2008-06-08
|
|
Joomla! Component yvComment 1.16 - Blind SQL Injection
|
4 |
WEB
|
His0k4
|
2008-06-08
|
|
phpinv 0.8.0 - Local File Inclusion / Cross-Site Scripting
|
4 |
WEB
|
CWH Underground
|
2008-06-08
|
|
JiRo's FAQ Manager eXperience 1.0 - 'fID' SQL Injection
|
4 |
WEB
|
Zigma
|
2008-06-07
|
|
Joomla! Component GameQ 4.0 - SQL Injection
|
4 |
WEB
|
His0k4
|
2008-06-05
|
|
Joomla! Component JoomlaDate 1.2 - 'user' SQL Injection
|
4 |
WEB
|
His0k4
|
2008-06-05
|
|
pSys 0.7.0.a - 'shownews' SQL Injection
|
4 |
WEB
|
anonymous
|
2008-06-05
|
|
Power Phlogger 2.2.5 - 'css_str' SQL Injection
|
4 |
WEB
|
MustLive
|
2008-06-05
|
|
Joomla! Component SimpleShop 3.4 - SQL Injection
|
4 |
WEB
|
His0k4
|
2008-06-05
|
|
427bb 2.3.1 - SQL Injection / Cross-Site Scripting
|
3 |
WEB
|
CWH Underground
|
2008-06-04
|
|
Joomla! Component EasyBook 1.1 - 'gbid' SQL Injection
|
4 |
WEB
|
ZAMUT
|
2008-06-04
|
|
PHP-Address Book 3.1.5 - SQL Injection / Cross-Site Scripting
|
4 |
WEB
|
CWH Underground
|
2008-06-04
|
|
Joomla! Component Jotloader 1.2.1.a - Blind SQL Injection
|
4 |
WEB
|
His0k4
|
2008-06-03
|
|
1Book Guestbook Script 1.0.1 - Code Execution
|
4 |
WEB
|
JIKO
|
2008-06-03
|
|
Joomla! Component JooBlog 0.1.1 - Blind SQL Injection
|
4 |
WEB
|
His0k4
|
2008-06-03
|
|
QuickerSite 1.8.5 - Multiple Vulnerabilities
|
3 |
WEB
|
BugReport.IR
|
2008-06-03
|
|
Battle Blog 1.25 - 'comment.asp' SQL Injection
|
4 |
WEB
|
Bl@ckbe@rD
|
2008-06-03
|
|
Joomla! Component iDoBlog b24 - SQL Injection
|
4 |
WEB
|
His0k4
|
2008-06-03
|
|
Joomla! Component JoomRadio 1.0 - 'id' SQL Injection
|
4 |
WEB
|
His0k4
|
2008-06-03
|
|
FlashBlog 0.31b - Arbitrary File Upload
|
4 |
WEB
|
ilker Kandemir
|
2008-06-02
|
|
smeweb 1.4b - SQL Injection / Cross-Site Scripting
|
4 |
WEB
|
CWH Underground
|
2008-06-02
|
|
PLog 1.0.6 - 'albumID' SQL Injection
|
4 |
WEB
|
DreamTurk
|
2008-06-02
|
|
Joomla! Component equotes 0.9.4 - SQL Injection
|
4 |
WEB
|
His0k4
|
2008-06-02
|
|
Booby 1.0.1 - Multiple Remote File Inclusions
|
4 |
WEB
|
HaiHui
|
2008-06-02
|
|
Joomla! Component acctexp 0.12.x - Blind SQL Injection
|
4 |
WEB
|
His0k4
|
2008-06-01
|
|
Joomla! Component JooBB 0.5.9 - Blind SQL Injection
|
4 |
WEB
|
His0k4
|
2008-06-01
|
|
I-Pos Internet Pay Online Store 1.3 Beta - SQL Injection
|
4 |
WEB
|
KnocKout
|
2008-06-01
|
|
mebiblio 0.4.7 - SQL Injection / Arbitrary File Upload / Cross-Site Scripting
|
4 |
WEB
|
CWH Underground
|
2008-06-01
|
|
DesktopOnNet 3 Beta - Multiple Remote File Inclusions
|
4 |
WEB
|
MK
|
2008-06-01
|
|
Joomla! Component MyContent 1.1.13 - Blind SQL Injection
|
4 |
WEB
|
His0k4
|
2008-06-01
|
|
ComicShout 2.8 - 'news_id' SQL Injection
|
4 |
WEB
|
JosS
|
2008-06-01
|
|
Social Site Generator 2.0 - Multiple Remote File Disclosure Vulnerabilities
|
4 |
WEB
|
Stack
|
2008-05-31
|
|
Joomla! Component Bible Study 1.5.0 - 'id' SQL Injection
|
4 |
WEB
|
Stack
|
2008-05-31
|
|
Joomla! Component prayercenter 1.4.9 - 'id' SQL Injection
|
4 |
WEB
|
His0k4
|
2008-05-31
|
|
Social Site Generator 2.0 - 'path' Remote File Inclusion
|
4 |
WEB
|
vBmad
|
2008-05-31
|
|
EasyWay CMS - 'mid' SQL Injection
|
4 |
WEB
|
Lidloses_Auge
|
2008-05-31
|
|
BP Blog 6.0 - 'id' Blind SQL Injection
|
4 |
WEB
|
JosS
|
2008-05-31
|
|
PassWiki 0.9.16 RC3 - 'site_id' Local File Inclusion
|
4 |
WEB
|
mozi
|
2008-05-31
|
|
PHP Visit Counter 0.4 - 'datespan' SQL Injection
|
4 |
WEB
|
Lidloses_Auge
|
2008-05-31
|
|
Azuresites CMS - Multiple Vulnerabilities
|
3 |
WEB
|
Lidloses_Auge
|
2008-05-31
|
|
Social Site Generator 2.0 - 'sgc_id' SQL Injection
|
3 |
WEB
|
DeAr Ev!L
|
2008-05-31
|
|
CMSimple 3.1 - Local File Inclusion / Arbitrary File Upload
|
4 |
WEB
|
irk4z
|
2008-05-31
|
|
PsychoStats 2.3.3 - Multiple SQL Injections
|
4 |
WEB
|
Mr.SQL
|
2008-05-30
|
|
HiveMaker Professional 1.0.2 - 'cid' SQL Injection
|
4 |
WEB
|
K-159
|
2008-05-29
|
|
PHP Booking Calendar 10 d - 'FCKeditor' Arbitrary File Upload
|
4 |
WEB
|
Stack
|
2008-05-29
|
|
phpBookingCalendar 10 d - SQL Injection
|
4 |
WEB
|
Stack
|
2008-05-29
|
|
CMS from Scratch 1.1.3 - 'image.php' Directory Traversal
|
4 |
WEB
|
Stack
|
2008-05-29
|
|
Mambo Component mambads 1.0 RC1 Beta - SQL Injection
|
4 |
WEB
|
Houssamix
|
2008-05-29
|
|
CMS from Scratch 1.1.3 - 'FCKeditor' Arbitrary File Upload
|
4 |
WEB
|
EgiX
|
2008-05-29
|
|
PicoFlat CMS 0.5.9 (Windows) - Local File Inclusion
|
4 |
WEB
|
gmda
|
2008-05-29
|
|
AirvaeCommerce 3.0 - 'pid' SQL Injection
|
4 |
WEB
|
QTRinux
|
2008-05-29
|
|
SyntaxCMS 1.3 - 'FCKeditor' Arbitrary File Upload
|
4 |
WEB
|
Stack
|
2008-05-28
|
|
FlashBlog - 'articulo_id' SQL Injection
|
4 |
WEB
|
HER0
|
2008-05-28
|
|
Joomla! Component Artist - 'idgalery' SQL Injection
|
4 |
WEB
|
Cr@zy_King
|
2008-05-28
|
|
PHPhotoalbum 0.5 - Multiple SQL Injections
|
4 |
WEB
|
cOndemned
|
2008-05-27
|
|
OtomiGen.x 2.2 - 'lang' Local File Inclusion
|
3 |
WEB
|
Saime
|
2008-05-27
|
|
CKGold Shopping Cart 2.5 - 'category_id' SQL Injection
|
4 |
WEB
|
Cr@zy_King
|
2008-05-27
|
|
RevokeBB 1.0 RC11 - 'Search' SQL Injection
|
4 |
WEB
|
The:Paradox
|
2008-05-26
|
|
CMS MAXSITE 1.10 - 'category' SQL Injection
|
4 |
WEB
|
Tesz
|
2008-05-26
|
|
RoomPHPlanning 1.5 - Multiple SQL Injections
|
4 |
WEB
|
Virangar Security
|
2008-05-26
|
|
RoomPHPlanning 1.5 - Arbitrary Add Admin
|
4 |
WEB
|
Stack
|
2008-05-25
|
|
Xomol CMS 1.2 - Authentication Bypass / Local File Inclusion
|
4 |
WEB
|
DNX
|
2008-05-25
|
|
plusphp url shortening software 1.6 - Remote File Inclusion
|
4 |
WEB
|
DR.TOXIC
|
2008-05-24
|
|
PHPRaider 1.0.7 - 'PHPbb3.functions.php' Remote File Inclusion
|
4 |
WEB
|
Kacak
|
2008-05-24
|
|
RoomPHPlanning 1.5 - 'idresa' SQL Injection
|
4 |
WEB
|
His0k4
|
2008-05-23
|
|
OneCMS 2.5 - 'install_mod.php' Local File Inclusion
|
4 |
WEB
|
DSecRG
|
2008-05-23
|
|
Quate CMS 0.3.4 - Multiple Vulnerabilities
|
4 |
WEB
|
DSecRG
|
2008-05-22
|
|
e107 Plugin BLOG Engine 2.2 - 'uid' Blind SQL Injection
|
4 |
WEB
|
Virangar Security
|
2008-05-21
|
|
Netbutikker 4 - SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2008-05-21
|
|
Weblosninger 4 - Cross-Site Scripting / SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2008-05-21
|
|
6rbScript - 'news.php' SQL Injection
|
4 |
WEB
|
Hussin X
|
2008-05-21
|
|
Alcatel OmniPCX Office 210/061.1 - Remote Command Execution
|
4 |
WEB
|
DSecRG
|
2008-05-21
|
|
Netious CMS 0.4 - 'pageid' SQL Injection
|
4 |
WEB
|
InjEctOr5
|
2008-05-20
|
|
PHP Jokesite 2.0 - 'cat_id' SQL Injection
|
4 |
WEB
|
InjEctOr5
|
2008-05-20
|
|
MX-System 2.7.3 - 'index.php' SQL Injection
|
3 |
WEB
|
cOndemned
|
2008-05-20
|
|
ComicShout 2.5 - 'comic_id' SQL Injection
|
4 |
WEB
|
Niiub
|
2008-05-20
|
|
Mantis Bug Tracker 1.1.1 - Code Execution / Cross-Site Scripting / Cross-Site Request Forgery
|
4 |
WEB
|
USH
|
2008-05-20
|
|
eCMS 0.4.2 - SQL Injection / Security Bypass
|
4 |
WEB
|
Virangar Security
|
2008-05-20
|
|
EntertainmentScript 1.4.0 - 'page.php' Local File Inclusion
|
4 |
WEB
|
Stack
|
2008-05-19
|
|
EntertainmentScript 1.4.0 - 'play.php' SQL Injection
|
4 |
WEB
|
Mr.SQL
|
2008-05-19
|
|
MercuryBoard 1.1.5 - 'login.php' Blind SQL Injection
|
3 |
WEB
|
EgiX
|
2008-05-19
|
|
AlkalinePHP 0.80.00 Beta - 'thread.php' SQL Injection
|
4 |
WEB
|
Stack
|
2008-05-19
|
|
microssys CMS 1.5 - Remote File Inclusion
|
4 |
WEB
|
Raz0r
|
2008-05-18
|
|
MyPicGallery 1.0 - Arbitrary Add Admin
|
3 |
WEB
|
t0pP8uZz
|
2008-05-18
|
|
PHP-AGTC Membership System 1.1a - Arbitrary Add Admin
|
4 |
WEB
|
t0pP8uZz
|
2008-05-18
|
|
MeltingIce File System 1.0 - Arbitrary Add User
|
4 |
WEB
|
t0pP8uZz
|
2008-05-18
|
|
GNU/Gallery 1.1.1.0 - 'admin.php' Local File Inclusion
|
4 |
WEB
|
t0pP8uZz
|
2008-05-18
|
|
Easycms 0.4.2 - Multiple Vulnerabilities
|
4 |
WEB
|
t0pP8uZz
|
2008-05-18
|
|
AlkalinePHP 0.77.35 - 'adduser.php' Arbitrary Add Admin
|
4 |
WEB
|
t0pP8uZz
|
2008-05-18
|
|
Lulieblog 1.2 - Multiple Vulnerabilities
|
3 |
WEB
|
Cod3rZ
|
2008-05-18
|
|
Ajax Framework - 'lang' Local File Inclusion
|
4 |
WEB
|
dun
|
2008-05-18
|
|
TAGWORX.CMS 3.00.02 - Multiple SQL Injections
|
4 |
WEB
|
dun
|
2008-05-18
|
|
CMS WebManager-Pro - Multiple SQL Injections
|
3 |
WEB
|
dun
|
2008-05-17
|
|
Smeego 1.0 - 'Cookie lang' Local File Inclusion
|
4 |
WEB
|
0in
|
2008-05-17
|
|
FicHive 1.0 - 'category' Blind SQL Injection
|
4 |
WEB
|
His0k4
|
2008-05-17
|
|
How2ASP.net WebBoard 4.1 - SQL Injection
|
4 |
WEB
|
CWH Underground
|
2008-05-17
|
|
WR-Meeting 1.0 - 'msnum' Local File Disclosure
|
4 |
WEB
|
Cr@zy_King
|
2008-05-16
|
|
Zomplog 3.8.2 - 'force_download.php' File Disclosure
|
4 |
WEB
|
Stack
|
2008-05-16
|
|
Archangel Weblog 0.90.02 - 'post_id' SQL Injection
|
4 |
WEB
|
Stack
|
2008-05-16
|
|
Zomplog 3.8.2 - 'newuser.php' Arbitrary Add Admin
|
4 |
WEB
|
ArxWolf
|
2008-05-16
|
|
StanWeb.CMS - SQL Injection
|
4 |
WEB
|
JosS
|
2008-05-15
|
|
IMGallery 2.5 - Multiple SQL Injections
|
4 |
WEB
|
cOndemned
|
2008-05-15
|
|
Multi-Page Comment System 1.1.0 - Insecure Cookie Handling
|
3 |
WEB
|
t0pP8uZz
|
2008-05-15
|
|
Web Slider 0.6 - Insecure Cookie/Authentication Handling
|
4 |
WEB
|
t0pP8uZz
|
2008-05-15
|
|
RantX 1.0 - Insecure Admin Authentication
|
4 |
WEB
|
t0pP8uZz
|
2008-05-15
|
|
Pet Grooming Management System 2.0 - Arbitrary Add Admin
|
3 |
WEB
|
t0pP8uZz
|
2008-05-15
|
|
68 Classifieds 4.0 - 'category.php' SQL Injection
|
4 |
WEB
|
HaCkeR_EgY
|
2008-05-15
|
|
newsmanager 2.0 - Remote File Inclusion / File Disclosure / SQL Injection
|
4 |
WEB
|
GoLd_M
|
2008-05-15
|
|
Kostenloses Linkmanagementscript - SQL Injection
|
5 |
WEB
|
Virangar Security
|
2008-05-14
|
|
Kostenloses Linkmanagementscript - Remote File Inclusion
|
4 |
WEB
|
HaCkeR_EgY
|
2008-05-14
|
|
rgboard 3.0.12 - Remote File Inclusioni / Cross-Site Scripting
|
4 |
WEB
|
e.wiZz!
|
2008-05-14
|
|
Lanius CMS 1.2.16 - 'FCKeditor' Arbitrary File Upload
|
4 |
WEB
|
EgiX
|
2008-05-14
|
|
Internet PhotoShow (Special Edition) - Insecure Cookie Handling
|
4 |
WEB
|
t0pP8uZz
|
2008-05-14
|
|
ActiveKB 1.5 - Insecure Cookie Handling/Arbitrary Admin Access
|
4 |
WEB
|
t0pP8uZz
|
2008-05-14
|
|
AS-GasTracker 1.0.0 - Insecure Cookie Handling
|
4 |
WEB
|
t0pP8uZz
|
2008-05-14
|
|
Feedback and Rating Script 1.0 - 'detail.php' SQL Injection
|
4 |
WEB
|
t0pP8uZz
|
2008-05-14
|
|
Freelance Auction Script 1.0 - 'browseproject.php' SQL Injection
|
4 |
WEB
|
t0pP8uZz
|
2008-05-13
|
|
Linkspile - 'cat_id' SQL Injection
|
4 |
WEB
|
HaCkeR_EgY
|
2008-05-13
|
|
The Real Estate Script - 'docID' SQL Injection
|
4 |
WEB
|
HaCkeR_EgY
|
2008-05-13
|
|
EMO Realty Manager - 'ida' SQL Injection
|
4 |
WEB
|
HaCkeR_EgY
|
2008-05-13
|
|
Meto Forum 1.1 - Multiple SQL Injections
|
4 |
WEB
|
U238
|
2008-05-13
|
|
CaLogic Calendars 1.2.2 - 'langsel' SQL Injection
|
4 |
WEB
|
His0k4
|
2008-05-13
|
|
Web Group Communication Center (WGCC) 1.0.3 - SQL Injection
|
4 |
WEB
|
myvx
|
2008-05-13
|
|
e-107 Plugin ZoGo-Shop 1.16 Beta 13 - SQL Injection
|
4 |
WEB
|
Cr@zy_King
|
2008-05-13
|
|
e107 Plugin BLOG Engine 2.2 - 'rid' Blind SQL Injection
|
4 |
WEB
|
Saime
|
2008-05-13
|
|
EQdkp 1.3.2f - 'user_id' Authentication Bypass
|
4 |
WEB
|
vortfu
|