Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2009-07-23   Joomla! Component com_Joomlaoads - 'packageId' SQL Injection 35 WEB Mr.tro0oqy
2009-07-23   AWCM 2.1 - Local File Inclusion / Authentication Bypass 38 WEB SwEET-DeViL
2009-07-23   Groone's GLink ORGanizer 2.1 - 'cat' Blind SQL Injection 37 WEB 599eme Man
2009-07-23   e107 Plugin my_gallery 2.4.1 - 'readfile()' Local File Disclosure 40 WEB NoGe
2009-07-22   Phorum 5.2.11 - Persistent Cross-Site Scripting 35 WEB Crashfr
2009-07-21   Meta Search Engine Script - 'url' Local File Disclosure 37 WEB Moudi
2009-07-21   phpDirectorySource 1.0 - Cross-Site Scripting / SQL Injection 37 WEB Moudi
2009-07-21   AnotherPHPBook (APB) 1.3.0 - Authentication Bypass 34 WEB n3w7u
2009-07-20   powerUpload 2.4 - (Authentication Bypass) Insecure Cookie Handling 40 WEB InjEctOr5
2009-07-20   E-Xoopport 3.1 Module MyAnnonces - 'lid' SQL Injection 34 WEB Vrs-hCk
2009-07-20   Alibaba-clone CMS - SQL Injection / Blind SQL Injection 38 WEB 599eme Man
2009-07-20   mcshoutbox 1.1 - SQL Injection / Cross-Site Scripting / shell 37 WEB SirGod
2009-07-20   MiniCWB 2.3.0 - 'lang' Remote File Inclusion 37 WEB NoGe
2009-07-20   Netrix CMS 1.0 - Authentication Bypass 35 WEB Mr.tro0oqy
2009-07-20   Silentum Guestbook 2.0.2 - 'silentum_Guestbook.php' SQL Injection 39 WEB Bgh7
2009-07-17   radnics gold 5.0 - Multiple Vulnerabilities 35 WEB Moudi
2009-07-17   radlance gold 7.5 - Multiple Vulnerabilities 36 WEB Moudi
2009-07-17   radbids gold 4.0 - Multiple Vulnerabilities 40 WEB Moudi
2009-07-17   WebVision 2.1 - 'news.php?n' SQL Injection 37 WEB Mr.tro0oqy
2009-07-17   Joomla! Component Jobline 1.3.1 - Blind SQL Injection 36 WEB ManhLuat93
2009-07-17   good/bad vote - Cross-Site Scripting / Local File Inclusion 34 WEB Moudi
2009-07-17   Ger Versluis 2000 5.5 24 - 'SITE_fiche.php' SQL Injection 38 WEB DeCo017
2009-07-17   Battle Blog 1.25 - Authentication Bypass / SQL Injection / HTML Injection 34 WEB $qL_DoCt0r
2009-07-17   AJOX Poll - 'managepoll.php' Authentication Bypass 36 WEB SirGod
2009-07-17   Super Simple Blog Script 2.5.4 - 'entry' SQL Injection 35 WEB JIKO
2009-07-17   Super Simple Blog Script 2.5.4 - Local File Inclusion 39 WEB JIKO
2009-07-16   dB Masters MultiMedia's Content Manager 4.5 - SQL Injection 37 WEB NoGe
2009-07-16   PHP Live! 3.2.1/2 - 'x' Blind SQL Injection 41 WEB boom3rang
2009-07-16   VS PANEL 7.5.5 - 'results.php?Cat_ID' SQL Injection 35 WEB C0D3R-Dz
2009-07-16   ZenPhoto Gallery 1.2.5 - Admin Password Reset (Cross-Site Request Forgery) 35 WEB petros
2009-07-16   webLeague 2.2.0 - Authentication Bypass 38 WEB ka0x
2009-07-16   webLeague 2.2.0 - 'install.php' Remote Change Password 35 WEB TiGeR-Dz
2009-07-15   WebLeague 2.2.0 - 'profile.php' SQL Injection 36 WEB Arka69
2009-07-15   Admin News Tools - Remote Contents Change 39 WEB Securitylab.ir
2009-07-15   Infinity 2.0.5 - Arbitrary Create Admin 38 WEB Qabandi
2009-07-15   Greenwood Content Manager 0.3.2 - Local File Inclusion 39 WEB Khashayar Fereidani
2009-07-15   PHPGenealogy 2.0 - 'DataDirectory' Remote File Inclusion 34 WEB Khashayar Fereidani
2009-07-15   ZenPhoto 1.2.5 - Completely Blind SQL Injection 37 WEB petros
2009-07-15   Admin News Tools 2.5 - 'fichier' Remote File Disclosure 35 WEB Securitylab.ir
2009-07-15   ILIAS Lms 3.9.9/3.10.7 - Arbitrary Edition / Information Disclosure 39 WEB YEnH4ckEr
2009-07-15   WordPress Plugin My Category Order 2.8 - SQL Injection 37 WEB Manh Luat
2009-07-14   Traidnt UP 2.0 - Blind SQL Injection 38 WEB Qabandi
2009-07-14   Mobilelib Gold 3.0 - Local File Disclosure 37 WEB Qabandi
2009-07-14   DJ Calendar - 'DJcalendar.cgi TEMPLATE' File Disclosure 39 WEB cibbao
2009-07-13   onepound shop 1.x - 'products.php' SQL Injection 36 WEB Affix
2009-07-13   RunCMS 1.6.3 - Remote Shell Injection 35 WEB StAkeR
2009-07-12   PHP AdminPanel Free 1.0.5 - Remote File Disclosure 36 WEB Khashayar Fereidani
2009-07-12   censura 1.16.04 - Blind SQL Injection / Cross-Site Scripting 37 WEB Vrs-hCk
2009-07-11   d.net CMS - Arbitrary Reinstall/Blind SQL Injection 38 WEB darkjoker
2009-07-11   Joomla! Component com_category - 'catid' SQL Injection 36 WEB Prince_Pwn3r
2009-07-11   Ebay Clone 2009 - Multiple SQL Injections 34 WEB MizoZ
2009-07-11   Opial 1.0 - Arbitrary File Upload / Cross-Site Scripting / SQL Injection 36 WEB LMaster
2009-07-10   Morcego CMS 1.7.6 - Blind SQL Injection 35 WEB darkjoker
2009-07-10   LionWiki - 'index.php' Local File Inclusion 36 WEB MoDaMeR
2009-07-10   ebay clone 2009 - Cross-Site Scripting / Blind SQL Injection 36 WEB Moudi
2009-07-10   Digitaldesign CMS 0.1 - Remote Database Disclosure 36 WEB darkjoker
2009-07-10   Joomla! Component com_propertylab - 'auction_id' SQL Injection 36 WEB Chip d3 bi0s
2009-07-10   Jobbr 2.2.7 - Multiple SQL Injections 36 WEB Moudi
2009-07-10   WordPress Core / MU / Plugins - '/admin.php' Privileges Unchecked / Multiple Information Disclosures 35 WEB Core Security
2009-07-10   ToyLog 0.1 - SQL Injection / Remote Code Execution 37 WEB darkjoker
2009-07-10   Phenotype CMS 2.8 - 'login.php?user' Blind SQL Injection 35 WEB Khashayar Fereidani
2009-07-10   MyMsg 1.0.3 - 'uid' SQL Injection 35 WEB Monster-Dz
2009-07-10   gencms 2006 - Multiple Vulnerabilities 36 WEB eLwaux
2009-07-10   phpbms 0.96 - Multiple Vulnerabilities 39 WEB eLwaux
2009-07-09   Universe CMS 1.0.6 - 'vnews.php?id' SQL Injection 35 WEB Mr.tro0oqy
2009-07-09   Siteframe CMS 3.2.x - SQL Injection / phpinfo() 35 WEB NoGe
2009-07-09   TalkBack 2.3.14 - Multiple Vulnerabilities 35 WEB JIKO
2009-07-09   EasyVillaRentalSite - 'id' SQL Injection 38 WEB BazOka-HaCkEr
2009-07-09   webasyst shop-script - Blind SQL Injection / Cross-Site Scripting 36 WEB Vrs-hCk
2009-07-09   Mlffat 2.2 - Blind SQL Injection 37 WEB Qabandi
2009-07-09   ClearContent - '/image.php?url' Local/Remote File Inclusion 37 WEB MizoZ
2009-07-09   Glossword 1.8.11 - Arbitrary Uninstall / Install 36 WEB Evil-Cod3r
2009-07-09   Nwahy Dir 2.1 - Arbitrary Change Admin Password 39 WEB rEcruit
2009-07-09   MRCGIGUY Thumbnail Gallery Post 1b - Arbitrary File Upload 38 WEB ThE g0bL!N
2009-07-02   Rentventory - Multiple SQL Injections 39 WEB Moudi
2009-07-02   Opial 1.0 - 'albumID' SQL Injection 38 WEB ThE g0bL!N
2009-07-02   Opial 1.0 - Authentication Bypass 39 WEB Moudi
2009-07-02   ConPresso 3.4.8 - 'detail.php' Blind SQL Injection 35 WEB tmh
2009-07-02   Almnzm 2.0 - Blind SQL Injection 35 WEB Qabandi
2009-07-02   AdminLog 0.5 - 'valid_login' Authentication Bypass 35 WEB SirGod
2009-07-02   Sourcefire 3D Sensor & Defense Center 4.8.x - Privilege Escalation 37 WEB Gregory Duchemin
2009-07-02   YourTube 2.0 - Arbitrary Database Disclosure 36 WEB Security Code Team
2009-07-01   CMS chainuk 1.2 - Multiple Vulnerabilities 37 WEB eLwaux
2009-07-01   kervinet forum 1.1 - Multiple Vulnerabilities 34 WEB eLwaux
2009-07-01   Messages Library 2.0 - Insecure Cookie Handling 37 WEB Stack
2009-07-01   Messages Library 2.0 - Arbitrary Delete Message 37 WEB Stack
2009-06-30   Messages Library 2.0 - Arbitrary Administrator Account 43 WEB ThE g0bL!N
2009-06-30   PunBB Extension Vote For Us 1.0.1 - Blind SQL Injection 38 WEB Dante90
2009-06-30   tsep 0.942.02 - Multiple Vulnerabilities 37 WEB eLwaux
2009-06-30   MDPro Module CWGuestBook 2.1 - SQL Injection 36 WEB Dante90
2009-06-30   PunBB Affiliates Mod 1.1 - Blind SQL Injection 33 WEB Dante90
2009-06-30   WordPress Plugin Related Sites 2.1 - Blind SQL Injection 33 WEB eLwaux
2009-06-30   phpMyBlockchecker 1.0.0055 - Insecure Cookie Handling 33 WEB SirGod
2009-06-30   BigACE 2.6 - 'cmd' Local File Inclusion 37 WEB CWD@rBe
2009-06-30   jax formmailer 3.0.0 - Remote File Inclusion 33 WEB ahmadbady
2009-06-30   SMF Mod Member Awards 1.0.2 - Blind SQL Injection 39 WEB eLwaux
2009-06-30   DM FileManager 3.9.4 - Remote File Disclosure 45 WEB Stack
2009-06-30   WordPress Plugin DM Albums 1.9.2 - Remote File Disclosure 42 WEB Stack
2009-06-29   dm FileManager 3.9.4 - Remote File Inclusion 37 WEB Septemb0x
2009-06-29   WordPress Plugin DM Albums 1.9.2 - Remote File Inclusion 35 WEB Septemb0x
2009-06-29   NEWSolved 1.1.6 - 'login grabber' Multiple SQL Injections 36 WEB jmp-esp
2009-06-29   Audio Article Directory - 'file' Remote File Disclosure 38 WEB ThE g0bL!N
2009-06-29   Joomla! Component com_bookflip - 'book_id' SQL Injection 38 WEB boom3rang
2009-06-29   Clicknet CMS 2.1 - 'side' Arbitrary File Disclosure 38 WEB ThE g0bL!N
2009-06-29   PHP-Sugar 0.80 - 'index.php?t' Local File Inclusion 37 WEB ahmadbady
2009-06-29   Almnzm - 'COOKIE: customer' SQL Injection 38 WEB Qabandi
2009-06-29   osTicket 1.6 RC4 - Admin Login Blind SQL Injection 37 WEB Adam Baldwin
2009-06-29   Joomla! Component com_K2 -q 1.0.1b - 'category' SQL Injection 34 WEB Chip d3 bi0s
2009-06-29   Joomla! Component com_php - 'id' Blind SQL Injection 38 WEB Chip d3 bi0s
2009-06-29   Messages Library 2.0 - 'cat.php?CatID' SQL Injection 35 WEB SecurityRules
2009-06-29   WHOISCART - Authentication Bypass / Information Disclosure 35 WEB SecurityRules
2009-06-26   Mega File Manager 1.0 - 'index.php' Local File Inclusion 37 WEB SirGod
2009-06-26   ForumPal FE 1.1 - Authentication Bypass 38 WEB ThE g0bL!N
2009-06-26   PHP-Address Book 4.0.x - Multiple SQL Injections 35 WEB YEnH4ckEr
2009-06-26   Virtue Online Test Generator - Authentication Bypass / SQL Injection / Cross-Site Scripting 36 WEB HxH
2009-06-25   MD-Pro 1.083.x - Survey Module 'pollID' Blind SQL Injection 33 WEB XaDoS
2009-06-25   AlumniServer 1.0.1 - 'resetpwemail' Blind SQL Injection 35 WEB YEnH4ckEr
2009-06-25   AlumniServer 1.0.1 - Authentication Bypass 38 WEB YEnH4ckEr
2009-06-25   MyFusion 6b - settings[locale] Local File Inclusion 37 WEB CraCkEr
2009-06-25   Joomla! Component com_pinboard - 'task' SQL Injection 34 WEB Stack
2009-06-24   Joomla! Component com_amocourse - 'catid' SQL Injection 36 WEB Chip d3 bi0s
2009-06-24   LightOpenCMS 0.1 - 'smarty.php?cwd' Local File Inclusion 33 WEB JosS
2009-06-24   PHPEcho CMS 2.0-rc3 - 'forum' Cross-Site Scripting Cookie Stealing / Blind SQL Injection 36 WEB JosS
2009-06-24   Tribiq CMS 5.0.12c - Cross-Site Scripting / Local File Inclusion 35 WEB CraCkEr
2009-06-24   Joomla! Component com_pinboard - Arbitrary File Upload 33 WEB ViRuSMaN