Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2015-01-21   D-Link DSL-2730B Modem - XSS Injection Stored Exploit Lancfg2get.cgi 109 WEB Mauricio Correa
2015-01-21   D-Link DSL-2730B Modem - XSS Injection Stored Exploit DnsProxy.cmd 117 WEB Mauricio Correa
2015-01-15   Congstar Internet-Manager SEH Buffer Overflow 98 WEB metacom
2015-01-15   T-Mobile Internet Manager SEH Buffer Overflow 84 WEB metacom
2015-01-14   Wordpress Photo Gallery Unauthenticated SQL Injection User Enumeration 74 WEB Brandon Perry
2015-01-14   Dell iDRAC IPMI 1.5 - Insufficient Session ID Randomness 83 WEB Yong Chuan, Koh
2015-01-13   WordPress WP Symposium 14.11 Shell Upload 94 WEB Claudio Viviani
2015-01-06   AdaptCMS 3.0.3 HTTP Referer Header Open Redirect 156 WEB LiquidWorm
2015-01-06   WordPress Banner Effect Header 1.2.6 XSS / CSRF 160 WEB Mahdi.Hidden
2015-01-06   Wordpress Infocus3 Theme Arbitrary File Download Vulnerability 175 WEB killer~x
2015-01-06   Wordpress Infocus2 Theme Arbitrary File Download Vulnerability 195 WEB killer~x
2015-01-06   Wordpress WP-EMail 2.64 Cross Site Scripting Vulnerability 71 WEB Ashiyane
2015-01-06   Wordpress Email 1.1 Cross Site Scripting Vulnerability 84 WEB Ashiyane
2015-01-06   Wordpress Email newsletter 20.9 Cross Site Scripting Vulnerability 89 WEB Ashiyane
2015-01-06   Wordpress sumome 1.6 Cross Site Scripting Vulnerability 71 WEB Ashiyane
2015-01-06   AdaptCMS 3.0.3 XSS / Remote Code Execute Vulnerabilities 71 WEB LiquidWorm
2015-01-06   HikaShop 2.3.3 Local File Inclusion Vulnerability 106 WEB HauntIT Blog
2015-01-04   WordPress RevSlider Local File Disclosure 88 WEB FarbodEZRaeL
2015-01-04   PHPads <= 213607 - Authentication Bypass / Password Change Exploit 122 WEB Shaker msallm
2014-12-30   ProjectSend Arbitrary File Upload 121 WEB Fady Mohammed Osman
2014-12-30   WordPress Dmsguestbook Unauthenticated Data Injection 85 WEB Evex
2014-12-25   WordPress Themes download.php File Disclosure 199 WEB Cleiton Pinheiro
2014-12-25   AMSI 3.20.47 Build 37 File Disclosure 203 WEB KnocKout
2014-12-24   Phase botnet blind SQL injection vulnerability 78 WEB Xylitol
2014-12-22   Cacti Superlinks Plugin 1.4-2 RCE(LFI) via SQL Injection Exploit 91 WEB Wireghoul
2014-12-17   ProjectSend r-561 - Arbitrary File Upload 99 WEB Fady Mohammed Osman
2014-12-16   Wordpress Download Manager 2.7.4 - Remote Code Execution Vulnerability 94 WEB Claudio Viviani
2014-12-15   Tuleap PHP Unserialize Code Execution 167 WEB EgiX
2014-12-15   WordPress WP Symposium 14.11 Shell Upload 92 WEB Claudio Viviani
2014-12-09   Flat Calendar 1.1 HTML Injection 132 WEB ZoRLu
2014-11-27   Device42 Embedded Credentials 104 WEB Brandon Perry
2014-11-27   Slider Revolution/Showbiz Pro Shell Upload Exploit 92 WEB Simo Ben Youssef
2014-11-27   Device42 WAN Emulator 2.3 Ping Command Injection 69 WEB Brandon Perry
2014-11-27   Device42 WAN Emulator 2.3 Traceroute Command Injection 85 WEB Brandon Perry
2014-11-26   All-in-One WP Migration 2.0.2 Remote Code Execution Vulnerability 96 WEB Kacper Szurek
2014-11-26   Arris VAP2500 Authentication Bypass 111 WEB HeadlessZeke
2014-11-26   phpMyRecipes 1.2.2 (dosearch.php, words_exact param) - SQL Injection 153 WEB bard
2014-11-25   WordPress WP-DB-Backup 2.2.4 Backup Theft 123 WEB Larry W. Cashdollar
2014-11-25   FluxBB 1.5.6 SQL Injection 100 WEB secthrowaway
2014-11-25   Atrax Botnet Shell Upload Vulnerability 94 WEB Xylitol
2014-11-24   Wordpress wpDataTables 1.5.3 shell Upload Exploit 84 WEB Claudio Viviani
2014-11-18   MantisBT XmlImportExport Plugin PHP Code Injection 69 WEB EgiX
2014-11-18   Joomla HD FLV 2.1.0.1 Arbitrary File Download 110 WEB Claudio Viviani
2014-11-18   PHP 5.x - Bypass Disable Functions Vulnerability 161 WEB Ryan King
2014-11-18   Proticaret E-Commerce Script 3.0 - SQL Injection Vulnerability 78 WEB Onur Alanbel
2014-11-18   ZTE ZXHN H108L - Authentication Bypass 217 WEB Project Zero Labs
2014-11-18   ZTE ZXHN H108L - Authentication Bypass 66 WEB Project Zero Labs
2014-11-14   Who's Who Script Cross Site Request Forgery 93 WEB ZoRLu
2014-11-14   Joomla HD FLV 2.1.0.1 SQL Injection 101 WEB Claudio Viviani
2014-11-11   IP.Board 3.4.7 SQL Injection 96 WEB secthrowaway
2014-11-05   Drupal < 7.32 Pre Auth SQL Injection 164 WEB Stefan Horst
2014-10-31   Joomla RD Download SQL Injection 142 WEB Claudio Viviani
2014-10-30   MAARCH 1.4 - Arbitrary File Upload 88 WEB Adrien Thierry
2014-10-29   vBulletin Tapatalk - Blind SQL Injection 199 WEB tintinweb
2014-10-28   vBulletin 4.x Tapatalk Blind SQL Injection 111 WEB tintinweb
2014-10-28   Incredible PBX 2.0.6.5.0 - Remote Command Execution Exploit 92 WEB Simo Ben Youssef
2014-10-28   HP Operations Agent Remote XSS iFrame Injection 109 WEB Matt Schmidt
2014-10-28   Creative Contact Form (Wordpress 0.9.7 and Joomla 2.0.0) - Shell Upload Vulnerability 98 WEB Claudio Viviani
2014-10-24   Centreon SQL / Command Injection 106 WEB MaZ
2014-10-24   WordPress / Joomla Creative Contact Form 0.9.7 Shell Upload 106 WEB Claudio Viviani
2014-10-24   Feng Office 1.7.4 - Arbitrary File Upload 80 WEB AutoSec Tools
2014-10-23   DotNetNuke DNNspot Store 3.0.0 Arbitary File Upload 173 WEB Glafkos Charalambous
2014-10-21   ZTE ZXDSL-931VII - Unauthenticated Configuration Dump 260 WEB L0ukanik0-s S0kniaku0l
2014-10-20   Fonality Trixbox CE 2.8.0.4 Command Execution Vulnerability 95 WEB Simo Ben
2014-10-20   NETIS DL4322D Multiple Vulnerabilities 89 WEB AkaStep
2014-10-20   Wordpress Theme Dazzling Shell Upload Vulnerability 109 WEB king_cobra
2014-10-20   Drupal Core <= 7.32 - SQL Injection (PHP) 98 WEB Dustin Dörr
2014-10-20   Drupal Core <= 7.32 - SQL Injection 89 WEB fyukyuk
2014-10-17   Drupal 7.X SQL Injection 200 WEB Claudio Viviani
2014-10-15   SEO Control Panel 3.6.0 - Authenticated SQL Injection 89 WEB Tiago Carvalho
2014-10-14   Croogo 2.0.0 Arbitrary PHP Code Execution / Cross Site Scripting Vulnerabilities 93 WEB LiquidWorm
2014-10-09   Nessus Web UI 2.3.3 Cross Site Scripting Vulnerability 74 WEB Frank Lycops
2014-10-09   Wordpress InfusionSoft Upload 130 WEB us3r777
2014-10-08   Toast Forums Database Disclosure 105 WEB indoushka
2014-10-08   Snitz Forums 2000 3.4.07 Database Disclosure 95 WEB indoushka
2014-10-08   AutoWeb 3.0 SQL Injection 267 WEB ZoRLu
2014-10-08   Wordpress Slideshow Gallery 1.4.6 - Shell Upload (Python Exploit) 80 WEB Claudio Viviani
2014-10-08   IPFire Cgi Web Interface Authenticated Bash Environment Variable Code Injection exploit 103 WEB Claudio Viviani
2014-09-30   Microsoft Exchange IIS HTTP Internal IP Address Disclosure 85 WEB Nate Power
2014-09-30   OpenFiler 2.99.1 - CSRF Vulnerability 96 WEB Dolev Farhi
2014-09-28   Comersus Sophisticated Cart Database Disclosure 92 WEB indoushka
2014-09-26   Nucom ADSL ADSLR5000UN ISP Credentials Disclosure 81 WEB Sebastián Magof
2014-09-25   ZyXEL Prestig P-660HNU-T1 ISP Credentials Disclosure Exploit 96 WEB Sebastián Magof
2014-09-23   Joomla Face Gallery 1.0 Multiple Vulnerabilities 102 WEB Claudio Viviani
2014-09-23   Joomla Mac Gallery <= 1.5 Arbitrary File Download Exploit 92 WEB Claudio Viviani
2014-09-22   GetSimpleCMS PHP File Upload 82 WEB Ahmed Elhady Mohamed
2014-09-19   Briefcase 4.0 iOS - Code Execution & File Include Vulnerability 105 WEB Vulnerability-Lab
2014-09-18   ZTE ZXDSL-931VII Unauthenticated Configuration Dump 353 WEB L0ukanik0s
2014-09-17   WordPress Slideshow Gallery 1.4.6 Shell Upload 85 WEB Claudio Viviani
2014-09-16   ALCASAR <= 2.8.1 - Remote Root Code Execution Vulnerability 137 WEB eF
2014-09-15   EGYWEB (Mantrac) <= Remote File Disclosure Exploit 116 WEB KnocKout
2014-09-12   Onlineon E-Ticaret Database Disclosure 97 WEB ZoRLu
2014-09-12   Joomla Spider Contacts 1.3.6 (index.php, contacts_id param) - SQL Injection 99 WEB Claudio Viviani
2014-08-29   DomainTrader Domain Parking / Auction Script 2.5.3 CSRF / XSS 83 WEB Haider Mahmood
2014-08-29   XRMS - Blind SQL Injection and Command Execution 117 WEB Benjamin Harris
2014-08-29   PhpWiki - Remote Command Execution 65 WEB Benjamin Harris
2014-08-29   ActualAnalyzer Lite 2.81 - Unauthenticated Command Execution 84 WEB Benjamin Harris
2014-08-29   Plogger 1.0-RC1 - Authenticated Arbitrary File Upload 84 WEB b0z
2014-08-20   HybridAuth install.php PHP Code Execution 97 WEB Pichaya Morimoto
2014-08-14   WordPress Disqus 2.7.5 CSRF / Cross Site Scripting Vulnerabilities 124 WEB Nik Cubrilovic
2014-08-13   CS-Cart 4.2.0 Session Hijacking 76 WEB Nik Cubrilovic
2014-08-04   TigerCom iFolder+ v1.2 iOS - Multiple Vulnerabilities 103 WEB Vulnerability-Lab
2014-07-31   D-Link AP 3200 Multiple Vulnerabilities 110 WEB pws
2014-07-31   SkaDate Lite 2.0 - Remote Code Execution Exploit 194 WEB LiquidWorm
2014-07-29   Oxwall 1.7.0 - Remote Code Execution Exploit 145 WEB LiquidWorm
2014-07-29   Oxwall 1.7.0 - Multiple CSRF And HTML Injection Vulnerabilities 99 WEB LiquidWorm
2014-07-28   Pligg 2.0.1 - Multiple Vulnerabilities 92 WEB BlackHawk
2014-07-25   NETGEAR DGN2200 1.0.0.29_1.7.29_HotS - Password Disclosure vulnerability 97 WEB Dolev Farhi
2014-07-22   vBulletin 5.1.2 SQL Injection 101 WEB Nytro
2014-07-22   MTS MBlaze Ultra Wi-Fi / ZTE AC3633 - Multiple Vulnerabilities 84 WEB Ajin Abraham
2014-07-16   Wordpress WPTouch Authenticated File Upload 74 WEB Marc-Alexandre Montpas
2014-07-09   Yokogawa CS3000 BKFSim_vhfd.exe Buffer Overflow 117 WEB Redsadic
2014-07-09   Wordpress Theme ProjectTheme Shell Upload Vulnerability 129 WEB Aloulou
2014-07-09   Wordpress Theme PricerrTheme Shell Upload Vulnerability 137 WEB Aloulou
2014-07-08   Netgear WNR1000v3 - Password Recovery Credential Disclosure Vulnerability 151 WEB c1ph04
2014-07-01   IBM Algorithmics RICOS Disclosure / XSS / CSRF 153 WEB F. Lukavsky
2014-07-01   Horde Framework Unserialize PHP Code Execution 86 WEB Akra Macha
2014-06-30   WordPress wp-crm Plugin Arbitrary File Upload Vulnerability 318 WEB brunox
2014-06-27   Python CGIHTTPServer File Disclosure / Code Execution 267 WEB Jens Liebchen
2014-06-25   WordPress image-symlinks Plugin Arbitrary File Upload Vulnerability 165 WEB brunox
2014-06-25   Cogent DataHub Command Injection 119 WEB juan vazquez
2014-06-24   Supermicro IPMI/BMC Cleartext Password Scanner 219 WEB 1N3
2014-06-23   D-link DSL-2760U-E1 - Persistent XSS 90 WEB Yuval tisf Nativ
2014-06-20   AlienVault OSSIM av-centerd Command Injection 69 WEB temp66
2014-06-19   Ericom AccessNow Server Buffer Overflow 102 WEB temp66