|
2008-12-24
|
|
Joomla! Component mDigg 2.2.8 - 'category' SQL Injection
|
19 |
WEB
|
boom3rang
|
|
2008-12-24
|
|
Joomla! Component Live Ticker 1.0 - Blind SQL Injection
|
18 |
WEB
|
boom3rang
|
|
2008-12-24
|
|
Joomla! Component Ice Gallery 0.5b2 - 'catid' Blind SQL Injection
|
22 |
WEB
|
boom3rang
|
|
2008-12-24
|
|
ILIAS 3.7.4 - 'ref_id' Blind SQL Injection
|
19 |
WEB
|
Lidloses_Auge
|
|
2008-12-24
|
|
doop CMS 1.4.0b - Cross-Site Request Forgery / Arbitrary File Upload
|
20 |
WEB
|
x0r
|
|
2008-12-23
|
|
Joomla! Component com_allhotels - Blind SQL Injection
|
19 |
WEB
|
Hussin X
|
|
2008-12-23
|
|
Joomla! Component com_lowcosthotels - Blind SQL Injection
|
20 |
WEB
|
Hussin X
|
|
2008-12-23
|
|
StormBoard 1.0.1 - SQL Injection
|
22 |
WEB
|
Samir-M
|
|
2008-12-23
|
|
phpEmployment - 'PHP Upload' Arbitrary File Upload
|
21 |
WEB
|
ahmadbady
|
|
2008-12-23
|
|
PHPAdBoard - PHP uploads Arbitrary File Upload
|
17 |
WEB
|
ahmadbady
|
|
2008-12-23
|
|
phpGreetCards - Cross-Site Scripting / Arbitrary File Upload
|
21 |
WEB
|
ahmadbady
|
|
2008-12-23
|
|
CMS NetCat 3.12 - Multiple Vulnerabilities
|
22 |
WEB
|
s4avrd0w
|
|
2008-12-23
|
|
CMS NetCat 3.12 - 'password_recovery.php' Blind SQL Injection
|
20 |
WEB
|
s4avrd0w
|
|
2008-12-23
|
|
PHPLD 3.3 - Blind SQL Injection
|
20 |
WEB
|
fuzion
|
|
2008-12-23
|
|
PHPmotion 2.1 - Cross-Site Request Forgery
|
17 |
WEB
|
Ausome1
|
|
2008-12-22
|
|
Roundcube Webmail 0.2b - Remote Code Execution
|
18 |
WEB
|
Hunger
|
|
2008-12-22
|
|
REDPEACH CMS - SQL Injection
|
16 |
WEB
|
Lidloses_Auge
|
|
2008-12-22
|
|
Calendar Script 1.1 - Authentication Bypass
|
17 |
WEB
|
StAkeR
|
|
2008-12-22
|
|
Roundcube Webmail 0.2-3 Beta - Code Execution
|
20 |
WEB
|
Jacobo Avariento
|
|
2008-12-22
|
|
SolarCMS 0.53.8 - 'Forum' Remote Cookies Disclosure
|
20 |
WEB
|
StAkeR
|
|
2008-12-22
|
|
Joomla! Component Volunteer 2.0 - SQL Injection
|
17 |
WEB
|
boom3rang
|
|
2008-12-22
|
|
yourplace 1.0.2 - Multiple Vulnerabilities / Remote Code Execution
|
17 |
WEB
|
Osirys
|
|
2008-12-22
|
|
Pligg 9.9.5b - Arbitrary File Upload / SQL Injection
|
19 |
WEB
|
Ams
|
|
2008-12-22
|
|
WordPress Plugin Page Flip Image Gallery 0.2.2 - Remote File Disclosure
|
20 |
WEB
|
GoLd_M
|
|
2008-12-22
|
|
Text Lines Rearrange Script - 'Filename' File Disclosure
|
20 |
WEB
|
SirGod
|
|
2008-12-22
|
|
RSS Simple News - SQL Injection
|
20 |
WEB
|
Piker
|
|
2008-12-21
|
|
phpg 1.6 - Cross-Site Scripting / Full Path Disclosure / Denial of Service
|
19 |
WEB
|
Anarchy Angel
|
|
2008-12-21
|
|
Joomla! Component com_tophotelmodule 1.0 - Blind SQL Injection
|
17 |
WEB
|
boom3rang
|
|
2008-12-21
|
|
Joomla! Component com_hbssearch 1.0 - Blind SQL Injection
|
17 |
WEB
|
boom3rang
|
|
2008-12-21
|
|
BLOG 1.55B - 'image_upload.php' Arbitrary File Upload
|
20 |
WEB
|
Piker
|
|
2008-12-21
|
|
Emefa Guestbook 3.0 - Remote Database Disclosure
|
18 |
WEB
|
Cyber.Zer0
|
|
2008-12-21
|
|
Chicomas 2.0.4 - Database Backup / File Disclosure / Cross-Site Scripting
|
18 |
WEB
|
BugReport.IR
|
|
2008-12-21
|
|
ReVou Twitter Clone - Arbitrary File Upload
|
19 |
WEB
|
S.W.A.T.
|
|
2008-12-21
|
|
Userlocator 3.0 - Blind SQL Injection
|
22 |
WEB
|
katharsis
|
|
2008-12-19
|
|
Constructr CMS 3.02.5 stable - Multiple Vulnerabilities
|
21 |
WEB
|
fuzion
|
|
2008-12-19
|
|
OneOrZero helpdesk 1.6.x. - Arbitrary File Upload
|
17 |
WEB
|
Ams
|
|
2008-12-19
|
|
FreeLyrics 1.0 - Remote File Disclosure
|
16 |
WEB
|
Piker
|
|
2008-12-19
|
|
myPHPscripts Login Session 2.0 - Cross-Site Scripting / Database Disclosure
|
20 |
WEB
|
Osirys
|
|
2008-12-19
|
|
Extract Website - 'Filename' File Disclosure
|
16 |
WEB
|
Cold Zero
|
|
2008-12-19
|
|
Online Keyword Research Tool - 'download.php' File Disclosure
|
20 |
WEB
|
Cold Zero
|
|
2008-12-19
|
|
ReVou Twitter Clone - Admin Password Change
|
19 |
WEB
|
G4N0K
|
|
2008-12-19
|
|
MyPBS - 'seasonID' SQL Injection
|
18 |
WEB
|
Piker
|
|
2008-12-18
|
|
MyPHPsite - Local File Inclusion
|
19 |
WEB
|
Piker
|
|
2008-12-18
|
|
Gobbl CMS 1.0 - Insecure Cookie Handling
|
18 |
WEB
|
x0r
|
|
2008-12-18
|
|
Injader CMS 2.1.1 - 'id' SQL Injection
|
19 |
WEB
|
fuzion
|
|
2008-12-18
|
|
phpclanwebsite 1.23.3 fix pack #5 - Multiple Vulnerabilities
|
19 |
WEB
|
s4avrd0w
|
|
2008-12-18
|
|
I-Rater Basic - SQL Injection
|
18 |
WEB
|
boom3rang
|
|
2008-12-18
|
|
Calendar Script 1.1 - Insecure Cookie Handling
|
18 |
WEB
|
Osirys
|
|
2008-12-18
|
|
2532/Gigs 1.2.2 Stable - Remote Command Execution
|
23 |
WEB
|
StAkeR
|
|
2008-12-18
|
|
2532/Gigs 1.2.2 Stable - Remote Authentication Bypass
|
17 |
WEB
|
StAkeR
|
|
2008-12-18
|
|
2532/Gigs 1.2.2 Stable - Multiple Vulnerabilities
|
20 |
WEB
|
Osirys
|
|
2008-12-18
|
|
Mini File Host 1.x - Arbitrary '.PHP' File Upload
|
19 |
WEB
|
Pouya_Server
|
|
2008-12-17
|
|
QuickerSite Easy CMS - Database Disclosure
|
16 |
WEB
|
AlpHaNiX
|
|
2008-12-17
|
|
Lizardware CMS 0.6.0 - Blind SQL Injection
|
21 |
WEB
|
StAkeR
|
|
2008-12-17
|
|
TinyMCE 2.0.1 - 'menuID' SQL Injection
|
18 |
WEB
|
AnGeL25dZ
|
|
2008-12-17
|
|
Joomla! Component Tech Article 1.x - SQL Injection
|
21 |
WEB
|
InjEctOr5
|
|
2008-12-17
|
|
r.cms 2.0 - Multiple SQL Injections
|
18 |
WEB
|
Lidloses_Auge
|
|
2008-12-17
|
|
K&S Shopsysteme - Arbitrary File Upload
|
18 |
WEB
|
mNt
|
|
2008-12-17
|
|
BP Blog 6.0/7.0/8.0/9.0 - Remote Database Disclosure
|
17 |
WEB
|
Dxil
|
|
2008-12-17
|
|
RSMScript 1.21 - Cross-Site Scripting / Insecure Cookie Handling
|
17 |
WEB
|
Osirys
|
|
2008-12-16
|
|
Gnews Publisher .NET - SQL Injection
|
19 |
WEB
|
AlpHaNiX
|
|
2008-12-16
|
|
Zelta E Store - Arbitrary File Upload / Bypass / SQL Injection / Blind SQL Injection
|
17 |
WEB
|
ZoRLu
|
|
2008-12-16
|
|
Liberum Help Desk 0.97.3 - SQL Injection / File Disclosure
|
19 |
WEB
|
Cold Zero
|
|
2008-12-16
|
|
Nukedit 4.9.8 - Remote Database Disclosure
|
19 |
WEB
|
Cyber.Zer0
|
|
2008-12-16
|
|
Aiyoota! CMS - Blind SQL Injection
|
18 |
WEB
|
Lidloses_Auge
|
|
2008-12-16
|
|
FLDS 1.2a - 'report.php' SQL Injection
|
18 |
WEB
|
ka0x
|
|
2008-12-16
|
|
Web Wiz Guestbook 8.21 - Database Disclosure
|
20 |
WEB
|
Cold Zero
|
|
2008-12-16
|
|
FaScript FaUpload - SQL Injection
|
16 |
WEB
|
Aria-Security Team
|
|
2008-12-15
|
|
Click&Rank - SQL Injection / Cross-Site Scripting
|
16 |
WEB
|
AlpHaNiX
|
|
2008-12-15
|
|
clickandemail - SQL Injection / Cross-Site Scripting
|
17 |
WEB
|
AlpHaNiX
|
|
2008-12-15
|
|
Click&BaneX - Multiple SQL Injections
|
19 |
WEB
|
AlpHaNiX
|
|
2008-12-15
|
|
CFAGCMS 1 - SQL Injection
|
17 |
WEB
|
ZoRLu
|
|
2008-12-15
|
|
Aperto Blog 0.1.1 - Local File Inclusion / SQL Injection
|
16 |
WEB
|
NoGe
|
|
2008-12-15
|
|
WorkSimple 1.2.1 - Remote File Inclusion / Sensitive Data Disclosure
|
23 |
WEB
|
Osirys
|
|
2008-12-15
|
|
CadeNix - SQL Injection
|
19 |
WEB
|
HaCkeR_EgY
|
|
2008-12-15
|
|
XOOPS Module Amevents - SQL Injection
|
18 |
WEB
|
nétRoot
|
|
2008-12-15
|
|
The Rat CMS Alpha 2 - Authentication Bypass
|
21 |
WEB
|
x0r
|
|
2008-12-15
|
|
Mediatheka 4.2 - Blind SQL Injection
|
16 |
WEB
|
StAkeR
|
|
2008-12-15
|
|
BabbleBoard 1.1.6 - Cross-Site Request Forgery/Cookie Grabber
|
19 |
WEB
|
SirGod
|
|
2008-12-15
|
|
FLDS 1.2a - 'lpro.php' SQL Injection
|
19 |
WEB
|
nuclear
|
|
2008-12-15
|
|
EZ Publish < 3.9.5/3.10.1/4.0.1 - 'token' Privilege Escalation
|
17 |
WEB
|
s4avrd0w
|
|
2008-12-15
|
|
CodeAvalanche RateMySite - Database Disclosure
|
22 |
WEB
|
Pouya_Server
|
|
2008-12-15
|
|
CodeAvalanche Articles - Database Disclosure
|
17 |
WEB
|
Pouya_Server
|
|
2008-12-15
|
|
CodeAvalanche FreeWallpaper - Remote Database Disclosure
|
20 |
WEB
|
Pouya_Server
|
|
2008-12-15
|
|
CodeAvalanche FreeForAll - Database Disclosure
|
19 |
WEB
|
Pouya_Server
|
|
2008-12-15
|
|
CodeAvalanche Directory - Database Disclosure
|
17 |
WEB
|
Pouya_Server
|
|
2008-12-15
|
|
Forest Blog 1.3.2 - Remote Database Disclosure
|
19 |
WEB
|
Cold Zero
|
|
2008-12-14
|
|
isweb CMS 3.0 - SQL Injection / Cross-Site Scripting
|
19 |
WEB
|
XaDoS
|
|
2008-12-14
|
|
ASPSiteWare RealtyListing 1.0/2.0 - SQL Injection
|
19 |
WEB
|
AlpHaNiX
|
|
2008-12-14
|
|
ASPSiteWare Automotive Dealer 1.0/2.0 - SQL Injection
|
19 |
WEB
|
AlpHaNiX
|
|
2008-12-14
|
|
ASPSiteWare Home Builder 1.0/2.0 - SQL Injection
|
19 |
WEB
|
AlpHaNiX
|
|
2008-12-14
|
|
Flatnux - html/JavaScript Injection Cookie Grabber
|
17 |
WEB
|
gmda
|
|
2008-12-14
|
|
CFAGCMS 1 - Remote File Inclusion
|
18 |
WEB
|
BeyazKurt
|
|
2008-12-14
|
|
Mediatheka 4.2 - 'lang' Local File Inclusion
|
20 |
WEB
|
Osirys
|
|
2008-12-14
|
|
AvailScript Classmate Script - Arbitrary File Upload
|
18 |
WEB
|
S.W.A.T.
|
|
2008-12-14
|
|
AvailScript Article Script - Arbitrary File Upload
|
22 |
WEB
|
S.W.A.T.
|
|
2008-12-14
|
|
The Rat CMS Alpha 2 - 'download.php' Priviledge Escalation
|
20 |
WEB
|
x0r
|
|
2008-12-14
|
|
FLDS 1.2a - 'redir.php' SQL Injection
|
20 |
WEB
|
nuclear
|
|
2008-12-14
|
|
PHP weather 2.2.2 - Local File Inclusion / Cross-Site Scripting
|
15 |
WEB
|
ahmadbady
|
|
2008-12-14
|
|
CodeAvalanche FreeForum - Database Disclosure
|
19 |
WEB
|
Ghost Hacker
|
|
2008-12-14
|
|
iyzi Forum 1.0b3 - Database Disclosure
|
17 |
WEB
|
Ghost Hacker
|
|
2008-12-14
|
|
autositephp 2.0.3 - Local File Inclusion / Cross-Site Request Forgery / Edit File
|
19 |
WEB
|
SirGod
|
|
2008-12-14
|
|
ASP-DEV Internal E-Mail System - Authentication Bypass
|
16 |
WEB
|
Pouya_Server
|
|
2008-12-14
|
|
ASPired2Quote - Remote Database Disclosure
|
16 |
WEB
|
Pouya_Server
|
|
2008-12-14
|
|
Discussion Web 4 - Remote Database Disclosure
|
21 |
WEB
|
Pouya_Server
|
|
2008-12-14
|
|
Simple Text-File Login script (SiTeFiLo) 1.0.6 - File Disclosure / Remote File Inclusion
|
18 |
WEB
|
Osirys
|
|
2008-12-14
|
|
FlexPHPNews 0.0.6 / PRO - Authentication Bypass
|
18 |
WEB
|
Osirys
|
|
2008-12-12
|
|
Joomla! Component live chat - SQL Injection / Open Proxy
|
20 |
WEB
|
jdc
|
|
2008-12-12
|
|
ColdFusion Scripts Red_Reservations - Database Disclosure
|
18 |
WEB
|
Cyber-Zone
|
|
2008-12-12
|
|
Umer Inc Songs Portal Script - 'id' SQL Injection
|
17 |
WEB
|
InjEctOr5
|
|
2008-12-12
|
|
VP-ASP Shopping Cart 6.50 - Database Disclosure
|
16 |
WEB
|
Dxil
|
|
2008-12-12
|
|
Moodle 1.9.3 - Remote Code Execution
|
16 |
WEB
|
USH
|
|
2008-12-12
|
|
the net guys aspired2blog - SQL Injection / File Disclosure
|
19 |
WEB
|
Pouya_Server
|
|
2008-12-12
|
|
Social Groupie - 'create_album.php' Arbitrary File Upload
|
18 |
WEB
|
InjEctOr5
|
|
2008-12-12
|
|
Wysi Wiki Wyg 1.0 - Remote Password Retrieve
|
22 |
WEB
|
StAkeR
|
|
2008-12-12
|
|
Social Groupie - 'id' SQL Injection
|
19 |
WEB
|
InjEctOr5
|
|
2008-12-12
|
|
Xpoze 4.10 - 'menu' Blind SQL Injection
|
19 |
WEB
|
XaDoS
|
|
2008-12-12
|
|
SUMON 0.7.0 - Command Execution
|
17 |
WEB
|
dun
|
|
2008-12-12
|
|
ASP-CMS 1.0 - 'cha' SQL Injection
|
20 |
WEB
|
Khashayar Fereidani
|
|
2008-12-12
|
|
The Net Guys ASPired2Protect - Database Disclosure
|
19 |
WEB
|
AlpHaNiX
|
|
2008-12-11
|
|
The Net Guys ASPired2Poll - Remote Database Disclosure
|
18 |
WEB
|
AlpHaNiX
|
|
2008-12-11
|
|
PHP Support Tickets 2.2 - Arbitrary File Upload
|
20 |
WEB
|
ahmadbady
|
|
2008-12-11
|
|
Banner Exchange Java - Authentication Bypass
|
19 |
WEB
|
R3d-D3V!L
|
|
2008-12-11
|
|
Ad Management Java - Authentication Bypass
|
17 |
WEB
|
R3d-D3V!L
|
|
2008-12-11
|
|
Affiliate Software Java 4.0 - Authentication Bypass
|
19 |
WEB
|
R3d-D3V!L
|