Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2008-05-16   Zomplog 3.8.2 - 'force_download.php' File Disclosure 34 WEB Stack
2008-05-16   Archangel Weblog 0.90.02 - 'post_id' SQL Injection 34 WEB Stack
2008-05-16   Zomplog 3.8.2 - 'newuser.php' Arbitrary Add Admin 35 WEB ArxWolf
2008-05-16   StanWeb.CMS - SQL Injection 33 WEB JosS
2008-05-15   IMGallery 2.5 - Multiple SQL Injections 33 WEB cOndemned
2008-05-15   Multi-Page Comment System 1.1.0 - Insecure Cookie Handling 34 WEB t0pP8uZz
2008-05-15   Web Slider 0.6 - Insecure Cookie/Authentication Handling 33 WEB t0pP8uZz
2008-05-15   RantX 1.0 - Insecure Admin Authentication 33 WEB t0pP8uZz
2008-05-15   Pet Grooming Management System 2.0 - Arbitrary Add Admin 38 WEB t0pP8uZz
2008-05-15   68 Classifieds 4.0 - 'category.php' SQL Injection 35 WEB HaCkeR_EgY
2008-05-15   newsmanager 2.0 - Remote File Inclusion / File Disclosure / SQL Injection 38 WEB GoLd_M
2008-05-15   Kostenloses Linkmanagementscript - SQL Injection 34 WEB Virangar Security
2008-05-14   Kostenloses Linkmanagementscript - Remote File Inclusion 35 WEB HaCkeR_EgY
2008-05-14   rgboard 3.0.12 - Remote File Inclusioni / Cross-Site Scripting 33 WEB e.wiZz!
2008-05-14   Lanius CMS 1.2.16 - 'FCKeditor' Arbitrary File Upload 37 WEB EgiX
2008-05-14   Internet PhotoShow (Special Edition) - Insecure Cookie Handling 34 WEB t0pP8uZz
2008-05-14   ActiveKB 1.5 - Insecure Cookie Handling/Arbitrary Admin Access 35 WEB t0pP8uZz
2008-05-14   AS-GasTracker 1.0.0 - Insecure Cookie Handling 36 WEB t0pP8uZz
2008-05-14   Feedback and Rating Script 1.0 - 'detail.php' SQL Injection 33 WEB t0pP8uZz
2008-05-14   Freelance Auction Script 1.0 - 'browseproject.php' SQL Injection 34 WEB t0pP8uZz
2008-05-13   Linkspile - 'cat_id' SQL Injection 35 WEB HaCkeR_EgY
2008-05-13   The Real Estate Script - 'docID' SQL Injection 35 WEB HaCkeR_EgY
2008-05-13   EMO Realty Manager - 'ida' SQL Injection 32 WEB HaCkeR_EgY
2008-05-13   Meto Forum 1.1 - Multiple SQL Injections 34 WEB U238
2008-05-13   CaLogic Calendars 1.2.2 - 'langsel' SQL Injection 32 WEB His0k4
2008-05-13   Web Group Communication Center (WGCC) 1.0.3 - SQL Injection 33 WEB myvx
2008-05-13   e-107 Plugin ZoGo-Shop 1.16 Beta 13 - SQL Injection 31 WEB Cr@zy_King
2008-05-13   e107 Plugin BLOG Engine 2.2 - 'rid' Blind SQL Injection 33 WEB Saime
2008-05-13   EQdkp 1.3.2f - 'user_id' Authentication Bypass 34 WEB vortfu
2008-05-12   AJ HYIP ACME - 'topic_detail.php' SQL Injection 31 WEB InjEctOr5
2008-05-12   Advanced Image Hosting (AIH) 2.1 - SQL Injection 30 WEB Stack
2008-05-12   CMS Made Simple 1.2.4 Module FileManager - Arbitrary File Upload 36 WEB EgiX
2008-05-12   PHP Classifieds Script 05122008 - SQL Injection 31 WEB InjEctOr5
2008-05-12   Mega File Hosting Script 1.2 - 'fid' SQL Injection 35 WEB TurkishWarriorr
2008-05-12   Battle.net Clan Script 1.5.x - SQL Injection 35 WEB Stack
2008-05-12   BigACE 2.4 - Multiple Remote File Inclusions 36 WEB BiNgZa
2008-05-12   ClanLite 2.x - SQL Injection / Cross-Site Scripting 35 WEB ZoRLu
2008-05-12   ZeusCart 2.0 - 'category_list.php' SQL Injection 32 WEB t0pP8uZz
2008-05-12   AJ Classifieds 2008 - 'index.php' SQL Injection 31 WEB t0pP8uZz
2008-05-12   AJ Auction 6.2.1 - 'classifide_ad.php' SQL Injection 33 WEB t0pP8uZz
2008-05-12   AJ Article 1.0 - 'featured_article.php' SQL Injection 33 WEB t0pP8uZz
2008-05-11   Vortex CMS - 'pageid' Blind SQL Injection 35 WEB Lidloses_Auge
2008-05-11   QuickUpCMS - Multiple SQL Injections Vulnerabilities 32 WEB Lidloses_Auge
2008-05-11   Joomla! Component xsstream-dm 0.01b - SQL Injection 31 WEB Houssamix
2008-05-11   PhpBlock a8.5 - Multiple Remote File Inclusions 34 WEB CraCkEr
2008-05-10   Joomla! Component Datsogallery 1.6 - Blind SQL Injection 30 WEB +toxa+
2008-05-10   Ktools Photostore 3.5.2 - Multiple SQL Injections 34 WEB DNX
2008-05-10   Advanced Links Management (ALM) 1.52 - SQL Injection 35 WEB His0k4
2008-05-09   Ktools Photostore 3.5.1 - 'gid' SQL Injection 31 WEB Mr.SQL
2008-05-09   txtCMS 0.3 - 'index.php' Local File Inclusion 31 WEB cOndemned
2008-05-09   Phoenix View CMS Pre Alpha2 - SQL Injection / Local File Inclusion / Cross-Site Scripting 34 WEB tw8
2008-05-09   HispaH Model Search - 'cat.php?cat' SQL Injection 32 WEB InjEctOr5
2008-05-09   SazCart 1.5.1 - 'prodid' SQL Injection 34 WEB JosS
2008-05-09   Admidio 1.4.8 - 'getfile.php' Remote File Disclosure 35 WEB n3v3rh00d
2008-05-08   miniBloggie 1.0 - 'del.php' Arbitrary Delete Post 37 WEB Cod3rZ
2008-05-08   Cyberfolio 7.12 - 'rep' Remote File Inclusion 35 WEB RoMaNcYxHaCkEr
2008-05-08   SazCart 1.5.1 - Multiple Remote File Inclusions 34 WEB RoMaNcYxHaCkEr
2008-05-08   vShare YouTube Clone 2.6 - 'tid' SQL Injection 36 WEB Saime
2008-05-08   Shader TV (Beta) - Multiple SQL Injections 34 WEB U238
2008-05-08   RunCMS 1.6.1 - 'msg_image' SQL Injection 33 WEB The:Paradox
2008-05-07   MusicBox 2.3.7 - 'artistId' SQL Injection 35 WEB HaCkeR_EgY
2008-05-07   EZContents CMS 2.0.0 - Multiple SQL Injections 35 WEB Virangar Security
2008-05-07   CMS Faethon 2.2 Ultimate - Remote File Inclusion / Cross-Site Scripting 37 WEB RoMaNcYxHaCkEr
2008-05-07   OneCMS 2.5 - Blind SQL Injection 36 WEB Cod3rZ
2008-05-07   PostcardMentor - 'cat_fldAuto' SQL Injection 33 WEB InjEctOr5
2008-05-07   GameCMS Lite 1.0 - 'systemId' SQL Injection 35 WEB InjEctOr5
2008-05-07   Galleristic 1.0 - 'cat' SQL Injection 32 WEB cOndemned
2008-05-07   FipsCMS 2.1 - 'print.asp' SQL Injection 35 WEB InjEctOr5
2008-05-06   PHPEasyData 1.5.4 - 'cat_id' SQL Injection 30 WEB InjEctOr5
2008-05-06   Pre Shopping Mall 1.1 - 'search.php' SQL Injection 30 WEB t0pP8uZz
2008-05-05   DeluxeBB 1.2 - Multiple Vulnerabilities 33 WEB EgiX
2008-05-05   Power Editor 2.0 - Remote File Disclosure / Edit 36 WEB Virangar Security
2008-05-05   Miniweb 2.0 - 'historymonth' SQL Injection 38 WEB HaCkeR_EgY
2008-05-05   BackLinkSpider 1.1 - 'cat_id' SQL Injection 33 WEB K-159
2008-05-05   Kmita Mail 3.0 - 'file' Remote File Inclusion 33 WEB K-159
2008-05-05   Kmita Tellfriend 2.0 - 'file' Remote File Inclusion 33 WEB K-159
2008-05-05   Anserv Auction XL - 'cat' SQL Injection 32 WEB K-159
2008-05-05   Online Rental Property Script 4.5 - 'pid' SQL Injection 33 WEB K-159
2008-05-05   PostNuke Module pnEncyclopedia 0.2.0 - SQL Injection 34 WEB K-159
2008-05-04   Scout Portal Toolkit 1.4.0 - 'ParentId' SQL Injection 29 WEB JosS
2008-05-04   ScorpNews 1.0 - 'site' Remote File Inclusion 32 WEB Silver
2008-05-04   Cplinks 1.03 - Authentication Bypass / SQL Injection / Cross-Site Scripting 32 WEB InjEctOr5
2008-05-03   phpDirectorySource 1.1 - Multiple SQL Injections 32 WEB InjEctOr5
2008-05-03   SmartBlog 1.3 - 'index.php' SQL Injection 33 WEB His0k4
2008-05-03   BlogMe PHP 1.1 - 'comments.php' SQL Injection 33 WEB His0k4
2008-05-02   ItCMS 1.9 - 'boxpop.php' Remote Code Execution 31 WEB Cod3rZ
2008-05-02   Open Auto Classifieds 1.4.3b - SQL Injection 32 WEB InjEctOr5
2008-05-01   Vlbook 1.21 - Cross-Site Scripting / Local File Inclusion 35 WEB Khashayar Fereidani
2008-05-01   ActualAnalyzer Lite (free) 2.78 - Local File Inclusion 33 WEB Khashayar Fereidani
2008-05-01   Joomla! Component Webhosting - 'catid' Blind SQL Injection 30 WEB cO2
2008-04-30   Interact 2.4.1 - Multiple Remote File Inclusions 35 WEB RoMaNcYxHaCkEr
2008-04-30   Harris WapChat 1 - Multiple Remote File Inclusions 32 WEB k1n9k0ng
2008-04-30   OxYProject 0.85 - 'edithistory.php' Remote Code Execution 33 WEB GoLd_M
2008-04-30   Project Based Calendaring System (PBCS) 0.7.1 - Multiple Vulnerabilities 36 WEB GoLd_M
2008-04-29   LokiCMS 0.3.3 - Arbitrary File Delete 31 WEB cOndemned
2008-04-29   SugarCRM Community Edition 4.5.1/5.0.0 - File Disclosure 33 WEB Roberto Suggi Liverani
2008-04-28   Joovili 3.1 - 'browse.videos.php' SQL Injection 34 WEB HaCkeR_EgY
2008-04-28   Softbiz Web Host Directory Script - 'host_id' SQL Injection 32 WEB K-159
2008-04-28   Prozilla Hosting Index - 'cat_id' SQL Injection 33 WEB K-159
2008-04-27   Joomla! Component paxxgallery 0.2 - 'gid' Blind SQL Injection 33 WEB ZAMUT
2008-04-27   ODFaq 2.1.0 - Blind SQL Injection 32 WEB cO2
2008-04-27   Joomla! Component Alphacontent 2.5.8 - Blind SQL Injection 33 WEB cO2
2008-04-27   Content Management System for Phprojekt 0.6.1 - File Disclosure 34 WEB Houssamix
2008-04-27   FluentCMS - 'view.php' SQL Injection 33 WEB cO2
2008-04-27   Jokes Site Script - 'jokes.php' SQL Injection 31 WEB ProgenTR
2008-04-27   Megabbs Forum 2.2 - SQL Injection / Cross-Site Scripting 33 WEB BugReport.IR
2008-04-26   PHPizabi 0.848b C1 HFP3 - Database Information Disclosure 34 WEB YOUCODE
2008-04-26   RunCMS Module MyArticles 0.6 Beta-1 - SQL Injection 30 WEB Cr@zy_King
2008-04-26   PHP Forge 3 Beta 2 - 'id' SQL Injection 31 WEB JIKO
2008-04-26   Angelo-Emlak 1.0 - Multiple SQL Injections 35 WEB U238
2008-04-26   Clever Copy 3.0 - 'postview.php' SQL Injection 36 WEB U238
2008-04-26   Content Management System for Phprojekt 0.6.1 - Remote File Inclusion 35 WEB RoMaNcYxHaCkEr
2008-04-26   PostNuke Module pnFlashGames 2.5 - SQL Injection 35 WEB Kacper
2008-04-26   Siteman 2.x - Code Execution / Local File Inclusion / Cross-Site Scripting 36 WEB Khashayar Fereidani
2008-04-25   Joomla! Component Joomla-Visites 1.1 RC2 - Remote File Inclusion 34 WEB NoGe
2008-04-25   PostNuke Module PostSchedule 1.0 - 'eid' SQL Injection 36 WEB Kacper
2008-04-25   MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure 35 WEB girex
2008-04-24   Joomla! Component JPad 1.0 - (Authenticated) SQL Injection 37 WEB His0k4
2008-04-23   Joomla! Component Community Builder 1.0.1 - Blind SQL Injection 36 WEB $hur!k'n
2008-04-23   YouTube Clone Script - 'spages.php' Remote Code Execution 34 WEB Inphex
2008-04-23   Joomla! Component Filiale 1.0.4 - 'idFiliale' SQL Injection 37 WEB str0xo
2008-04-23   E RESERV 2.1 - 'index.php' SQL Injection 34 WEB JIKO
2008-04-22   WordPress Plugin Spreadsheet 0.6 - SQL Injection 32 WEB 1ten0.0net1
2008-04-22   Web Calendar 4.1 - Blind SQL Injection 33 WEB t0pP8uZz
2008-04-22   Joomla! Component FlippingBook 1.0.4 - SQL Injection 38 WEB cO2