2009-06-12
|
|
Zip Store Chat 4.0/5.0 - Authentication Bypass
|
4 |
WEB
|
ByALBAYX
|
2009-06-11
|
|
Sniggabo CMS - 'article.php?id' SQL Injection
|
3 |
WEB
|
Lidloses_Auge
|
2009-06-11
|
|
yogurt 0.3 - Cross-Site Scripting / SQL Injection
|
4 |
WEB
|
Br0ly
|
2009-06-11
|
|
TorrentVolve 1.4 - 'deleteTorrent' Delete Arbitrary File
|
4 |
WEB
|
Br0ly
|
2009-06-11
|
|
Splog 1.2 Beta - Multiple SQL Injections
|
4 |
WEB
|
YEnH4ckEr
|
2009-06-11
|
|
PHPWebThings 1.5.2 - 'help.php?module' Local File Inclusion
|
4 |
WEB
|
Br0ly
|
2009-06-10
|
|
Open Biller 0.1 - 'Username' Blind SQL Injection
|
4 |
WEB
|
YEnH4ckEr
|
2009-06-10
|
|
mrcgiguy freeticket - Cookie Handling / SQL Injection
|
4 |
WEB
|
ThE g0bL!N
|
2009-06-10
|
|
Desi Short URL Script - (Authentication Bypass) Insecure Cookie Handling
|
4 |
WEB
|
N@bilX
|
2009-06-10
|
|
School Data Navigator - 'page' Local/Remote File Inclusion
|
4 |
WEB
|
Br0ly
|
2009-06-10
|
|
LightNEasy sql/no-db 2.2.x - System Configuration Disclosure
|
4 |
WEB
|
StAkeR
|
2009-06-09
|
|
phpMyAdmin - '/scripts/setup.php' PHP Code Injection
|
4 |
WEB
|
Adrian _pagvac_ Pastor
|
2009-06-09
|
|
Joomla! Component com_vehiclemanager 1.0 - Remote File Inclusion
|
3 |
WEB
|
Mehmet Ince
|
2009-06-09
|
|
Joomla! Component com_realestatemanager 1.0 - Remote File Inclusion
|
4 |
WEB
|
Mehmet Ince
|
2009-06-09
|
|
MRCGIGUY Hot Links - 'report.php?id' SQL Injection
|
4 |
WEB
|
ThE g0bL!N
|
2009-06-09
|
|
mrcgiguy the ticket system 2.0 PHP - Multiple Vulnerabilities
|
4 |
WEB
|
ThE g0bL!N
|
2009-06-09
|
|
S-CMS 2.0b3 - 'Username' Blind SQL Injection
|
4 |
WEB
|
YEnH4ckEr
|
2009-06-09
|
|
S-CMS 2.0b3 - Multiple SQL Injections
|
4 |
WEB
|
YEnH4ckEr
|
2009-06-09
|
|
S-CMS 2.0b3 - Multiple Local File Inclusions
|
4 |
WEB
|
YEnH4ckEr
|
2009-06-09
|
|
Joomla! Component com_media_library 1.5.3 - Remote File Inclusion
|
4 |
WEB
|
Mehmet Ince
|
2009-06-09
|
|
Joomla! Component Akobook 2.3 - 'gbid' SQL Injection
|
4 |
WEB
|
Ab1i
|
2009-06-09
|
|
Joomla! Component BookLibrary 1.5.2.4 - Remote File Inclusion
|
4 |
WEB
|
Mehmet Ince
|
2009-06-08
|
|
Shop Script Pro 2.12 - SQL Injection
|
4 |
WEB
|
Ams
|
2009-06-08
|
|
Joomla! Component com_portafolio - 'cid' SQL Injection
|
4 |
WEB
|
Chip d3 bi0s
|
2009-06-08
|
|
Automated link exchange portal 1.3 - Multiple Vulnerabilities
|
4 |
WEB
|
TiGeR-Dz
|
2009-06-08
|
|
DM FileManager 3.9.2 - Insecure Cookie Handling
|
4 |
WEB
|
ThE g0bL!N
|
2009-06-08
|
|
Grestul 1.2 - Remote Add Administrator Account
|
4 |
WEB
|
ThE g0bL!N
|
2009-06-08
|
|
virtue news - SQL Injection / Cross-Site Scripting
|
4 |
WEB
|
snakespc
|
2009-06-08
|
|
Frontis 3.9.01.24 - 'source_class' SQL Injection
|
4 |
WEB
|
snakespc
|
2009-06-08
|
|
Joomla! Component MooFAQ (com_moofaq) - Local File Inclusion
|
4 |
WEB
|
Chip d3 bi0s
|
2009-06-08
|
|
Interlogy Profile Manager Basic - Insecure Cookie Handling
|
3 |
WEB
|
ZoRLu
|
2009-06-08
|
|
Virtue Shopping Mall - 'cid' SQL Injection
|
3 |
WEB
|
OzX
|
2009-06-08
|
|
Virtue Book Store - 'cid' SQL Injection
|
3 |
WEB
|
OzX
|
2009-06-08
|
|
Virtue Classifieds - 'category' SQL Injection
|
4 |
WEB
|
OzX
|
2009-06-08
|
|
Joomla! Component com_school 1.4 - 'classid' SQL Injection
|
3 |
WEB
|
Chip d3 bi0s
|
2009-06-08
|
|
FipsCMS Light 2.1 - 'db.mdb' Remote Database Disclosure
|
4 |
WEB
|
ByALBAYX
|
2009-06-08
|
|
VT-Auth 1.0 - 'zHk8dEes3.txt' File Disclosure
|
3 |
WEB
|
ByALBAYX
|
2009-06-08
|
|
MyCars Automotive - Authentication Bypass
|
4 |
WEB
|
snakespc
|
2009-06-05
|
|
Kjtechforce mailman b1 - 'dest' Blind SQL Injection
|
4 |
WEB
|
YEnH4ckEr
|
2009-06-05
|
|
Kjtechforce mailman b1 - Delete Row 'code' SQL Injection
|
4 |
WEB
|
YEnH4ckEr
|
2009-06-05
|
|
Pixelactivo 3.0 - Authentication Bypass
|
4 |
WEB
|
ThE g0bL!N
|
2009-06-05
|
|
Pixelactivo 3.0 - 'idx' SQL Injection
|
4 |
WEB
|
snakespc
|
2009-06-04
|
|
Host Directory PRO 2.1.0 - Remote Change Admin Password
|
4 |
WEB
|
TiGeR-Dz
|
2009-06-04
|
|
Web Directory PRO - Remote Database Backup
|
4 |
WEB
|
TiGeR-Dz
|
2009-06-04
|
|
Host Directory PRO 2.1.0 - Remote Database Backup
|
3 |
WEB
|
ZoRLu
|
2009-06-04
|
|
Web Directory PRO - 'Admins.php' Change Admin Password
|
5 |
WEB
|
TiGeR-Dz
|
2009-06-04
|
|
SuperCali PHP Event Calendar - Arbitrary Change Admin Password
|
4 |
WEB
|
TiGeR-Dz
|
2009-06-03
|
|
Joomla! Component com_mosres - Multiple SQL Injections
|
4 |
WEB
|
Chip d3 bi0s
|
2009-06-03
|
|
Movie PHP Script 2.0 - 'init.php?anticode' Code Execution
|
4 |
WEB
|
SirGod
|
2009-06-03
|
|
Joomla! Component Omilen Photo Gallery 0.5b - Local File Inclusion
|
4 |
WEB
|
ByALBAYX
|
2009-06-03
|
|
Supernews 2.6 - 'index.php?noticia' SQL Injection
|
4 |
WEB
|
DD3str0y3r
|
2009-06-03
|
|
OCS Inventory NG 1.02 - Remote File Disclosure
|
4 |
WEB
|
Nico Leidecker
|
2009-06-03
|
|
Joomla! Component Seminar 1.28 - 'id' Blind SQL Injection
|
3 |
WEB
|
ThE g0bL!N
|
2009-06-03
|
|
Podcast Generator 1.2 - Unauthorized Re-Installation
|
4 |
WEB
|
StAkeR
|
2009-06-03
|
|
EgyPlus 7ml 1.0.1 - Authentication Bypass
|
4 |
WEB
|
Qabandi
|
2009-06-03
|
|
My Mini Bill - 'orderid' SQL Injection
|
4 |
WEB
|
ThE g0bL!N
|
2009-06-02
|
|
Podcast Generator 1.2 - 'GLOBALS[]' Multiple Vulnerabilities
|
4 |
WEB
|
StAkeR
|
2009-06-02
|
|
WebEyes Guest Book 3 - 'yorum.asp?mesajid' SQL Injection
|
4 |
WEB
|
Bl@ckbe@rD
|
2009-06-02
|
|
propertymax pro free - SQL Injection / Cross-Site Scripting
|
4 |
WEB
|
SirGod
|
2009-06-02
|
|
WebCal - 'webCal3_detail.asp?event_id' SQL Injection
|
4 |
WEB
|
Bl@ckbe@rD
|
2009-06-02
|
|
flashlight free edition - Local File Inclusion / SQL Injection
|
4 |
WEB
|
K4m1k451
|
2009-06-02
|
|
Alstrasoft Article Manager Pro - Arbitrary File Upload
|
4 |
WEB
|
ZoRLu
|
2009-06-02
|
|
Online Grades & Attendance 3.2.6 - Blind SQL Injection
|
4 |
WEB
|
YEnH4ckEr
|
2009-06-02
|
|
Online Grades & Attendance 3.2.6 - Multiple Local File Inclusions
|
4 |
WEB
|
YEnH4ckEr
|
2009-06-01
|
|
ASP Football Pool 2.3 - Remote Database Disclosure
|
4 |
WEB
|
ByALBAYX
|
2009-06-01
|
|
AdaptBB 1.0 - 'forumspath' Remote File Inclusion
|
4 |
WEB
|
Mehmet Ince
|
2009-06-01
|
|
PAD Site Scripts 3.6 - Arbitrary Database Backup
|
3 |
WEB
|
TiGeR-Dz
|
2009-06-01
|
|
R2 NewsLetter Lite/Pro/Stats - 'admin.mdb' Database Disclosure
|
3 |
WEB
|
TiGeR-Dz
|
2009-06-01
|
|
ecsportal rel 6.5 - 'article_view_photo.php?id' SQL Injection
|
4 |
WEB
|
taRentReXx
|
2009-06-01
|
|
Joomla! Component Joomlaequipment (com_juser) 2.0.4 - SQL Injection
|
4 |
WEB
|
Chip d3 bi0s
|
2009-06-01
|
|
Online Grades & Attendance 3.2.6 - Multiple SQL Injections
|
4 |
WEB
|
YEnH4ckEr
|
2009-06-01
|
|
Online Grades & Attendance 3.2.6 - Credentials Changer SQL
|
4 |
WEB
|
YEnH4ckEr
|
2009-06-01
|
|
unclassified NewsBoard 1.6.4 - Multiple Vulnerabilities
|
4 |
WEB
|
girex
|
2009-06-01
|
|
Escon SupportPortal Pro 3.0 - 'tid' Blind SQL Injection
|
4 |
WEB
|
OzX
|
2009-06-01
|
|
Open-school 1.0 - 'id' SQL Injection
|
4 |
WEB
|
OzX
|
2009-06-01
|
|
elitecms 1.01 - SQL Injection / Cross-Site Scripting
|
4 |
WEB
|
xeno_hive
|
2009-06-01
|
|
OCS Inventory NG 1.02 - Multiple SQL Injections
|
4 |
WEB
|
Nico Leidecker
|
2009-06-01
|
|
RadCLASSIFIEDS Gold 2 - 'seller' SQL Injection
|
4 |
WEB
|
Br0ly
|
2009-05-29
|
|
Traidnt Up 2.0 - Cookie Authentication Bypass
|
4 |
WEB
|
Qabandi
|
2009-05-29
|
|
Million Dollar Text Links 1.0 - 'id' SQL Injection
|
4 |
WEB
|
Qabandi
|
2009-05-29
|
|
ZeusCart 2.3 - 'maincatid' SQL Injection
|
4 |
WEB
|
Br0ly
|
2009-05-29
|
|
Arab Portal 2.2 - Authentication Bypass
|
4 |
WEB
|
sniper code
|
2009-05-29
|
|
ecshop 2.6.2 - Multiple Remote Command Execution Vulnerabilities
|
4 |
WEB
|
Securitylab.ir
|
2009-05-29
|
|
Zen Help Desk 2.1 - Authentication Bypass
|
4 |
WEB
|
TiGeR-Dz
|
2009-05-29
|
|
212Cafe WebBoard 2.90 Beta - Remote File Disclosure
|
4 |
WEB
|
MrDoug
|
2009-05-29
|
|
Joomla! Component JVideo 0.3.x - SQL Injection
|
4 |
WEB
|
Chip d3 bi0s
|
2009-05-29
|
|
amember 3.1.7 - Cross-Site Scripting / SQL Injection / HTML Injection
|
4 |
WEB
|
intern0t
|
2009-05-29
|
|
small pirate 2.1 - Cross-Site Scripting / SQL Injection
|
4 |
WEB
|
YEnH4ckEr
|
2009-05-27
|
|
Impact Software AdPeeps 8.5d1 - Cross-Site Scripting / HTML Injection
|
4 |
WEB
|
intern0t
|
2009-05-27
|
|
Evernew Free Joke Script 1.2 - 'cat_id' SQL Injection
|
4 |
WEB
|
taRentReXx
|
2009-05-27
|
|
SiteX 0.7.4.418 - 'THEME_FOLDER' Local File Inclusion
|
4 |
WEB
|
ahmadbady
|
2009-05-27
|
|
Easy Px 41 CMS 09.00.00B1 - 'fiche' Local File Inclusion
|
3 |
WEB
|
ThE g0bL!N
|
2009-05-27
|
|
Joomla! Component AgoraGroup 0.3.5.3 - Blind SQL Injection
|
4 |
WEB
|
Chip d3 bi0s
|
2009-05-27
|
|
Million Dollar Text Links 1.x - Insecure Cookie Handling
|
3 |
WEB
|
HxH
|
2009-05-26
|
|
Dokuwiki 2009-02-14 - Temporary/Remote File Inclusion
|
4 |
WEB
|
Nine:Situations:Group
|
2009-05-26
|
|
Joomla! Component Com_Agora 3.0.0 RC1 - Arbitrary File Upload
|
5 |
WEB
|
ByALBAYX
|
2009-05-26
|
|
WebMember 1.0 - 'formID' SQL Injection
|
4 |
WEB
|
KIM
|
2009-05-26
|
|
ZeeCareers 2.0 - 'addAdminmembercode.php' Arbitrary Add Admin
|
4 |
WEB
|
x.CJP.x
|
2009-05-26
|
|
phpBugTracker 1.0.3 - Authentication Bypass
|
4 |
WEB
|
ByALBAYX
|
2009-05-26
|
|
ShaadiClone 2.0 - 'addAdminmembercode.php' Arbitrary Add Admin
|
4 |
WEB
|
x.CJP.x
|
2009-05-26
|
|
Flash Image Gallery 1.1 - Arbitrary Configuration File Disclosure
|
4 |
WEB
|
DarkbiteX
|
2009-05-26
|
|
MyForum 1.3 - Authentication Bypass
|
4 |
WEB
|
ThE g0bL!N
|
2009-05-26
|
|
Kensei Board 2.0.0b - Multiple SQL Injections
|
4 |
WEB
|
cOndemned
|
2009-05-26
|
|
Joomla! Component com_rsgallery2 1.14.x/2.x - Remote Backdoor Access
|
4 |
WEB
|
Jan Van Niekerk
|
2009-05-26
|
|
roomphplanning 1.6 - Multiple Vulnerabilities
|
4 |
WEB
|
ThE g0bL!N
|
2009-05-26
|
|
Gallarific - 'user.php' Arbirary Change Admin Information
|
4 |
WEB
|
TiGeR-Dz
|
2009-05-26
|
|
Ultimate Media Script 2.0 - Remote Change Content
|
2 |
WEB
|
ThE g0bL!N
|
2009-05-26
|
|
eZoneScripts Hotornot2 Script - (Authentication Bypass) Multiple Remote Vulnerabilities
|
3 |
WEB
|
sniper code
|
2009-05-26
|
|
Webradev Download Protect 1.0 - Remote File Inclusion
|
3 |
WEB
|
asL-Sabia
|
2009-05-26
|
|
WordPress Plugin Lytebox - 'wp-lytebox' Local File Inclusion
|
4 |
WEB
|
TurkGuvenligi
|
2009-05-26
|
|
CPCommerce 1.2.x - 'GLOBALS[prefix]' Arbitrary File Inclusion
|
5 |
WEB
|
StAkeR
|
2009-05-26
|
|
Mole Adult Portal Script - 'profile.php?user_id' SQL Injection
|
4 |
WEB
|
Qabandi
|
2009-05-26
|
|
MyFirstCMS 1.0.2 - Arbitrary File Delete
|
4 |
WEB
|
darkjoker
|
2009-05-26
|
|
Cute Editor ASP.NET - Remote File Disclosure
|
4 |
WEB
|
Securitylab.ir
|
2009-05-26
|
|
vBulletin vbBux/vbPlaza 2.x - 'vbplaza.php' Blind SQL Injection
|
3 |
WEB
|
Cold Zero
|
2009-05-26
|
|
Dokuwiki 2009-02-14 - Local File Inclusion
|
4 |
WEB
|
girex
|
2009-05-26
|
|
Joomla! Component Boy Scout Advancement 0.3 - 'id' SQL Injection
|
4 |
WEB
|
YEnH4ckEr
|
2009-05-26
|
|
minitwitter 0.3-beta - SQL Injection / Cross-Site Scripting
|
4 |
WEB
|
YEnH4ckEr
|
2009-05-22
|
|
photovideotube 1.11 - Multiple Vulnerabilities
|
4 |
WEB
|
Hakxer
|
2009-05-22
|
|
Mole Group Restaurant Directory Script 3.0 - Change Admin Password
|
4 |
WEB
|
G4N0K
|
2009-05-22
|
|
Mole Group Sky Hunter/Bus Ticket Scripts - Change Admin Password
|
4 |
WEB
|
G4N0K
|
2009-05-22
|
|
ZaoCMS (PhpCommander) - Arbitrary File Upload
|
4 |
WEB
|
Qabandi
|
2009-05-22
|
|
ZaoCMS - 'user_updated.php' Remote Change Password
|
4 |
WEB
|
ThE g0bL!N
|
2009-05-22
|
|
ZaoCMS - 'user_id' SQL Injection
|
3 |
WEB
|
Qabandi
|
2009-05-22
|
|
Tutorial Share 3.5.0 - Insecure Cookie Handling
|
5 |
WEB
|
Evil-Cod3r
|