2008-09-25
|
|
PHPOCS 0.1-beta3 - 'act' Local File Inclusion
|
4 |
WEB
|
dun
|
2008-09-25
|
|
LanSuite 3.3.2 - 'design' Local File Inclusion
|
4 |
WEB
|
dun
|
2008-09-25
|
|
AJ Auction Pro Platinum - 'seller_id' SQL Injection
|
4 |
WEB
|
InjEctOr5
|
2008-09-24
|
|
Observer 0.3.2.1 - Multiple Remote Command Execution Vulnerabilities
|
4 |
WEB
|
dun
|
2008-09-24
|
|
barcodegen 2.0.0 - Local File Inclusion
|
4 |
WEB
|
dun
|
2008-09-24
|
|
ADN Forum 1.0b - Insecure Cookie Handling
|
4 |
WEB
|
Pepelux
|
2008-09-24
|
|
webcp 0.5.7 - 'filelocation' Remote File Disclosure
|
4 |
WEB
|
GoLd_M
|
2008-09-24
|
|
Jadu CMS for Government - 'recruit_details.php' SQL Injection
|
4 |
WEB
|
r45c4l
|
2008-09-24
|
|
PHPcounter 1.3.2 - 'defs.php' Local File Inclusion
|
4 |
WEB
|
dun
|
2008-09-24
|
|
mailwatch 1.0.4 - 'doc' Local File Inclusion
|
3 |
WEB
|
dun
|
2008-09-24
|
|
emergecolab 1.0 - 'sitecode' Local File Inclusion
|
4 |
WEB
|
dun
|
2008-09-24
|
|
AJ Auction Pro Platinum Skin - 'item_id' SQL Injection
|
4 |
WEB
|
GoLd_M
|
2008-09-24
|
|
Jetik Emlak ESA 2.0 - Multiple SQL Injections
|
4 |
WEB
|
ZoRLu
|
2008-09-24
|
|
Ol BookMarks Manager 0.7.5 - Local File Inclusion / Remote File Inclusion / SQL Injection
|
4 |
WEB
|
GoLd_M
|
2008-09-24
|
|
Rianxosencabos CMS 0.9 - Remote Add Admin
|
4 |
WEB
|
ka0x
|
2008-09-24
|
|
HotScripts Clone - 'cid' SQL Injection
|
4 |
WEB
|
Hussin X
|
2008-09-23
|
|
WebPortal CMS 0.7.4 - 'code' Remote Code Execution
|
4 |
WEB
|
GoLd_M
|
2008-09-23
|
|
Ol BookMarks Manager 0.7.5 - Local File Inclusion
|
4 |
WEB
|
dun
|
2008-09-23
|
|
JETIK-WEB Software - 'kat' SQL Injection
|
4 |
WEB
|
d3v1l
|
2008-09-23
|
|
Galmeta Post CMS 0.2 - Remote Code Execution / Arbitrary File Upload
|
4 |
WEB
|
GoLd_M
|
2008-09-23
|
|
iGaming CMS 1.5 - Multiple SQL Injections
|
5 |
WEB
|
StAkeR
|
2008-09-23
|
|
Sofi WebGui 0.6.3 PRE - 'mod_dir' Remote File Inclusion
|
4 |
WEB
|
dun
|
2008-09-23
|
|
OpenRat 0.8-beta4 - 'tpl_dir' Remote File Inclusion
|
4 |
WEB
|
dun
|
2008-09-22
|
|
CJ Ultra Plus 1.0.4 - Cookie SQL Injection
|
4 |
WEB
|
-SmoG-
|
2008-09-22
|
|
Fez 1.3/2.0 RC1 - 'list.php' SQL Injection
|
4 |
WEB
|
d3v1l
|
2008-09-22
|
|
basebuilder 2.0.1 - 'main.inc.php' Remote File Inclusion
|
4 |
WEB
|
dun
|
2008-09-22
|
|
MyBlog 0.9.8 - Insecure Cookie Handling
|
4 |
WEB
|
Pepelux
|
2008-09-22
|
|
OpenElec 3.01 - 'obj' Local File Inclusion
|
4 |
WEB
|
dun
|
2008-09-22
|
|
WSN Links Free 4.0.34P - 'comments.php' Blind SQL Injection
|
4 |
WEB
|
Stack
|
2008-09-22
|
|
WCMS 1.0b - 'news_detail.asp' SQL Injection
|
3 |
WEB
|
CWH Underground
|
2008-09-22
|
|
BuzzyWall 1.3.1 - 'search' SQL Injection
|
4 |
WEB
|
~!Dok_tOR!~
|
2008-09-22
|
|
PHP iCalendar 2.24 - Insecure Cookie Handling
|
4 |
WEB
|
Stack
|
2008-09-22
|
|
WSN Links 2.20 - 'comments.php' SQL Injection
|
4 |
WEB
|
d3v1l
|
2008-09-22
|
|
WSN Links 2.22/2.23 - 'vote.php' SQL Injection
|
4 |
WEB
|
d3v1l
|
2008-09-22
|
|
WCMS 1.0b - Arbitrary Add Admin
|
4 |
WEB
|
CWH Underground
|
2008-09-21
|
|
AvailScript Article Script - 'view.php' SQL Injection
|
3 |
WEB
|
Hussin X
|
2008-09-21
|
|
Rianxosencabos CMS 0.9 - Insecure Cookie Handling
|
4 |
WEB
|
Stack
|
2008-09-21
|
|
6rbScript 3.3 - 'section.php' Local File Inclusion
|
4 |
WEB
|
Stack
|
2008-09-21
|
|
PHP iCalendar 2.24 - 'cookie_language' Local File Inclusion / Arbitrary File Upload
|
4 |
WEB
|
EgiX
|
2008-09-21
|
|
Netartmedia Real Estate Portal 1.2 - SQL Injection
|
4 |
WEB
|
Encrypt3d.M!nd
|
2008-09-21
|
|
Netartmedia Jobs Portal 1.3 - Multiple SQL Injections
|
4 |
WEB
|
Encrypt3d.M!nd
|
2008-09-21
|
|
e107 Plugin Image Gallery 0.9.6.2 - SQL Injection
|
4 |
WEB
|
boom3rang
|
2008-09-21
|
|
AvailScript Jobs Portal Script - (Authenticated) Arbitrary File Upload
|
4 |
WEB
|
InjEctOr5
|
2008-09-21
|
|
Rianxosencabos CMS 0.9 - Arbitrary Add Admin
|
4 |
WEB
|
CWH Underground
|
2008-09-21
|
|
Diesel Job Site - 'job_id' Blind SQL Injection
|
4 |
WEB
|
Stack
|
2008-09-21
|
|
6rbScript 3.3 - 'singerid' SQL Injection
|
4 |
WEB
|
Hussin X
|
2008-09-21
|
|
PHPKB 1.5 Professional - Multiple SQL Injections
|
4 |
WEB
|
d3v1l
|
2008-09-21
|
|
TWiki 4.2.2 - 'action' Remote Code Execution
|
4 |
WEB
|
webDEViL
|
2008-09-21
|
|
Basic PHP Events Lister 1.0 - SQL Injection
|
4 |
WEB
|
0x90
|
2008-09-21
|
|
Invision Power Board 2.3.5 - SQL Injection
|
4 |
WEB
|
waraxe
|
2008-09-20
|
|
jPORTAL 2 - 'humor.php' SQL Injection
|
4 |
WEB
|
r45c4l
|
2008-09-20
|
|
Oceandir 2.9 - 'show_vote.php' SQL Injection
|
4 |
WEB
|
JEEN HACKER TEAM
|
2008-09-20
|
|
Plaincart 1.1.2 - 'p' SQL Injection
|
4 |
WEB
|
r45c4l
|
2008-09-20
|
|
Diesel Pay Script - 'area' SQL Injection
|
4 |
WEB
|
ZoRLu
|
2008-09-20
|
|
MyFWB 1.0 - 'index.php' SQL Injection
|
4 |
WEB
|
0x90
|
2008-09-20
|
|
Explay CMS 2.1 - Insecure Cookie Handling
|
4 |
WEB
|
Stack
|
2008-09-20
|
|
Advanced Electron Forum 1.0.6 - Remote Code Execution
|
4 |
WEB
|
GulfTech Security
|
2008-09-19
|
|
Explay CMS 2.1 - Persistent Cross-Site Scripting / Cross-Site Request Forgery
|
4 |
WEB
|
hodik
|
2008-09-19
|
|
easyLink 1.1.0 - 'detail.php' SQL Injection
|
4 |
WEB
|
Egypt Coder
|
2008-09-19
|
|
Pluck CMS 4.5.3 - 'update.php' Remote File Corruption
|
4 |
WEB
|
Nine:Situations:Group
|
2008-09-18
|
|
AssetMan 2.5-b - SQL Injection using Session Fixation
|
4 |
WEB
|
Neo Anderson
|
2008-09-18
|
|
ProActive CMS - 'template' Local File Inclusion
|
4 |
WEB
|
r45c4l
|
2008-09-18
|
|
Diesel Joke Site - 'picture_category.php' SQL Injection
|
4 |
WEB
|
SarBoT511
|
2008-09-18
|
|
CYASK 3.x - 'neturl' Local File Disclosure
|
4 |
WEB
|
xy7
|
2008-09-18
|
|
ProArcadeScript 1.3 - 'random' SQL Injection
|
4 |
WEB
|
SuNHouSe2
|
2008-09-18
|
|
addalink 4 - 'category_id' SQL Injection
|
4 |
WEB
|
ka0x
|
2008-09-18
|
|
E-PHP CMS - 'article.php' SQL Injection
|
4 |
WEB
|
HaCkeR_EgY
|
2008-09-17
|
|
addalink 4 Beta - Write Approved Links
|
4 |
WEB
|
Pepelux
|
2008-09-17
|
|
X10media Mp3 Search Engine 1.5.5 - Remote File Inclusion
|
4 |
WEB
|
THUNDER
|
2008-09-17
|
|
Technote 7 - 'shop_this_skin_path' Remote File Inclusion
|
4 |
WEB
|
webDEViL
|
2008-09-17
|
|
PHP Crawler 0.8 - Remote File Inclusion
|
4 |
WEB
|
Piker
|
2008-09-17
|
|
phpRealty 0.3 - 'INC' Remote File Inclusion
|
4 |
WEB
|
ka0x
|
2008-09-16
|
|
Hotel Reservation System - 'city.asp' Blind SQL Injection
|
4 |
WEB
|
JosS
|
2008-09-16
|
|
Gonafish LinksCaffePRO 4.5 - 'index.php' SQL Injection
|
4 |
WEB
|
sl4xUz
|
2008-09-16
|
|
Attachmax Dolphin 2.1.0 - Multiple Vulnerabilities
|
4 |
WEB
|
K-159
|
2008-09-16
|
|
iScripts EasyIndex - 'produid' SQL Injection
|
4 |
WEB
|
SirGod
|
2008-09-15
|
|
Link Bid Script 1.5 - Multiple SQL Injections
|
4 |
WEB
|
SirGod
|
2008-09-15
|
|
Pre Real Estate Listings - 'search.php' SQL Injection
|
4 |
WEB
|
JosS
|
2008-09-15
|
|
CzarNews 1.20 - Account Hijacking SQL Injection
|
4 |
WEB
|
0ut0fbound
|
2008-09-15
|
|
CzarNews 1.20 - 'cookie' SQL Injection
|
4 |
WEB
|
StAkeR
|
2008-09-14
|
|
cPanel 11.x - 'Fantastico' Local File Inclusion
|
4 |
WEB
|
joker_1
|
2008-09-14
|
|
Kasseler CMS 1.1.0/1.2.0 Lite - SQL Injection
|
4 |
WEB
|
~!Dok_tOR!~
|
2008-09-14
|
|
Free PHP VX Guestbook 1.06 - Insecure Cookie Handling
|
4 |
WEB
|
Stack
|
2008-09-13
|
|
Free PHP VX Guestbook 1.06 - Arbitrary Database Backup
|
4 |
WEB
|
SirGod
|
2008-09-13
|
|
Linkarity - 'link.php' SQL Injection
|
4 |
WEB
|
Egypt Coder
|
2008-09-13
|
|
FoT Video scripti 1.1b - 'oyun' SQL Injection
|
4 |
WEB
|
Crackers_Child
|
2008-09-13
|
|
phpsmartcom 0.2 - Local File Inclusion / SQL Injection
|
4 |
WEB
|
r3dm0v3
|
2008-09-13
|
|
Talkback 2.3.6 - Multiple Local File Inclusion / PHPInfo Disclosure Vulnerabilities
|
5 |
WEB
|
SirGod
|
2008-09-13
|
|
Sports Clubs Web Panel 0.0.1 - Remote Game Delete
|
4 |
WEB
|
ka0x
|
2008-09-13
|
|
pLink 2.07 - 'linkto.php' Blind SQL Injection
|
4 |
WEB
|
Stack
|
2008-09-12
|
|
WebPortal CMS 0.7.4 - 'FCKeditor' Arbitrary File Upload
|
3 |
WEB
|
S.W.A.T.
|
2008-09-12
|
|
pNews 2.03 - 'newsid' SQL Injection
|
3 |
WEB
|
r45c4l
|
2008-09-12
|
|
vbLOGIX Tutorial Script 1.0 - 'cat_id' SQL Injection
|
4 |
WEB
|
FIREH4CK3R
|
2008-09-12
|
|
SkaLinks 1.5 - 'register.php' Arbitrary Add Editor
|
4 |
WEB
|
mr.al7rbi
|
2008-09-12
|
|
iBoutique 4.0 - 'cat' SQL Injection
|
3 |
WEB
|
r45c4l
|
2008-09-12
|
|
WebPortal CMS 0.7.4 - 'download.php' SQL Injection
|
4 |
WEB
|
StAkeR
|
2008-09-12
|
|
pForum 1.30 - 'showprofil.php' SQL Injection
|
4 |
WEB
|
tmh
|
2008-09-12
|
|
PHPWebGallery 1.3.4 - Blind SQL Injection (2)
|
4 |
WEB
|
ka0x
|
2008-09-12
|
|
Sports Clubs Web Panel 0.0.1 - Arbitrary File Upload
|
5 |
WEB
|
Stack
|
2008-09-11
|
|
Yourownbux 4.0 - 'cookie' Authentication Bypass
|
4 |
WEB
|
Tec-n0x
|
2008-09-11
|
|
Easy Photo Gallery 2.1 - Arbitrary Add Admin / remove user
|
4 |
WEB
|
Stack
|
2008-09-11
|
|
PHPWebGallery 1.3.4 - Blind SQL Injection (1)
|
4 |
WEB
|
Stack
|
2008-09-11
|
|
Sports Clubs Web Panel 0.0.1 - 'id' SQL Injection
|
4 |
WEB
|
Virangar Security
|
2008-09-11
|
|
Autodealers CMS AutOnline - 'id' SQL Injection
|
4 |
WEB
|
ZoRLu
|
2008-09-11
|
|
minb 0.1.0 - Remote Code Execution
|
4 |
WEB
|
Khashayar Fereidani
|
2008-09-11
|
|
phsBlog 0.2 - Bypass SQL Injection Filtering
|
4 |
WEB
|
Khashayar Fereidani
|
2008-09-11
|
|
D-iscussion Board 3.01 - 'topic' Local File Inclusion
|
4 |
WEB
|
SirGod
|
2008-09-11
|
|
Easy Photo Gallery 2.1 - Cross-Site Scripting / File Disclosure/Bypass / SQL Injection
|
5 |
WEB
|
Khashayar Fereidani
|
2008-09-11
|
|
Sports Clubs Web Panel 0.0.1 - 'p' Local File Inclusion
|
4 |
WEB
|
StAkeR
|
2008-09-11
|
|
Autodealers CMS AutOnline - 'pageid' SQL Injection
|
4 |
WEB
|
r45c4l
|
2008-09-11
|
|
PHPWebGallery 1.3.4 - Cross-Site Scripting / Local File Inclusion
|
4 |
WEB
|
Khashayar Fereidani
|
2008-09-10
|
|
Zanfi CMS lite / Jaw Portal free - 'page' SQL Injection
|
4 |
WEB
|
Cru3l.b0y
|
2008-09-10
|
|
PHPVID 1.1 - Cross-Site Scripting / SQL Injection
|
4 |
WEB
|
r45c4l
|
2008-09-10
|
|
WordPress Core 2.6.1 - Admin Takeover (SQL Column Truncation)
|
4 |
WEB
|
iso^kpsbr
|
2008-09-10
|
|
aspwebalbum 3.2 - Multiple Vulnerabilities
|
4 |
WEB
|
e.wiZz!
|
2008-09-10
|
|
Zanfi CMS lite 2.1 / Jaw Portal free - 'FCKeditor' Arbitrary File Upload
|
3 |
WEB
|
reptil
|
2008-09-10
|
|
AvailScript Jobs Portal Script - 'jid' SQL Injection
|
3 |
WEB
|
InjEctOr5
|
2008-09-10
|
|
Libera CMS 1.12 - 'cookie' SQL Injection
|
4 |
WEB
|
StAkeR
|
2008-09-10
|
|
Zanfi CMS lite 1.2 - Multiple Local File Inclusions
|
4 |
WEB
|
SirGod
|
2008-09-09
|
|
AvailScript Classmate Script - 'viewprofile.php' SQL Injection
|
3 |
WEB
|
Stack
|
2008-09-09
|
|
AvailScript Photo Album - 'pics.php' Multiple Vulnerabilities
|
4 |
WEB
|
sl4xUz
|
2008-09-09
|
|
Kim Websites 1.0 - 'FCKeditor' Arbitrary File Upload
|
4 |
WEB
|
Ciph3r
|
2008-09-09
|
|
AvailScript Article Script - 'articles.php' Multiple Vulnerabilities
|
4 |
WEB
|
sl4xUz
|
2008-09-09
|
|
CMS Buzz - 'id' SQL Injection
|
3 |
WEB
|
security fears team
|
2008-09-09
|
|
Stash 1.0.3 - Insecure Cookie Handling
|
4 |
WEB
|
Ciph3r
|