2009-09-09
|
|
The Rat CMS Alpha 2 - Arbitrary File Upload
|
4 |
WEB
|
Securitylab.ir
|
2009-09-04
|
|
Joomla! Component com_Joomlaub - 'aid' SQL Injection
|
3 |
WEB
|
599eme Man
|
2009-09-04
|
|
Ticket Support Script - 'ticket.php' Arbitrary File Upload
|
4 |
WEB
|
InjEctOr5
|
2009-09-04
|
|
ZeroBoard 4.1 pl7 - 'now_connect()' Remote Code Execution
|
4 |
WEB
|
SpeeDr00t
|
2009-09-04
|
|
Mambo Component com_zoom - 'catid' Blind SQL Injection
|
4 |
WEB
|
boom3rang
|
2009-09-03
|
|
PHPope 1.0.0 - Multiple Remote File Inclusions
|
4 |
WEB
|
cr4wl3r
|
2009-09-03
|
|
FreeSchool 1.1.0 - Multiple Remote File Inclusions
|
4 |
WEB
|
cr4wl3r
|
2009-09-02
|
|
PHP Live! 3.3 - 'deptid' SQL Injection
|
6 |
WEB
|
v3n0m
|
2009-09-02
|
|
Ve-EDIT 0.1.4 - 'highlighter' Remote File Inclusion
|
5 |
WEB
|
RoMaNcYxHaCkEr
|
2009-09-02
|
|
Discuz! Plugin JiangHu 1.1 - 'id' SQL Injection
|
4 |
WEB
|
ZhaoHuAn
|
2009-09-01
|
|
DataLife Engine 8.2 - dle_config_api Remote File Inclusion
|
4 |
WEB
|
Kurd-Team
|
2009-09-01
|
|
Joomla! Component com_gameserver 1.0 - 'id' SQL Injection
|
5 |
WEB
|
v3n0m
|
2009-09-01
|
|
Ve-EDIT 0.1.4 - 'debug_PHP.php' Local File Inclusion
|
4 |
WEB
|
CoBRa_21
|
2009-09-01
|
|
phpBB3 - addon prime_quick_style GetAdmin
|
4 |
WEB
|
-SmoG-
|
2009-09-01
|
|
KingCMS 0.6.0 - 'menu.php' Remote File Inclusion
|
4 |
WEB
|
CoBRa_21
|
2009-09-01
|
|
Xstate Real Estate 1.0 - Blind SQL Injection / Cross-Site Scripting
|
4 |
WEB
|
Moudi
|
2009-09-01
|
|
Joomla! Component Agora 3.0.0b (com_agora) - Local File Inclusion
|
4 |
WEB
|
ByALBAYX
|
2009-09-01
|
|
Joomla! Component com_artportal 1.0 - 'portalid' SQL Injection
|
4 |
WEB
|
599eme Man
|
2009-09-01
|
|
JSFTemplating / Mojarra Scales / GlassFish - File Disclosure
|
4 |
WEB
|
SEC Consult
|
2009-08-31
|
|
osCommerce Online Merchant 2.2 RC2a - Code Execution
|
4 |
WEB
|
flyh4t
|
2009-08-31
|
|
Mybuxscript PTC-BUX - 'spnews.php' SQL Injection
|
4 |
WEB
|
HxH
|
2009-08-31
|
|
Rock Band CMS 0.10 - 'news.php' Multiple SQL Injections (1)
|
4 |
WEB
|
Affix
|
2009-08-31
|
|
Re-Script 0.99 Beta - 'listings.php?op' SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2009-08-31
|
|
Modern Script 5.0 - 'index.php?s' SQL Injection
|
4 |
WEB
|
Red-D3v1L
|
2009-08-28
|
|
Silurus Classifieds System - 'category.php' SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2009-08-27
|
|
Uiga Church Portal - 'year' SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2009-08-27
|
|
Joomla! Component com_digifolio 1.52 - 'id' SQL Injection
|
4 |
WEB
|
v3n0m
|
2009-08-26
|
|
PHPSANE 0.5.0 - 'save.php' Remote File Inclusion
|
4 |
WEB
|
CoBRa_21
|
2009-08-26
|
|
allomani 2007 - 'cat' SQL Injection
|
4 |
WEB
|
NeX HaCkEr
|
2009-08-26
|
|
PAD Site Scripts 3.6 - 'list.php?string' SQL Injection
|
5 |
WEB
|
Mr.SQL
|
2009-08-26
|
|
Open Auto Classifieds 1.5.9 - Multiple Vulnerabilities
|
4 |
WEB
|
Andrew Horton
|
2009-08-26
|
|
Discuz! Plugin Crazy Star 2.0 - 'fmid' SQL Injection
|
4 |
WEB
|
ZhaoHuAn
|
2009-08-26
|
|
Simple CMS Framework 1.0 - 'page' SQL Injection
|
4 |
WEB
|
Red-D3v1L
|
2009-08-26
|
|
Moa Gallery 1.2.0 - 'p_filename' Remote File Disclosure
|
4 |
WEB
|
GoLd_M
|
2009-08-26
|
|
totalcalendar 2.4 - Blind SQL Injection / Local File Inclusion
|
4 |
WEB
|
Moudi
|
2009-08-26
|
|
Moa Gallery 1.2.0 - 'index.php?action' SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2009-08-26
|
|
Moa Gallery 1.2.0 - Multiple Remote File Inclusions
|
4 |
WEB
|
cr4wl3r
|
2009-08-25
|
|
EMO Breader Manager - 'video.php?movie' SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2009-08-25
|
|
TCPDB 3.8 - Remote Content Change Bypass
|
4 |
WEB
|
Securitylab.ir
|
2009-08-25
|
|
Turnkey Arcade Script - SQL Injection (2)
|
4 |
WEB
|
Red-D3v1L
|
2009-08-25
|
|
Joomla! Component com_siirler 1.2 - 'sid' SQL Injection
|
3 |
WEB
|
v3n0m
|
2009-08-24
|
|
Geeklog 1.6.0sr1 - Arbitrary File Upload
|
4 |
WEB
|
JaL0h
|
2009-08-24
|
|
Joomla! Component com_jtips 1.0.x - 'season' Blind SQL Injection
|
4 |
WEB
|
Chip d3 bi0s
|
2009-08-24
|
|
Joomla! Component com_ninjamonial 1.1 - 'testimID' SQL Injection
|
4 |
WEB
|
Chip d3 bi0s
|
2009-08-24
|
|
New5starRating 1.0 - 'rating.php' SQL Injection
|
5 |
WEB
|
Bgh7
|
2009-08-24
|
|
ITechBids 8.0 - 'ProductID' Blind SQL Injection
|
5 |
WEB
|
Mr.SQL
|
2009-08-24
|
|
humanCMS - Authentication Bypass
|
4 |
WEB
|
next
|
2009-08-24
|
|
Uebimiau Webmail 3.2.0-2.0 - Arbitrary Database Disclosure
|
4 |
WEB
|
Septemb0x
|
2009-11-16
|
|
Dow Group - 'new.php' SQL Injection
|
4 |
WEB
|
ProF.Code
|
2009-08-24
|
|
Lanai Core 0.6 - Remote File Disclosure / Info Disclosure
|
4 |
WEB
|
Khashayar Fereidani
|
2009-08-24
|
|
Cuteflow 2.10.3 - 'edituser.php' Security Bypass
|
4 |
WEB
|
Hever Costa Rocha
|
2009-08-24
|
|
PHP Dir Submit - 'aid' SQL Injection
|
4 |
WEB
|
Mr.tro0oqy
|
2009-08-24
|
|
Arcade Trade Script 1.0b - (Authentication Bypass) Insecure Cookie Handling
|
5 |
WEB
|
Mr.tro0oqy
|
2009-08-24
|
|
Moa Gallery 1.1.0 - 'gallery_id' SQL Injection
|
4 |
WEB
|
Mr.tro0oqy
|
2009-08-18
|
|
asaher pro 1.0.4 - Remote Database Backup
|
4 |
WEB
|
alnjm33
|
2009-08-18
|
|
Traidnt UP 2.0 - SQL Injection
|
4 |
WEB
|
Jafer Al Zidjali
|
2009-08-18
|
|
Best Dating Script - Arbitrary File Upload
|
5 |
WEB
|
jetli007
|
2009-08-18
|
|
CBAuthority - ClickBank Affiliate Management SQL Injection
|
4 |
WEB
|
Angela Chang
|
2009-08-18
|
|
PHP Email Manager - 'remove.php?ID' SQL Injection
|
4 |
WEB
|
MuShTaQ
|
2009-08-18
|
|
Ultimate Fade-in Slideshow 1.51 - Arbitrary File Upload
|
3 |
WEB
|
NeX HaCkEr
|
2009-08-18
|
|
phpfreeBB 1.0 - Blind SQL Injection
|
4 |
WEB
|
Moudi
|
2009-08-18
|
|
Fotoshow PRO - 'category' SQL Injection
|
4 |
WEB
|
darkmasking
|
2009-08-18
|
|
Joomla! Component MisterEstate - Blind SQL Injection
|
4 |
WEB
|
jdc
|
2009-08-18
|
|
Infinity 2.x - 'options[style_dir]' Local File Disclosure
|
4 |
WEB
|
SwEET-DeViL
|
2009-08-18
|
|
E CMS 1.0 - 'index.php?s' SQL Injection
|
4 |
WEB
|
Red-D3v1L
|
2009-08-18
|
|
autonomous lan party 0.98.3 - Remote File Inclusion
|
4 |
WEB
|
cr4wl3r
|
2009-08-18
|
|
2WIRE Gateway - Authentication Bypass / Password Reset (2)
|
4 |
WEB
|
bugz
|
2009-08-18
|
|
Videos Broadcast Yourself 2 - 'UploadID' SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2009-08-18
|
|
Arcadem Pro 2.8 - 'article' Blind SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2009-08-18
|
|
DreamPics Builder - 'exhibition_id' SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2009-08-18
|
|
vTiger CRM 5.0.4 - Remote Code Execution / Cross-Site Request Forgery / Local File Inclusion / Cross
|
5 |
WEB
|
USH
|
2009-08-18
|
|
SPIP < 2.0.9 - Arbitrary Copy All Passwords to '.XML' File
|
5 |
WEB
|
Kernel_Panik
|
2009-08-18
|
|
AJ Auction Pro OOPD 2.x - 'id' SQL Injection
|
4 |
WEB
|
NoGe
|
2009-08-18
|
|
BaBB 2.8 - Remote Code Injection
|
4 |
WEB
|
Khashayar Fereidani
|
2009-08-18
|
|
PHP-Lance 1.52 - Multiple Local File Inclusions
|
4 |
WEB
|
jetli007
|
2009-08-14
|
|
MyWeight 1.0 - Arbitrary File Upload
|
4 |
WEB
|
Mr.tro0oqy
|
2009-08-14
|
|
DS CMS 1.0 - 'nFileId' SQL Injection
|
4 |
WEB
|
Mr.tro0oqy
|
2009-08-14
|
|
PHP Competition System 0.84 - 'competition' SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2009-08-14
|
|
Ignition 1.2 - 'comment' Remote Code Injection
|
4 |
WEB
|
Khashayar Fereidani
|
2009-08-13
|
|
tgs CMS 0.x - Cross-Site Scripting / SQL Injection / File Disclosure
|
4 |
WEB
|
[]ViZiOn
|
2009-08-13
|
|
Gazelle CMS 1.0 - Arbitrary File Upload
|
4 |
WEB
|
RoMaNcYxHaCkEr
|
2009-08-27
|
|
WordPress Plugin WP-Syntax 0.9.1 - Remote Command Execution
|
4 |
WEB
|
Raz0r
|
2009-08-13
|
|
JBLOG 1.5.1 - SQL Table Backup
|
4 |
WEB
|
Ams
|
2009-08-12
|
|
Gazelle CMS 1.0 - Multiple Vulnerabilities / Remote Code Execution
|
3 |
WEB
|
IHTeam
|
2009-08-12
|
|
Plume CMS 1.2.3 - Multiple SQL Injections
|
5 |
WEB
|
Sense of Security
|
2009-08-12
|
|
Gallarific 1.1 - '/gallery.php' Arbitrary Delete/Edit Category
|
4 |
WEB
|
ilker Kandemir
|
2009-08-12
|
|
Shorty 0.7.1b - (Authentication Bypass) Insecure Cookie Handling
|
4 |
WEB
|
Pedro Laguna
|
2009-08-11
|
|
OCS Inventory NG 1.2.1 - 'systemid' SQL Injection
|
5 |
WEB
|
Guilherme Marinheiro
|
2009-08-11
|
|
Joomla! Component idoblog 1.1b30 (com_idoblog) - SQL Injection
|
5 |
WEB
|
kkr
|
2009-08-11
|
|
WordPress Core 2.8.3 - Remote Admin Reset Password
|
5 |
WEB
|
laurent gaffié
|
2009-08-10
|
|
Joomla! Component Kunena Forums (com_kunena) - Blind SQL Injection
|
5 |
WEB
|
ilker Kandemir
|
2009-08-10
|
|
CMS Made Simple 1.6.2 - Local File Disclosure
|
4 |
WEB
|
IHTeam
|
2009-08-10
|
|
Mini-CMS 1.0.1 - 'page.php' SQL Injection
|
4 |
WEB
|
Ins3t
|
2009-08-10
|
|
Papoo CMS 3.7.3 - (Authenticated) Arbitrary Code Execution
|
4 |
WEB
|
RedTeam Pentesting
|
2009-08-10
|
|
SmilieScript 1.0 - Authentication Bypass
|
4 |
WEB
|
Mr.tro0oqy
|
2009-08-07
|
|
logoshows bbs 2.0 - File Disclosure / Insecure Cookie Handling
|
4 |
WEB
|
ZoRLu
|
2009-08-07
|
|
Logoshows BBS 2.0 - Authentication Bypass
|
4 |
WEB
|
Dns-Team
|
2009-08-07
|
|
Joomla! Component com_pms 2.0.4 - 'Ignore-List' SQL Injection
|
4 |
WEB
|
M4dhead
|
2009-08-07
|
|
IsolSoft Support Center 2.5 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
|
4 |
WEB
|
Moudi
|
2009-08-07
|
|
Facil Helpdesk - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
|
3 |
WEB
|
Moudi
|
2009-08-07
|
|
PHPCityPortal - Authentication Bypass
|
3 |
WEB
|
CoBRa_21
|
2009-08-07
|
|
Arab Portal 2.2 - Blind Cookie Authentication Bypass
|
4 |
WEB
|
Jafer Al Zidjali
|
2009-08-07
|
|
Typing Pal 1.0 - 'idTableProduit' SQL Injection
|
3 |
WEB
|
Red-D3v1L
|
2009-08-07
|
|
Logoshows BBS 2.0 - 'forumid' SQL Injection
|
4 |
WEB
|
Ruzgarin_Oglu
|
2009-08-07
|
|
Banner Exchange Script 1.0 - 'targetid' Blind SQL Injection
|
4 |
WEB
|
599eme Man
|
2009-08-07
|
|
PHotoLa Gallery 1.0 - Authentication Bypass
|
4 |
WEB
|
Red-D3v1L
|
2009-08-07
|
|
Alwasel 1.5 - Multiple SQL Injections
|
4 |
WEB
|
SwEET-DeViL
|
2009-08-06
|
|
LM Starmail 2.0 - SQL Injection / File Inclusion
|
3 |
WEB
|
int_main();
|
2009-08-06
|
|
TYPO3 CMS 4.0 - 'showUid' SQL Injection
|
4 |
WEB
|
Ro0T-MaFia
|
2009-08-06
|
|
PHP Script Forum Hoster - Topic Delete / Cross-Site Scripting
|
4 |
WEB
|
int_main();
|
2009-08-05
|
|
Portel 2008 - 'decide.php?patron' Blind SQL Injection
|
4 |
WEB
|
Chip d3 bi0s
|
2009-08-05
|
|
opennews 1.0 - SQL Injection / Remote Code Execution
|
5 |
WEB
|
SirGod
|
2009-08-05
|
|
AccessoriesMe PHP Affiliate Script 1.4 - Blind SQL Injection / Cross-Site Scripting
|
4 |
WEB
|
Moudi
|
2009-08-05
|
|
Irokez CMS 0.7.1 - SQL Injection
|
4 |
WEB
|
Ins3t
|
2009-08-05
|
|
tenrok 1.1.0 - File Disclosure / Remote Code Execution
|
4 |
WEB
|
SirGod
|
2009-08-05
|
|
mybackup 1.4.0 - File Download / Remote File Inclusion
|
4 |
WEB
|
SirGod
|
2009-08-04
|
|
In-portal 4.3.1 - 'index.php?env' Local File Inclusion
|
4 |
WEB
|
Angela Chang
|
2009-08-04
|
|
Perl$hop E-Commerce Script - Trust Boundary Input Parameter Injection
|
4 |
WEB
|
Shadow
|
2009-08-04
|
|
ShopMaker CMS 2.0 - Blind SQL Injection / Local File Inclusion
|
4 |
WEB
|
PLATEN
|
2009-08-04
|
|
elgg 1.5 - '/_css/js.php' Local File Inclusion
|
4 |
WEB
|
eLwaux
|
2009-08-04
|
|
MOC Designs PHP News 1.1 - Authentication Bypass
|
4 |
WEB
|
SirGod
|
2009-08-03
|
|
Payment Processor Script (PPScript) - 'shop.htm cid' SQL Injection
|
4 |
WEB
|
ZoRLu
|
2009-08-03
|
|
MAXcms 3.11.20b - Remote File Inclusion / File Disclosure
|
4 |
WEB
|
GoLd_M
|
2009-08-03
|
|
Discloser 0.0.4-rc2 - 'index.php?more' SQL Injection
|
4 |
WEB
|
Salvatore Fresta
|
2009-08-03
|
|
Blink Blog System - Authentication Bypass
|
4 |
WEB
|
Salvatore Fresta
|