|
2009-06-24
|
|
Joomla! Component com_amocourse - 'catid' SQL Injection
|
21 |
WEB
|
Chip d3 bi0s
|
|
2009-06-24
|
|
LightOpenCMS 0.1 - 'smarty.php?cwd' Local File Inclusion
|
17 |
WEB
|
JosS
|
|
2009-06-24
|
|
PHPEcho CMS 2.0-rc3 - 'forum' Cross-Site Scripting Cookie Stealing / Blind SQL Injection
|
21 |
WEB
|
JosS
|
|
2009-06-24
|
|
Tribiq CMS 5.0.12c - Cross-Site Scripting / Local File Inclusion
|
16 |
WEB
|
CraCkEr
|
|
2009-06-24
|
|
Joomla! Component com_pinboard - Arbitrary File Upload
|
18 |
WEB
|
ViRuSMaN
|
|
2009-06-24
|
|
Glossword 1.8.11 - 'index.php?x' Local File Inclusion
|
18 |
WEB
|
t0fx
|
|
2009-06-24
|
|
BASE 1.2.4 - (Authentication Bypass) Insecure Cookie Handling
|
19 |
WEB
|
Tim Medin
|
|
2009-06-23
|
|
phpCollegeExchange 0.1.5c - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
|
17 |
WEB
|
CraCkEr
|
|
2009-06-23
|
|
Zen Cart 1.3.8 - SQL Execution
|
17 |
WEB
|
BlackH
|
|
2009-06-23
|
|
Zen Cart 1.3.8 - Remote Code Execution
|
16 |
WEB
|
BlackH
|
|
2009-06-22
|
|
MyBB 1.4.6 - Remote Code Execution
|
18 |
WEB
|
The:Paradox
|
|
2009-06-22
|
|
RS-CMS 2.1 - 'key' SQL Injection
|
16 |
WEB
|
Mr.tro0oqy
|
|
2009-06-22
|
|
Joomla! Component com_tickets 2.1 - 'id' SQL Injection
|
15 |
WEB
|
Chip d3 bi0s
|
|
2009-06-22
|
|
SourceBans 1.4.2 - Arbitrary Change Admin Email
|
15 |
WEB
|
Mr. Anonymous
|
|
2009-06-22
|
|
Kasseler CMS - File Disclosure / Cross-Site Scripting
|
18 |
WEB
|
S(r1pt
|
|
2009-06-22
|
|
Gravy Media Photo Host 1.0.8 - Local File Disclosure
|
18 |
WEB
|
Lo$er
|
|
2009-06-22
|
|
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
|
23 |
WEB
|
CraCkEr
|
|
2009-06-22
|
|
AWScripts Gallery Search Engine 1.x - Insecure Cookie
|
20 |
WEB
|
TiGeR-Dz
|
|
2009-06-22
|
|
elgg - Cross-Site Scripting / Cross-Site Request Forgery / Change Password
|
19 |
WEB
|
lorddemon
|
|
2009-06-22
|
|
phpMyAdmin - 'pmaPWN!' Code Injection / Remote Code Execution
|
20 |
WEB
|
Hacking Expose!
|
|
2009-06-22
|
|
phpDatingClub 3.7 - SQL Injection / Cross-Site Scripting Injection
|
20 |
WEB
|
ThE g0bL!N
|
|
2009-06-22
|
|
pc4 Uploader 10.0 - Remote File Disclosure
|
17 |
WEB
|
Qabandi
|
|
2009-06-22
|
|
MIDAS 1.43 - (Authentication Bypass) Insecure Cookie Handling
|
20 |
WEB
|
HxH
|
|
2009-06-18
|
|
CMS buzz - Cross-Site Scripting / Password Change / HTML Injection
|
19 |
WEB
|
ThE g0bL!N
|
|
2009-06-17
|
|
PHPortal 1.0 - Insecure Cookie Handling
|
17 |
WEB
|
KnocKout
|
|
2009-06-17
|
|
FretsWeb 1.2 - 'name' Blind SQL Injection
|
17 |
WEB
|
YEnH4ckEr
|
|
2009-06-17
|
|
FretsWeb 1.2 - Multiple Local File Inclusions
|
21 |
WEB
|
YEnH4ckEr
|
|
2009-06-17
|
|
Fuzzylime CMS 3.03a - Local Inclusion / Arbitrary File Corruption
|
18 |
WEB
|
StAkeR
|
|
2009-06-17
|
|
TekBase All-in-One 3.1 - Multiple SQL Injections
|
19 |
WEB
|
n3wb0ss
|
|
2009-06-17
|
|
PHPFK 7.03 - 'page_bottom.php' Local File Inclusion
|
19 |
WEB
|
ahmadbady
|
|
2009-06-16
|
|
XOOPS 2.3.3 - '.htaccess' Remote File Disclosure
|
19 |
WEB
|
daath
|
|
2009-06-15
|
|
Joomla! Component Jumi - 'fileid' Blind SQL Injection
|
15 |
WEB
|
Chip d3 bi0s
|
|
2009-06-15
|
|
The Recipe Script 5 - Cross-Site Scripting
|
19 |
WEB
|
ThE g0bL!N
|
|
2009-06-15
|
|
PHPortal 1 - 'topicler.php?id' SQL Injection
|
16 |
WEB
|
Mehmet Ince
|
|
2009-06-15
|
|
vBulletin Radio and TV Player AddOn - HTML Injection
|
18 |
WEB
|
d3v1l
|
|
2009-06-15
|
|
PHPCollegeExchange 0.1.5c - 'listing_view.php?itemnr' SQL Injection
|
19 |
WEB
|
SirGod
|
|
2009-06-15
|
|
WordPress Plugin Photoracer 1.0 - 'id' SQL Injection
|
18 |
WEB
|
Kacper
|
|
2009-06-15
|
|
Joomla! Component com_iJoomla_rss - Blind SQL Injection
|
19 |
WEB
|
Mehmet Ince
|
|
2009-06-15
|
|
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
|
16 |
WEB
|
waraxe
|
|
2009-06-15
|
|
Evernew Free Joke Script 1.2 - Remote Change Password
|
19 |
WEB
|
Hakxer
|
|
2009-06-15
|
|
adaptweb 0.9.2 - Local File Inclusion / SQL Injection
|
17 |
WEB
|
SirGod
|
|
2009-06-15
|
|
elvin bts 1.2.0 - Multiple Vulnerabilities
|
18 |
WEB
|
SirGod
|
|
2009-06-15
|
|
DB Top Sites 1.0 - 'index.php?u' Local File Inclusion
|
17 |
WEB
|
SirGod
|
|
2009-06-15
|
|
DB Top Sites 1.0 - Remote Command Execution
|
20 |
WEB
|
SirGod
|
|
2009-06-15
|
|
formmail 1.92 - Multiple Vulnerabilities
|
22 |
WEB
|
USH
|
|
2009-06-15
|
|
SugarCRM 5.2.0e - Remote Code Execution
|
20 |
WEB
|
USH
|
|
2009-06-15
|
|
Mundi Mail 0.8.2 - 'top' Remote File Inclusion
|
20 |
WEB
|
Br0ly
|
|
2009-06-15
|
|
impleo music Collection 2.0 - SQL Injection / Cross-Site Scripting
|
18 |
WEB
|
SirGod
|
|
2009-06-15
|
|
Joomla! Component com_Projectfork 2.0.10 - Local File Inclusion
|
19 |
WEB
|
ByALBAYX
|
|
2009-06-12
|
|
Uebimiau Web-Mail 3.2.0-1.8 - Remote File / Overwrite
|
16 |
WEB
|
GoLd_M
|
|
2009-06-12
|
|
TransLucid 1.75 - Multiple Vulnerabilities
|
20 |
WEB
|
intern0t
|
|
2009-06-12
|
|
tbdev 01-01-2008 - Multiple Vulnerabilities
|
20 |
WEB
|
intern0t
|
|
2009-06-12
|
|
pivot 1.40.4-7 - Multiple Vulnerabilities
|
20 |
WEB
|
intern0t
|
|
2009-06-12
|
|
phpWebThings 1.5.2 - MD5 Hash Retrieve/File Disclosure
|
20 |
WEB
|
StAkeR
|
|
2009-06-12
|
|
campus virtual-lms - Cross-Site Scripting / SQL Injection
|
18 |
WEB
|
Yasión
|
|
2009-06-12
|
|
4Images 1.7.7 - Filter Bypass HTML Injection / Cross-Site Scripting
|
16 |
WEB
|
Qabandi
|
|
2009-06-12
|
|
Zip Store Chat 4.0/5.0 - Authentication Bypass
|
20 |
WEB
|
ByALBAYX
|
|
2009-06-11
|
|
Sniggabo CMS - 'article.php?id' SQL Injection
|
17 |
WEB
|
Lidloses_Auge
|
|
2009-06-11
|
|
yogurt 0.3 - Cross-Site Scripting / SQL Injection
|
18 |
WEB
|
Br0ly
|
|
2009-06-11
|
|
TorrentVolve 1.4 - 'deleteTorrent' Delete Arbitrary File
|
19 |
WEB
|
Br0ly
|
|
2009-06-11
|
|
Splog 1.2 Beta - Multiple SQL Injections
|
17 |
WEB
|
YEnH4ckEr
|
|
2009-06-11
|
|
PHPWebThings 1.5.2 - 'help.php?module' Local File Inclusion
|
20 |
WEB
|
Br0ly
|
|
2009-06-10
|
|
Open Biller 0.1 - 'Username' Blind SQL Injection
|
18 |
WEB
|
YEnH4ckEr
|
|
2009-06-10
|
|
mrcgiguy freeticket - Cookie Handling / SQL Injection
|
19 |
WEB
|
ThE g0bL!N
|
|
2009-06-10
|
|
Desi Short URL Script - (Authentication Bypass) Insecure Cookie Handling
|
20 |
WEB
|
N@bilX
|
|
2009-06-10
|
|
School Data Navigator - 'page' Local/Remote File Inclusion
|
19 |
WEB
|
Br0ly
|
|
2009-06-10
|
|
LightNEasy sql/no-db 2.2.x - System Configuration Disclosure
|
19 |
WEB
|
StAkeR
|
|
2009-06-09
|
|
phpMyAdmin - '/scripts/setup.php' PHP Code Injection
|
15 |
WEB
|
Adrian _pagvac_ Pastor
|
|
2009-06-09
|
|
Joomla! Component com_vehiclemanager 1.0 - Remote File Inclusion
|
18 |
WEB
|
Mehmet Ince
|
|
2009-06-09
|
|
Joomla! Component com_realestatemanager 1.0 - Remote File Inclusion
|
16 |
WEB
|
Mehmet Ince
|
|
2009-06-09
|
|
MRCGIGUY Hot Links - 'report.php?id' SQL Injection
|
22 |
WEB
|
ThE g0bL!N
|
|
2009-06-09
|
|
mrcgiguy the ticket system 2.0 PHP - Multiple Vulnerabilities
|
16 |
WEB
|
ThE g0bL!N
|
|
2009-06-09
|
|
S-CMS 2.0b3 - 'Username' Blind SQL Injection
|
19 |
WEB
|
YEnH4ckEr
|
|
2009-06-09
|
|
S-CMS 2.0b3 - Multiple SQL Injections
|
17 |
WEB
|
YEnH4ckEr
|
|
2009-06-09
|
|
S-CMS 2.0b3 - Multiple Local File Inclusions
|
17 |
WEB
|
YEnH4ckEr
|
|
2009-06-09
|
|
Joomla! Component com_media_library 1.5.3 - Remote File Inclusion
|
18 |
WEB
|
Mehmet Ince
|
|
2009-06-09
|
|
Joomla! Component Akobook 2.3 - 'gbid' SQL Injection
|
17 |
WEB
|
Ab1i
|
|
2009-06-09
|
|
Joomla! Component BookLibrary 1.5.2.4 - Remote File Inclusion
|
16 |
WEB
|
Mehmet Ince
|
|
2009-06-08
|
|
Shop Script Pro 2.12 - SQL Injection
|
18 |
WEB
|
Ams
|
|
2009-06-08
|
|
Joomla! Component com_portafolio - 'cid' SQL Injection
|
19 |
WEB
|
Chip d3 bi0s
|
|
2009-06-08
|
|
Automated link exchange portal 1.3 - Multiple Vulnerabilities
|
17 |
WEB
|
TiGeR-Dz
|
|
2009-06-08
|
|
DM FileManager 3.9.2 - Insecure Cookie Handling
|
16 |
WEB
|
ThE g0bL!N
|
|
2009-06-08
|
|
Grestul 1.2 - Remote Add Administrator Account
|
17 |
WEB
|
ThE g0bL!N
|
|
2009-06-08
|
|
virtue news - SQL Injection / Cross-Site Scripting
|
21 |
WEB
|
snakespc
|
|
2009-06-08
|
|
Frontis 3.9.01.24 - 'source_class' SQL Injection
|
18 |
WEB
|
snakespc
|
|
2009-06-08
|
|
Joomla! Component MooFAQ (com_moofaq) - Local File Inclusion
|
20 |
WEB
|
Chip d3 bi0s
|
|
2009-06-08
|
|
Interlogy Profile Manager Basic - Insecure Cookie Handling
|
15 |
WEB
|
ZoRLu
|
|
2009-06-08
|
|
Virtue Shopping Mall - 'cid' SQL Injection
|
18 |
WEB
|
OzX
|
|
2009-06-08
|
|
Virtue Book Store - 'cid' SQL Injection
|
17 |
WEB
|
OzX
|
|
2009-06-08
|
|
Virtue Classifieds - 'category' SQL Injection
|
16 |
WEB
|
OzX
|
|
2009-06-08
|
|
Joomla! Component com_school 1.4 - 'classid' SQL Injection
|
17 |
WEB
|
Chip d3 bi0s
|
|
2009-06-08
|
|
FipsCMS Light 2.1 - 'db.mdb' Remote Database Disclosure
|
18 |
WEB
|
ByALBAYX
|
|
2009-06-08
|
|
VT-Auth 1.0 - 'zHk8dEes3.txt' File Disclosure
|
16 |
WEB
|
ByALBAYX
|
|
2009-06-08
|
|
MyCars Automotive - Authentication Bypass
|
20 |
WEB
|
snakespc
|
|
2009-06-05
|
|
Kjtechforce mailman b1 - 'dest' Blind SQL Injection
|
16 |
WEB
|
YEnH4ckEr
|
|
2009-06-05
|
|
Kjtechforce mailman b1 - Delete Row 'code' SQL Injection
|
17 |
WEB
|
YEnH4ckEr
|
|
2009-06-05
|
|
Pixelactivo 3.0 - Authentication Bypass
|
18 |
WEB
|
ThE g0bL!N
|
|
2009-06-05
|
|
Pixelactivo 3.0 - 'idx' SQL Injection
|
19 |
WEB
|
snakespc
|
|
2009-06-04
|
|
Host Directory PRO 2.1.0 - Remote Change Admin Password
|
20 |
WEB
|
TiGeR-Dz
|
|
2009-06-04
|
|
Web Directory PRO - Remote Database Backup
|
18 |
WEB
|
TiGeR-Dz
|
|
2009-06-04
|
|
Host Directory PRO 2.1.0 - Remote Database Backup
|
20 |
WEB
|
ZoRLu
|
|
2009-06-04
|
|
Web Directory PRO - 'Admins.php' Change Admin Password
|
17 |
WEB
|
TiGeR-Dz
|
|
2009-06-04
|
|
SuperCali PHP Event Calendar - Arbitrary Change Admin Password
|
20 |
WEB
|
TiGeR-Dz
|
|
2009-06-03
|
|
Joomla! Component com_mosres - Multiple SQL Injections
|
18 |
WEB
|
Chip d3 bi0s
|
|
2009-06-03
|
|
Movie PHP Script 2.0 - 'init.php?anticode' Code Execution
|
19 |
WEB
|
SirGod
|
|
2009-06-03
|
|
Joomla! Component Omilen Photo Gallery 0.5b - Local File Inclusion
|
19 |
WEB
|
ByALBAYX
|
|
2009-06-03
|
|
Supernews 2.6 - 'index.php?noticia' SQL Injection
|
21 |
WEB
|
DD3str0y3r
|
|
2009-06-03
|
|
OCS Inventory NG 1.02 - Remote File Disclosure
|
18 |
WEB
|
Nico Leidecker
|
|
2009-06-03
|
|
Joomla! Component Seminar 1.28 - 'id' Blind SQL Injection
|
18 |
WEB
|
ThE g0bL!N
|
|
2009-06-03
|
|
Podcast Generator 1.2 - Unauthorized Re-Installation
|
18 |
WEB
|
StAkeR
|
|
2009-06-03
|
|
EgyPlus 7ml 1.0.1 - Authentication Bypass
|
18 |
WEB
|
Qabandi
|
|
2009-06-03
|
|
My Mini Bill - 'orderid' SQL Injection
|
20 |
WEB
|
ThE g0bL!N
|
|
2009-06-02
|
|
Podcast Generator 1.2 - 'GLOBALS[]' Multiple Vulnerabilities
|
18 |
WEB
|
StAkeR
|
|
2009-06-02
|
|
WebEyes Guest Book 3 - 'yorum.asp?mesajid' SQL Injection
|
18 |
WEB
|
Bl@ckbe@rD
|
|
2009-06-02
|
|
propertymax pro free - SQL Injection / Cross-Site Scripting
|
19 |
WEB
|
SirGod
|
|
2009-06-02
|
|
WebCal - 'webCal3_detail.asp?event_id' SQL Injection
|
16 |
WEB
|
Bl@ckbe@rD
|
|
2009-06-02
|
|
flashlight free edition - Local File Inclusion / SQL Injection
|
20 |
WEB
|
K4m1k451
|
|
2009-06-02
|
|
Alstrasoft Article Manager Pro - Arbitrary File Upload
|
17 |
WEB
|
ZoRLu
|
|
2009-06-02
|
|
Online Grades & Attendance 3.2.6 - Blind SQL Injection
|
18 |
WEB
|
YEnH4ckEr
|
|
2009-06-02
|
|
Online Grades & Attendance 3.2.6 - Multiple Local File Inclusions
|
18 |
WEB
|
YEnH4ckEr
|
|
2009-06-01
|
|
ASP Football Pool 2.3 - Remote Database Disclosure
|
20 |
WEB
|
ByALBAYX
|
|
2009-06-01
|
|
AdaptBB 1.0 - 'forumspath' Remote File Inclusion
|
17 |
WEB
|
Mehmet Ince
|
|
2009-06-01
|
|
PAD Site Scripts 3.6 - Arbitrary Database Backup
|
16 |
WEB
|
TiGeR-Dz
|
|
2009-06-01
|
|
R2 NewsLetter Lite/Pro/Stats - 'admin.mdb' Database Disclosure
|
17 |
WEB
|
TiGeR-Dz
|
|
2009-06-01
|
|
ecsportal rel 6.5 - 'article_view_photo.php?id' SQL Injection
|
18 |
WEB
|
taRentReXx
|