Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2015-05-27   Apache Jackrabbit WebDAV XXE Exploit 79 WEB Mikhail Egorov
2015-05-27   Sendio ESP Information Disclosure Vulnerability 68 WEB Core Security
2015-05-25   Newsletter 4.3 SQL Injection 82 WEB Ashiyane Digital Security Team
2015-05-22   ElasticSearch 1.4.5 / 1.5.2 - Path Transversal Vulnerability 121 WEB Pedro Andujar
2015-05-20   ManageEngine EventLog Analyzer 10.0 Build 10001 CSRF Vulnerability 111 WEB Akash S. Chavan
2015-05-13   WordPress N-Media Website Contact Form with File Upload 1.3.4 - File Upload 59 WEB F17.c0de
2015-05-12   SixApart MovableType Storable Perl Code Execution 129 WEB John Lightsey
2015-05-12   D-Link DSL-500B Gen 2 - (URL Filter Configuration Panel) Stored XSS 75 WEB XLabs Security
2015-05-12   D-Link DSL-500B Gen 2 - (Parental Control Configuration Panel) Stored XSS 75 WEB XLabs Security
2015-05-08   WordPress RevSlider 3.0.95 File Upload / Execute 197 WEB Tom Sellers
2015-05-08   elFinder 2 Remote Command Execution (Via File Creation) Vulnerability 96 WEB TUNISIAN CYBER
2015-05-06   WordPress 4.2.1 XSS / Code Execution 84 WEB Evex
2015-04-28   ProjectSend r561 CSRF / XSS / Shell Upload 76 WEB TUNISIAN CYBER
2015-04-28   OTRS 3.x Cross Site Scripting 170 WEB Adam Ziaja
2015-04-28   OTRS < 3.1.x & < 3.2.x & < 3.3.x - Stored Cross-Site Scripting (XSS) Vulnerability 162 WEB Adam Ziaja
2015-04-27   WordPress WPshop eCommerce 1.3.9.5 Shell Upload 130 WEB Roberto Soares Espreto
2015-04-27   WordPress InBoundio Marketing 2.0 Shell Upload 63 WEB Roberto Soares Espreto
2015-04-23   Wolf CMS 0.8.2 Arbitrary File Upload Exploit 123 WEB CWH Underground
2015-04-22   WordPress NEX-Forms 3.0 SQL Injection 194 WEB Cleiton Pinheiro
2015-04-22   Open-Letters Remote PHP Code Injection Exploit 109 WEB TUNISIAN CYBER
2015-04-21   WordPress SlideShow Gallery Authenticated File Upload 72 WEB Roberto Soares Espreto
2015-04-21   MediaSuite CMS - Artibary File Disclosure Exploit 67 WEB KnocKout
2015-04-20   WordPress Reflex Gallery Upload 109 WEB Roberto Soares Espreto
2015-04-20   WordPress N-Media Website Contact Form Upload 79 WEB Roberto Soares Espreto
2015-04-20   WordPress Creative Contact Form Upload 59 WEB Roberto Soares Espreto
2015-04-13   TP-LINK Local File Disclosure 185 WEB Stefan Viehböck
2015-04-07   WordPress PHP Event Calendar 1.5 Arbitrary File Upload Vulnerability 73 WEB CrashBandicot
2015-04-02   WordPress VideoWhisper Video Presentation 3.31.17 Shell Upload 85 WEB Larry W. Cashdollar
2015-04-02   WordPress VideoWhisper Video Conference Integration 4.91.8 Shell Upload 103 WEB Larry W. Cashdollar
2015-04-02   WordPress Revolution Slider File Upload 73 WEB CrashBandicot
2015-04-02   WordPress DesignFolio+ Theme File Upload 75 WEB CrashBandicot
2015-04-01   Palo Alto Traps Server 3.1.2.1546 - Persistent XSS Vulnerability 176 WEB Michael Hendrickx
2015-03-31   WebDepo CMS SQL Injection 128 WEB Cleiton Pinheiro
2015-03-30   Wordpress Plugin Revolution Slider - Unrestricted File Upload Exploit 96 WEB CrashBandicot
2015-03-30   WordPress Aspose Cloud eBook Generator File Download Vulnerability 93 WEB ACC3SS
2015-03-26   WP Marketplace 2.4.0 - Remote Code Execution (Add WP Admin) 85 WEB Claudio Viviani
2015-03-25   Wordpress InfusionSoft Shell Upload 85 WEB us3r777
2015-03-25   WordPress OptimizePress Theme Shell Upload 85 WEB Mekanismen
2015-03-25   WordPress cache_lastpostdate Arbitrary Code Execution 80 WEB str0ke
2015-03-25   WordPress W3 Total Cache PHP Code Execution 77 WEB hdm
2015-03-25   WordPress Foxypress uploadify.php Arbitrary Code Execution 70 WEB patrick
2015-03-25   WordPress Marketplace 2.4.0 Arbitrary File Download 64 WEB Kacper Szurek
2015-03-25   Unasjee CMS Cross Site Request Forgery 188 WEB KnocKout
2015-03-25   WordPress Plugin InBoundio Marketing 1.0 - Shell Upload Vulnerability 179 WEB KedAns-Dz
2015-03-24   Powershell Remoting Remote Command Execution 78 WEB Ben Campbell
2015-03-24   Belkin Play N750 login.cgi Buffer Overflow 56 WEB Michael Messner
2015-03-23   Wordpress WP Marketplace 2.4.0 Arbitrary File Download Vulnerability 63 WEB Kacper Szurek
2015-03-20   Chamilo LMS 1.9.10 Cross Site Request Forgery / Cross Site Scripting 108 WEB Rehan Ahmed
2015-03-20   Metasploit Project < 4.11.1 - Initial User Creation CSRF Vulnerability 112 WEB Mohamed Abdelbaset Elnoby
2015-03-20   GoAutoDial CE 2.0 - Shell Upload Vulnerability 145 WEB R-73eN
2015-03-20   EMC M&R (Watch4net) - Credential Disclosure 62 WEB Han Sahin
2015-03-17   WordPress Reflex Gallery 3.1.3 Shell Upload 101 WEB Cleiton Pinheiro
2015-03-09   Betster 1.0.4 SQL Injection / Authentication Bypass 73 WEB ZeQ3uL
2015-03-06   PHPMoAdmin 1.1.2 Remote Code Execution 106 WEB Ricardo Jorge Borges de Almeida
2015-03-06   Wordpress Theme DesignFolio+ Arbitrary File Upload Vulnerability 97 WEB CrashBandicot
2015-03-05   PHPMoAdmin Remote Code Execution 154 WEB Pichaya Morimoto
2015-03-05   Generic Web Application DLL Injection 56 WEB Matthew Hall
2015-03-03   Symantec Web Gateway 5 restore.php Command Injection 76 WEB sinn3r
2015-03-02   Seagate Business NAS <= 2014.00319 - Pre-Authentication Remote Code Execution (0day) 113 WEB OJ Reeves
2015-02-25   WordPress Holding Pattern Theme Arbitrary File Upload 96 WEB Alexander Borg
2015-02-25   WordPress Admin Shell Upload 80 WEB Rob Carr
2015-02-25   WeBid 1.1.1 Unrestricted File Upload 73 WEB CWH Underground
2015-02-25   WordPress Webdorado Spider Event Calendar 1.4.9 - SQL Injection 83 WEB Mateusz Lach
2015-02-11   Achat 0.150 beta7 Buffer Overflow 74 WEB Balazs Bucsay
2015-02-11   LG DVR LE6016D - Unauthenticated Remote Users/Passwords Disclosure Exploit 172 WEB Todor Donev
2015-02-10   WordPress WP EasyCart Unrestricted File Upload 91 WEB Kacper Szurek
2015-02-10   Redaxscript CMS 2.2.0 - SQL Injection Vulnerability 109 WEB ITAS Team
2015-02-05   ManageEngine Desktop Central 9 Build 90087 - CSRF Vulnerability 81 WEB Mohamed Idris
2015-02-04   WordPress Pixabay Images PHP Code Upload 95 WEB h0ng10
2015-02-04   WordPress Platform Theme Remote Code Execution 93 WEB Christian Mehlmauer
2015-02-03   Sefrengo CMS 1.6.1 SQL Injection 103 WEB Nguyen Hung Tuan
2015-01-27   SWFupload 2.5.0 Cross Frame Scripting 103 WEB MindCracker
2015-01-27   Symantec Data Center Security - Multiple Vulnerabilities 160 WEB SEC Consult
2015-01-27   PHP Webquest 2.6 - SQL Injection 87 WEB jordan root
2015-01-23   Arris VAP2500 tools_command.php Command Execution 147 WEB HeadlessZeke
2015-01-21   WordPress Pixarbay Images 2.3 XSS / Bypass / Upload / Traversal 73 WEB Hans-Martin Muench
2015-01-21   N-Central Remote Support Manager 14.2.7.171 File Read / Code Execution 62 WEB Thomas Hibbert
2015-01-21   D-Link DSL-2730B Modem - XSS Injection Stored Exploit Lancfg2get.cgi 98 WEB Mauricio Correa
2015-01-21   D-Link DSL-2730B Modem - XSS Injection Stored Exploit DnsProxy.cmd 105 WEB Mauricio Correa
2015-01-15   Congstar Internet-Manager SEH Buffer Overflow 85 WEB metacom
2015-01-15   T-Mobile Internet Manager SEH Buffer Overflow 75 WEB metacom
2015-01-14   Wordpress Photo Gallery Unauthenticated SQL Injection User Enumeration 65 WEB Brandon Perry
2015-01-14   Dell iDRAC IPMI 1.5 - Insufficient Session ID Randomness 73 WEB Yong Chuan, Koh
2015-01-13   WordPress WP Symposium 14.11 Shell Upload 83 WEB Claudio Viviani
2015-01-06   AdaptCMS 3.0.3 HTTP Referer Header Open Redirect 146 WEB LiquidWorm
2015-01-06   WordPress Banner Effect Header 1.2.6 XSS / CSRF 149 WEB Mahdi.Hidden
2015-01-06   Wordpress Infocus3 Theme Arbitrary File Download Vulnerability 164 WEB killer~x
2015-01-06   Wordpress Infocus2 Theme Arbitrary File Download Vulnerability 186 WEB killer~x
2015-01-06   Wordpress WP-EMail 2.64 Cross Site Scripting Vulnerability 62 WEB Ashiyane
2015-01-06   Wordpress Email 1.1 Cross Site Scripting Vulnerability 74 WEB Ashiyane
2015-01-06   Wordpress Email newsletter 20.9 Cross Site Scripting Vulnerability 79 WEB Ashiyane
2015-01-06   Wordpress sumome 1.6 Cross Site Scripting Vulnerability 59 WEB Ashiyane
2015-01-06   AdaptCMS 3.0.3 XSS / Remote Code Execute Vulnerabilities 58 WEB LiquidWorm
2015-01-06   HikaShop 2.3.3 Local File Inclusion Vulnerability 93 WEB HauntIT Blog
2015-01-04   WordPress RevSlider Local File Disclosure 81 WEB FarbodEZRaeL
2015-01-04   PHPads <= 213607 - Authentication Bypass / Password Change Exploit 109 WEB Shaker msallm
2014-12-30   ProjectSend Arbitrary File Upload 110 WEB Fady Mohammed Osman
2014-12-30   WordPress Dmsguestbook Unauthenticated Data Injection 75 WEB Evex
2014-12-25   WordPress Themes download.php File Disclosure 190 WEB Cleiton Pinheiro
2014-12-25   AMSI 3.20.47 Build 37 File Disclosure 193 WEB KnocKout
2014-12-24   Phase botnet blind SQL injection vulnerability 68 WEB Xylitol
2014-12-22   Cacti Superlinks Plugin 1.4-2 RCE(LFI) via SQL Injection Exploit 80 WEB Wireghoul
2014-12-17   ProjectSend r-561 - Arbitrary File Upload 87 WEB Fady Mohammed Osman
2014-12-16   Wordpress Download Manager 2.7.4 - Remote Code Execution Vulnerability 83 WEB Claudio Viviani
2014-12-15   Tuleap PHP Unserialize Code Execution 158 WEB EgiX
2014-12-15   WordPress WP Symposium 14.11 Shell Upload 81 WEB Claudio Viviani
2014-12-09   Flat Calendar 1.1 HTML Injection 124 WEB ZoRLu
2014-11-27   Device42 Embedded Credentials 95 WEB Brandon Perry
2014-11-27   Slider Revolution/Showbiz Pro Shell Upload Exploit 81 WEB Simo Ben Youssef
2014-11-27   Device42 WAN Emulator 2.3 Ping Command Injection 58 WEB Brandon Perry
2014-11-27   Device42 WAN Emulator 2.3 Traceroute Command Injection 74 WEB Brandon Perry
2014-11-26   All-in-One WP Migration 2.0.2 Remote Code Execution Vulnerability 85 WEB Kacper Szurek
2014-11-26   Arris VAP2500 Authentication Bypass 99 WEB HeadlessZeke
2014-11-26   phpMyRecipes 1.2.2 (dosearch.php, words_exact param) - SQL Injection 144 WEB bard
2014-11-25   WordPress WP-DB-Backup 2.2.4 Backup Theft 111 WEB Larry W. Cashdollar
2014-11-25   FluxBB 1.5.6 SQL Injection 86 WEB secthrowaway
2014-11-25   Atrax Botnet Shell Upload Vulnerability 85 WEB Xylitol
2014-11-24   Wordpress wpDataTables 1.5.3 shell Upload Exploit 73 WEB Claudio Viviani
2014-11-18   MantisBT XmlImportExport Plugin PHP Code Injection 58 WEB EgiX
2014-11-18   Joomla HD FLV 2.1.0.1 Arbitrary File Download 98 WEB Claudio Viviani
2014-11-18   PHP 5.x - Bypass Disable Functions Vulnerability 152 WEB Ryan King
2014-11-18   Proticaret E-Commerce Script 3.0 - SQL Injection Vulnerability 68 WEB Onur Alanbel
2014-11-18   ZTE ZXHN H108L - Authentication Bypass 208 WEB Project Zero Labs
2014-11-18   ZTE ZXHN H108L - Authentication Bypass 56 WEB Project Zero Labs
2014-11-14   Who's Who Script Cross Site Request Forgery 84 WEB ZoRLu