Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2008-10-22   DorsaCMS - 'ShowPage.aspx' SQL Injection 20 WEB syst3m_f4ult
2008-10-22   Joomla! Component ionFiles 4.4.2 - File Disclosure 16 WEB Vrs-hCk
2008-10-22   LoudBlog 0.8.0a - 'ajax.php' SQL Injection 18 WEB Xianur0
2008-10-22   phpcrs 2.06 - 'importFunction' Local File Inclusion 18 WEB Pepelux
2008-10-22   Iamma Simple Gallery 1.0/2.0 - Arbitrary File Upload 21 WEB x0r
2008-10-22   Joomla! Component Daily Message 1.0.3 - 'id' SQL Injection 19 WEB H!tm@N
2008-10-21   ShopMaker CMS 1.0 - 'id' SQL Injection 18 WEB Hussin X
2008-10-21   LightBlog 9.8 - 'GET' / 'POST' / 'COOKIE' Local File Inclusion 19 WEB JosS
2008-10-21   Limbo CMS - Private Messaging Component SQL Injection 15 WEB StAkeR
2008-10-20   XOOPS Module makale 0.26 - SQL Injection 18 WEB EcHoLL
2008-10-20   Joomla! Component ds-syndicate - 'feed_id' SQL Injection 17 WEB boom3rang
2008-10-19   e107 < 0.7.13 - 'usersettings.php' Blind SQL Injection 18 WEB girex
2008-10-20   WBB Plugin rGallery 1.09 - 'itemID' Blind SQL Injection 21 WEB Five-Three-Nine
2008-10-19   Vivvo CMS 3.4 - Multiple Vulnerabilities 18 WEB Xianur0
2008-10-19   Yappa-ng 2.3.3-beta0 - 'album' Local File Inclusion 18 WEB Vrs-hCk
2008-10-19   Fast Click SQL 1.1.7 Lite - 'init.php' Remote File Inclusion 20 WEB NoGe
2008-10-18   PHP Easy Downloader 1.5 - Remote File Creation 16 WEB StAkeR
2008-10-18   Nuke ET 3.4 - 'FCKeditor' Arbitrary File Upload 17 WEB EgiX
2008-10-18   miniBloggie 1.0 - 'del.php' Blind SQL Injection 17 WEB StAkeR
2008-10-18   Meeting Room Booking System (MRBS) < 1.4 - SQL Injection 18 WEB Xianur0
2008-10-18   zeeproperty - 'adid' SQL Injection 17 WEB Hussin X
2008-10-18   phpFastNews 1.0.0 - Insecure Cookie Handling 17 WEB Qabandi
2008-10-18   XOOPS Module GesGaleri - SQL Injection 19 WEB EcHoLL
2008-10-17   WordPress Plugin st_newsletter - 'stnl_iframe.php' SQL Injection 17 WEB r45c4l
2008-10-16   Post Affiliate Pro 2.0 - 'md' Local File Inclusion 17 WEB ZeN
2008-10-16   Calendars for the Web 4.02 - Admin Authentication Bypass 20 WEB SecVuln
2008-10-16   PHP Easy Downloader 1.5 - 'file' File Disclosure 18 WEB LMaster
2008-10-16   iGaming CMS 2.0 Alpha 1 - 'search.php' SQL Injection 19 WEB StAkeR
2008-10-16   Mantis Bug Tracker 1.1.3 - Remote Code Execution 18 WEB EgiX
2008-10-16   Kure 0.6.3 - 'index.php' Local File Inclusion 16 WEB JosS
2008-10-16   PokerMax Poker League 0.13 - Insecure Cookie Handling 17 WEB DaRkLiFe
2008-10-16   IP Reg 0.4 - Multiple SQL Injections 21 WEB JosS
2008-10-16   Mic_blog 0.0.3 - SQL Injection / Privilege Escalation 19 WEB StAkeR
2008-10-16   Mosaic Commerce - 'cid' SQL Injection 18 WEB Ali Abbasi
2008-10-16   CafeEngine - Multiple SQL Injections 17 WEB 0xFFFFFF
2008-10-15   myEvent 1.6 - 'eventdate' SQL Injection 18 WEB JosS
2008-10-15   mystats - 'hits.php' Multiple Vulnerabilities 17 WEB JosS
2008-10-15   AstroSPACES 1.1.1 - 'id' SQL Injection 21 WEB TurkishWarriorr
2008-10-14   PHPWebGallery 1.7.2 - Session Hijacking / Code Execution 17 WEB EgiX
2008-10-14   My PHP Dating - 'id' SQL Injection 20 WEB Hakxer
2008-10-14   SezHoo 0.1 - Remote File Inclusion 17 WEB DaRkLiFe
2008-10-14   Nuked-klaN 1.7.7 / SP4.4 - Multiple Vulnerabilities 16 WEB Charles Fol
2008-10-14   XOOPS Module xhresim - SQL Injection 18 WEB EcHoLL
2008-10-14   WordPress Plugin WP Comment Remix 1.4.3 - SQL Injection 19 WEB g30rg3_x
2008-10-13   IndexScript 3.0 - 'parent_id' SQL Injection 19 WEB d3v1l
2008-10-13   ParsBlogger - 'links.asp' SQL Injection 18 WEB Hussin X
2008-10-13   LokiCMS 0.3.4 - 'admin.php' Create Local File Inclusion 20 WEB JosS
2008-10-13   LokiCMS 0.3.4 - 'writeconfig()' Remote Command Execution 19 WEB girex
2008-10-12   My PHP Indexer 1.0 - 'index.php' Local File Download 21 WEB JosS
2008-10-12   NewLife Blogger 3.0 - Insecure Cookie Handling / SQL Injection 19 WEB Pepelux
2008-10-12   LokiCMS 0.3.4 - 'index.php' Arbitrary Check File 18 WEB JosS
2008-10-12   Real Estate Scripts 2008 - 'cat' SQL Injection 20 WEB Hakxer
2008-10-12   Globsy 1.0 - Remote File Rewriting 18 WEB StAkeR
2008-10-12   mini-pub 0.3 - Local Directory Traversal / File Disclosure 23 WEB GoLd_M
2008-10-12   mini-pub 0.3 - File Disclosure / Code Execution 19 WEB muuratsalo
2008-10-11   Absolute Poll Manager XE 4.1 - 'xlacomments.asp' SQL Injection 17 WEB Hakxer
2008-10-11   Joomla! Component ownbiblio 1.5.3 - 'catid' SQL Injection 16 WEB H!tm@N
2008-10-10   SlimCMS 1.0.0 - 'redirect.php' Privilege Escalation 20 WEB StAkeR
2008-10-10   Easynet4u Link Host - 'cat_id' SQL Injection 18 WEB BeyazKurt
2008-10-10   MunzurSoft Wep Portal W3 - 'kat' SQL Injection 18 WEB LUPUS
2008-10-10   Joomla! Component mad4Joomla! - SQL Injection 17 WEB H!tm@N
2008-10-10   Joomla! Component Ignite Gallery 0.8.3 - SQL Injection 15 WEB H!tm@N
2008-10-10   Easynet4u faq Host - 'faq.php' SQL Injection 16 WEB SuB-ZeRo
2008-10-10   Easynet4u Forum Host - 'forum.php' SQL Injection 19 WEB SuB-ZeRo
2008-10-10   Ayco Okul Portali - 'linkid' SQL Injection 17 WEB Crackers_Child
2008-10-09   Scriptsez Easy Image Downloader - Local File Download 16 WEB JosS
2008-10-09   Stash 1.0.3 - SQL Injection User Credentials Disclosure 17 WEB gnix
2008-10-09   Scriptsez Mini Hosting Panel - 'members.php' Local File Inclusion 17 WEB JosS
2008-10-09   IranMC Arad Center - SQL Injection 16 WEB Hussin X
2008-10-09   Kusaba 1.0.4 - Remote Code Execution (2) 17 WEB Sausage
2008-10-09   Camera Life 2.6.2b4 - SQL Injection / Cross-Site Scripting 19 WEB BackDoor
2008-10-09   Joomla! Component Joomtracker 1.01 - SQL Injection 16 WEB rsauron
2008-10-09   Gforge 4.6 rc1 - 'skill_edit' SQL Injection 15 WEB beford
2008-10-09   GForge 4.5.19 - Multiple SQL Injections 17 WEB beford
2008-10-09   Kusaba 1.0.4 - Remote Code Execution (1) 21 WEB Sausage
2008-10-08   WebBiscuits Modules Controller 1.1 - Remote File Inclusion / Remote File Disclosure 17 WEB GoLd_M
2008-10-08   AdMan 1.1.20070907 - 'campaignId' SQL Injection 18 WEB SuB-ZeRo
2008-10-08   HispaH textlinksads - 'index.php' SQL Injection 18 WEB InjEctOr5
2008-10-08   DFF PHP Framework API - 'Data Feed File' Remote File Inclusion 15 WEB GoLd_M
2008-10-07   TorrentTrader Classic 1.04 - Blind SQL Injection 15 WEB BazOka-HaCkEr
2008-10-07   Built2Go PHP Realestate 1.5 - 'event_detail.php' SQL Injection 18 WEB d3v1l
2008-10-07   PHP Autos 2.9.1 - 'catid' SQL Injection 17 WEB Mr.SQL
2008-10-07   PHP Auto Dealer 2.7 - 'v_cat' SQL Injection 19 WEB Mr.SQL
2008-10-07   PHP Realtor 1.5 - 'v_cat' SQL Injection 15 WEB Mr.SQL
2008-10-07   Yourownbux 4.0 - 'cookie' SQL Injection 21 WEB Tec-n0x
2008-10-07   Joomla! Component com_hotspots - SQL Injection 20 WEB cOndemned
2008-10-07   Yerba SACphp 6.3 - Multiple Vulnerabilities 17 WEB StAkeR
2008-10-06   Yerba SACphp 6.3 - Local File Inclusion 16 WEB Pepelux
2008-10-06   asiCMS alpha 0.208 - Multiple Remote File Inclusions 18 WEB NoGe
2008-10-05   PHP-Fusion Mod triscoop_race_system - 'raceid' SQL Injection 20 WEB boom3rang
2008-10-05   PHP-Fusion Mod recept - 'kat_id' SQL Injection 20 WEB boom3rang
2008-10-05   PHP-Fusion Mod raidtracker_panel - 'INFO_RAID_ID' SQL Injection 18 WEB boom3rang
2008-10-05   PHP-Fusion Mod manuals - 'manual' SQL Injection 18 WEB boom3rang
2008-10-05   FOSS Gallery Public 1.0 - Arbitrary File Upload (PoC) 17 WEB Pepelux
2008-10-05   phpAbook 0.8.8b - 'cookie' Local File Inclusion 18 WEB JosS
2008-10-05   Fastpublish CMS 1.9999 - Local File Inclusion / SQL Injection 16 WEB ~!Dok_tOR!~
2008-10-05   geccBBlite 2.0 - 'id' SQL Injection 17 WEB Piker
2008-10-05   OpenNMS < 1.5.96 - Multiple Vulnerabilities 19 WEB BugSec LTD
2008-10-05   Galerie 3.2 - 'pic' WBB Lite Addon Blind SQL Injection 20 WEB J0hn.X3r
2008-10-05   FOSS Gallery Public 1.0 - Arbitrary File Upload 18 WEB JosS
2008-10-04   FOSS Gallery Admin 1.0 - Arbitrary File Upload 20 WEB Pepelux
2008-10-04   JMweb - 'src' Local File Inclusion 20 WEB SirGod
2008-10-04   pPIM 1.01 - 'notes.php' Local File Inclusion 16 WEB JosS
2008-10-03   Kwalbum 2.0.2 - Arbitrary File Upload 17 WEB CWH Underground
2008-10-03   CCMS 3.1 - 'skin' Local File Inclusion 18 WEB SirGod
2008-10-03   AdaptCMS Lite 1.3 - Blind SQL Injection 18 WEB StAkeR
2008-10-03   Full PHP Emlak Script - 'arsaprint.php' SQL Injection 16 WEB Hussin X
2008-10-03   IP Reg 0.4 - Blind SQL Injection 19 WEB StAkeR
2008-10-02   OpenX 2.6 - 'bannerid' Blind SQL Injection 18 WEB d00m3r4ng
2008-10-02   OLIB 7 WebView 2.5.1.1 - 'infile' Local File Inclusion 18 WEB ZeN
2008-10-02   Bux.to Clone Script - Insecure Cookie Handling 18 WEB SirGod
2008-10-01   Link Trader - 'lnkid' SQL Injection 18 WEB Hussin X
2008-10-01   phpscripts Ranking Script - Insecure Cookie Handling 20 WEB Crackers_Child
2008-10-01   RPortal 1.1 - 'file_op' Remote File Inclusion 18 WEB Kad
2008-10-01   phpScheduleIt 1.2.10 - 'reserve.php' Remote Code Execution 18 WEB EgiX
2008-10-01   Crux Gallery 1.32 - 'theme' Local File Inclusion 16 WEB StAkeR
2008-10-01   Noname CMS 1.0 - Multiple SQL Injections 18 WEB ~!Dok_tOR!~
2008-10-01   Discussion Forums 2k 3.3 - Multiple SQL Injections 15 WEB ~!Dok_tOR!~
2008-10-01   BMForum 5.6 - 'tagname' SQL Injection 20 WEB ~!Dok_tOR!~
2008-10-01   MySQL Quick Admin 1.5.5 - 'cookie' Local File Inclusion 17 WEB JosS
2008-10-01   ADN Forum 1.0b - Blind SQL Injection 17 WEB StAkeR
2008-09-30   Pritlog 0.4 - 'Filename' Remote File Disclosure 17 WEB Pepelux
2008-09-30   BookMarks Favourites Script - 'id' SQL Injection 18 WEB Hussin X
2008-09-30   Rianxosencabos CMS 0.9 - Blind SQL Injection 15 WEB ka0x
2008-09-30   SG Real Estate Portal 2.0 - Insecure Cookie Handling 16 WEB Stack