Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2019-04-02   Inout EasyRooms - SQL Injection 30 WEB Ahmet Ümit BAYRAM
2019-03-29   CentOS Web Panel 0.9.8.789 - NameServer Field Persistent Cross-Site Scripting 30 WEB DKM
2019-03-28   Jettweb PHP Hazır Rent A Car Sitesi Scripti V2 - 'arac_kategori_id' SQL Injection 45 WEB Ahmet Ümit BAYRAM
2019-03-28   BigTree 4.3.4 CMS - Multiple SQL Injection 29 WEB Mehmet EMIROGLU
2019-03-28   Job Portal 3.1 - 'job_submit' SQL Injection 34 WEB Mehmet EMIROGLU
2019-03-28   i-doit 1.12 - 'qr.php' Cross-Site Scripting 29 WEB BlackFog Team
2019-03-28   WordPress Plugin Loco Translate 2.2.1 - Local File Inclusion 31 WEB Ali S. Ahmad
2019-03-28   WordPress Plugin Anti-Malware Security and Brute-Force Firewall 4.18.63 - Local File Inclusion (PoC) 28 WEB Ali S. Ahmad
2019-03-28   Fat Free CRM 0.19.0 - HTML Injection 25 WEB Ismail Tasdelen
2019-03-28   Airbnb Clone Script - Multiple SQL Injection 26 WEB Ahmet Ümit BAYRAM
2019-03-28   Thomson Reuters Concourse & Firm Central < 2.13.0097 - Directory Traversal / Local File Inclusion 27 WEB 0v3rride
2019-03-28   Thomson Reuters Concourse & Firm Central < 2.13.0097 - Directory Traversal / Local File Inclusion 27 WEB 0v3rride
2019-03-27   Jettweb Hazır Rent A Car Scripti V4 - SQL Injection 29 WEB Ahmet Ümit BAYRAM
2019-03-26   SJS Simple Job Script - SQL Injection / Cross-Site Scripting 30 WEB Ahmet Ümit BAYRAM
2019-03-26   SJS Simple Job Script - SQL Injection / Cross-Site Scripting 26 WEB Ahmet Ümit BAYRAM
2019-03-26   Titan FTP Server Version 2019 Build 3505 - Directory Traversal / Local File Inclusion 26 WEB Kevin Randall
2019-03-26   Titan FTP Server Version 2019 Build 3505 - Directory Traversal / Local File Inclusion 28 WEB Kevin Randall
2019-03-26   XooDigital - 'p' SQL Injection 28 WEB Ahmet Ümit BAYRAM
2019-03-26   XooGallery - Multiple SQL Injection 30 WEB Ahmet Ümit BAYRAM
2019-03-26   Rukovoditel ERP & CRM 2.4.1 - 'path' Cross-Site Scripting 29 WEB Javier Olmedo
2019-03-26   Jettweb Php Hazır İlan Sitesi Scripti V2 - SQL Injection 31 WEB Ahmet Ümit BAYRAM
2019-03-25   Zeeways Matrimony CMS - SQL Injection 28 WEB Ahmet Ümit BAYRAM
2019-03-25   Zeeways Jobsite CMS - 'id' SQL Injection 30 WEB Ahmet Ümit BAYRAM
2019-03-25   Jettweb PHP Hazır Haber Sitesi Scripti V3 - SQL Injection 24 WEB Ahmet Ümit BAYRAM
2019-03-25   Jettweb PHP Hazır Haber Sitesi Scripti V2 - SQL Injection (Authentication Bypass) 22 WEB Ahmet Ümit BAYRAM
2019-03-25   Jettweb PHP Hazır Haber Sitesi Scripti V2 - SQL Injection (Authentication Bypass) 26 WEB Ahmet Ümit BAYRAM
2019-03-25   Jettweb PHP Hazır Haber Sitesi Scripti V1 - SQL Injection 27 WEB Ahmet Ümit BAYRAM
2019-03-25   Apache CouchDB 2.3.1 - Cross-Site Request Forgery / Cross-Site Scripting 27 WEB Ozer Goker
2019-03-25   Apache CouchDB 2.3.1 - Cross-Site Request Forgery / Cross-Site Scripting 28 WEB Ozer Goker
2019-03-22   Inout Article Base CMS - SQL Injection 30 WEB Ahmet Ümit BAYRAM
2019-03-22   Meeplace Business Review Script - 'id' SQL Injection 27 WEB Ahmet Ümit BAYRAM
2019-03-22   Matri4Web Matrimony Website Script - Multiple SQL Injection 26 WEB Ahmet Ümit BAYRAM
2019-03-21   Bootstrapy CMS - Multiple SQL Injection 32 WEB Ahmet Ümit BAYRAM
2019-03-21   Placeto CMS Alpha v4 - 'page' SQL Injection 28 WEB Abdullah Çelebi
2019-03-21   uHotelBooking System - 'system_page' SQL Injection 26 WEB Ahmet Ümit BAYRAM
2019-03-21   The Company Business Website CMS - Multiple Vulnerabilities 25 WEB Ahmet Ümit BAYRAM
2019-03-21   Rails 5.2.1 - Arbitrary File Content Disclosure 25 WEB NotoriousRebel
2019-03-21   Netartmedia Vlog System - 'email' SQL Injection 28 WEB Ahmet Ümit BAYRAM
2019-03-20   Netartmedia Deals Portal - 'Email' SQL Injection 23 WEB Ahmet Ümit BAYRAM
2019-03-20   PLC Wireless Router GPN2.4P21-C-CN - Cross-Site Request Forgery 26 WEB Kumar Saurav
2019-03-20   PLC Wireless Router GPN2.4P21-C-CN - Incorrect Access Control 26 WEB Kumar Saurav
2019-03-20   202CMS v10beta - Multiple SQL Injection 27 WEB Mehmet EMIROGLU
2019-03-20   Netartmedia PHP Business Directory 4.2 - SQL Injection 29 WEB Ahmet Ümit BAYRAM
2019-03-20   Netartmedia PHP Dating Site - SQL Injection 29 WEB Ahmet Ümit BAYRAM
2019-03-20   Netartmedia Jobs Portal 6.1 - SQL Injection 25 WEB Ahmet Ümit BAYRAM
2019-03-20   Netartmedia PHP Real Estate Agency 4.0 - SQL Injection 29 WEB Ahmet Ümit BAYRAM
2019-03-20   Netartmedia PHP Car Dealer - SQL Injection 33 WEB Ahmet Ümit BAYRAM
2019-03-19   Netartmedia Real Estate Portal 5.0 - SQL Injection 33 WEB Ahmet Ümit BAYRAM
2019-03-19   Netartmedia PHP Mall 4.1 - SQL Injection 25 WEB Ahmet Ümit BAYRAM
2019-03-19   Netartmedia Event Portal 2.0 - 'Email' SQL Injection 28 WEB Ahmet Ümit BAYRAM
2019-03-19   eNdonesia Portal 8.7 - Multiple Vulnerabilities 28 WEB Mehmet EMIROGLU
2019-03-19   MyBB Upcoming Events Plugin 1.32 - Cross-Site Scripting 28 WEB 0xB9
2019-03-19   Gila CMS 1.9.1 - Cross-Site Scripting 27 WEB Ahmet Ümit BAYRAM
2019-03-18   TheCarProject 2 - Multiple SQL Injection 33 WEB Mehmet EMIROGLU
2019-03-15   Moodle 3.4.1 - Remote Code Execution 32 WEB Darryn Ten
2019-03-15   Laundry CMS - Multiple Vulnerabilities 30 WEB Mehmet EMIROGLU
2019-03-15   Vembu Storegrid Web Interface 4.4.0 - Multiple Vulnerabilities 26 WEB Gionathan Reale
2019-03-15   ICE HRM 23.0 - Multiple Vulnerabilities 27 WEB Mehmet EMIROGLU
2019-03-15   CMS Made Simple Showtime2 Module 3.6.2 - (Authenticated) Arbitrary File Upload 32 WEB Daniele Scanu
2019-03-15   NetData 1.13.0 - HTML Injection 31 WEB s4vitar
2019-03-14   Pegasus CMS 1.0 - 'extra_fields.php' Plugin Remote Code Execution 36 WEB R3zk0n
2019-03-14   Intel Modular Server System 10.18 - Cross-Site Request Forgery (Change Admin Password) 33 WEB LiquidWorm
2019-03-13   pfSense 2.4.4-p1 (HAProxy Package 0.59_14) - Persistent Cross-Site Scripting 32 WEB Gionathan Reale
2019-03-13   WordPress Plugin GraceMedia Media Player 1.0 - Local File Inclusion 27 WEB Manuel García Cárdenas
2019-03-12   PilusCart 1.4.1 - Cross-Site Request Forgery (Add Admin) 32 WEB Gionathan Reale
2019-03-11   Flexpaper PHP Publish Service 2.3.6 - Remote Code Execution 28 WEB redtimmysec
2019-03-11   PRTG Network Monitor 18.2.38 - (Authenticated) Remote Code Execution 28 WEB M4LV0
2019-03-11   OpenKM 6.3.2 < 6.3.7 - Remote Command Execution (Metasploit) 29 WEB AkkuS
2019-03-11   Liferay CE Portal < 7.1.2 ga3 - Remote Command Execution (Metasploit) 29 WEB AkkuS
2019-03-08   DirectAdmin 1.55 - 'CMD_ACCOUNT_ADMIN' Cross-Site Request Forgery 33 WEB ManhNho
2019-03-08   McAfee ePO 5.9.1 - Registered Executable Local Access Bypass 31 WEB leonjza
2019-03-08   OrientDB 3.0.17 GA Community Edition - Cross-Site Request Forgery / Cross-Site Scripting 31 WEB Ozer Goker
2019-03-08   OrientDB 3.0.17 GA Community Edition - Cross-Site Request Forgery / Cross-Site Scripting 30 WEB Ozer Goker
2018-12-12   phpBB 3.2.3 - Remote Code Execution 32 WEB allyshka
2019-03-01   WordPress Core 5.0 - Remote Code Execution 32 WEB allyshka
2019-03-07   Kados R10 GreenBee - Multiple SQL Injection 35 WEB Mehmet EMIROGLU
2019-03-05   OpenDocMan 1.3.4 - 'search.php where' SQL Injection 25 WEB Mehmet EMIROGLU
2019-03-04   Fiberhome AN5506-04-F RP2669 - Persistent Cross-Site Scripting 28 WEB Tauco
2019-03-04   WordPress Plugin Cerber Security_ Antispam & Malware Scan 8.0 - Multiple Bypass Vulnerabilities 33 WEB ed0x21son
2019-03-04   Craft CMS 3.1.12 Pro - Cross-Site Scripting 29 WEB Ismail Tasdelen
2019-03-04   Bolt CMS 3.6.4 - Cross-Site Scripting 33 WEB Ismail Tasdelen
2019-03-04   MarcomCentral FusionPro VDP Creator < 10.0 - Directory Traversal 30 WEB 0v3rride
2019-03-04   Raisecom XPON ISCOMHT803G-U_2.0.0_140521_R4.1.47.002 - Remote Code Execution 33 WEB JameelNabbo
2019-03-04   zzzphp CMS 1.6.1 - Cross-Site Request Forgery 30 WEB Yang Chenglong
2019-03-04   Splunk Enterprise 7.2.4 - Custom App Remote Command Execution (Persistent Backdoor / Custom Binary) 33 WEB Matteo Malvica
2019-03-04   Booked Scheduler 2.7.5 - Remote Command Execution (Metasploit) 29 WEB AkkuS
2019-03-04   OOP CMS BLOG 1.0 - Multiple Cross-Site Request Forgery 32 WEB Mr Winst0n
2019-03-04   OOP CMS BLOG 1.0 - Multiple SQL Injection 32 WEB Mr Winst0n
2019-03-04   elFinder 2.1.47 - 'PHP connector' Command Injection 34 WEB q3rv0
2019-03-04   CMSsite 1.0 - Multiple Cross-Site Request Forgery 29 WEB Mr Winst0n
2019-02-28   Feng Office 3.7.0.5 - Remote Command Execution (Metasploit) 43 WEB AkkuS
2019-02-28   Usermin 1.750 - Remote Command Execution (Metasploit) 30 WEB AkkuS
2019-02-28   Joomla! Component J2Store < 3.3.7 - SQL Injection 31 WEB Andrei Conache
2019-02-28   Simple Online Hotel Reservation System - Cross-Site Request Forgery (Delete Admin) 32 WEB Mr Winst0n
2019-02-28   Simple Online Hotel Reservation System - Cross-Site Request Forgery (Add Admin) 29 WEB Mr Winst0n
2019-02-28   Simple Online Hotel Reservation System - SQL Injection 27 WEB Mr Winst0n
2019-02-25   Drupal < 8.6.9 - REST Module Remote Code Execution 34 WEB leonjza
2019-02-25   Advance Gift Shop Pro Script 2.0.3 - SQL Injection 36 WEB Mr Winst0n
2019-02-25   News Website Script 2.0.5 - SQL Injection 29 WEB Mr Winst0n
2019-02-25   PHP Ecommerce Script 2.0.6 - Cross-Site Scripting / SQL Injection 24 WEB Mr Winst0n
2019-02-25   zzzphp CMS 1.6.1 - Remote Code Execution 28 WEB Yang Chenglong
2019-02-25   Jenkins Plugin Script Security 1.49/Declarative 1.3.4/Groovy 2.60 - Remote Code Execution 28 WEB wetw0rk
2019-02-23   Drupal < 8.6.10 / < 8.5.11 - REST Module Remote Code Execution 29 WEB Charles Fol
2019-02-22   Teracue ENC-400 - Command Injection / Missing Authentication 29 WEB Stephen Shkardoon
2019-02-22   Micro Focus Filr 3.4.0.217 - Path Traversal / Local Privilege Escalation 39 WEB SecureAuth
2019-02-22   Quest NetVault Backup Server < 11.4.5 - Process Manager Service SQL Injection / Remote Code Executio 39 WEB Chris Anastasio
2019-02-21   EI-Tube 3 - SQL Injection 30 WEB Meisam Monsef
2019-02-21   C4G Basic Laboratory Information System (BLIS) 3.4 - SQL Injection 34 WEB Carlos Avila
2019-02-20   HotelDruid 2.3 - Cross-Site Scripting 32 WEB Mehmet EMIROGLU
2019-02-19   Jenkins Plugin Script Security < 1.50/Declarative < 1.3.4.1/Groovy < 2.61.1 - Remote Code Execution 35 WEB orange
2019-02-19   Ask Expert Script 3.0.5 - Cross Site Scripting / SQL Injection 27 WEB Mr Winst0n
2019-02-19   Ask Expert Script 3.0.5 - Cross Site Scripting / SQL Injection 29 WEB Mr Winst0n
2019-02-19   Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2 - Path Traversal / Cross-Site Scripting 29 WEB Rafael Pedrero
2019-02-19   Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2 - Path Traversal / Cross-Site Scripting 27 WEB Rafael Pedrero
2019-02-19   XAMPP 5.6.8 - SQL Injection / Persistent Cross-Site Scripting 32 WEB Rafael Pedrero
2019-02-19   XAMPP 5.6.8 - SQL Injection / Persistent Cross-Site Scripting 31 WEB Rafael Pedrero
2019-02-19   eDirectory - SQL Injection 32 WEB Efrén Díaz
2019-02-19   Zuz Music 2.1 - 'zuzconsole/___contact ' Persistent Cross-Site Scripting 38 WEB Deyaa Muhammad
2019-02-19   Listing Hub CMS 1.0 - 'pages.php id' SQL Injection 31 WEB Deyaa Muhammad
2019-02-19   Find a Place CMS Directory 1.5 - 'assets/external/data_2.php cate' SQL Injection 34 WEB Deyaa Muhammad
2019-02-18   WordPress Plugin WooCommerce - GloBee (cryptocurrency) Payment Gateway 1.1.1 - Payment Bypass / Unau 31 WEB GeekHack
2019-02-18   Zoho ManageEngine ServiceDesk Plus (SDP) < 10.0 build 10012 - Arbitrary File Upload 33 WEB Dao Duy Hung
2019-02-18   Comodo Dome Firewall 2.7.0 - Cross-Site Scripting 34 WEB Ozer Goker
2019-02-18   ArangoDB Community Edition 3.4.2-1 - Cross-Site Scripting 32 WEB Ozer Goker
2019-02-18   Apache CouchDB 2.3.0 - Cross-Site Scripting 33 WEB Ozer Goker