multiple Blind SQL Injections
|
4 |
WEB
|
Salvatore Fresta
|
2009-09-10
|
|
An image Gallery 1.0 - 'navigation.php' Local Directory Traversal
|
4 |
WEB
|
ThE g0bL!N
|
2009-09-10
|
|
Drunken:Golem Gaming Portal - 'admin_news_bot.php' Remote File Inclusion
|
4 |
WEB
|
EA Ngel
|
2009-09-10
|
|
Adult Portal escort listing - 'user_id' SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2009-09-10
|
|
Bus Script - 'sitetext_id' SQL Injection
|
3 |
WEB
|
Mr.SQL
|
2009-09-10
|
|
Accommodation Hotel Booking Portal - 'hotel_id' SQL Injection
|
3 |
WEB
|
Mr.SQL
|
2009-09-10
|
|
iDesk - 'download.php?cat_id' SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2009-09-10
|
|
MYRE Holiday Rental Manager - 'action' SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2009-09-10
|
|
Graffiti CMS 1.x - Arbitrary File Upload
|
5 |
WEB
|
Alexander Concha
|
2009-09-10
|
|
nullam blog 0.1.2 - Local File Inclusion / File Disclosure / SQL Injection / Cross-Site Scripting
|
6 |
WEB
|
Salvatore Fresta
|
2009-09-10
|
|
Advanced Comment System 1.0 - Multiple Remote File Inclusions
|
4 |
WEB
|
Kurd-Team
|
2009-09-09
|
|
ChartDirector 5.0.1 - 'cacheId' Arbitrary File Disclosure
|
5 |
WEB
|
DokFLeed
|
2009-09-09
|
|
PHPNagios 1.2.0 - 'menu.php' Local File Inclusion
|
4 |
WEB
|
CoBRa_21
|
2009-09-09
|
|
Mambo Component Hestar - SQL Injection
|
4 |
WEB
|
M3NW5
|
2009-09-09
|
|
Agoko CMS 0.4 - Remote Command Execution
|
5 |
WEB
|
StAkeR
|
2009-09-09
|
|
Joomla! Component Joomloc 1.0 - 'id' SQL Injection
|
4 |
WEB
|
Chip d3 bi0s
|
2009-09-09
|
|
Model Agency Manager Pro - 'user_id' SQL Injection
|
4 |
WEB
|
R3d-D3V!L
|
2009-09-09
|
|
Joomla! Component TPDugg 1.1 - Blind SQL Injection
|
4 |
WEB
|
NoGe
|
2009-09-09
|
|
Joomla! Component BF Survey Pro Free - SQL Injection
|
4 |
WEB
|
jdc
|
2009-09-09
|
|
OBOphiX 2.7.0 - 'fonctions_racine.php' Remote File Inclusion
|
4 |
WEB
|
EA Ngel
|