2009-07-11
|
|
Opial 1.0 - Arbitrary File Upload / Cross-Site Scripting / SQL Injection
|
4 |
WEB
|
LMaster
|
2009-07-10
|
|
Morcego CMS 1.7.6 - Blind SQL Injection
|
5 |
WEB
|
darkjoker
|
2009-07-10
|
|
LionWiki - 'index.php' Local File Inclusion
|
4 |
WEB
|
MoDaMeR
|
2009-07-10
|
|
ebay clone 2009 - Cross-Site Scripting / Blind SQL Injection
|
4 |
WEB
|
Moudi
|
2009-07-10
|
|
Digitaldesign CMS 0.1 - Remote Database Disclosure
|
4 |
WEB
|
darkjoker
|
2009-07-10
|
|
Joomla! Component com_propertylab - 'auction_id' SQL Injection
|
3 |
WEB
|
Chip d3 bi0s
|
2009-07-10
|
|
Jobbr 2.2.7 - Multiple SQL Injections
|
3 |
WEB
|
Moudi
|
2009-07-10
|
|
WordPress Core / MU / Plugins - '/admin.php' Privileges Unchecked / Multiple Information Disclosures
|
4 |
WEB
|
Core Security
|
2009-07-10
|
|
ToyLog 0.1 - SQL Injection / Remote Code Execution
|
4 |
WEB
|
darkjoker
|
2009-07-10
|
|
Phenotype CMS 2.8 - 'login.php?user' Blind SQL Injection
|
4 |
WEB
|
Khashayar Fereidani
|
2009-07-10
|
|
MyMsg 1.0.3 - 'uid' SQL Injection
|
4 |
WEB
|
Monster-Dz
|
2009-07-10
|
|
gencms 2006 - Multiple Vulnerabilities
|
4 |
WEB
|
eLwaux
|
2009-07-10
|
|
phpbms 0.96 - Multiple Vulnerabilities
|
4 |
WEB
|
eLwaux
|
2009-07-09
|
|
Universe CMS 1.0.6 - 'vnews.php?id' SQL Injection
|
4 |
WEB
|
Mr.tro0oqy
|
2009-07-09
|
|
Siteframe CMS 3.2.x - SQL Injection / phpinfo()
|
4 |
WEB
|
NoGe
|
2009-07-09
|
|
TalkBack 2.3.14 - Multiple Vulnerabilities
|
3 |
WEB
|
JIKO
|
2009-07-09
|
|
EasyVillaRentalSite - 'id' SQL Injection
|
4 |
WEB
|
BazOka-HaCkEr
|
2009-07-09
|
|
webasyst shop-script - Blind SQL Injection / Cross-Site Scripting
|
4 |
WEB
|
Vrs-hCk
|
2009-07-09
|
|
Mlffat 2.2 - Blind SQL Injection
|
4 |
WEB
|
Qabandi
|
2009-07-09
|
|
ClearContent - '/image.php?url' Local/Remote File Inclusion
|
4 |
WEB
|
MizoZ
|
2009-07-09
|
|
Glossword 1.8.11 - Arbitrary Uninstall / Install
|
4 |
WEB
|
Evil-Cod3r
|
2009-07-09
|
|
Nwahy Dir 2.1 - Arbitrary Change Admin Password
|
5 |
WEB
|
rEcruit
|
2009-07-09
|
|
MRCGIGUY Thumbnail Gallery Post 1b - Arbitrary File Upload
|
4 |
WEB
|
ThE g0bL!N
|
2009-07-02
|
|
Rentventory - Multiple SQL Injections
|
5 |
WEB
|
Moudi
|
2009-07-02
|
|
Opial 1.0 - 'albumID' SQL Injection
|
4 |
WEB
|
ThE g0bL!N
|
2009-07-02
|
|
Opial 1.0 - Authentication Bypass
|
4 |
WEB
|
Moudi
|
2009-07-02
|
|
ConPresso 3.4.8 - 'detail.php' Blind SQL Injection
|
4 |
WEB
|
tmh
|
2009-07-02
|
|
Almnzm 2.0 - Blind SQL Injection
|
4 |
WEB
|
Qabandi
|
2009-07-02
|
|
AdminLog 0.5 - 'valid_login' Authentication Bypass
|
4 |
WEB
|
SirGod
|
2009-07-02
|
|
Sourcefire 3D Sensor & Defense Center 4.8.x - Privilege Escalation
|
5 |
WEB
|
Gregory Duchemin
|
2009-07-02
|
|
YourTube 2.0 - Arbitrary Database Disclosure
|
4 |
WEB
|
Security Code Team
|
2009-07-01
|
|
CMS chainuk 1.2 - Multiple Vulnerabilities
|
4 |
WEB
|
eLwaux
|
2009-07-01
|
|
kervinet forum 1.1 - Multiple Vulnerabilities
|
5 |
WEB
|
eLwaux
|
2009-07-01
|
|
Messages Library 2.0 - Insecure Cookie Handling
|
4 |
WEB
|
Stack
|
2009-07-01
|
|
Messages Library 2.0 - Arbitrary Delete Message
|
3 |
WEB
|
Stack
|
2009-06-30
|
|
Messages Library 2.0 - Arbitrary Administrator Account
|
5 |
WEB
|
ThE g0bL!N
|
2009-06-30
|
|
PunBB Extension Vote For Us 1.0.1 - Blind SQL Injection
|
4 |
WEB
|
Dante90
|
2009-06-30
|
|
tsep 0.942.02 - Multiple Vulnerabilities
|
4 |
WEB
|
eLwaux
|
2009-06-30
|
|
MDPro Module CWGuestBook 2.1 - SQL Injection
|
4 |
WEB
|
Dante90
|
2009-06-30
|
|
PunBB Affiliates Mod 1.1 - Blind SQL Injection
|
3 |
WEB
|
Dante90
|
2009-06-30
|
|
WordPress Plugin Related Sites 2.1 - Blind SQL Injection
|
4 |
WEB
|
eLwaux
|
2009-06-30
|
|
phpMyBlockchecker 1.0.0055 - Insecure Cookie Handling
|
4 |
WEB
|
SirGod
|
2009-06-30
|
|
BigACE 2.6 - 'cmd' Local File Inclusion
|
4 |
WEB
|
CWD@rBe
|
2009-06-30
|
|
jax formmailer 3.0.0 - Remote File Inclusion
|
4 |
WEB
|
ahmadbady
|
2009-06-30
|
|
SMF Mod Member Awards 1.0.2 - Blind SQL Injection
|
4 |
WEB
|
eLwaux
|
2009-06-30
|
|
DM FileManager 3.9.4 - Remote File Disclosure
|
4 |
WEB
|
Stack
|
2009-06-30
|
|
WordPress Plugin DM Albums 1.9.2 - Remote File Disclosure
|
4 |
WEB
|
Stack
|
2009-06-29
|
|
dm FileManager 3.9.4 - Remote File Inclusion
|
4 |
WEB
|
Septemb0x
|
2009-06-29
|
|
WordPress Plugin DM Albums 1.9.2 - Remote File Inclusion
|
4 |
WEB
|
Septemb0x
|
2009-06-29
|
|
NEWSolved 1.1.6 - 'login grabber' Multiple SQL Injections
|
4 |
WEB
|
jmp-esp
|
2009-06-29
|
|
Audio Article Directory - 'file' Remote File Disclosure
|
3 |
WEB
|
ThE g0bL!N
|
2009-06-29
|
|
Joomla! Component com_bookflip - 'book_id' SQL Injection
|
3 |
WEB
|
boom3rang
|
2009-06-29
|
|
Clicknet CMS 2.1 - 'side' Arbitrary File Disclosure
|
4 |
WEB
|
ThE g0bL!N
|
2009-06-29
|
|
PHP-Sugar 0.80 - 'index.php?t' Local File Inclusion
|
4 |
WEB
|
ahmadbady
|
2009-06-29
|
|
Almnzm - 'COOKIE: customer' SQL Injection
|
4 |
WEB
|
Qabandi
|
2009-06-29
|
|
osTicket 1.6 RC4 - Admin Login Blind SQL Injection
|
4 |
WEB
|
Adam Baldwin
|
2009-06-29
|
|
Joomla! Component com_K2 -q 1.0.1b - 'category' SQL Injection
|
4 |
WEB
|
Chip d3 bi0s
|
2009-06-29
|
|
Joomla! Component com_php - 'id' Blind SQL Injection
|
4 |
WEB
|
Chip d3 bi0s
|
2009-06-29
|
|
Messages Library 2.0 - 'cat.php?CatID' SQL Injection
|
4 |
WEB
|
SecurityRules
|
2009-06-29
|
|
WHOISCART - Authentication Bypass / Information Disclosure
|
4 |
WEB
|
SecurityRules
|
2009-06-26
|
|
Mega File Manager 1.0 - 'index.php' Local File Inclusion
|
4 |
WEB
|
SirGod
|
2009-06-26
|
|
ForumPal FE 1.1 - Authentication Bypass
|
4 |
WEB
|
ThE g0bL!N
|
2009-06-26
|
|
PHP-Address Book 4.0.x - Multiple SQL Injections
|
4 |
WEB
|
YEnH4ckEr
|
2009-06-26
|
|
Virtue Online Test Generator - Authentication Bypass / SQL Injection / Cross-Site Scripting
|
4 |
WEB
|
HxH
|
2009-06-25
|
|
MD-Pro 1.083.x - Survey Module 'pollID' Blind SQL Injection
|
4 |
WEB
|
XaDoS
|
2009-06-25
|
|
AlumniServer 1.0.1 - 'resetpwemail' Blind SQL Injection
|
4 |
WEB
|
YEnH4ckEr
|
2009-06-25
|
|
AlumniServer 1.0.1 - Authentication Bypass
|
3 |
WEB
|
YEnH4ckEr
|
2009-06-25
|
|
MyFusion 6b - settings[locale] Local File Inclusion
|
3 |
WEB
|
CraCkEr
|
2009-06-25
|
|
Joomla! Component com_pinboard - 'task' SQL Injection
|
3 |
WEB
|
Stack
|
2009-06-24
|
|
Joomla! Component com_amocourse - 'catid' SQL Injection
|
3 |
WEB
|
Chip d3 bi0s
|
2009-06-24
|
|
LightOpenCMS 0.1 - 'smarty.php?cwd' Local File Inclusion
|
3 |
WEB
|
JosS
|
2009-06-24
|
|
PHPEcho CMS 2.0-rc3 - 'forum' Cross-Site Scripting Cookie Stealing / Blind SQL Injection
|
3 |
WEB
|
JosS
|
2009-06-24
|
|
Tribiq CMS 5.0.12c - Cross-Site Scripting / Local File Inclusion
|
4 |
WEB
|
CraCkEr
|
2009-06-24
|
|
Joomla! Component com_pinboard - Arbitrary File Upload
|
4 |
WEB
|
ViRuSMaN
|
2009-06-24
|
|
Glossword 1.8.11 - 'index.php?x' Local File Inclusion
|
4 |
WEB
|
t0fx
|
2009-06-24
|
|
BASE 1.2.4 - (Authentication Bypass) Insecure Cookie Handling
|
4 |
WEB
|
Tim Medin
|
2009-06-23
|
|
phpCollegeExchange 0.1.5c - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
|
3 |
WEB
|
CraCkEr
|
2009-06-23
|
|
Zen Cart 1.3.8 - SQL Execution
|
3 |
WEB
|
BlackH
|
2009-06-23
|
|
Zen Cart 1.3.8 - Remote Code Execution
|
4 |
WEB
|
BlackH
|
2009-06-22
|
|
MyBB 1.4.6 - Remote Code Execution
|
4 |
WEB
|
The:Paradox
|
2009-06-22
|
|
RS-CMS 2.1 - 'key' SQL Injection
|
3 |
WEB
|
Mr.tro0oqy
|
2009-06-22
|
|
Joomla! Component com_tickets 2.1 - 'id' SQL Injection
|
2 |
WEB
|
Chip d3 bi0s
|
2009-06-22
|
|
SourceBans 1.4.2 - Arbitrary Change Admin Email
|
3 |
WEB
|
Mr. Anonymous
|
2009-06-22
|
|
Kasseler CMS - File Disclosure / Cross-Site Scripting
|
3 |
WEB
|
S(r1pt
|
2009-06-22
|
|
Gravy Media Photo Host 1.0.8 - Local File Disclosure
|
4 |
WEB
|
Lo$er
|
2009-06-22
|
|
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
|
4 |
WEB
|
CraCkEr
|
2009-06-22
|
|
AWScripts Gallery Search Engine 1.x - Insecure Cookie
|
4 |
WEB
|
TiGeR-Dz
|
2009-06-22
|
|
elgg - Cross-Site Scripting / Cross-Site Request Forgery / Change Password
|
4 |
WEB
|
lorddemon
|
2009-06-22
|
|
phpMyAdmin - 'pmaPWN!' Code Injection / Remote Code Execution
|
4 |
WEB
|
Hacking Expose!
|
2009-06-22
|
|
phpDatingClub 3.7 - SQL Injection / Cross-Site Scripting Injection
|
4 |
WEB
|
ThE g0bL!N
|
2009-06-22
|
|
pc4 Uploader 10.0 - Remote File Disclosure
|
4 |
WEB
|
Qabandi
|
2009-06-22
|
|
MIDAS 1.43 - (Authentication Bypass) Insecure Cookie Handling
|
4 |
WEB
|
HxH
|
2009-06-18
|
|
CMS buzz - Cross-Site Scripting / Password Change / HTML Injection
|
5 |
WEB
|
ThE g0bL!N
|
2009-06-17
|
|
PHPortal 1.0 - Insecure Cookie Handling
|
4 |
WEB
|
KnocKout
|
2009-06-17
|
|
FretsWeb 1.2 - 'name' Blind SQL Injection
|
4 |
WEB
|
YEnH4ckEr
|
2009-06-17
|
|
FretsWeb 1.2 - Multiple Local File Inclusions
|
4 |
WEB
|
YEnH4ckEr
|
2009-06-17
|
|
Fuzzylime CMS 3.03a - Local Inclusion / Arbitrary File Corruption
|
3 |
WEB
|
StAkeR
|
2009-06-17
|
|
TekBase All-in-One 3.1 - Multiple SQL Injections
|
4 |
WEB
|
n3wb0ss
|
2009-06-17
|
|
PHPFK 7.03 - 'page_bottom.php' Local File Inclusion
|
4 |
WEB
|
ahmadbady
|
2009-06-16
|
|
XOOPS 2.3.3 - '.htaccess' Remote File Disclosure
|
4 |
WEB
|
daath
|
2009-06-15
|
|
Joomla! Component Jumi - 'fileid' Blind SQL Injection
|
4 |
WEB
|
Chip d3 bi0s
|
2009-06-15
|
|
The Recipe Script 5 - Cross-Site Scripting
|
4 |
WEB
|
ThE g0bL!N
|
2009-06-15
|
|
PHPortal 1 - 'topicler.php?id' SQL Injection
|
4 |
WEB
|
Mehmet Ince
|
2009-06-15
|
|
vBulletin Radio and TV Player AddOn - HTML Injection
|
4 |
WEB
|
d3v1l
|
2009-06-15
|
|
PHPCollegeExchange 0.1.5c - 'listing_view.php?itemnr' SQL Injection
|
4 |
WEB
|
SirGod
|
2009-06-15
|
|
WordPress Plugin Photoracer 1.0 - 'id' SQL Injection
|
4 |
WEB
|
Kacper
|
2009-06-15
|
|
Joomla! Component com_iJoomla_rss - Blind SQL Injection
|
4 |
WEB
|
Mehmet Ince
|
2009-06-15
|
|
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
|
4 |
WEB
|
waraxe
|
2009-06-15
|
|
Evernew Free Joke Script 1.2 - Remote Change Password
|
4 |
WEB
|
Hakxer
|
2009-06-15
|
|
adaptweb 0.9.2 - Local File Inclusion / SQL Injection
|
4 |
WEB
|
SirGod
|
2009-06-15
|
|
elvin bts 1.2.0 - Multiple Vulnerabilities
|
4 |
WEB
|
SirGod
|
2009-06-15
|
|
DB Top Sites 1.0 - 'index.php?u' Local File Inclusion
|
3 |
WEB
|
SirGod
|
2009-06-15
|
|
DB Top Sites 1.0 - Remote Command Execution
|
4 |
WEB
|
SirGod
|
2009-06-15
|
|
formmail 1.92 - Multiple Vulnerabilities
|
4 |
WEB
|
USH
|
2009-06-15
|
|
SugarCRM 5.2.0e - Remote Code Execution
|
4 |
WEB
|
USH
|
2009-06-15
|
|
Mundi Mail 0.8.2 - 'top' Remote File Inclusion
|
3 |
WEB
|
Br0ly
|
2009-06-15
|
|
impleo music Collection 2.0 - SQL Injection / Cross-Site Scripting
|
3 |
WEB
|
SirGod
|
2009-06-15
|
|
Joomla! Component com_Projectfork 2.0.10 - Local File Inclusion
|
3 |
WEB
|
ByALBAYX
|
2009-06-12
|
|
Uebimiau Web-Mail 3.2.0-1.8 - Remote File / Overwrite
|
3 |
WEB
|
GoLd_M
|
2009-06-12
|
|
TransLucid 1.75 - Multiple Vulnerabilities
|
4 |
WEB
|
intern0t
|
2009-06-12
|
|
tbdev 01-01-2008 - Multiple Vulnerabilities
|
3 |
WEB
|
intern0t
|
2009-06-12
|
|
pivot 1.40.4-7 - Multiple Vulnerabilities
|
4 |
WEB
|
intern0t
|
2009-06-12
|
|
phpWebThings 1.5.2 - MD5 Hash Retrieve/File Disclosure
|
4 |
WEB
|
StAkeR
|
2009-06-12
|
|
campus virtual-lms - Cross-Site Scripting / SQL Injection
|
4 |
WEB
|
Yasión
|
2009-06-12
|
|
4Images 1.7.7 - Filter Bypass HTML Injection / Cross-Site Scripting
|
4 |
WEB
|
Qabandi
|