Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2008-09-11   PHPWebGallery 1.3.4 - Blind SQL Injection (1) 7 WEB Stack
2008-09-11   Sports Clubs Web Panel 0.0.1 - 'id' SQL Injection 7 WEB Virangar Security
2008-09-11   Autodealers CMS AutOnline - 'id' SQL Injection 7 WEB ZoRLu
2008-09-11   minb 0.1.0 - Remote Code Execution 7 WEB Khashayar Fereidani
2008-09-11   phsBlog 0.2 - Bypass SQL Injection Filtering 7 WEB Khashayar Fereidani
2008-09-11   D-iscussion Board 3.01 - 'topic' Local File Inclusion 7 WEB SirGod
2008-09-11   Easy Photo Gallery 2.1 - Cross-Site Scripting / File Disclosure/Bypass / SQL Injection 8 WEB Khashayar Fereidani
2008-09-11   Sports Clubs Web Panel 0.0.1 - 'p' Local File Inclusion 7 WEB StAkeR
2008-09-11   Autodealers CMS AutOnline - 'pageid' SQL Injection 7 WEB r45c4l
2008-09-11   PHPWebGallery 1.3.4 - Cross-Site Scripting / Local File Inclusion 7 WEB Khashayar Fereidani
2008-09-10   Zanfi CMS lite / Jaw Portal free - 'page' SQL Injection 7 WEB Cru3l.b0y
2008-09-10   PHPVID 1.1 - Cross-Site Scripting / SQL Injection 7 WEB r45c4l
2008-09-10   WordPress Core 2.6.1 - Admin Takeover (SQL Column Truncation) 7 WEB iso^kpsbr
2008-09-10   aspwebalbum 3.2 - Multiple Vulnerabilities 7 WEB e.wiZz!
2008-09-10   Zanfi CMS lite 2.1 / Jaw Portal free - 'FCKeditor' Arbitrary File Upload 7 WEB reptil
2008-09-10   AvailScript Jobs Portal Script - 'jid' SQL Injection 6 WEB InjEctOr5
2008-09-10   Libera CMS 1.12 - 'cookie' SQL Injection 8 WEB StAkeR
2008-09-10   Zanfi CMS lite 1.2 - Multiple Local File Inclusions 7 WEB SirGod
2008-09-09   AvailScript Classmate Script - 'viewprofile.php' SQL Injection 6 WEB Stack
2008-09-09   AvailScript Photo Album - 'pics.php' Multiple Vulnerabilities 8 WEB sl4xUz
2008-09-09   Kim Websites 1.0 - 'FCKeditor' Arbitrary File Upload 7 WEB Ciph3r
2008-09-09   AvailScript Article Script - 'articles.php' Multiple Vulnerabilities 7 WEB sl4xUz
2008-09-09   CMS Buzz - 'id' SQL Injection 6 WEB security fears team
2008-09-09   Stash 1.0.3 - Insecure Cookie Handling 7 WEB Ciph3r
2008-09-09   Creator CMS 5.0 - 'sideid' SQL Injection 7 WEB ThE X-HaCkEr
2008-09-09   Live TV Script - 'index.php?mid' SQL Injection 7 WEB InjEctOr5
2008-09-09   Hot Links SQL-PHP 3 - 'report.php' Multiple Vulnerabilities 8 WEB sl4xUz
2008-09-09   Stash 1.0.3 - Multiple SQL Injections 7 WEB Khashayar Fereidani
2008-09-09   Alstrasoft Forum - 'catid' SQL Injection 7 WEB r45c4l
2008-09-07   E-Shop Shopping Cart Script - 'search_results.php' SQL Injection 7 WEB Mormoroth
2008-09-07   WordPress Core 2.6.1 - SQL Column Truncation 7 WEB irk4z
2008-09-07   Alstrasoft Forum - 'cat' SQL Injection 7 WEB r45c4l
2008-09-07   Masir Camp E-Shop Module 3.0 - 'ordercode' SQL Injection 7 WEB BugReport.IR
2008-09-06   MemHT Portal 3.9.0 - Remote Create Shell 7 WEB Ams
2008-09-06   Simple Machines Forum (SMF) 1.1.5 (Windows x86) - Admin Reset Password 7 WEB Raz0r
2008-09-06   Integramod 1.4.x - Insecure Directory Download Database 8 WEB TheJT
2008-09-06   Vastal I-Tech Dating Zone - 'fage' SQL Injection 6 WEB ZoRLu
2008-09-05   Vastal I-Tech Shaadi Zone 1.0.9 - 'tage' SQL Injection 7 WEB e.wiZz!
2008-09-05   EsFaq 2.0 - 'idcat' SQL Injection 7 WEB SuB-ZeRo
2008-09-05   Vastal I-Tech Cosmetics Zone - 'cat_id' SQL Injection 7 WEB Stack
2008-09-05   Vastal I-Tech Freelance Zone - 'coder_id' SQL Injection 7 WEB Stack
2008-09-05   Vastal I-Tech Mag Zone - 'cat_id' SQL Injection 7 WEB Stack
2008-09-05   Vastal I-Tech MMORPG Zone - 'game_id' SQL Injection 7 WEB Stack
2008-09-05   Vastal I-Tech Jobs Zone - 'news_id' SQL Injection 7 WEB Stack
2008-09-05   Vastal I-Tech DVD Zone - 'cat_id' SQL Injection 7 WEB DeViL iRaQ
2008-09-05   Vastal I-Tech Share Zone - 'id' SQL Injection 7 WEB DeViL iRaQ
2008-09-05   Vastal I-Tech Toner Cart - 'id' SQL Injection 7 WEB DeViL iRaQ
2008-09-05   Vastal I-Tech Visa Zone - 'news_id' SQL Injection 7 WEB DeViL iRaQ
2008-09-05   Vastal I-Tech Agent Zone - 'ann_id' SQL Injection 7 WEB DeViL iRaQ
2008-09-05   WebCMS Portal Edition - 'id' Blind SQL Injection 7 WEB JosS
2008-09-05   Devalcms 1.4a - Cross-Site Scripting / Remote Code Execution 6 WEB Khashayar Fereidani
2008-09-05   AWStats Totals 1.14 - 'AWStatstotals.php' Remote Code Execution 7 WEB Ricardo Almeida
2008-09-04   ACG-ScriptShop - 'cid' SQL Injection 7 WEB Hussin X
2008-09-04   qwicsite pro - SQL Injection / Cross-Site Scripting 7 WEB Cr@zy_King
2008-09-04   ACG-PTP 1.0.6 - 'adid' SQL Injection 7 WEB Hussin X
2008-09-03   Living Local Website - 'listtest.php' SQL Injection 7 WEB Hussin X
2008-09-03   TransLucid 1.75 - 'FCKeditor' Arbitrary File Upload 7 WEB BugReport.IR
2008-09-03   aspwebalbum 3.2 - Arbitrary File Upload / SQL Injection / Cross-Site Scripting 7 WEB Alemin_Krali
2008-09-03   Moodle 1.8.4 - Remote Code Execution 7 WEB zurlich.lpt
2008-09-03   Spice Classifieds - 'cat_path' SQL Injection 7 WEB InjEctOr5
2008-09-02   CS-Cart 1.3.5 - Authentication Bypass 7 WEB GulfTech Security
2008-09-02   AJ HYIP ACME - 'readarticle.php' SQL Injection 7 WEB InjEctOr5
2008-09-02   AJ HYIP ACME - 'comment.php' SQL Injection 7 WEB security fears team
2008-09-02   Reciprocal Links Manager 1.1 - 'site' SQL Injection 8 WEB Hussin X
2008-09-02   Coupon Script 4.0 - 'id' SQL Injection 7 WEB Hussin X
2008-09-02   myPHPNuke < 1.8.8_8rc2 - 'artid' SQL Injection 7 WEB MustLive
2008-09-01   e107 Plugin BLOG Engine 2.2 - 'uid' SQL Injection 7 WEB Virangar Security
2008-09-01   WeBid 0.5.4 - 'FCKeditor' Arbitrary File Upload 7 WEB Stack
2008-09-01   CMSbright - 'id_rub_page' SQL Injection 7 WEB h4ck3r
2008-09-01   EasyClassifields 3.0 - 'go' SQL Injection 7 WEB e.wiZz!
2008-09-01   WeBid 0.5.4 - 'item.php' SQL Injection 7 WEB Stack
2008-08-31   webid 0.5.4 - Multiple Vulnerabilities 7 WEB InjEctOr5
2008-08-31   myPHPNuke < 1.8.8_8rc2 - Cross-Site Scripting / SQL Injection 7 WEB MustLive
2008-08-31   Words tag script 1.2 - 'word' SQL Injection 7 WEB Hussin X
2008-08-31   Web Directory Script 1.5.3 - 'site' SQL Injection 7 WEB Hussin X
2008-08-30   Brim 2.0.0 - SQL Injection / Cross-Site Scripting 7 WEB InjEctOr5
2008-08-29   Invision Power Board (IP.Board) 2.3.5 - Multiple Vulnerabilities (2) 11 WEB DarkFig
2008-08-27   Yourownbux 3.1/3.2 Beta - SQL Injection 7 WEB ~!Dok_tOR!~
2008-08-27   PHPMyRealty 1.0.9 - Multiple SQL Injections 7 WEB ~!Dok_tOR!~
2008-08-26   MyBulletinBoard (MyBB) 1.2.11 - 'private.php' SQL Injection (2) 7 WEB c411k
2008-08-26   iFdate 2.0.3 - SQL Injection 7 WEB ~!Dok_tOR!~
2008-08-26   Thickbox Gallery 2.0 - 'Admins.php' Admin Data Disclosure 7 WEB SirGod
2008-08-26   CMME 1.12 - Local File Inclusion / Cross-Site Scripting / Cross-Site Request Forgery/Download Backup 6 WEB SirGod
2008-08-26   k-rate - SQL Injection / Cross-Site Scripting 7 WEB Corwin
2008-08-26   Simple PHP Blog (SPHPBlog) 0.5.1 - Code Execution 7 WEB mAXzA
2008-08-26   Kolifa.net Download Script 1.2 - 'id' SQL Injection 7 WEB Kacak
2008-08-26   z-breaknews 2.0 - 'single.php' SQL Injection 7 WEB cOndemned
2008-08-25   Crafty Syntax Live Help 2.14.6 - 'department' SQL Injection 7 WEB GulfTech Security
2008-08-25   GeekLog 1.5.0 - Arbitrary File Upload 7 WEB t0pP8uZz
2008-08-25   WebBoard 2.0 - Arbitrary SQL Question/Anwser Delete 8 WEB t0pP8uZz
2008-08-25   EZContents CMS 2.0.3 - Multiple Local File Inclusions 7 WEB DSecRG
2008-08-25   Pluck CMS 4.5.2 - Multiple Local File Inclusions 7 WEB DSecRG
2008-08-25   Web Directory Script 2.0 - 'name' SQL Injection 7 WEB ~!Dok_tOR!~
2008-08-25   Matterdaddy Market 1.1 - 'index.php' Multiple SQL Injections 7 WEB ~!Dok_tOR!~
2008-08-25   BtiTracker 1.4.7 / xbtit 2.0.542 - SQL Injection 7 WEB InATeam
2008-08-24   MiaCMS 4.6.5 - Multiple SQL Injections 7 WEB ~!Dok_tOR!~
2008-08-24   5 star review - Cross-Site Scripting / SQL Injection 7 WEB Mr.SQL
2008-08-23   onenews Beta 2 - Cross-Site Scripting / HTML Injection / SQL Injection 7 WEB suN8Hclf
2008-08-23   noname script 1.1 - Multiple Vulnerabilities 7 WEB SirGod
2008-08-21   easysite 2.3 - Multiple Vulnerabilities 7 WEB SirGod
2008-08-21   TinyCMS 1.1.2 - 'templater.php' Local File Inclusion 7 WEB cOndemned
2008-08-21   BandSite CMS 1.1.4 - Download Backup / Cross-Site Scripting / Cross-Site Request Forgery 7 WEB SirGod
2008-08-21   Photocart 3.9 - Multiple SQL Injections 7 WEB ~!Dok_tOR!~
2008-08-21   CustomCMS 4.0 - 'print.php' SQL Injection 7 WEB ~!Dok_tOR!~
2008-08-20   webEdition CMS - 'we_objectID' Blind SQL Injection 7 WEB Lidloses_Auge
2008-08-20   phpBazar 2.0.2 - 'adid' SQL Injection 7 WEB e.wiZz!
2008-08-20   Pars4U Videosharing 1.0 - Cross-Site Scripting / Blind SQL Injection 7 WEB Mr.SQL
2008-08-19   Active PHP BookMarks 1.1.02 - SQL Injection 7 WEB Hussin X
2008-08-19   Banner Management Script - 'id' SQL Injection 7 WEB S.W.A.T.
2008-08-19   SunShop Shopping Cart 4.1.4 - 'id' SQL Injection 7 WEB GulfTech Security
2008-08-19   Ad Board - 'id' SQL Injection 7 WEB Hussin X
2008-08-19   Affiliate Directory - 'id' SQL Injection 7 WEB Hussin X
2008-08-19   TWiki 4.2.0 - 'configure' Remote File Disclosure 7 WEB Th1nk3r
2008-08-18   PHP Live Helper 2.0.1 - Multiple Vulnerabilities 7 WEB GulfTech Security
2008-08-18   cyberBB 0.6 - Multiple SQL Injections 7 WEB cOndemned
2008-08-18   VidiScript (Avatar) - Arbitrary File Upload 7 WEB InjEctOr5
2008-08-17   PHPBasket - 'pro_id' SQL Injection 7 WEB r45c4l
2008-08-17   phpArcadeScript 4 - 'cat' SQL Injection 7 WEB Hussin X
2008-08-17   XNova 0.8 sp1 - 'xnova_root_path' Remote File Inclusion 7 WEB NuclearHaxor
2008-08-15   deeemm CMS (dmcms) 0.7.4 - Multiple Vulnerabilities 6 WEB Khashayar Fereidani
2008-08-15   Zeeways ZeeJobsite 2.0 - 'adid' SQL Injection 7 WEB Hussin X
2008-08-15   dotCMS 1.6 - 'id' Local File Inclusion 7 WEB Don
2008-08-13   gelato CMS 0.95 - 'img' Remote File Disclosure 7 WEB JIKO
2008-08-12   Joomla! 1.5.x - 'Token' Remote Admin Change Password 7 WEB d3m0n
2008-08-12   BBlog 0.7.6 - 'mod' SQL Injection 8 WEB IP-Sh0k