Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2009-09-18   FanUpdate 2.2.1 - 'show-cat.php' SQL Injection 34 WEB (In)Security Romania
2009-09-18   Network Management/Inventory System - 'header.php' Remote File Inclusion 38 WEB EA Ngel
2009-09-18   Zainu 1.0 - SQL Injection 34 WEB snakespc
2009-10-18   Mambo Component com_koesubmit 1.0.0 - Remote File Inclusion 36 WEB Don Tukulesto
2009-09-17   Joomla! Component com_jreservation 1.5 - 'pid' Blind SQL Injection 37 WEB Chip d3 bi0s
2009-09-17   Nephp Publisher Enterprise 4.5 - Authentication Bypass 35 WEB learn3r hacker
2009-09-17   FMyClone 2.3 - Multiple SQL Injections 38 WEB learn3r hacker
2009-09-17   CF Shopkart 5.3x - 'itemID' SQL Injection 37 WEB learn3r hacker
2009-09-17   OpenSiteAdmin 0.9.7b - 'pageHeader.php?path' Remote File Inclusion 39 WEB EA Ngel
2009-09-17   Joomla! Component com_album 1.14 - Directory Traversal 36 WEB DreamTurk
2009-09-16   phpPollScript 1.3 - 'include_class' Remote File Inclusion 38 WEB cr4wl3r
2009-09-16   Elite Gaming Ladders 3.2 - 'platform' SQL Injection 34 WEB snakespc
2009-09-16   SaphpLesson 4.3 - Blind SQL Injection 36 WEB Jafer Al Zidjali
2009-09-16   Micro CMS 3.5 - SQL Injection / Local File Inclusion 34 WEB learn3r hacker
2009-09-16   Joomla! Component com_jlord_rss - 'id' Blind SQL Injection 39 WEB Chip d3 bi0s
2009-09-16   Joomla! Component com_foobla_suggestions (idea_id) 1.5.11 - SQL Injection 36 WEB Chip d3 bi0s
2009-09-16   AdsDX 3.05 - Authentication Bypass 36 WEB snakespc
2009-09-15   Joomla! Component com_djcatalog - SQL Injection / Blind SQL Injection 36 WEB Chip d3 bi0s
2009-09-15   iBoutique.MALL 1.2 - 'cat' Blind SQL Injection 36 WEB InjEctOr5
2009-09-15   efront 3.5.4 - 'database.php?path' Remote File Inclusion 37 WEB cr4wl3r
2009-09-15   HotWeb Rentals - 'details.asp?PropId' Blind SQL Injection 34 WEB R3d-D3V!L
2009-09-15   Three Pillars Help Desk 3.0 - Authentication Bypass 36 WEB snakespc
2009-09-14   Bs Counter 2.5.3 - 'page' SQL Injection 39 WEB Bgh7
2009-09-14   PHP Pro Bid - Blind SQL Injection 35 WEB NoGe
2009-09-14   Aurora CMS 1.0.2 - 'install.plugin.php' Remote File Inclusion 37 WEB EA Ngel
2009-09-14   Joomla! Component AlphaUserPoints - SQL Injection 38 WEB jdc
2009-09-14   Joomla! Component Turtushout 0.11 - 'Name' SQL Injection 41 WEB jdc
2009-09-11   Joomla! Component Hotel Booking System - Cross-Site Scripting / SQL Injection 36 WEB K-159
2009-09-11   PHP-IPNMonitor - 'maincat_id' SQL Injection 37 WEB noname
2009-09-11   gyro 5.0 - SQL Injection / Cross-Site Scripting 38 WEB OoN_Boy
2009-09-11   Image voting 1.0 - 'index.php?show' SQL Injection 41 WEB SkuLL-HackeR
2009-09-10   T-HTB Manager 0.5 - Multiple Blind SQL Injections 38 WEB Salvatore Fresta
2009-09-10   An image Gallery 1.0 - 'navigation.php' Local Directory Traversal 38 WEB ThE g0bL!N
2009-09-10   Drunken:Golem Gaming Portal - 'admin_news_bot.php' Remote File Inclusion 40 WEB EA Ngel
2009-09-10   Adult Portal escort listing - 'user_id' SQL Injection 39 WEB Mr.SQL
2009-09-10   Bus Script - 'sitetext_id' SQL Injection 39 WEB Mr.SQL
2009-09-10   Accommodation Hotel Booking Portal - 'hotel_id' SQL Injection 36 WEB Mr.SQL
2009-09-10   iDesk - 'download.php?cat_id' SQL Injection 39 WEB Mr.SQL
2009-09-10   MYRE Holiday Rental Manager - 'action' SQL Injection 38 WEB Mr.SQL
2009-09-10   Graffiti CMS 1.x - Arbitrary File Upload 38 WEB Alexander Concha
2009-09-10   nullam blog 0.1.2 - Local File Inclusion / File Disclosure / SQL Injection / Cross-Site Scripting 38 WEB Salvatore Fresta
2009-09-10   Advanced Comment System 1.0 - Multiple Remote File Inclusions 37 WEB Kurd-Team
2009-09-09   ChartDirector 5.0.1 - 'cacheId' Arbitrary File Disclosure 35 WEB DokFLeed
2009-09-09   PHPNagios 1.2.0 - 'menu.php' Local File Inclusion 39 WEB CoBRa_21
2009-09-09   Mambo Component Hestar - SQL Injection 38 WEB M3NW5
2009-09-09   Agoko CMS 0.4 - Remote Command Execution 37 WEB StAkeR
2009-09-09   Joomla! Component Joomloc 1.0 - 'id' SQL Injection 37 WEB Chip d3 bi0s
2009-09-09   Model Agency Manager Pro - 'user_id' SQL Injection 38 WEB R3d-D3V!L
2009-09-09   Joomla! Component TPDugg 1.1 - Blind SQL Injection 37 WEB NoGe
2009-09-09   Joomla! Component BF Survey Pro Free - SQL Injection 36 WEB jdc
2009-09-09   OBOphiX 2.7.0 - 'fonctions_racine.php' Remote File Inclusion 36 WEB EA Ngel
2009-09-09   The Rat CMS Alpha 2 - Arbitrary File Upload 38 WEB Securitylab.ir
2009-09-04   Joomla! Component com_Joomlaub - 'aid' SQL Injection 33 WEB 599eme Man
2009-09-04   Ticket Support Script - 'ticket.php' Arbitrary File Upload 37 WEB InjEctOr5
2009-09-04   ZeroBoard 4.1 pl7 - 'now_connect()' Remote Code Execution 36 WEB SpeeDr00t
2009-09-04   Mambo Component com_zoom - 'catid' Blind SQL Injection 38 WEB boom3rang
2009-09-03   PHPope 1.0.0 - Multiple Remote File Inclusions 36 WEB cr4wl3r
2009-09-03   FreeSchool 1.1.0 - Multiple Remote File Inclusions 40 WEB cr4wl3r
2009-09-02   PHP Live! 3.3 - 'deptid' SQL Injection 37 WEB v3n0m
2009-09-02   Ve-EDIT 0.1.4 - 'highlighter' Remote File Inclusion 35 WEB RoMaNcYxHaCkEr
2009-09-02   Discuz! Plugin JiangHu 1.1 - 'id' SQL Injection 37 WEB ZhaoHuAn
2009-09-01   DataLife Engine 8.2 - dle_config_api Remote File Inclusion 38 WEB Kurd-Team
2009-09-01   Joomla! Component com_gameserver 1.0 - 'id' SQL Injection 38 WEB v3n0m
2009-09-01   Ve-EDIT 0.1.4 - 'debug_PHP.php' Local File Inclusion 36 WEB CoBRa_21
2009-09-01   phpBB3 - addon prime_quick_style GetAdmin 36 WEB -SmoG-
2009-09-01   KingCMS 0.6.0 - 'menu.php' Remote File Inclusion 37 WEB CoBRa_21
2009-09-01   Xstate Real Estate 1.0 - Blind SQL Injection / Cross-Site Scripting 36 WEB Moudi
2009-09-01   Joomla! Component Agora 3.0.0b (com_agora) - Local File Inclusion 42 WEB ByALBAYX
2009-09-01   Joomla! Component com_artportal 1.0 - 'portalid' SQL Injection 34 WEB 599eme Man
2009-09-01   JSFTemplating / Mojarra Scales / GlassFish - File Disclosure 38 WEB SEC Consult
2009-08-31   osCommerce Online Merchant 2.2 RC2a - Code Execution 36 WEB flyh4t
2009-08-31   Mybuxscript PTC-BUX - 'spnews.php' SQL Injection 38 WEB HxH
2009-08-31   Rock Band CMS 0.10 - 'news.php' Multiple SQL Injections (1) 38 WEB Affix
2009-08-31   Re-Script 0.99 Beta - 'listings.php?op' SQL Injection 41 WEB Mr.SQL
2009-08-31   Modern Script 5.0 - 'index.php?s' SQL Injection 36 WEB Red-D3v1L
2009-08-28   Silurus Classifieds System - 'category.php' SQL Injection 43 WEB Mr.SQL
2009-08-27   Uiga Church Portal - 'year' SQL Injection 38 WEB Mr.SQL
2009-08-27   Joomla! Component com_digifolio 1.52 - 'id' SQL Injection 35 WEB v3n0m
2009-08-26   PHPSANE 0.5.0 - 'save.php' Remote File Inclusion 35 WEB CoBRa_21
2009-08-26   allomani 2007 - 'cat' SQL Injection 34 WEB NeX HaCkEr
2009-08-26   PAD Site Scripts 3.6 - 'list.php?string' SQL Injection 36 WEB Mr.SQL
2009-08-26   Open Auto Classifieds 1.5.9 - Multiple Vulnerabilities 36 WEB Andrew Horton
2009-08-26   Discuz! Plugin Crazy Star 2.0 - 'fmid' SQL Injection 37 WEB ZhaoHuAn
2009-08-26   Simple CMS Framework 1.0 - 'page' SQL Injection 38 WEB Red-D3v1L
2009-08-26   Moa Gallery 1.2.0 - 'p_filename' Remote File Disclosure 35 WEB GoLd_M
2009-08-26   totalcalendar 2.4 - Blind SQL Injection / Local File Inclusion 33 WEB Moudi
2009-08-26   Moa Gallery 1.2.0 - 'index.php?action' SQL Injection 38 WEB Mr.SQL
2009-08-26   Moa Gallery 1.2.0 - Multiple Remote File Inclusions 39 WEB cr4wl3r
2009-08-25   EMO Breader Manager - 'video.php?movie' SQL Injection 41 WEB Mr.SQL
2009-08-25   TCPDB 3.8 - Remote Content Change Bypass 34 WEB Securitylab.ir
2009-08-25   Turnkey Arcade Script - SQL Injection (2) 37 WEB Red-D3v1L
2009-08-25   Joomla! Component com_siirler 1.2 - 'sid' SQL Injection 37 WEB v3n0m
2009-08-24   Geeklog 1.6.0sr1 - Arbitrary File Upload 35 WEB JaL0h
2009-08-24   Joomla! Component com_jtips 1.0.x - 'season' Blind SQL Injection 38 WEB Chip d3 bi0s
2009-08-24   Joomla! Component com_ninjamonial 1.1 - 'testimID' SQL Injection 35 WEB Chip d3 bi0s
2009-08-24   New5starRating 1.0 - 'rating.php' SQL Injection 38 WEB Bgh7
2009-08-24   ITechBids 8.0 - 'ProductID' Blind SQL Injection 38 WEB Mr.SQL
2009-08-24   humanCMS - Authentication Bypass 40 WEB next
2009-08-24   Uebimiau Webmail 3.2.0-2.0 - Arbitrary Database Disclosure 36 WEB Septemb0x
2009-11-16   Dow Group - 'new.php' SQL Injection 37 WEB ProF.Code
2009-08-24   Lanai Core 0.6 - Remote File Disclosure / Info Disclosure 38 WEB Khashayar Fereidani
2009-08-24   Cuteflow 2.10.3 - 'edituser.php' Security Bypass 40 WEB Hever Costa Rocha
2009-08-24   PHP Dir Submit - 'aid' SQL Injection 39 WEB Mr.tro0oqy
2009-08-24   Arcade Trade Script 1.0b - (Authentication Bypass) Insecure Cookie Handling 42 WEB Mr.tro0oqy
2009-08-24   Moa Gallery 1.1.0 - 'gallery_id' SQL Injection 36 WEB Mr.tro0oqy
2009-08-18   asaher pro 1.0.4 - Remote Database Backup 38 WEB alnjm33
2009-08-18   Traidnt UP 2.0 - SQL Injection 37 WEB Jafer Al Zidjali
2009-08-18   Best Dating Script - Arbitrary File Upload 38 WEB jetli007
2009-08-18   CBAuthority - ClickBank Affiliate Management SQL Injection 38 WEB Angela Chang
2009-08-18   PHP Email Manager - 'remove.php?ID' SQL Injection 39 WEB MuShTaQ
2009-08-18   Ultimate Fade-in Slideshow 1.51 - Arbitrary File Upload 38 WEB NeX HaCkEr
2009-08-18   phpfreeBB 1.0 - Blind SQL Injection 37 WEB Moudi
2009-08-18   Fotoshow PRO - 'category' SQL Injection 37 WEB darkmasking
2009-08-18   Joomla! Component MisterEstate - Blind SQL Injection 35 WEB jdc
2009-08-18   Infinity 2.x - 'options[style_dir]' Local File Disclosure 33 WEB SwEET-DeViL
2009-08-18   E CMS 1.0 - 'index.php?s' SQL Injection 35 WEB Red-D3v1L
2009-08-18   autonomous lan party 0.98.3 - Remote File Inclusion 36 WEB cr4wl3r
2009-08-18   2WIRE Gateway - Authentication Bypass / Password Reset (2) 38 WEB bugz
2009-08-18   Videos Broadcast Yourself 2 - 'UploadID' SQL Injection 37 WEB Mr.SQL
2009-08-18   Arcadem Pro 2.8 - 'article' Blind SQL Injection 38 WEB Mr.SQL
2009-08-18   DreamPics Builder - 'exhibition_id' SQL Injection 36 WEB Mr.SQL
2009-08-18   vTiger CRM 5.0.4 - Remote Code Execution / Cross-Site Request Forgery / Local File Inclusion / Cross 40 WEB USH
2009-08-18   SPIP < 2.0.9 - Arbitrary Copy All Passwords to '.XML' File 38 WEB Kernel_Panik
2009-08-18   AJ Auction Pro OOPD 2.x - 'id' SQL Injection 37 WEB NoGe
2009-08-18   BaBB 2.8 - Remote Code Injection 36 WEB Khashayar Fereidani