2012-03-06
|
|
Drupal CMS 7.12 (latest stable release) Multiple Vulnerabilities
|
85 |
WEB
|
Ivano Binetti
|
2012-03-06
|
|
ForkCMS 3.2.5 Multiple Vulnerabilities
|
69 |
WEB
|
Ivano Binetti
|
2012-03-06
|
|
lizard cart SQLi (search.php)
|
75 |
WEB
|
Number 7
|
2012-03-06
|
|
Symfony2 Local File Disclosure - Security Advisory - SOS-12-002
|
87 |
WEB
|
Lists
|
2012-03-06
|
|
EbizCare => SQL Injection Vulnerability
|
101 |
WEB
|
dbx
|
2012-03-06
|
|
Open-Realty 2.5.8 Local File Inclusion
|
85 |
WEB
|
Transparent
|
2012-03-06
|
|
BigDump Importer v0.32b RFU
|
129 |
WEB
|
TeaM MosTa
|
2012-03-06
|
|
piwigo <== SQL Injector
|
77 |
WEB
|
TeaM MosTa
|
2012-03-06
|
|
Multiple SQL injections in rivettracker <=1.03
|
76 |
WEB
|
Ali Raheem
|
2012-03-06
|
|
CnnCMS 1.x SQL Injection Vulnerability
|
88 |
WEB
|
X-Cisadane
|
2012-03-05
|
|
AneCMS v.2e2c583 LFI exploit
|
80 |
WEB
|
I2sec-PJH
|
2012-03-05
|
|
deV!L`z Clanportal Witze Addon Versions 0.9 SQL Injection Vulnerability
|
106 |
WEB
|
Easy Laster
|
2012-03-04
|
|
Timesheet Next Gen 1.5.2 Multiple SQLi
|
65 |
WEB
|
G13
|
2012-03-04
|
|
Multiple SQL injection rivettracker <=1.03
|
96 |
WEB
|
Ali Raheem
|
2012-03-03
|
|
Infoserve SQL Vulnerability
|
76 |
WEB
|
Optimiz3r
|
2012-03-03
|
|
Endian UTM Firewall v2.4.x & v2.5.0 - Multiple Web Vulnerabilities
|
88 |
WEB
|
expku
|
2012-03-03
|
|
Wpmanager version wpm 2.2.0 (FCKeditor) Remote File Upload
|
120 |
WEB
|
T0x!c
|
2012-03-03
|
|
phxEventManager 2.0 beta 5 search.php search_terms SQL Injection
|
99 |
WEB
|
skysbsb
|
2012-03-01
|
|
Wolf CMS v0.7.5 Multiple Vulnerabilities
|
88 |
WEB
|
longrifle0x
|
2012-03-01
|
|
ImgPals Photo Host Version 1.0 Admin Account Disactivation
|
94 |
WEB
|
CorryL
|
2012-03-01
|
|
Yealink VOIP Phone Persistent Cross Site Scripting Vulnerability
|
103 |
WEB
|
Narendra Shinde
|
2012-03-01
|
|
Topics Viewer CSRF Add Admin
|
90 |
WEB
|
Green Hornet
|
2012-03-01
|
|
BrewBlogger v2.3.2 Multiple (XSRF/ShellUpload/SQLi) Vulnerabilities
|
82 |
WEB
|
KedAns-Dz
|
2012-02-29
|
|
WebfolioCMS <= 1.1.4 CSRF (Add Admin/Modify Pages)
|
81 |
WEB
|
Ivano Binetti
|
2012-02-28
|
|
Bitweaver v2.81 Local File Inclusion Vulnerability
|
84 |
WEB
|
I2sec-PJH
|
2012-02-28
|
|
Dotclear 2.4.2 Arbitrary File Upload Vulnerability
|
75 |
WEB
|
T0x!c
|
2012-02-28
|
|
ContaoCMS (aka TYPOlight) <= 2.11 CSRF (Delete Admin - Delete Article)
|
88 |
WEB
|
Ivano Binetti
|
2012-02-27
|
|
YVS Image Gallery Sql Injection
|
88 |
WEB
|
CorryL
|
2012-02-27
|
|
CreateVision CMS Database injection.
|
144 |
WEB
|
Zwierzchowski Oskar
|
2012-02-27
|
|
webgrind 1.0 (file param) Local File Inclusion Vulnerability
|
154 |
WEB
|
LiquidWorm
|
2012-02-27
|
|
cPassMan v1.82 Remote Command Execution Exploit
|
69 |
WEB
|
ls
|
2012-02-27
|
|
PHP Gift Registry 1.5.5 SQL Injection
|
83 |
WEB
|
G13
|
2012-02-24
|
|
Snom IP Phone Privilege Escalation - Security Advisory - SOS-12-001
|
77 |
WEB
|
Lists
|
2012-02-24
|
|
phpDenora <= 1.4.6 Multiple SQL Injection Vulnerabilities
|
118 |
WEB
|
KnickLighter
|
2012-02-24
|
|
The Uploader 2.0.4 (Eng/Ita) Remote File Upload Remote Code Execution
|
96 |
WEB
|
Danny Moules
|
2012-02-23
|
|
DFLabs PTK <= 1.0.5 Multiple Vulnerabilities (Steal Authentication Credentials)
|
86 |
WEB
|
Ivano Binetti
|
2012-02-23
|
|
D-Link DSL-2640B Authentication Bypass
|
67 |
WEB
|
Ivano Binetti
|
2012-02-23
|
|
WebcamXP and Webcam 7 Directory Traversal Vulnerability
|
98 |
WEB
|
Silent Dream
|
2012-02-23
|
|
Dlink DCS series CSRF Change Admin Password
|
91 |
WEB
|
rigan
|
2012-02-23
|
|
BRIM < 2.0.0 SQL Injection
|
83 |
WEB
|
ifnull
|
2012-02-23
|
|
ForkCMS 3.2.5 Multiple Vulnerabilities
|
89 |
WEB
|
Ivano Binetti
|
2012-02-23
|
|
Sagem F@ST 2604 CSRF Vulnerability (ADSL Router)
|
94 |
WEB
|
KinG Of PiraTeS
|
2012-02-23
|
|
Limesurvey (PHPSurveyor v.1.91+ stable) Blind SQL Injection
|
80 |
WEB
|
TorTukiTu
|
2012-02-23
|
|
VOXTRONIC Voxlog Professional 3.7.2.729 SQL Injection
|
304 |
WEB
|
J. Greil
|
2012-02-23
|
|
TestLink SQL Injection Vulnerabilities
|
99 |
WEB
|
Juan M. Natal
|
2012-02-23
|
|
Cisco Linksys WAG54GS (ADSL Router) change admin password
|
71 |
WEB
|
Ivano Binetti
|
2012-02-23
|
|
MySQLDumper v1.2x.x SQL Injection/Execute Vulnerability
|
129 |
WEB
|
KedAns-Dz
|
2012-02-23
|
|
Beats Website SQL Injection Vulnerability
|
88 |
WEB
|
system k1ller
|
2012-02-22
|
|
Cisco Linksys WAG54GS CSRF Change Admin Password
|
107 |
WEB
|
Ivano Binetti
|
2012-02-21
|
|
PlumeCMS <= 1.2.4 CSRF Vulnerability
|
65 |
WEB
|
Ivano Binetti
|
2012-02-21
|
|
D-Link DSL-2640B (ADSL Router) CSRF Vulnerability
|
114 |
WEB
|
Ivano Binetti
|
2012-02-21
|
|
Joomla com_etree Blind SQL-inj Vuln
|
88 |
WEB
|
Mach1ne
|
2012-02-20
|
|
SyndeoCMS <= 3.0 CSRF Vulnerability
|
64 |
WEB
|
Ivano Binetti
|
2012-02-20
|
|
4PSA CMS SQL Injection Vulnerabilities
|
57 |
WEB
|
BHG Security Center
|
2012-02-20
|
|
almnzm 2.4 <= CSRF Vulnerability (Add Admin)
|
166 |
WEB
|
HaNniBaL KsA
|
2012-02-20
|
|
Pandora FMS v4.0.1 - Local File Include Vulnerability
|
96 |
WEB
|
Vulnerability-Lab
|
2012-02-20
|
|
Mitra Iranian CMS Remote File Upload
|
103 |
WEB
|
Nitrojen90
|
2012-02-20
|
|
Joomla Component com_x-shop (idd) <= SQLi Vulnerability
|
72 |
WEB
|
KedAns-Dz
|
2012-02-20
|
|
Joomla Component (com_xcomp) <= Local File Inclusion Vulnerability
|
76 |
WEB
|
KedAns-Dz
|
2012-02-20
|
|
Joomla Component (com_xvs) <= Local File Inclusion Vulnerability
|
80 |
WEB
|
KedAns-Dz
|
2012-02-20
|
|
CDPI Software SQL Injection Vulnerability
|
90 |
WEB
|
ITTIHACK
|
2012-02-20
|
|
TopForm CMS SQL Injection Vulnerability
|
92 |
WEB
|
faza02
|
2012-02-20
|
|
Solgens SQLInjection Vulnerability
|
69 |
WEB
|
the_cyber_nuxbie
|
2012-02-20
|
|
Pirelli Discus DSL-DRGA112-07 Remote Change Password
|
76 |
WEB
|
Daniel Godoy
|
2012-02-20
|
|
Telerom CMS SQLi Vulnerability
|
69 |
WEB
|
ITTIHACK
|
2012-02-17
|
|
SocialCMS CSRF Vulnerability
|
91 |
WEB
|
Ivano Binetti
|
2012-02-17
|
|
LEPTON 1.1.3 SQL Injection / XSS / Local File Inclusion
|
169 |
WEB
|
expku
|
2012-02-17
|
|
BuyWebArt <<< SQL Injection Vulnerability
|
92 |
WEB
|
Infamous
|
2012-02-17
|
|
Fork CMS v.3.2.4 - Multiple Vulnerabilities
|
57 |
WEB
|
RandomStorm
|
2012-02-16
|
|
AHLANNET<<< SQL Injection Vulnerability
|
82 |
WEB
|
Infamous
|
2012-02-15
|
|
Chicago Tribune Cross Site Scripting
|
100 |
WEB
|
Janne Ahlberg
|
2012-02-15
|
|
Sonexis ConferenceManager Information Disclosure
|
129 |
WEB
|
Netragard
|
2012-02-13
|
|
PBBoard v2.1.4 <= Multiple Vulnerabilites
|
83 |
WEB
|
KedAns-Dz
|
2012-02-13
|
|
Razor CMS v1.2 <= Multiple File Disclosure Vulnerabilites
|
82 |
WEB
|
KedAns-Dz
|
2012-02-13
|
|
Dolibarr CMS v3.2.0 Alpha - File Include Vulnerabilities
|
103 |
WEB
|
Vulnerability-Lab
|
2012-02-10
|
|
SimogeoFilemanager Upload File Vulnerability
|
317 |
WEB
|
hack`
|
2012-02-10
|
|
Pluck CMS 4.7 Multiple CSRF Vulnerabilities
|
91 |
WEB
|
Gordon Security
|
2012-02-09
|
|
D-Link ShareCenter Remote Code Execution
|
75 |
WEB
|
Roberto Paleari
|
2012-02-09
|
|
Tibetsystem OwnServer 1.0 Directory Traversal
|
190 |
WEB
|
Jason Ellison
|
2012-02-09
|
|
Cyberoam Central Console v2.00.2 - File Include Vulnerability
|
110 |
WEB
|
Vulnerability-Lab
|
2012-02-09
|
|
Ananta Gazelle CMS - Update Statement Sql injection
|
72 |
WEB
|
hackme
|
2012-02-08
|
|
Flyspray 0.9.9.6 CSRF Vulnerability
|
94 |
WEB
|
Vaibhav Gupta
|
2012-02-07
|
|
XRayCMS 1.1.1 SQL Injection Vulnerability
|
76 |
WEB
|
chap0
|
2012-02-07
|
|
Tube Ace(Adult PHP Tube Script) SQL Injection
|
115 |
WEB
|
Daniel Godoy
|
2012-02-07
|
|
BASE 1.4.5 (base_qry_main.php t_view) SQL Injection Vulnerability
|
68 |
WEB
|
a.kadir altan
|
2012-02-06
|
|
Tube Ace(Adult PHP Tube Script) SQL Injection
|
77 |
WEB
|
Daniel Godoy
|
2012-02-06
|
|
GAzie <= 5.20 Cross Site Request Forgery
|
80 |
WEB
|
Giuseppe D'Inverno
|
2012-02-03
|
|
Achievo v1.4.3 - Multiple Web Vulnerabilities
|
82 |
WEB
|
Vulnerability-Lab
|
2012-02-03
|
|
OSCommerce v3.0.2 - Persistent Cross Site Vulnerability
|
169 |
WEB
|
Vulnerability-Lab
|
2012-02-03
|
|
Apache Struts Multiple Persistent Cross-Site Scripting Vulnerabilities
|
212 |
WEB
|
SecPod Research
|
2012-02-03
|
|
Sphinix Mobile Web Server 3.1.2.47 Multiple Persistent XSS Vulnerabilities
|
86 |
WEB
|
SecPod Research
|
2012-02-02
|
|
MailEnable Webmail Cross-Site Scripting Vulnerability
|
88 |
WEB
|
Sajjad Pourali
|
2012-02-02
|
|
Webkit normalize bug for android 2.2 (CVE-2010-1759)
|
94 |
WEB
|
MJ Keith
|
2012-02-02
|
|
SiT! Support Incident Tracker 3.64 Multiple Vulnerabilities
|
78 |
WEB
|
High-Tech Bridge SA
|
2012-02-02
|
|
swDesk Multiple Vulnerabilities
|
87 |
WEB
|
Red Security TEAM
|
2011-12-13
|
|
Squiz Matrix - User Account Enumeration
|
76 |
WEB
|
Troy Rose
|
2011-12-12
|
|
Docebo LMS <= v4.0.4 (messages) Remote Code Execution
|
95 |
WEB
|
mr_me
|
2011-12-09
|
|
QContacts 1.0.6 (Joomla component) SQL injection
|
83 |
WEB
|
Don
|
2011-12-09
|
|
SantriaCMS SQL Injection Vulnerability
|
102 |
WEB
|
Troy
|
2011-12-09
|
|
QContacts 1.0.6 (Joomla component) SQL injection
|
89 |
WEB
|
Don
|
2011-12-08
|
|
SourceBans <= 1.4.8 SQL/LFI Injection
|
99 |
WEB
|
Havok
|
2011-12-08
|
|
SMF <= 2.0.1 SQL Injection, Privilege Escalation
|
105 |
WEB
|
The:Paradox
|
2011-12-08
|
|
Traq <= 2.3 Authentication Bypass / Remote Code Execution Exploit
|
87 |
WEB
|
EgiX
|
2011-12-08
|
|
phpBB MyPage Plugin SQL Injection
|
100 |
WEB
|
CrazyMouse
|
2011-12-08
|
|
Family Connections less.php Remote Command Execution
|
89 |
WEB
|
mr_me
|
2011-12-08
|
|
Php City Portal Script Software SQL Injection
|
122 |
WEB
|
Don
|
2011-12-07
|
|
AlstraSoft EPay Enterprise v4.0 Blind SQL Injection
|
186 |
WEB
|
Don
|
2011-12-07
|
|
PEC php calendars script SQL Injection
|
85 |
WEB
|
Mr.MLL
|
2011-12-07
|
|
Five Star Review Remote SQL Injection (recommend.php)
|
97 |
WEB
|
EthicalPractice
|
2011-12-07
|
|
Meditate Web Content Editor 'username_input' SQL-Injection vulnerability
|
78 |
WEB
|
Stefan Schurtz
|
2011-12-06
|
|
Apache MyFaces information disclosure vulnerability
|
212 |
WEB
|
expku
|
2011-12-06
|
|
Meditate Web Content Editor 'username_input' SQL-Injection vulnerability
|
81 |
WEB
|
Stefan Schurtz
|
2011-12-06
|
|
majalty (category.php) Blind SQL Injection Vulnerability
|
258 |
WEB
|
TH3.ONE
|
2011-12-05
|
|
Family Connections CMS v2.5.0-v2.7.1 (less.php) Remote Command Execution
|
85 |
WEB
|
mr_me
|
2011-12-05
|
|
WSN Classifieds v.6.2.12 and 6.2.18 Multiple Vulnerabilities
|
107 |
WEB
|
d3v1l
|
2011-12-05
|
|
Joomla Jobprofile Component (com_jobprofile) SQL Injection
|
95 |
WEB
|
kaMtiEz
|
2011-12-05
|
|
CLEVAR CMS Multiple Vulnerabilities
|
119 |
WEB
|
Mr.XHat
|
2011-12-05
|
|
Con-IMedia SQL inj: vulnerable
|
212 |
WEB
|
nGa Sa Lu
|
2011-12-02
|
|
Muster Render Farm Management System Arbitrary File Download
|
77 |
WEB
|
Nick Freeman
|
2011-12-01
|
|
WikkaWiki <= 1.3.2 Multiple Security Vulnerabilities
|
193 |
WEB
|
EgiX
|
2011-11-29
|
|
Bypass the JQuery-Real-Person captcha plugin 0-day
|
127 |
WEB
|
Alberto_García_Illera
|
2011-11-28
|
|
Android 'content://' URI Multiple Information Disclosure Vulnerabilities
|
89 |
WEB
|
Thomas Cannon
|
2011-11-28
|
|
php video script SQL Injection Vulnerability
|
100 |
WEB
|
longrifle0x
|
2011-11-25
|
|
Zabbix <= 1.8.4 (popup.php) SQL Injection
|
88 |
WEB
|
Marcio Almeida
|
2011-11-25
|
|
LibLime Koha <= 4.2 Local File Inclusion Vulnerability
|
91 |
WEB
|
Akin Tosunlar
|