Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2018-02-14   userSpice 4.3 - Cross-Site Scripting 28 WEB Dolev Farhi
2018-02-14   SOA School Management - 'access_login' SQL Injection 29 WEB L0RD
2018-02-14   Social Oauth Login PHP - Authentication Bypass 29 WEB L0RD
2018-02-14   NAT32 2.2 Build 22284 - Cross-Site Request Forgery 37 WEB hyp3rlinx
2018-02-14   NAT32 2.2 Build 22284 - Remote Command Execution 48 WEB hyp3rlinx
2018-02-13   News Website Script 2.0.4 - 'search' SQL Injection 31 WEB Varun Bagaria
2018-02-13   TypeSetter CMS 5.1 - Cross-Site Request Forgery 36 WEB Navina Asrani
2018-02-13   TypeSetter CMS 5.1 - 'Host' Header Injection 41 WEB Navina Asrani
2018-02-12   LogicalDOC Enterprise 7.7.4 - Root Remote Code Execution 38 WEB LiquidWorm
2018-02-12   LogicalDOC Enterprise 7.7.4 - User Enumeration 35 WEB LiquidWorm
2018-02-12   LogicalDOC Enterprise 7.7.4 - Directory Traversal 30 WEB LiquidWorm
2018-02-11   Readymade Video Sharing Script 3.2 - 'search' SQL Injection 33 WEB Varun Bagaria
2018-02-11   Paypal Clone Script 1.0.9 - 'id' / 'acctype' SQL Injection 29 WEB L0RD
2018-02-10   Multi Language Olx Clone Script - Cross-Site Scripting 33 WEB Varun Bagaria
2018-02-10   Naukri Clone Script 3.0.3 - 'indus' SQL Injection 36 WEB L0RD
2018-02-07   Entrepreneur Dating Script 2.0.2 - Authentication Bypass 33 WEB L0RD
2018-02-07   Online Test Script 2.0.7 - 'cid' SQL Injection 35 WEB L0RD
2018-02-05   Netis WF2419 Router - Cross-Site Scripting 38 WEB Sajibe Kanti
2018-02-05   Student Profile Management System Script 2.0.6 - Authentication Bypass 33 WEB L0RD
2018-02-05   Joomla! Component JSP Tickets 1.1 - SQL Injection 30 WEB Ihsan Sencan
2018-02-05   Joomla! Component jLike 1.0 - Information Leak 31 WEB Ihsan Sencan
2018-02-05   Joomla! Component Zh GoogleMap 8.4.0.0 - SQL Injection 28 WEB Ihsan Sencan
2018-02-05   Joomla! Component Zh YandexMap 6.2.1.0 - 'id' SQL Injection 32 WEB Ihsan Sencan
2018-02-05   Joomla! Component Zh BaiduMap 3.0.0.1 - SQL Injection 35 WEB Ihsan Sencan
2018-02-05   Online Voting System - Authentication Bypass 34 WEB Giulio Comi
2018-02-05   NixCMS 1.0 - 'category_id' SQL Injection 31 WEB Bora Bozdogan
2018-02-05   Matrimonial Website Script 2.1.6 - 'uid' SQL Injection 31 WEB L0RD
2018-02-05   Wonder CMS 2.3.1 - 'Host' Header Injection 30 WEB Samrat Das
2018-02-05   Wonder CMS 2.3.1 - Unrestricted File Upload 31 WEB Samrat Das
2018-02-02   FiberHome AN5506 - Remote DNS Change 31 WEB r0ots3c
2018-02-02   Oracle Hospitality Simphony (MICROS) 2.7 < 2.9 - Directory Traversal 31 WEB Dmitry Chastuhin
2018-02-02   Joomla! Component JMS Music 1.1.1 - SQL Injection 28 WEB Ihsan Sencan
2018-02-02   Joomla! Component Jimtawl 2.1.6 - Arbitrary File Upload 30 WEB Ihsan Sencan
2018-02-02   Joomla! Component JEXTN Classified 1.0.0 - 'sid' SQL Injection 28 WEB Ihsan Sencan
2018-02-02   Joomla! Component JEXTN Reverse Auction 3.1.0 - SQL Injection 34 WEB Ihsan Sencan
2018-02-02   Event Manager 1.0 - SQL Injection 34 WEB Ihsan Sencan
2018-02-02   Joomla! Component JE PayperVideo 3.0.0 - 'usr_plan' SQL Injection 26 WEB Ihsan Sencan
2018-02-02   IPSwitch MOVEit 8.1 < 9.4 - Cross-Site Scripting 28 WEB 1n3
2018-02-02   Advance Loan Management System - 'id' SQL Injection 24 WEB 8bitsec
2018-02-02   Real Estate Custom Script - 'route' SQL Injection 27 WEB 8bitsec
2018-02-02   Fancy Clone Script - 'search_browse_product' SQL Injection 29 WEB 8bitsec
2018-02-02   Joomla! Component JEXTN Membership 3.1.0 - 'usr_plan' SQL Injection 34 WEB Ihsan Sencan
2018-01-30   BMC BladeLogic RSCD Agent 8.3.00.64 - Windows Users Disclosure 28 WEB Paul Taylor
2018-01-30   Joomla! Component Visual Calendar 3.1.3 - 'id' SQL Injection 29 WEB Ihsan Sencan
2018-01-30   Joomla! Component CP Event Calendar 3.0.1 - 'id' SQL Injection 32 WEB Ihsan Sencan
2018-01-30   Joomla! Component Picture Calendar for Joomla! 3.1.4 - Directory Traversal 29 WEB Ihsan Sencan
2018-01-30   Advantech WebAccess < 8.3 - SQL Injection 36 WEB Chris Lyne
2018-01-28   KeystoneJS < 4.0.0-beta.7 - Cross-Site Request Forgery 29 WEB Saurabh Banawar
2018-01-28   Netis WF2419 Router - Cross-Site Request Forgery 35 WEB Sajibe Kanti
2018-01-28   Buddy Zone 2.9.9 - SQL Injection 30 WEB Ihsan Sencan
2018-01-28   Multilanguage Real Estate MLM Script 3.0 - 'srch' SQL Injection 30 WEB Ihsan Sencan
2018-01-28   Hot Scripts Clone - 'subctid' SQL Injection 30 WEB Ihsan Sencan
2018-01-28   TSiteBuilder 1.0 - SQL Injection 28 WEB Ihsan Sencan
2018-01-28   Task Rabbit Clone 1.0 - 'id' SQL Injection 27 WEB Ihsan Sencan
2018-01-28   Joomla! Component Jtag Members Directory 5.3.7 - Arbitrary File Download 27 WEB Ihsan Sencan
2018-01-28   Joomla! Component JS Support Ticket 1.1.0 - Cross-Site Request Forgery 26 WEB Ihsan Sencan
2018-01-28   Nexpose < 6.4.66 - Cross-Site Request Forgery 28 WEB Shwetabh Vishnoi
2018-01-28   Gnew 2018.1 - Cross-Site Request Forgery 29 WEB Cyril Vallicari
2018-01-28   PACSOne Server 6.6.2 DICOM Web Viewer - SQL Injection 33 WEB Carlos Avila
2018-01-28   PACSOne Server 6.6.2 DICOM Web Viewer - Directory Trasversal 32 WEB Carlos Avila
2018-01-26   WordPress Plugin Learning Management System - 'course_id' SQL Injection 32 WEB Esecurity.ir
2018-01-25   ASUS DSL-N14U B1 Router 1.1.2.3_345 - Change Administrator Password 29 WEB Víctor Calvo
2018-01-26   Dodocool DC38 N300 - Cross-site Request Forgery 30 WEB Raffaele Sabato
2014-11-09   ManageEngine OpManager / Social IT Plus / IT360 - Multiple Vulnerabilities 29 WEB Pedro Ribeiro
2014-12-03   ManageEngine Netflow Analyzer / IT360 - Arbitrary File Download 30 WEB Pedro Ribeiro
2015-02-09   ManageEngine OpManager / Applications Manager / IT360 - 'FailOverServlet' Multiple Vulnerabilities 38 WEB Pedro Ribeiro
2014-11-05   ManageEngine EventLog Analyzer - Multiple Vulnerabilities (2) 31 WEB Pedro Ribeiro
2015-01-15   ManageEngine Desktop Central - Create Administrator 30 WEB Pedro Ribeiro
2014-10-12   CMS Made Simple 1.11.9 - Multiple Vulnerabilities 35 WEB Pedro Ribeiro
2014-10-12   GetSimple CMS 3.3.1 - Cross-Site Scripting 30 WEB Pedro Ribeiro
2014-10-12   Pimcore CMS 1.4.9 <2.1.0 - Multiple Vulnerabilities 30 WEB Pedro Ribeiro
2015-06-10   SysAid Help Desk 14.4 - Multiple Vulnerabilities 31 WEB Pedro Ribeiro
2017-01-31   Billion / TrueOnline / ZyXEL Routers - Multiple Vulnerabilities 25 WEB Pedro Ribeiro
2015-09-28   BMC Track-It! 11.4 - Multiple Vulnerabilities 41 WEB Pedro Ribeiro
2015-09-28   Kaseya Virtual System Administrator (VSA) 7.0 < 9.1 - (Authenticated) Arbitrary File Upload 33 WEB Pedro Ribeiro
2018-01-24   Telerik UI for ASP.NET AJAX 2012.3.1308 < 2017.1.118 - Arbitrary File Upload 30 WEB Paul Taylor
2018-01-24   Telerik UI for ASP.NET AJAX 2012.3.1308 < 2017.1.118 - Encryption Keys Disclosure 27 WEB Paul Taylor
2018-01-24   WordPress Plugin Email Subscribers & Newsletters 3.4.7 - Information Disclosure 32 WEB ThreatPress Security
2018-01-24   Professional Local Directory Script 1.0 - SQL Injection 30 WEB Ihsan Sencan
2018-01-23   Flexible Poll 1.2 - SQL Injection 28 WEB Ihsan Sencan
2018-01-23   Quickad 4.0 - SQL Injection 32 WEB Ihsan Sencan
2018-01-23   Photography CMS 1.0 - Cross-Site Request Forgery (Add Admin) 29 WEB Ihsan Sencan
2018-01-23   Tumder 2.1 - SQL Injection 30 WEB Ihsan Sencan
2018-01-23   Zechat 1.5 - SQL Injection 32 WEB Ihsan Sencan
2018-01-23   Wchat 1.5 - SQL Injection 30 WEB Ihsan Sencan
2018-01-23   Easy Car Script 2014 - SQL Injection 33 WEB Ihsan Sencan
2018-01-23   RSVP Invitation Online 1.0 - Cross-Site Request Forgery (Update Admin) 27 WEB Ihsan Sencan
2018-01-23   Affiligator 2.1.0 - SQL Injection 30 WEB Ihsan Sencan
2018-01-23   LiveCRM SaaS Cloud 1.0 - SQL Injection 29 WEB Ihsan Sencan
2018-01-23   NEC Univerge SV9100/SV8100 WebPro 10.0 - Configuration Download 33 WEB LiquidWorm
2018-01-23   CentOS Web Panel 0.9.8.12 - 'row_id' / 'domain' SQL Injection 34 WEB Vulnerability-Lab
2018-01-21   OTRS 5.0.x/6.0.x - Remote Command Execution (1) 33 WEB Bæln0rn
2018-01-21   CentOS Web Panel 0.9.8.12 - Multiple Vulnerabilities 31 WEB Vulnerability-Lab
2018-01-21   Shopware 5.2.5/5.3 - Cross-Site Scripting 31 WEB Vulnerability-Lab
2018-01-21   Oracle JDeveloper 11.1.x/12.x - Directory Traversal 31 WEB hyp3rlinx
2018-01-15   DarkComet (C2 Server) - File Upload 28 WEB Pseudo Laboratories
2018-01-15   D-Link DNS-325 ShareCenter < 1.05B03 - Multiple Vulnerabilities 28 WEB GulfTech Security
2018-01-15   D-Link DNS-343 ShareCenter < 1.05 - Command Injection 29 WEB GulfTech Security
2018-01-08   Synology Photostation < 6.7.2-3429 - Multiple Vulnerabilities 32 WEB GulfTech Security
2016-10-04   Mambo < 4.5.4 - SQL Injection 36 WEB GulfTech Security
2016-08-18   X-Cart < 4.1.3 - Arbitrary Variable Overwrite 29 WEB GulfTech Security
2016-08-14   Claroline < 1.7.7 - Arbitrary File Inclusion 29 WEB GulfTech Security
2016-08-28   CubeCart < 3.0.12 - Multiple Vulnerabilities 30 WEB GulfTech Security
2016-08-11   SquirrelMail < 1.4.7 - Arbitrary Variable Overwrite 30 WEB GulfTech Security
2016-03-05   PHPLib < 7.4 - SQL Injection 31 WEB GulfTech Security
2016-03-02   Gallery 2 < 2.0.2 - Multiple Vulnerabilities 41 WEB GulfTech Security
2016-02-26   phpRPC < 0.7 - Remote Code Execution 31 WEB GulfTech Security
2016-02-24   Mambo < 4.5.3h - Multiple Vulnerabilities 27 WEB GulfTech Security
2016-02-21   PEAR LiveUser < 0.16.8 - Arbitrary File Access 25 WEB GulfTech Security
2016-02-19   Geeklog < 1.4.0 - Multiple Vulnerabilities 23 WEB GulfTech Security
2016-02-18   ADOdb < 4.71 - Cross Site Scripting 23 WEB GulfTech Security
2015-07-21   XPCOM - Race Condition 25 WEB GulfTech Security
2015-07-14   SquirrelMail < 1.4.5-RC1 - Arbitrary Variable Overwrite 30 WEB GulfTech Security
2015-07-02   PHPXMLRPC < 1.1 - Remote Code Execution 29 WEB GulfTech Security
2015-07-01   PEAR XML_RPC < 1.3.0 - Remote Code Execution 32 WEB GulfTech Security
2015-06-29   XOOPS < 2.0.11 - Multiple Vulnerabilities 34 WEB GulfTech Security
2015-05-16   Burning Board < 2.3.1 - SQL Injection 26 WEB GulfTech Security
2015-05-05   Invision Power Board (IP.Board) < 2.0.3 - Multiple Vulnerabilities 36 WEB GulfTech Security
2015-04-19   AZBB < 1.0.07d - Multiple Vulnerabilities 28 WEB GulfTech Security
2015-01-03   PhotoPost < 4.85 - Multiple Vulnerabilities 27 WEB GulfTech Security
2015-01-02   ReviewPost < 2.84 - Multiple Vulnerabilities 26 WEB GulfTech Security
2015-01-01   PhotoPost Classifieds < 2.01 - Multiple Vulnerabilities 28 WEB GulfTech Security
2014-12-29   PHP-Calendar < 0.10.1 - Arbitrary File Inclusion 36 WEB GulfTech Security
2014-12-27   WHM.AutoPilot < 2.4.6.5 - Multiple Vulnerabilities 25 WEB GulfTech Security
2014-08-23   LiveWorld Multiple Products - Cross Site Scripting 32 WEB GulfTech Security