Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2014-05-22   SPIP - CMS < 3.0.9 / 2.1.22 / 2.0.23 - Privilege Escalation 88 WEB Gregory DRAPERI
2014-05-20   UPS Web/SNMP-Manager CS121 Login Bypass 88 WEB jkmac
2014-05-20   SafeNet Sentinel Protection Server 7.0 - 7.4 and Sentinel Keys Server 1.0.3 - 1.0.4 Directory Traver 76 WEB Matt Schmidt
2014-05-20   HP Release Control Authenticated XXE 99 WEB Brandon Perry
2014-05-16   ElasticSearch Remote Code Execution 81 WEB Jeff Geiger
2014-05-14   WordPress Formidable Forms Remote Code Execution 94 WEB Manish Tanwar
2014-05-14   AlienVault OSSIM 4.6.1 - Authenticated SQL Injection 111 WEB Chris Hebert
2014-05-09   F5 iControl Remote Command Execution Vulnerability 76 WEB Brandon Perry
2014-05-04   HP Laser Jet - JavaScript Persistent XSS via PJL Directory Traversal 85 WEB @0x00string
2014-04-25   Bonefire v.0.7.1 - Reinstall Admin Account Exploit 70 WEB Mehmet Ince
2014-04-23   No-CMS 0.6.6 rev 1 - Admin Account Hijacking / RCE Exploit via Static Encryption Key 183 WEB Mehmet Ince
2014-04-23   Sixnet Sixview 2.4.1 - Web Console Directory Traversal 68 WEB daniel svartman
2014-04-22   Comtrend CT 5361T Cross Site Request Forgery / Cross Site Scripting 94 WEB TUNISIAN CYBER
2014-04-22   ATSEngine credential disclosure vulnerability 62 WEB Xylitol
2014-04-21   CU3ER 1.24 Cross Site Scripting / Content Spoofing 84 WEB MustLive
2014-04-16   NETGEAR N600 WIRELESS DUAL BAND WNDR3400 - Multiple Vulnerabilities 89 WEB Santhosh Kumar
2014-04-15   Madss Software Solution SQL Injection 135 WEB Ashiyane Digital Security Team
2014-04-14   Plex Media Server 0.9.9.10 CSRF / Disclosure 183 WEB S. Viehbock
2014-04-14   eScan Web Management Console Command Injection 75 WEB juan vazquez
2014-04-10   Sophos Web Protection Appliance Command Execution 70 WEB Brandon Perry
2014-04-10   RunCMS 1.6.1 - 'pm.class.php' Multiple SQL Injection Vulnerabilities 122 WEB The:Paradox
2014-04-09   Vtiger Install Unauthenticated Remote Command Execution 48 WEB Jonathan Borgeaud
2014-04-08   PHPFox 3.7.5 Authorization Bypass 107 WEB Wesley Henrique Leite
2014-04-04   Kyocera FS5250 Cross Site Scripting 68 WEB Jeff Sergeant
2014-04-04   Kloxo-MR 6.5.0 - CSRF Vulnerability 99 WEB Necmettin COSKUN
2014-04-04   Kloxo 6.1.18 Stable - CSRF Vulnerability 82 WEB Necmettin COSKUN
2014-04-03   iShare Your Moving Library 1.0 iOS - Multiple Vulnerabilities 51 WEB Vulnerability-Lab
2014-04-03   ICOMM 610 Wireless Modem - CSRF Vulnerability 106 WEB Blessen Thomas
2014-04-01   AlienVault 4.5.0 SQL Injection 91 WEB Brandon Perry
2014-04-01   EMC Cloud Tiering Appliance v10.0 Unauthenticated XXE Arbitrary File Read 190 WEB Brandon Perry
2014-03-31   WordPress Business Intelligence 1.0.6 Shell Upload 109 WEB Manish Tanwar
2014-03-27   IBM Tealeaf CX 8.8 - Remote OS Command Injection 65 WEB drone
2014-03-26   qEngine CMS 6.0.0 - Multiple Vulnerabilities 85 WEB LiquidWorm
2014-03-26   Kemana Directory 1.5.6 (qvc_init()) Cookie Poisoning CAPTCHA Bypass Exploit 81 WEB LiquidWorm
2014-03-26   Kemana Directory 1.5.6 Database Backup Disclosure Exploit 98 WEB LiquidWorm
2014-03-26   Cart Engine 3.0.0 Database Backup Disclosure Exploit 87 WEB LiquidWorm
2014-03-18   osCmax 2.5.X Cross-Site Request Forgery (Add Admin) Vulnerability 81 WEB TUNISIAN CYBER
2014-03-17   OpenSupports v2.x AuthBypass/CSRF Vulnerabilities 80 WEB TUNISIAN CYBER
2014-03-11   Herpes Net 3.0 SQL Injection 90 WEB bwall
2014-03-06   Ganib 2.3 SQL Injection 96 WEB drone
2014-02-14   Dexter CasinoLoader SQL Injection 109 WEB bwall
2014-02-11   ZTE ZXV10 W300 Hardcoded Credentials 114 WEB Cesar Neira
2014-02-11   WordPress Kidoo Shell Upload 93 WEB TUNISIAN CYBER
2014-01-21   WordPress Global Flash Galleries File Upload 86 WEB Ashiyane Digital Security Team
2014-01-20   bloofoxCMS 0.5.0 CSRF / PHP Code Injection 158 WEB AtT4CKxT3rR0r1ST
2014-01-17   SmarterMail 11.x Cross Site Scripting 165 WEB Saeed reza Zamanian
2014-01-09   Eyou Mail System Remote Code Execution 77 WEB conqu3r.zeng
2014-01-08   Command School Student Management System 1.06.01 SQL Injection / CSRF / XSS 91 WEB AtT4CKxT3rR0r1ST
2014-01-08   vTiger CRM SOAP AddEmailAttachment Arbitrary File Upload 94 WEB EgiX
2014-01-07   Seagate BlackArmor NAS sg2000-2000.1331 - Multiple Persistent Cross Site Scripting Vulnerabilities 90 WEB Jeroen - IT Nerdbox
2014-01-07   Seagate BlackArmor NAS sg2000-2000.1331 - Cross Site Request Forgery 72 WEB Jeroen - IT Nerdbox
2014-01-07   Seagate BlackArmor NAS sg2000-2000.1331 - Remote Command Execution 201 WEB Jeroen - IT Nerdbox
2014-01-07   Seagate BlackArmor - Root Exploit 113 WEB Jeroen - IT Nerdbox
2013-12-31   PhotoStore 4.0.7. Shell Upload 86 WEB Gabby
2013-12-24   Synology DiskStation Manager SLICEUPLOAD Remote Command Execution 78 WEB Markus Wulftange
2013-12-24   OpenSIS 'modname' PHP Code Execution 94 WEB EgiX
2013-12-24   Zimbra Collaboration Server LFI 114 WEB rubina119
2013-12-24   Song Exporter 2.1.1 RS Local File Inclusion 69 WEB Benjamin Kunz Mejri
2013-12-24   WordPress Persuasion Theme File Download / Deletion 79 WEB Interference Security
2013-12-23   USP Secure Entry Server URL Redirection 66 WEB Alexandre Herzog
2013-12-18   iScripts Support Desk 4.1 SQL Injection 147 WEB i-Hmx
2013-12-18   Traidnt Upload 3 Add Administrator 80 WEB i-Hmx
2013-12-16   PHP openssl_x509_parse() Memory Corruption 131 WEB Stefan Esser
2013-12-16   iScripts AutoHoster PHP Code Injection 79 WEB i-Hmx
2013-12-11   vBulletin index.php/ajax/api/reputation/vote nodeid Parameter SQL Injection 92 WEB Orestis Kourides
2013-12-09   Up.Time Monitoring Station post2file.php Arbitrary File Upload 94 WEB Denis Andzakovic
2013-12-09   Eaton Network Shutdown Module 3.21 PHP Code Injection 88 WEB Filip Waeytens
2013-12-06   Joomla Hotornot2 Shell Upload 105 WEB DevilScreaM
2013-12-05   Kaseya uploadImage Arbitrary File Upload 103 WEB Thomas Hibbert
2013-12-03   WordPress OptimizePress Theme File Upload 99 WEB Mekanismen
2013-12-02   Joomla JMultimedia Command Execution 99 WEB Deepankar Arora
2013-11-29   Kimai 0.9.2 db_restore.php SQL Injection 85 WEB drone
2013-11-26   LimeSurvey 2.00+ (build 131107) - Multiple Vulnerabilities 99 WEB LiquidWorm
2013-11-11   RASPcalendar 1.01 SQL Injection 75 WEB Hackeri-AL
2013-11-01   Joomla Joomleague Shell Upload 93 WEB wantexz
2013-11-01   Unicorn WB-3300NR Cross Site Request Forgery 94 WEB absane
2013-10-31   ProcessMaker Open Source Authenticated PHP Code Execution 79 WEB Brendan Coles
2013-10-28   WordPress GeoPlaces 4.x Shell Upload 75 WEB DevilScreaM
2013-10-28   WebCollab 3.30 HTTP Response Splitting 88 WEB Manuel Garcia Cardenas
2013-10-24   Joomla Component com_maianmedia Remote Code Execution 109 WEB indexphp
2013-10-23   Apache Shindig 2.5.0 XXE Injection 83 WEB Kousuke Ebihara
2013-10-21   Bluetooth U 1.2.0 Directory Traversal 83 WEB Benjamin Kunz Mejri
2013-10-21   WebTester 5.x Command Execution 74 WEB Brendan Coles
2013-10-18   Oracle Portal Demo Organization Chart PL/SQL Injection 123 WEB Manuel Garcia Cardenas
2013-10-18   Level One Enterprise Access Points Password Disclosure 79 WEB Richard Weinberger
2013-10-15   Zabbix 2.0.8 SQL Injection / Remote Code Execution 103 WEB Lincoln
2013-10-08   WordPress Woopra Remote Code Execution 108 WEB wantexz
2013-10-08   WordPress Slimstat Ex Code Execution 78 WEB wantexz
2013-10-08   WordPress SEO Watcher Remote Code Execution 88 WEB wantexz
2013-09-27   Astium Remote Code Execution 147 WEB xistence
2013-09-26   Nodejs js-yaml load() Code Execution 124 WEB joev
2013-09-24   Raidsonic NAS Devices Unauthenticated Remote Command Execution 128 WEB juan vazquez
2013-08-29   SPIP Connect Parameter PHP Injection 96 WEB Frederic Cikala
2013-08-15   Struts2 2.3.15 Open Redirect 92 WEB Takeshi Terada
2013-08-15   Struts2 2.3.15 OGNL Injection 364 WEB Takeshi Terada
2013-08-12   Sybase EAServer XXE Injection 75 WEB MustLive
2013-08-08   MyBB 1.6.10 Open Redirection 68 WEB LiquidWorm
2013-07-30   PineApp Mail-SeCure test_li_connection.php Arbitrary Command Execution 76 WEB Dave Weinstein
2013-07-30   PineApp Mail-SeCure ldapsyncnow.php Arbitrary Command Execution 84 WEB Dave Weinstein
2013-07-30   PineApp Mail-SeCure livelog.html Arbitrary Command Execution 94 WEB temp66
2013-07-26   Powershell Payload Web Delivery 81 WEB Chris Campbell
2013-06-24   HP System Management Homepage JustGetSNMPQueue Command Injection 99 WEB sinn3r
2013-06-24   LibrettoCMS File Manager Arbitrary File Upload 121 WEB sinn3r
2013-06-19   MoinMoin twikidraw Action Traversal File Upload 90 WEB HTP
2013-06-09   Resin Application Server 4.0.36 Cross Site Scripting 83 WEB LiquidWorm
2013-06-09   Resin Application Server 4.0.36 Source Code Disclosure 83 WEB LiquidWorm
2013-06-08   JBoss AS Administrative Console Password Disclosure 248 WEB amroot
2013-06-04   Seowonintech Routers Remote Root File Dumper 69 WEB Todor Donev
2013-06-03   PhpTax 0.8 - File Manipulation(newvalue,field) Remote Code Execution 113 WEB CWH Underground
2013-05-31   HP LaserJet Pro P1606dn Password Reset 101 WEB m3tamantra
2013-05-29   Matterdaddy Market 1.4.2 Cross Site Request Forgery / Arbitrary File Upload 86 WEB KedAns-Dz
2013-05-20   D-Link DIR615h OS Command Injection 210 WEB juan vazquez
2013-04-26   phpMyAdmin 3.5.8 and 4.0.0-RC2 - Multiple Vulnerabilities 88 WEB waraxe
2013-04-26   Hornbill Supportworks ITSM 1.0.0 - SQL Injection Vulnerability 87 WEB Joseph Sheridan
2013-04-25   CiviCRM for Joomla 4.2.2 - Remote Code Injection 97 WEB iskorpitx
2013-04-25   SMF 2.0.4 PHP Code Injection 193 WEB Jakub Galczyk
2013-04-23   Janissaries Joomla Civicrm Shell Upload 79 WEB miyachung
2013-04-22   nginx 0.6.x Arbitrary Code Execution NullByte Injection 93 WEB Neal Poole
2013-04-22   Netgear DGN2200B pppoe.cgi Remote Command Execution 202 WEB juan vazquez
2013-04-18   Java Web Start Launcher Memory Corruption 192 WEB A. Antukh
2013-04-03   Aspen 0.8 Directory Traversal 85 WEB Daniel Ricardo dos Santos
2013-04-03   Netgear WNR1000 Authentication Bypass 117 WEB Roberto Paleari
2013-03-29   PsychoStats 3.2.2b Blind SQL Injection 75 WEB Mohamed from ALG
2013-03-29   McAfee Virtual Technician (MVT) 6.5.0.2101 Unsafe Active-X 93 WEB High-Tech Bridge SA
2013-03-29   AWS XMS 2.5 Path Traversal 92 WEB High-Tech Bridge SA