2009-01-06
|
|
ezpack 4.2b2 - Cross-Site Scripting / SQL Injection
|
4 |
WEB
|
!-BUGJACK-!
|
2009-01-06
|
|
RiotPix 0.61 - 'forumid' Blind SQL Injection
|
4 |
WEB
|
cOndemned
|
2009-01-06
|
|
PHPAuctionSystem - Multiple Remote File Inclusions
|
4 |
WEB
|
darkmasking
|
2009-01-05
|
|
PHPAuctionSystem - Insecure Cookie Handling
|
4 |
WEB
|
ZoRLu
|
2009-01-05
|
|
PHPAuctionSystem - Cross-Site Scripting / SQL Injection
|
4 |
WEB
|
x0r
|
2009-01-05
|
|
Joomla! Component com_phocadocumentation - 'id' SQL Injection
|
4 |
WEB
|
EcHoLL
|
2009-01-05
|
|
Joomla! Component com_na_newsdescription - 'newsid' SQL Injection
|
4 |
WEB
|
EcHoLL
|
2009-01-05
|
|
Cybershade CMS 0.2b - 'index.php' Remote File Inclusion
|
4 |
WEB
|
JosS
|
2009-01-05
|
|
Joomla! Component simple_review 1.x - SQL Injection
|
4 |
WEB
|
EcHoLL
|
2009-01-05
|
|
Ayemsis Emlak Pro - Authentication Bypass
|
4 |
WEB
|
ByALBAYX
|
2009-01-05
|
|
Ayemsis Emlak Pro - 'acc.mdb' Database Disclosure
|
4 |
WEB
|
ByALBAYX
|
2009-01-04
|
|
The Rat CMS Alpha 2 - Blind SQL Injection
|
4 |
WEB
|
darkjoker
|
2009-01-04
|
|
plxAutoReminder 3.7 - 'id' SQL Injection
|
4 |
WEB
|
ZoRLu
|
2009-01-04
|
|
PHPMesFilms 1.0 - 'index.php?id' SQL Injection
|
4 |
WEB
|
SuB-ZeRo
|
2009-01-04
|
|
WSN Guest 1.23 - 'Search' SQL Injection
|
4 |
WEB
|
DaiMon
|
2009-01-04
|
|
PNPHPBB2 < 1.2i - 'ModName' Multiple Local File Inclusions
|
2 |
WEB
|
StAkeR
|
2009-01-04
|
|
webSPELL 4.01.02 - 'id' Remote Edit Topics
|
4 |
WEB
|
StAkeR
|
2009-01-03
|
|
webSPELL 4 - Authentication Bypass
|
4 |
WEB
|
anonymous
|
2009-01-03
|
|
Lito Lite CMS - Multiple Cross-Site Scripting / Blind SQL Injection Vulnerabilities
|
4 |
WEB
|
darkjoker
|
2009-01-02
|
|
phpskelsite 1.4 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
|
4 |
WEB
|
ahmadbady
|
2009-01-02
|
|
Built2Go PHP Rate My Photo 1.46.4 - Arbitrary File Upload
|
5 |
WEB
|
ZoRLu
|
2009-01-02
|
|
Built2Go PHP Link Portal 1.95.1 - Arbitrary File Upload
|
4 |
WEB
|
ZoRLu
|
2009-01-01
|
|
PowerClan 1.14a - Authentication Bypass
|
4 |
WEB
|
Virangar Security
|
2009-01-01
|
|
PowerNews 2.5.4 - 'newsid' SQL Injection
|
4 |
WEB
|
Virangar Security
|
2009-01-01
|
|
w3blabor CMS 3.3.0 - Authentication Bypass
|
4 |
WEB
|
DNX
|
2009-01-01
|
|
phpScribe 0.9 - 'user.cfg' Remote Configuration Disclosure
|
4 |
WEB
|
ahmadbady
|
2009-01-01
|
|
Memberkit 1.0 - Arbitrary File Upload
|
4 |
WEB
|
Lo$er
|
2009-01-01
|
|
PHPFootball 1.6 - Remote Hash Disclosure
|
4 |
WEB
|
KinG-LioN
|
2009-01-01
|
|
ASPThai.Net WebBoard 6.0 - SQL Injection
|
3 |
WEB
|
DaiMon
|
2009-01-01
|
|
EggBlog 3.1.10 - Cross-Site Request Forgery (Change Admin Password)
|
4 |
WEB
|
x0r
|
2009-01-01
|
|
2Capsule - SQL Injection
|
3 |
WEB
|
Zenith
|
2009-01-01
|
|
DDL-Speed Script - 'acp/backup' Admin Backup Bypass
|
4 |
WEB
|
tmh
|
2009-01-01
|
|
Viart shopping cart 3.5 - Multiple Vulnerabilities
|
5 |
WEB
|
Xia Shing Zee
|
2008-12-30
|
|
Pixel8 Web Photo Album 3.0 - SQL Injection
|
4 |
WEB
|
AlpHaNiX
|
2008-12-30
|
|
Mole Group Vacation Estate Listing Script - Blind SQL Injection
|
4 |
WEB
|
x0r
|
2008-12-30
|
|
CMScout 2.06 - SQL Injection / Local File Inclusion
|
4 |
WEB
|
SirGod
|
2008-12-30
|
|
Flexphpic 0.0.x - Authentication Bypass
|
4 |
WEB
|
S.W.A.T.
|
2008-12-29
|
|
Flexcustomer 0.0.6 - Admin Authentication Bypass / Possible PHP Code Writing
|
5 |
WEB
|
Osirys
|
2008-12-29
|
|
PHPAlumni - SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2008-12-29
|
|
ThePortal 2.2 - Arbitrary File Upload
|
4 |
WEB
|
siurek22
|
2008-12-29
|
|
eDNews 2.0 - SQL Injection
|
3 |
WEB
|
Virangar Security
|
2008-12-29
|
|
Flexphplink 0.0.x - Authentication Bypass
|
4 |
WEB
|
x0r
|
2008-12-29
|
|
Flexphpsite 0.0.1 - Authentication Bypass
|
4 |
WEB
|
x0r
|
2008-12-29
|
|
FlexPHPDirectory 0.0.1 - Authentication Bypass
|
4 |
WEB
|
x0r
|
2008-12-29
|
|
Sepcity Classified - 'ID' SQL Injection
|
4 |
WEB
|
S.W.A.T.
|
2008-12-29
|
|
Joomla! Component com_na_content 1.0 - Blind SQL Injection
|
4 |
WEB
|
Mehmet Ince
|
2008-12-29
|
|
CMS NetCat 3.0/3.12 - Blind SQL Injection
|
4 |
WEB
|
s4avrd0w
|
2008-12-29
|
|
Sepcity Lawyer Portal - SQL Injection
|
4 |
WEB
|
Osmanizim
|
2008-12-29
|
|
Sepcity Shopping Mall - SQL Injection
|
4 |
WEB
|
Osmanizim
|
2008-12-29
|
|
Ultimate PHP Board 2.2.1 - Privilege Escalation
|
4 |
WEB
|
StAkeR
|
2008-12-29
|
|
FubarForum 1.6 - Authentication Bypass Change User Password
|
5 |
WEB
|
R31P0l
|
2008-12-29
|
|
TaskDriver 1.3 - Remote Change Admin Password
|
4 |
WEB
|
cOndemned
|
2008-12-29
|
|
eDContainer 2.22 - Local File Inclusion
|
4 |
WEB
|
GoLd_M
|
2008-12-29
|
|
eDNews 2.0 - Local File Inclusion
|
4 |
WEB
|
GoLd_M
|
2008-12-29
|
|
webClassifieds 2005 - Authentication Bypass
|
4 |
WEB
|
AnGeL25dZ
|
2008-12-28
|
|
Silentum LoginSys 1.0.0 - Insecure Cookie Handling
|
4 |
WEB
|
Osirys
|
2008-12-28
|
|
Flexphplink Pro - Arbitrary File Upload
|
4 |
WEB
|
Osirys
|
2008-12-28
|
|
ForumApp 3.3 - Remote Database Disclosure
|
4 |
WEB
|
Cyber.Zer0
|
2008-12-28
|
|
PHP-Fusion Mod TI - 'id' SQL Injection
|
4 |
WEB
|
Khashayar Fereidani
|
2008-12-28
|
|
OwenPoll 1.0 - Insecure Cookie Handling
|
4 |
WEB
|
Osirys
|
2008-12-28
|
|
Alstrasoft Web Email Script Enterprise - 'id' SQL Injection
|
4 |
WEB
|
Bgh7
|
2008-12-28
|
|
FubarForum 1.6 - Arbitrary Authentication Bypass
|
5 |
WEB
|
k3yv4n
|
2008-12-28
|
|
DeluxeBB 1.2 - Blind SQL Injection
|
4 |
WEB
|
StAkeR
|
2008-12-28
|
|
Joomla! Component PAX Gallery 0.1 - Blind SQL Injection
|
4 |
WEB
|
XaDoS
|
2008-12-28
|
|
Miniweb 2.0 - Authentication Bypass
|
3 |
WEB
|
bizzit
|
2008-12-24
|
|
BloofoxCMS 0.3.4 - 'lang' Local File Inclusion
|
4 |
WEB
|
fuzion
|
2008-12-24
|
|
ClaSS 0.8.60 - 'export.php' Local File Inclusion
|
5 |
WEB
|
fuzion
|
2008-12-24
|
|
PHP-Fusion 7.0.2 - Blind SQL Injection
|
5 |
WEB
|
StAkeR
|
2008-12-24
|
|
Joomla! Component 5starhotels - SQL Injection
|
4 |
WEB
|
EcHoLL
|
2008-12-24
|
|
Joomla! Component mDigg 2.2.8 - 'category' SQL Injection
|
4 |
WEB
|
boom3rang
|
2008-12-24
|
|
Joomla! Component Live Ticker 1.0 - Blind SQL Injection
|
4 |
WEB
|
boom3rang
|
2008-12-24
|
|
Joomla! Component Ice Gallery 0.5b2 - 'catid' Blind SQL Injection
|
4 |
WEB
|
boom3rang
|
2008-12-24
|
|
ILIAS 3.7.4 - 'ref_id' Blind SQL Injection
|
4 |
WEB
|
Lidloses_Auge
|
2008-12-24
|
|
doop CMS 1.4.0b - Cross-Site Request Forgery / Arbitrary File Upload
|
4 |
WEB
|
x0r
|
2008-12-23
|
|
Joomla! Component com_allhotels - Blind SQL Injection
|
4 |
WEB
|
Hussin X
|
2008-12-23
|
|
Joomla! Component com_lowcosthotels - Blind SQL Injection
|
5 |
WEB
|
Hussin X
|
2008-12-23
|
|
StormBoard 1.0.1 - SQL Injection
|
5 |
WEB
|
Samir-M
|
2008-12-23
|
|
phpEmployment - 'PHP Upload' Arbitrary File Upload
|
4 |
WEB
|
ahmadbady
|
2008-12-23
|
|
PHPAdBoard - PHP uploads Arbitrary File Upload
|
4 |
WEB
|
ahmadbady
|
2008-12-23
|
|
phpGreetCards - Cross-Site Scripting / Arbitrary File Upload
|
4 |
WEB
|
ahmadbady
|
2008-12-23
|
|
CMS NetCat 3.12 - Multiple Vulnerabilities
|
4 |
WEB
|
s4avrd0w
|
2008-12-23
|
|
CMS NetCat 3.12 - 'password_recovery.php' Blind SQL Injection
|
4 |
WEB
|
s4avrd0w
|
2008-12-23
|
|
PHPLD 3.3 - Blind SQL Injection
|
4 |
WEB
|
fuzion
|
2008-12-23
|
|
PHPmotion 2.1 - Cross-Site Request Forgery
|
4 |
WEB
|
Ausome1
|
2008-12-22
|
|
Roundcube Webmail 0.2b - Remote Code Execution
|
4 |
WEB
|
Hunger
|
2008-12-22
|
|
REDPEACH CMS - SQL Injection
|
4 |
WEB
|
Lidloses_Auge
|
2008-12-22
|
|
Calendar Script 1.1 - Authentication Bypass
|
4 |
WEB
|
StAkeR
|
2008-12-22
|
|
Roundcube Webmail 0.2-3 Beta - Code Execution
|
5 |
WEB
|
Jacobo Avariento
|
2008-12-22
|
|
SolarCMS 0.53.8 - 'Forum' Remote Cookies Disclosure
|
4 |
WEB
|
StAkeR
|
2008-12-22
|
|
Joomla! Component Volunteer 2.0 - SQL Injection
|
4 |
WEB
|
boom3rang
|
2008-12-22
|
|
yourplace 1.0.2 - Multiple Vulnerabilities / Remote Code Execution
|
4 |
WEB
|
Osirys
|
2008-12-22
|
|
Pligg 9.9.5b - Arbitrary File Upload / SQL Injection
|
4 |
WEB
|
Ams
|
2008-12-22
|
|
WordPress Plugin Page Flip Image Gallery 0.2.2 - Remote File Disclosure
|
3 |
WEB
|
GoLd_M
|
2008-12-22
|
|
Text Lines Rearrange Script - 'Filename' File Disclosure
|
4 |
WEB
|
SirGod
|
2008-12-22
|
|
RSS Simple News - SQL Injection
|
4 |
WEB
|
Piker
|
2008-12-21
|
|
phpg 1.6 - Cross-Site Scripting / Full Path Disclosure / Denial of Service
|
4 |
WEB
|
Anarchy Angel
|
2008-12-21
|
|
Joomla! Component com_tophotelmodule 1.0 - Blind SQL Injection
|
4 |
WEB
|
boom3rang
|
2008-12-21
|
|
Joomla! Component com_hbssearch 1.0 - Blind SQL Injection
|
4 |
WEB
|
boom3rang
|
2008-12-21
|
|
BLOG 1.55B - 'image_upload.php' Arbitrary File Upload
|
3 |
WEB
|
Piker
|
2008-12-21
|
|
Emefa Guestbook 3.0 - Remote Database Disclosure
|
4 |
WEB
|
Cyber.Zer0
|
2008-12-21
|
|
Chicomas 2.0.4 - Database Backup / File Disclosure / Cross-Site Scripting
|
4 |
WEB
|
BugReport.IR
|
2008-12-21
|
|
ReVou Twitter Clone - Arbitrary File Upload
|
4 |
WEB
|
S.W.A.T.
|
2008-12-21
|
|
Userlocator 3.0 - Blind SQL Injection
|
4 |
WEB
|
katharsis
|
2008-12-19
|
|
Constructr CMS 3.02.5 stable - Multiple Vulnerabilities
|
4 |
WEB
|
fuzion
|
2008-12-19
|
|
OneOrZero helpdesk 1.6.x. - Arbitrary File Upload
|
4 |
WEB
|
Ams
|
2008-12-19
|
|
FreeLyrics 1.0 - Remote File Disclosure
|
3 |
WEB
|
Piker
|
2008-12-19
|
|
myPHPscripts Login Session 2.0 - Cross-Site Scripting / Database Disclosure
|
5 |
WEB
|
Osirys
|
2008-12-19
|
|
Extract Website - 'Filename' File Disclosure
|
4 |
WEB
|
Cold Zero
|
2008-12-19
|
|
Online Keyword Research Tool - 'download.php' File Disclosure
|
4 |
WEB
|
Cold Zero
|
2008-12-19
|
|
ReVou Twitter Clone - Admin Password Change
|
4 |
WEB
|
G4N0K
|
2008-12-19
|
|
MyPBS - 'seasonID' SQL Injection
|
5 |
WEB
|
Piker
|
2008-12-18
|
|
MyPHPsite - Local File Inclusion
|
4 |
WEB
|
Piker
|
2008-12-18
|
|
Gobbl CMS 1.0 - Insecure Cookie Handling
|
5 |
WEB
|
x0r
|
2008-12-18
|
|
Injader CMS 2.1.1 - 'id' SQL Injection
|
3 |
WEB
|
fuzion
|
2008-12-18
|
|
phpclanwebsite 1.23.3 fix pack #5 - Multiple Vulnerabilities
|
4 |
WEB
|
s4avrd0w
|
2008-12-18
|
|
I-Rater Basic - SQL Injection
|
4 |
WEB
|
boom3rang
|
2008-12-18
|
|
Calendar Script 1.1 - Insecure Cookie Handling
|
4 |
WEB
|
Osirys
|
2008-12-18
|
|
2532/Gigs 1.2.2 Stable - Remote Command Execution
|
4 |
WEB
|
StAkeR
|
2008-12-18
|
|
2532/Gigs 1.2.2 Stable - Remote Authentication Bypass
|
3 |
WEB
|
StAkeR
|
2008-12-18
|
|
2532/Gigs 1.2.2 Stable - Multiple Vulnerabilities
|
4 |
WEB
|
Osirys
|
2008-12-18
|
|
Mini File Host 1.x - Arbitrary '.PHP' File Upload
|
4 |
WEB
|
Pouya_Server
|
2008-12-17
|
|
QuickerSite Easy CMS - Database Disclosure
|
4 |
WEB
|
AlpHaNiX
|
2008-12-17
|
|
Lizardware CMS 0.6.0 - Blind SQL Injection
|
5 |
WEB
|
StAkeR
|
2008-12-17
|
|
TinyMCE 2.0.1 - 'menuID' SQL Injection
|
5 |
WEB
|
AnGeL25dZ
|
2008-12-17
|
|
Joomla! Component Tech Article 1.x - SQL Injection
|
5 |
WEB
|
InjEctOr5
|