2008-08-02
|
|
moziloCMS 1.10.1 - 'download.php' Arbitrary Download File
|
3 |
WEB
|
Ams
|
2008-08-02
|
|
E-Store Kit-1 < 2 PayPal Edition - 'pid' SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2008-08-02
|
|
k-links directory - SQL Injection / Cross-Site Scripting
|
5 |
WEB
|
Corwin
|
2008-08-02
|
|
e-vision CMS 2.02 - SQL Injection / Arbitrary File Upload / Information Gathering
|
4 |
WEB
|
Khashayar Fereidani
|
2008-08-01
|
|
phsBlog 0.1.1 - Multiple SQL Injections
|
4 |
WEB
|
cOndemned
|
2008-08-01
|
|
GreenCart PHP Shopping Cart - 'id' SQL Injection
|
5 |
WEB
|
Hussin X
|
2008-08-01
|
|
eStoreAff 0.1 - 'cid' SQL Injection
|
3 |
WEB
|
Mr.SQL
|
2008-08-01
|
|
Scripts24 iPost 1.0.1 - 'id' SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2008-08-01
|
|
Scripts24 iTGP 1.0.4 - 'id' SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2008-08-01
|
|
E-topbiz Dating 3 PHP Script - 'mail_id' SQL Injection
|
4 |
WEB
|
Corwin
|
2008-08-01
|
|
ABG Blocking Script 1.0a - 'abg_path' Remote File Inclusion
|
3 |
WEB
|
Lo$er
|
2008-08-01
|
|
phpAuction GPL Enhanced 2.51 - 'profile.php' SQL Injection
|
4 |
WEB
|
Hussin X
|
2008-08-01
|
|
phpMyRealty 2.0.0 - 'location' SQL Injection
|
4 |
WEB
|
CraCkEr
|
2008-07-31
|
|
LetterIt 2 - 'Language' Local File Inclusion
|
4 |
WEB
|
NoGe
|
2008-07-31
|
|
Coppermine Photo Gallery 1.4.18 - Local File Inclusion / Remote Code Execution
|
4 |
WEB
|
EgiX
|
2008-07-31
|
|
Symphony 1.7.01 (non-patched) - Remote Code Execution
|
4 |
WEB
|
Raz0r
|
2008-07-31
|
|
PHPX 3.5.16 - Cookie Poisoning / Authentication Bypass
|
4 |
WEB
|
gnix
|
2008-07-30
|
|
Pligg CMS 9.9.0 - Cross-Site Scripting / Local File Inclusion / SQL Injection
|
4 |
WEB
|
GulfTech Security
|
2008-07-30
|
|
Pligg CMS 9.9.0 - Remote Code Execution
|
4 |
WEB
|
GulfTech Security
|
2008-07-30
|
|
eNdonesia 8.4 (Calendar Module) - SQL Injection
|
4 |
WEB
|
Jack
|
2008-07-30
|
|
TubeGuru Video Sharing Script - 'UID' SQL Injection
|
4 |
WEB
|
Hussin X
|
2008-07-30
|
|
PozScripts Classified Ads Script - 'cid' SQL Injection
|
4 |
WEB
|
Hussin X
|
2008-07-30
|
|
HIOX Browser Statistics 2.0 - Arbitrary Add Admin
|
4 |
WEB
|
Stack
|
2008-07-30
|
|
Article Friendly Pro/Standard - SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2008-07-30
|
|
HIOX Random Ad 1.3 - Arbitrary Add Admin
|
4 |
WEB
|
Stack
|
2008-07-30
|
|
ZeeReviews - SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2008-07-30
|
|
nzFotolog 0.4.1 - 'action_file' Local File Inclusion
|
5 |
WEB
|
Khashayar Fereidani
|
2008-07-30
|
|
PHP Hosting Directory 2.0 - Insecure Cookie Handling
|
4 |
WEB
|
Stack
|
2008-07-30
|
|
HIOX Browser Statistics 2.0 - Remote File Inclusion
|
4 |
WEB
|
Ghost Hacker
|
2008-07-30
|
|
HIOX Random Ad 1.3 - Remote File Inclusion
|
4 |
WEB
|
Ghost Hacker
|
2008-07-29
|
|
PHP Hosting Directory 2.0 - Remote File Inclusion
|
4 |
WEB
|
RoMaNcYxHaCkEr
|
2008-07-29
|
|
Gregarius 0.5.4 - SQL Injection
|
4 |
WEB
|
GulfTech Security
|
2008-07-29
|
|
e107 Plugin BLOG Engine 2.2 - Blind SQL Injection
|
4 |
WEB
|
Virangar Security
|
2008-07-29
|
|
Minishowcase 09b136 - 'lang' Local File Inclusion
|
4 |
WEB
|
DSecRG
|
2008-07-28
|
|
ViArt Shop 3.5 - 'category_id' SQL Injection
|
4 |
WEB
|
GulfTech Security
|
2008-07-28
|
|
ATutor 1.6.1-pl1 - 'import.php' Remote File Inclusion
|
4 |
WEB
|
Khashayar Fereidani
|
2008-07-28
|
|
PixelPost 1.7.1 - 'language_full' Local File Inclusion
|
4 |
WEB
|
DSecRG
|
2008-07-28
|
|
Dokeos E-Learning System 1.8.5 - Local File Inclusion
|
4 |
WEB
|
DSecRG
|
2008-07-28
|
|
TalkBack 2.3.5 - 'Language' Local File Inclusion
|
4 |
WEB
|
NoGe
|
2008-07-28
|
|
Youtuber Clone - SQL Injection
|
4 |
WEB
|
Hussin X
|
2008-07-28
|
|
Pligg CMS 9.9.0 - 'story.php' SQL Injection
|
4 |
WEB
|
Hussin X
|
2008-07-27
|
|
SiteAdmin CMS - 'art' SQL Injection
|
3 |
WEB
|
Cr@zy_King
|
2008-07-27
|
|
GC Auction Platinum - 'cate_id' SQL Injection
|
4 |
WEB
|
Hussin X
|
2008-07-27
|
|
Getacoder clone - 'sb_protype' SQL Injection
|
4 |
WEB
|
Hussin X
|
2008-07-27
|
|
CMScout 2.05 - 'bit' Local File Inclusion
|
5 |
WEB
|
Khashayar Fereidani
|
2008-07-26
|
|
TriO 2.1 - 'browse.php' SQL Injection
|
4 |
WEB
|
dun
|
2008-07-26
|
|
phpLinkat 0.1 - Insecure Cookie Handling / SQL Injection
|
4 |
WEB
|
Encrypt3d.M!nd
|
2008-07-26
|
|
EPShop < 3.0 - 'pid' SQL Injection
|
3 |
WEB
|
mikeX
|
2008-07-26
|
|
Mobius 1.4.4.1 - SQL Injection
|
4 |
WEB
|
dun
|
2008-07-26
|
|
IceBB 1.0-RC9.2 - Blind SQL Injection / Session Hijacking
|
4 |
WEB
|
girex
|
2008-07-26
|
|
PHPwebnews 0.2 MySQL Edition - 'SQL' Insecure Cookie Handling
|
4 |
WEB
|
Virangar Security
|
2008-07-26
|
|
FipsCMS Light 2.1 - 'r' SQL Injection
|
4 |
WEB
|
U238
|
2008-07-25
|
|
PHPTest 0.6.3 - SQL Injection
|
4 |
WEB
|
cOndemned
|
2008-07-25
|
|
FizzMedia 1.51.2 - SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2008-07-25
|
|
Camera Life 2.6.2 - 'id' SQL Injection
|
4 |
WEB
|
nuclear
|
2008-07-25
|
|
XRms 1.99.2 - Remote File Inclusion / Cross-Site Scripting / Information Gathering
|
4 |
WEB
|
AzzCoder
|
2008-07-24
|
|
Live Music Plus 1.1.0 - 'id' SQL Injection
|
4 |
WEB
|
IRAQI
|
2008-07-24
|
|
WordPress Plugin Download Manager 0.2 - Arbitrary File Upload
|
4 |
WEB
|
SaO
|
2008-07-24
|
|
ibase 2.03 - Remote File Disclosure
|
4 |
WEB
|
Dyshoo
|
2008-07-24
|
|
Atom Photoblog 1.1.5b1 - 'photoId' SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2008-07-22
|
|
Pre Survey Poll - 'catid' SQL Injection
|
4 |
WEB
|
DreamTurk
|
2008-07-22
|
|
YouTube blog 0.1 - Remote File Inclusion / SQL Injection / Cross-Site Scripting
|
4 |
WEB
|
Unohope
|
2008-07-21
|
|
EZWebAlbum - Insecure Cookie Handling
|
4 |
WEB
|
Virangar Security
|
2008-07-21
|
|
ShopCartDx 4.30 - 'pid' SQL Injection
|
4 |
WEB
|
Cr@zy_King
|
2008-07-21
|
|
Arctic Issue Tracker 2.0.0 - 'filter' SQL Injection (2)
|
4 |
WEB
|
ldma
|
2008-07-21
|
|
EZWebAlbum - Remote File Disclosure
|
2 |
WEB
|
Ghost Hacker
|
2008-07-21
|
|
MojoAuto - Blind SQL Injection
|
3 |
WEB
|
Mr.SQL
|
2008-07-21
|
|
MojoJobs - Blind SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2008-07-21
|
|
MojoPersonals - Blind SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2008-07-21
|
|
MojoClassifieds 2.0 - Blind SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2008-07-21
|
|
Interact 2.4.1 - 'help.php' Local File Inclusion
|
5 |
WEB
|
DSecRG
|
2008-07-21
|
|
HRS Multi - 'key' Blind SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2008-07-21
|
|
DigiLeave 1.2 - 'book_id' Blind SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2008-07-20
|
|
PHPFootball 1.6 - SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2008-07-18
|
|
Siteframe CMS 3.2.3 - 'folder.php' SQL Injection
|
3 |
WEB
|
n0ne
|
2008-07-18
|
|
Aprox CMS Engine 5.1.0.4 - 'index.php' SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2008-07-17
|
|
Arctic Issue Tracker 2.0.0 - 'filter' SQL Injection (1)
|
4 |
WEB
|
QTRinux
|
2008-07-17
|
|
preCMS 1 - 'index.php' SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2008-07-17
|
|
Alstrasoft Article Manager Pro 1.6 - Blind SQL Injection
|
4 |
WEB
|
GoLd_M
|
2008-07-17
|
|
Alstrasoft Video Share Enterprise 4.5.1 - 'UID' SQL Injection
|
4 |
WEB
|
Hussin X
|
2008-07-17
|
|
PHPHoo3 < 5.2.6 - 'viewCat' SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2008-07-16
|
|
tplSoccerSite 1.0 - Multiple SQL Injections
|
4 |
WEB
|
Mr.SQL
|
2008-07-16
|
|
Alstrasoft Affiliate Network Pro - 'pgm' SQL Injection
|
4 |
WEB
|
Hussin X
|
2008-07-16
|
|
Joomla! Component DT Register - SQL Injection
|
4 |
WEB
|
His0k4
|
2008-07-16
|
|
PHPizabi 0.848b C1 HFP1 - Remote Code Execution
|
3 |
WEB
|
Inphex
|
2008-07-15
|
|
HockeySTATS Online 2.0 - Multiple SQL Injections
|
4 |
WEB
|
Mr.SQL
|
2008-07-15
|
|
PhotoPost vBGallery 2.4.2 - Arbitrary File Upload
|
4 |
WEB
|
Cold Zero
|
2008-07-15
|
|
Galatolo Web Manager 1.3a - Insecure Cookie Handling
|
4 |
WEB
|
Virangar Security
|
2008-07-15
|
|
PHP Help Agent 1.1 - 'content' Local File Inclusion
|
4 |
WEB
|
BeyazKurt
|
2008-07-15
|
|
Comdev Web Blogger 4.1.3 - 'arcmonth' SQL Injection
|
4 |
WEB
|
K-159
|
2008-07-15
|
|
Pragyan CMS 2.6.2 - 'sourceFolder' Remote File Inclusion
|
4 |
WEB
|
N3TR00T3R
|
2008-07-15
|
|
pSys 0.7.0 Alpha - Multiple Remote File Inclusions
|
4 |
WEB
|
RoMaNcYxHaCkEr
|
2008-07-15
|
|
Galatolo Web Manager 1.3a - Cross-Site Scripting / SQL Injection
|
4 |
WEB
|
StAkeR
|
2008-07-14
|
|
Pluck CMS 4.5.1 (Windows) - 'blogpost' Local File Inclusion
|
4 |
WEB
|
BugReport.IR
|
2008-07-14
|
|
bilboblog 2.1 - Multiple Vulnerabilities
|
4 |
WEB
|
BlackH
|
2008-07-14
|
|
CodeDB 1.1.1 - 'list.php' Local File Inclusion
|
4 |
WEB
|
cOndemned
|
2008-07-13
|
|
Scripteen Free Image Hosting Script 1.2 - 'cookie' Pass Grabber
|
4 |
WEB
|
RMx
|
2008-07-13
|
|
ITechBids 7.0 gold - Cross-Site Scripting / SQL Injection
|
4 |
WEB
|
Encrypt3d.M!nd
|
2008-07-13
|
|
MFORUM 0.1a - Arbitrary Add Admin
|
4 |
WEB
|
CWH Underground
|
2008-07-13
|
|
Ultrastats 0.2.142 - 'players-detail.php' Blind SQL Injection
|
4 |
WEB
|
DNX
|
2008-07-13
|
|
Maian Search 1.1 - Insecure Cookie Handling
|
4 |
WEB
|
S.W.A.T.
|
2008-07-13
|
|
Maian Uploader 4.0 - Insecure Cookie Handling
|
4 |
WEB
|
S.W.A.T.
|
2008-07-13
|
|
Maian Weblog 4.0 - Insecure Cookie Handling
|
5 |
WEB
|
S.W.A.T.
|
2008-07-13
|
|
Maian Recipe 1.2 - Insecure Cookie Handling
|
4 |
WEB
|
S.W.A.T.
|
2008-07-13
|
|
Maian Links 3.1 - Insecure Cookie Handling
|
4 |
WEB
|
S.W.A.T.
|
2008-07-13
|
|
Maian Guestbook 3.2 - Insecure Cookie Handling
|
4 |
WEB
|
S.W.A.T.
|
2008-07-13
|
|
Fuzzylime CMS 3.01 - 'commrss.php' Remote Code Execution
|
2 |
WEB
|
Charles Fol
|
2008-07-12
|
|
Avlc Forum - 'vlc_forum.php' SQL Injection
|
4 |
WEB
|
CWH Underground
|
2008-07-12
|
|
jsite 1.0 oe - SQL Injection / Local File Inclusion
|
4 |
WEB
|
S.W.A.T.
|
2008-07-12
|
|
WebCMS Portal Edition - 'id' SQL Injection
|
3 |
WEB
|
Mr.SQL
|
2008-07-12
|
|
Joomla! Component n-forms 1.01 - Blind SQL Injection
|
4 |
WEB
|
The Moorish
|
2008-07-12
|
|
Fuzzylime CMS 3.01 - 'poll' Remote Code Execution
|
4 |
WEB
|
Inphex & real
|
2008-07-12
|
|
Fuzzylime CMS 3.01 - 'poll' Remote Code Execution
|
4 |
WEB
|
Inphex & real
|
2008-07-12
|
|
Maian Music 1.0 - Insecure Cookie Handling
|
4 |
WEB
|
Saime
|
2008-07-12
|
|
Maian Greetings 2.1 - Insecure Cookie Handling
|
4 |
WEB
|
Saime
|
2008-07-12
|
|
Maian Gallery 2.0 - Insecure Cookie Handling
|
4 |
WEB
|
Saime
|
2008-07-12
|
|
Maian Events 2.0 - Insecure Cookie Handling
|
4 |
WEB
|
Saime
|
2008-07-12
|
|
Maian Cart 1.1 - Insecure Cookie Handling
|
4 |
WEB
|
Saime
|
2008-07-11
|
|
Million Pixels 3 - 'id_cat' SQL Injection
|
4 |
WEB
|
Hussin X
|
2008-10-20
|
|
Wysi Wiki Wyg 1.0 - Local File Inclusion / Cross-Site Scripting / PHPInfo
|
4 |
WEB
|
StAkeR
|
2008-07-11
|
|
facebook newsroom CMS 0.5.0 Beta 1 - Remote File Inclusion
|
4 |
WEB
|
Ciph3r
|
2008-07-11
|
|
File Store PRO 3.2 - Multiple Blind SQL Injections
|
3 |
WEB
|
Nu Am Bani
|
2008-07-10
|
|
phpDatingClub 3.7 - 'website.php' Local File Inclusion
|
4 |
WEB
|
S.W.A.T.
|
2008-07-10
|
|
gapicms 9.0.2 - 'dirDepth' Remote File Inclusion
|
4 |
WEB
|
Ghost Hacker
|
2008-07-10
|
|
DreamNews Manager - 'id' SQL Injection
|
4 |
WEB
|
Hussin X
|