Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2004-05-17   HelpCenter Live! < 1.2.7 - Multiple Vulnerabilities 36 WEB GulfTech Security
2004-05-04   Invision Power Board (IP.Board) < 1.3.1 - Design Error 29 WEB GulfTech Security
2004-05-04   PHPX < 3.26 - Multiple Vulnerabilities 28 WEB GulfTech Security
2004-04-24   OpenBB < 1.0.6 - Multiple Vulnerabilities 25 WEB GulfTech Security
2004-04-14   phpBugTracker < 0.9.1 - Multiple Vulnerabilities 30 WEB GulfTech Security
2004-04-11   TikiWiki < 1.8.1 - Multiple Vulnerabilities 37 WEB GulfTech Security
2004-03-28   PhotoPost < 4.6 - Multiple Vulnerabilities 40 WEB GulfTech Security
2004-03-21   Invision Gallery < 1.0.1 - SQL Injection 25 WEB GulfTech Security
2004-03-21   Invision Power Top Site List < 1.1 RC 2 - SQL Injection 28 WEB GulfTech Security
2004-03-20   phpBB < 2.0.7a - Multiple Vulnerabilities 33 WEB GulfTech Security
2004-03-15   Mambo < 4.5 - Multiple Vulnerabilities 35 WEB GulfTech Security
2004-03-15   vBulletin < 3.0.0 RC4 - Cross Site Scripting 30 WEB GulfTech Security
2004-03-15   Phorum < 5.0.3 Beta - Cross Site Scripting 39 WEB GulfTech Security
2004-03-12   phpBB < 2.0.6d - Cross Site Scripting 29 WEB GulfTech Security
2004-03-02   Invision Power Board (IP.Board) < 1.3 - SQL Injection 29 WEB GulfTech Security
2004-01-13   phpShop < 0.6.1-b - Multiple Vulnerabilities 33 WEB GulfTech Security
2004-01-13   phpGedView < 2.65 beta 5 - Multiple Vulnerabilities 32 WEB GulfTech Security
2004-01-12   MetaDot < 5.6.5.4b5 - Multiple Vulnerabilities 31 WEB GulfTech Security
2004-01-03   PostNuke < 0.726 Phoenix - Multiple Vulnerabilities 27 WEB GulfTech Security
2003-12-22   osCommerce < 2.2-MS2 - Multiple Vulnerabilities 39 WEB GulfTech Security
2003-12-18   ASPapp Multiple Products - Multiple Vulnerabilities 30 WEB GulfTech Security
2003-12-18   AutoRank PHP < 2.0.4 - SQL Injection (PoC) 29 WEB GulfTech Security
2003-12-16   Aardvark Topsites < 4.1.0 - Multiple Vulnerabilities 44 WEB GulfTech Security
2003-12-16   Invision Power Board (IP.Board) < 2.0 Alpha 3 - SQL Injection (PoC) 27 WEB GulfTech Security
2003-12-15   Invision Power Top Site List < 2.0 Alpha 3 - SQL Injection (PoC) 28 WEB GulfTech Security
2003-12-15   DUWare Multiple Products - Multiple Vulnerabilities 34 WEB GulfTech Security
2018-01-18   GitStack 2.3.10 - Remote Code Execution 29 WEB Kacper Szurek
2018-01-18   Primefaces 5.x - Remote Code Execution (Metasploit) 33 WEB Bjoern Schuette
2018-01-17   SugarCRM 3.5.1 - Cross-Site Scripting 29 WEB Guilherme Assmann
2018-01-17   Belkin N600DB Wireless Router - Multiple Vulnerabilities 25 WEB Wadeek
2018-01-17   D-Link DSL-2640R - DNS Change 30 WEB Todor Donev
2018-01-17   Reservo Image Hosting Script 1.5 - Cross-Site Scripting 28 WEB Dennis Veninga
2018-01-17   Zomato Clone Script - Arbitrary File Upload 27 WEB Tauco
2018-01-15   Flash Operator Panel 2.31.03 - Command Execution 29 WEB Vulnerability-Lab
2018-01-15   ILIAS < 5.2.4 - Cross-Site Scripting 29 WEB Florian Kunushevci
2018-01-15   Oracle PeopleSoft 8.5x - Remote Code Execution 28 WEB Vahagn Vardanyan
2018-01-15   Adminer 4.3.1 - Server-Side Request Forgery 31 WEB hyp3rlinx
2018-01-15   Oracle E-Business Suite 12.1.3/12.2.x - Open Redirect 32 WEB Andrew Gill
2018-01-15   RISE 1.9 - 'search' SQL Injection 27 WEB Ahmad Mahfouz
2018-01-15   PerfexCRM 1.9.7 - Arbitrary File Upload 35 WEB Ahmad Mahfouz
2018-01-15   Domains & Hostings Manager PRO 3.0 - Authentication Bypass 31 WEB Tauco
2018-01-15   ImgHosting 1.5 - Cross-Site Scripting 31 WEB Dennis Veninga
2018-01-15   pfSense < 2.1.4 - 'status_rrd_graph_img.php' Command Injection 33 WEB absolomb
2018-01-12   Taxi Booking Script 1.0 - Cross-site Scripting 31 WEB Tauco
2018-01-12   Xnami 1.0 - Cross-Site Scripting 31 WEB Dennis Veninga
2018-01-10   D-Link Routers 110/412/615/815 < 1.03 - 'service.cgi' Arbitrary Code Execution 32 WEB Cr0n1c
2018-01-10   SAP NetWeaver J2EE Engine 7.40 - SQL Injection 29 WEB Vahagn Vardanyan
2018-01-10   Joomla! Component Easydiscuss < 4.0.21 - Cross-Site Scripting 31 WEB Mattia Furlani
2018-01-10   WordPress Plugin WordPress Download Manager 2.9.60 - Cross-Site Request Forgery 31 WEB Panagiotis Vagenas
2018-01-10   WordPress Plugin Admin Menu Tree Page View 2.6.9 - Cross-Site Request Forgery / Privilege Escalation 31 WEB Panagiotis Vagenas
2018-01-10   WordPress Plugin CMS Tree Page View 1.4 - Cross-Site Request Forgery / Privilege Escalation 33 WEB Panagiotis Vagenas
2018-01-10   WordPress Plugin Social Media Widget by Acurax 3.2.5 - Cross-Site Request Forgery 30 WEB Panagiotis Vagenas
2018-01-10   WordPress Plugin Events Calendar - 'event_id' SQL Injection 35 WEB Dennis Veninga
2018-01-10   Muviko 1.1 - SQL Injection 27 WEB Ahmad Mahfouz
2018-01-10   WordPress Plugin Service Finder Booking < 3.2 - Local File Disclosure 31 WEB telahdihapus
2018-01-10   Synology Photostation 6.7.2-3429 - Remote Code Execution (Metasploit) 40 WEB James Bercegay
2018-01-08   Vanilla < 2.1.5 - Cross-Site Request Forgery 30 WEB Anand Meyyappan
2018-01-08   WordPress Plugin LearnDash 2.5.3 - Arbitrary File Upload 32 WEB NinTechNet
2018-01-08   FiberHome LM53Q1 - Multiple Vulnerabilities 28 WEB Ibad Shah
2018-01-08   SonicWall NSA 6600/5600/4600/3600/2600/250M - Multiple Vulnerabilities 31 WEB Vulnerability-Lab
2018-01-08   Photos in Wifi 1.0.1 - Path Traversal 31 WEB Vulnerability-Lab
2018-01-08   Synology DiskStation Manager (DSM) < 6.1.3-15152 - 'forget_passwd.cgi' User Enumeration 37 WEB Steve Kaun
2018-01-05   Gespage 7.4.8 - SQL Injection 33 WEB Sysdream
2003-06-16   Snitz Forums 2000 < 3.4.0.3 - Multiple Vulnerabilities 28 WEB GulfTech Security
2003-06-06   Max Web Portal < 1.30 - Multiple Vulnerabilities 28 WEB GulfTech Security
2003-06-04   MegaBrowser < 0.71b - Multiple Vulnerabilities 28 WEB GulfTech Security
2003-06-03   FTP Service < 1.2 - Multiple Vulnerabilities 30 WEB GulfTech Security
2003-06-02   WinMX < 2.6 - Design Error 32 WEB GulfTech Security
2003-05-30   P-Synch < 6.2.5 - Multiple Vulnerabilities 26 WEB GulfTech Security
2003-01-17   phpLinks < 2.1.2 - Multiple Vulnerabilities 29 WEB GulfTech Security
2003-01-13   PHP Topsites < 2.2 - Multiple Vulnerabilities 27 WEB GulfTech Security
2008-09-04   Zen Cart < 1.3.8a - SQL Injection 28 WEB GulfTech Security
2018-01-05   gps-server.net GPS Tracking Software < 3.1 - Multiple Vulnerabilities 31 WEB Noman Riffat
2018-01-03   EMC xPression 4.5SP1 Patch 13 - 'model.jobHistoryId' SQL Injection 30 WEB Pawel Gocyla
2018-01-03   WordPress Plugin Smart Google Code Inserter < 3.5 - Authentication Bypass / SQL Injection 34 WEB Benjamin Lim
2017-12-25   Huawei Router HG532 - Arbitrary Command Execution 32 WEB anonymous
2017-12-31   PHP Melody 2.7.1 - 'playlist' SQL Injection 27 WEB Ahmad Mahfouz
2017-12-27   DotNetNuke DreamSlider 01.01.02 - Arbitrary File Download (Metasploit) 30 WEB Glafkos Charalambous
2017-12-27   SAP BusinessObjects launch pad - Server-Side Request Forgery 36 WEB Ahmad Mahfouz
2017-12-27   Telesquare SKT LTE Router SDT-CS3B1 - Information Disclosure 40 WEB LiquidWorm
2017-12-27   Telesquare SKT LTE Router SDT-CS3B1 - Cross-Site Request Forgery 35 WEB LiquidWorm
2017-12-27   Easy!Appointments 1.2.1 - Cross-Site Scripting 28 WEB LiquidWorm
2017-12-27   Xerox DC260 EFI Fiery Controller Webtools 2.0 - Arbitrary File Disclosure 32 WEB LiquidWorm
2017-12-26   SilverStripe CMS 3.6.2 - CSV Excel Macro Injection 31 WEB Ishaq Mohammed
2017-12-26   Sendroid < 6.5.0 - SQL Injection 30 WEB Onwuka Gideon
2017-12-26   Biometric Shift Employee Management System 3.0 - Local File Disclosure 34 WEB Ihsan Sencan
2017-12-26   Joomla! Component JEXTN FAQ Pro 4.0.0 - 'id' SQL Injection 38 WEB Ihsan Sencan
2017-12-20   BEIMS ContractorWeb 5.18.0.0 - SQL Injection 33 WEB Rajwinder Singh
2017-12-20   Ability Mail Server 3.3.2 - Cross-Site Scripting 30 WEB Aloyce J. Makalanga
2017-12-20   Conarc iChannel - Improper Access Restrictions 35 WEB Information Paradox
2017-12-19   Joomla! Component NextGen Editor 2.1.0 - 'plname' SQL Injection 33 WEB Ihsan Sencan
2017-12-19   BrightSign Digital Signage - Multiple Vulnerablities 31 WEB Information Paradox
2017-12-14   Linksys WVBR0 - 'User-Agent' Remote Command Injection 27 WEB nixawk
2017-12-13   vBulletin 5.x - 'cacheTemplates' Remote Arbitrary File Deletion 32 WEB SecuriTeam
2017-12-13   vBulletin 5.x - 'routestring' Remote Code Execution 29 WEB SecuriTeam
2017-12-18   Joomla! Component My Projects 2.0 - SQL Injection 31 WEB Ihsan Sencan
2017-12-18   Joomla! Component User Bench 1.0 - 'userid' SQL Injection 32 WEB Ihsan Sencan
2017-12-18   Joomla! Component Guru Pro - 'promocode' SQL Injection 33 WEB Ihsan Sencan
2017-12-18   Joomla! Component JB Visa 1.0 - 'visatype' SQL Injection 28 WEB Ihsan Sencan
2017-12-18   Cells Blog 3.5 - 'bgid' / 'fmid' / 'fnid' SQL Injection 31 WEB Ihsan Sencan
2017-12-18   Monstra CMS 3.0.4 - (Authenticated) Arbitrary File Upload / Remote Code Execution 30 WEB Ishaq Mohammed
2017-12-18   Ciuis CRM 1.0.7 - SQL Injection 34 WEB Zahid Abbasi
2017-12-15   Movie Guide 2.0 - SQL Injection 29 WEB Ihsan Sencan
2017-12-15   ITGuard-Manager 0.0.0.1 - Remote Code Execution 36 WEB Nassim Asrir
2017-12-14   Advantech WebAccess 8.2-2017.03.31 - Webvrpcs Service Opcode 80061 Stack Buffer Overflow (Metasploit 29 WEB Metasploit
2017-12-14   Piwigo 2.9.1 - 'cat_true' / 'cat_false' SQL Injection 33 WEB Akityo
2017-12-14   Bus Booking Script 1.0 - 'txtname' SQL Injection 33 WEB Ihsan Sencan
2017-12-14   FS Lynda Clone 1.0 - SQL Injection 32 WEB Ihsan Sencan
2017-12-14   Paid To Read Script 2.0.5 - 'uid' / 'fnum' / 'fn' SQL Injection 34 WEB Ihsan Sencan
2017-12-14   Readymade Video Sharing Script 3.2 - HTML Injection 29 WEB Ihsan Sencan
2017-12-13   Meinberg LANTIME Web Configuration Utility 6.16.008 - Arbitrary File Read 30 WEB Jakub Palaczynski
2017-12-13   Joomla! Component JEXTN Video Gallery 3.0.5 - 'id' SQL Injection 31 WEB Ihsan Sencan
2017-12-13   Joomla! Component JEXTN Question And Answer 3.1.0 - SQL Injection 32 WEB Ihsan Sencan
2017-12-12   Accesspress Anonymous Post Pro < 3.2.0 - Arbitrary File Upload 34 WEB Colette Chamberland
2017-12-12   Joomla! Component JBuildozer 1.4.1 - 'appid' SQL Injection 35 WEB Ihsan Sencan
2017-12-11   Vanguard 1.4 - SQL Injection 33 WEB Ihsan Sencan
2017-12-11   Vanguard 1.4 - Arbitrary File Upload 35 WEB Ihsan Sencan
2017-12-11   Basic Job Site Script 2.0.5 - SQL Injection 34 WEB Ihsan Sencan
2017-12-11   Resume Clone Script 2.0.5 - SQL Injection 35 WEB Ihsan Sencan
2017-12-11   Advanced World Database 2.0.5 - SQL Injection 31 WEB Ihsan Sencan
2017-12-11   Muslim Matrimonial Script 3.02 - 'succid' SQL Injection 26 WEB Ihsan Sencan
2017-12-11   Groupon Clone Script 3.01 - 'state_id' / 'search' SQL Injection 28 WEB Ihsan Sencan
2017-12-11   Car Rental Script 2.0.4 - 'val' SQL Injection 32 WEB Ihsan Sencan
2017-12-11   MLM Forced Matrix 2.0.9 - 'newid' SQL Injection 27 WEB Ihsan Sencan
2017-12-11   MLM Forex Market Plan Script 2.0.4 - 'newid' / 'eventid' SQL Injection 30 WEB Ihsan Sencan