Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2017-12-27   Xerox DC260 EFI Fiery Controller Webtools 2.0 - Arbitrary File Disclosure 11 WEB LiquidWorm
2017-12-26   SilverStripe CMS 3.6.2 - CSV Excel Macro Injection 10 WEB Ishaq Mohammed
2017-12-26   Sendroid < 6.5.0 - SQL Injection 11 WEB Onwuka Gideon
2017-12-26   Biometric Shift Employee Management System 3.0 - Local File Disclosure 8 WEB Ihsan Sencan
2017-12-26   Joomla! Component JEXTN FAQ Pro 4.0.0 - 'id' SQL Injection 13 WEB Ihsan Sencan
2017-12-20   BEIMS ContractorWeb 5.18.0.0 - SQL Injection 13 WEB Rajwinder Singh
2017-12-20   Ability Mail Server 3.3.2 - Cross-Site Scripting 9 WEB Aloyce J. Makalanga
2017-12-20   Conarc iChannel - Improper Access Restrictions 13 WEB Information Paradox
2017-12-19   Joomla! Component NextGen Editor 2.1.0 - 'plname' SQL Injection 11 WEB Ihsan Sencan
2017-12-19   BrightSign Digital Signage - Multiple Vulnerablities 11 WEB Information Paradox
2017-12-14   Linksys WVBR0 - 'User-Agent' Remote Command Injection 8 WEB nixawk
2017-12-13   vBulletin 5.x - 'cacheTemplates' Remote Arbitrary File Deletion 11 WEB SecuriTeam
2017-12-13   vBulletin 5.x - 'routestring' Remote Code Execution 10 WEB SecuriTeam
2017-12-18   Joomla! Component My Projects 2.0 - SQL Injection 11 WEB Ihsan Sencan
2017-12-18   Joomla! Component User Bench 1.0 - 'userid' SQL Injection 11 WEB Ihsan Sencan
2017-12-18   Joomla! Component Guru Pro - 'promocode' SQL Injection 11 WEB Ihsan Sencan
2017-12-18   Joomla! Component JB Visa 1.0 - 'visatype' SQL Injection 10 WEB Ihsan Sencan
2017-12-18   Cells Blog 3.5 - 'bgid' / 'fmid' / 'fnid' SQL Injection 10 WEB Ihsan Sencan
2017-12-18   Monstra CMS 3.0.4 - (Authenticated) Arbitrary File Upload / Remote Code Execution 12 WEB Ishaq Mohammed
2017-12-18   Ciuis CRM 1.0.7 - SQL Injection 9 WEB Zahid Abbasi
2017-12-15   Movie Guide 2.0 - SQL Injection 10 WEB Ihsan Sencan
2017-12-15   ITGuard-Manager 0.0.0.1 - Remote Code Execution 11 WEB Nassim Asrir
2017-12-14   Advantech WebAccess 8.2-2017.03.31 - Webvrpcs Service Opcode 80061 Stack Buffer Overflow (Metasploit 10 WEB Metasploit
2017-12-14   Piwigo 2.9.1 - 'cat_true' / 'cat_false' SQL Injection 11 WEB Akityo
2017-12-14   Bus Booking Script 1.0 - 'txtname' SQL Injection 10 WEB Ihsan Sencan
2017-12-14   FS Lynda Clone 1.0 - SQL Injection 10 WEB Ihsan Sencan
2017-12-14   Paid To Read Script 2.0.5 - 'uid' / 'fnum' / 'fn' SQL Injection 9 WEB Ihsan Sencan
2017-12-14   Readymade Video Sharing Script 3.2 - HTML Injection 9 WEB Ihsan Sencan
2017-12-13   Meinberg LANTIME Web Configuration Utility 6.16.008 - Arbitrary File Read 9 WEB Jakub Palaczynski
2017-12-13   Joomla! Component JEXTN Video Gallery 3.0.5 - 'id' SQL Injection 10 WEB Ihsan Sencan
2017-12-13   Joomla! Component JEXTN Question And Answer 3.1.0 - SQL Injection 11 WEB Ihsan Sencan
2017-12-12   Accesspress Anonymous Post Pro < 3.2.0 - Arbitrary File Upload 11 WEB Colette Chamberland
2017-12-12   Joomla! Component JBuildozer 1.4.1 - 'appid' SQL Injection 11 WEB Ihsan Sencan
2017-12-11   Vanguard 1.4 - SQL Injection 10 WEB Ihsan Sencan
2017-12-11   Vanguard 1.4 - Arbitrary File Upload 13 WEB Ihsan Sencan
2017-12-11   Basic Job Site Script 2.0.5 - SQL Injection 10 WEB Ihsan Sencan
2017-12-11   Resume Clone Script 2.0.5 - SQL Injection 9 WEB Ihsan Sencan
2017-12-11   Advanced World Database 2.0.5 - SQL Injection 9 WEB Ihsan Sencan
2017-12-11   Muslim Matrimonial Script 3.02 - 'succid' SQL Injection 9 WEB Ihsan Sencan
2017-12-11   Groupon Clone Script 3.01 - 'state_id' / 'search' SQL Injection 9 WEB Ihsan Sencan
2017-12-11   Car Rental Script 2.0.4 - 'val' SQL Injection 9 WEB Ihsan Sencan
2017-12-11   MLM Forced Matrix 2.0.9 - 'newid' SQL Injection 8 WEB Ihsan Sencan
2017-12-11   MLM Forex Market Plan Script 2.0.4 - 'newid' / 'eventid' SQL Injection 8 WEB Ihsan Sencan
2017-12-11   Entrepreneur Bus Booking Script 3.0.4 - 'sourcebus' SQL Injection 9 WEB Ihsan Sencan
2017-12-11   Advanced Real Estate Script 4.0.7 - SQL Injection 10 WEB Ihsan Sencan
2017-12-11   Single Theater Booking Script 3.2.1 - 'findcity.php?q' SQL Injection 10 WEB Ihsan Sencan
2017-12-11   Multiplex Movie Theater Booking Script 3.1.5 - 'moid' / 'eid' SQL Injection 8 WEB Ihsan Sencan
2017-12-11   Responsive Events & Movie Ticket Booking Script 3.2.1 - 'findcity.php?q' SQL Injection 8 WEB Ihsan Sencan
2017-12-11   Multireligion Responsive Matrimonial 4.7.2 - 'succid' SQL Injection 10 WEB Ihsan Sencan
2017-12-11   Responsive Realestate Script 3.2 - 'property-list?tbud' SQL Injection 9 WEB Ihsan Sencan
2017-12-11   Readymade Video Sharing Script 3.2 - SQL Injection 8 WEB Ihsan Sencan
2017-12-11   Readymade PHP Classified Script 3.3 - 'subctid' / 'mctid' SQL Injection 9 WEB Ihsan Sencan
2017-12-11   Professional Service Script 1.0 - 'service-list?city' SQL Injection 9 WEB Ihsan Sencan
2017-12-11   PHP Multivendor Ecommerce 1.0 - 'sid' / 'searchcat' / 'chid1' SQL Injection 10 WEB Ihsan Sencan
2017-12-11   Opensource Classified Ads Script 3.2 - SQL Injection 9 WEB Ihsan Sencan
2017-12-11   Online Exam Test Application Script 1.6 - 'exams.php?sort' SQL Injection 9 WEB Ihsan Sencan
2017-12-11   Multivendor Penny Auction Clone Script 1.0 - SQL Injection 10 WEB Ihsan Sencan
2017-12-11   Lawyer Search Script 1.1 - 'lawyer-list?city' SQL Injection 9 WEB Ihsan Sencan
2017-12-11   Laundry Booking Script 1.0 - 'list?city' SQL Injection 9 WEB Ihsan Sencan
2017-12-11   Secure E-commerce Script 2.0.1 - 'searchcat' / 'searchmain' SQL Injection 10 WEB Ihsan Sencan
2017-12-11   Kickstarter Clone Acript 2.0 - 'projid' SQL Injection 9 WEB Ihsan Sencan
2017-12-11   Foodspotting Clone Script 1.0 - 'quicksearch.php?q' SQL Injection 9 WEB Ihsan Sencan
2017-12-11   Hot Scripts Clone 3.1 - 'subctid' / 'mctid' SQL Injection 10 WEB Ihsan Sencan
2017-12-11   Freelance Website Script 2.0.6 - 'pr_id' / 'catid' SQL Injection 9 WEB Ihsan Sencan
2017-12-11   Yoga Class Script 1.0 - 'list?city' SQL Injection 9 WEB Ihsan Sencan
2017-12-11   Food Order Script 1.0 - 'list?city' SQL Injection 10 WEB Ihsan Sencan
2017-12-11   Facebook Clone Script 1.0 - 'id' / 'send' SQL Injection 9 WEB Ihsan Sencan
2017-12-08   Event Calendar Category Script 1.0 - 'city' SQL Injection 10 WEB Ihsan Sencan
2017-12-08   Entrepreneur Dating Script 2.0.1 - 'marital' / 'gender' / 'country' / 'profileid' SQL Injection 9 WEB Ihsan Sencan
2017-12-08   E-commerce MLM Software 1.0 - SQL Injection 10 WEB Ihsan Sencan
2017-12-08   Doctor Search Script 1.0 - 'city' SQL Injection 9 WEB Ihsan Sencan
2017-12-08   Entrepreneur Job Portal Script 2.0.6 - 'jobsearch_all.php?rid1' SQL Injection 9 WEB Ihsan Sencan
2017-12-08   Consumer Complaints Clone Script 1.0 - 'id' SQL Injection 8 WEB Ihsan Sencan
2017-12-08   Co-work Space Search Script 1.0 - 'city' SQL Injection 8 WEB Ihsan Sencan
2017-12-08   CMS Auditor Website 1.0 - SQL Injection 8 WEB Ihsan Sencan
2017-12-08   Child Care Script 1.0 - 'city' SQL Injection 10 WEB Ihsan Sencan
2017-12-08   Chartered Accountant Booking Script 1.0 - 'city' SQL Injection 11 WEB Ihsan Sencan
2017-12-08   Cab Booking Script 1.0 - 'city' SQL Injection 9 WEB Ihsan Sencan
2017-12-08   Nearbuy Clone Script 3.2 - 'search' SQL Injection 10 WEB Ihsan Sencan
2017-12-09   Beauty Parlour Booking Script 1.0 - 'gender' / 'city' SQL Injection 8 WEB Ihsan Sencan
2017-12-09   Basic B2B Script 2.0.8 - 'product_details.php?id' SQL Injection 8 WEB Ihsan Sencan
2017-12-09   Affiliate MLM Script 1.0 - 'product-category.php?key' SQL Injection 8 WEB Ihsan Sencan
2017-12-09   Advance Online Learning Management Script 3.1 - 'subcatid' / 'popcourseid' SQL Injection 9 WEB Ihsan Sencan
2017-12-09   Advance B2B Script 2.1.3 - 'show_id' / 'pid' SQL Injection 9 WEB Ihsan Sencan
2017-12-09   FS Foodpanda Clone 1.0 - SQL Injection 9 WEB Ihsan Sencan
2017-12-09   FS Expedia Clone 1.0 - 'fl_orig' / 'fl_dest' / 'id' SQL Injection 10 WEB Ihsan Sencan
2017-12-09   FS Trademe Clone 1.0 - 'search' / 'id' SQL Injection 9 WEB Ihsan Sencan
2017-12-09   FS Amazon Clone 1.0 - SQL Injection 10 WEB Ihsan Sencan
2017-12-09   FS Care Clone 1.0 - 'jobFrequency' / 'jobType' SQL Injection 8 WEB Ihsan Sencan
2017-12-09   FS Crowdfunding Script 1.0 - 'latest_news_details.php?id' SQL Injection 10 WEB Ihsan Sencan
2017-12-09   FS Ebay Clone 1.0 - 'id' / 'sub_category_id' / 'category_id' SQL Injection 9 WEB Ihsan Sencan
2017-12-09   FS Freelancer Clone 1.0 - 'profile.php?u' SQL Injection 10 WEB Ihsan Sencan
2017-12-09   FS Gigs Script 1.0 - 'cat' / 'sc' SQL Injection 10 WEB Ihsan Sencan
2017-12-09   FS Groupon Clone 1.0 - 'id' SQL Injection 8 WEB Ihsan Sencan
2017-12-09   FS Grubhub Clone 1.0 - 'keywords' SQL Injection 10 WEB Ihsan Sencan
2017-12-09   FS IMDB Clone 1.0 - 'f' / 's' / 'id' SQL Injection 9 WEB Ihsan Sencan
2017-12-09   FS Indiamart Clone 1.0 - 'token' / 'id' / 'c' SQL Injection 10 WEB Ihsan Sencan
2017-12-09   FS Linkedin Clone 1.0 - 'grid' / 'fid' / 'id' SQL Injection 11 WEB Ihsan Sencan
2017-12-08   FS Makemytrip Clone 1.0 - 'fl_orig' / 'fl_dest' SQL Injection 10 WEB Ihsan Sencan
2017-12-08   FS Monster Clone 1.0 - 'Employer_Details.php?id' SQL Injection 10 WEB Ihsan Sencan
2017-12-08   FS Olx Clone 1.0 - 'scat' / 'pid' SQL Injection 9 WEB Ihsan Sencan
2017-12-08   FS Quibids Clone 1.0 - SQL Injection 9 WEB Ihsan Sencan
2017-12-08   FS Shutterstock Clone 1.0 - 'keywords' SQL Injection 10 WEB Ihsan Sencan
2017-12-08   FS Stackoverflow Clone 1.0 - 'keywords' SQL Injection 10 WEB Ihsan Sencan
2017-12-08   FS Thumbtack Clone 1.0 - 'cat' / 'sc' SQL Injection 9 WEB Ihsan Sencan
2017-12-08   Realestate Crowdfunding Script 2.7.2 - 'pid' SQL Injection 9 WEB Ihsan Sencan
2017-12-08   Website Auction Marketplace 2.0.5 - 'cat_id' SQL Injection 10 WEB Ihsan Sencan
2017-12-08   Simple Chatting System 1.0.0 - Arbitrary File Upload 10 WEB Ihsan Sencan
2017-12-08   DomainSale PHP Script 1.0 - 'id' SQL Injection 11 WEB Ihsan Sencan
2017-12-07   OpenEMR 5.0.0 - OS Command Injection / Cross-Site Scripting 12 WEB SEC Consult
2017-12-07   OpenEMR 5.0.0 - OS Command Injection / Cross-Site Scripting 10 WEB SEC Consult
2017-12-07   FS Facebook Clone - 'token' SQL Injection 9 WEB Dan°
2017-12-07   FS IMDB Clone - 'id' SQL Injection 10 WEB Dan°
2017-12-06   FS Shaadi Clone - 'token' SQL Injection 11 WEB Dan°
2017-12-06   WinduCMS 3.1 - Local File Disclosure 11 WEB Maciek Krupa
2017-12-06   FS Makemytrip Clone - 'id' SQL Injection 10 WEB Dan°
2017-12-05   Readymade Classifieds Script 1.0 - SQL Injection 12 WEB Ihsan Sencan
2017-12-05   Techno Portfolio Management Panel - 'id' SQL Injection 12 WEB Ihsan Sencan
2017-12-05   Perspective ICM Investigation & Case 5.1.1.16 - Privilege Escalation 11 WEB Konstantinos Alexiou
2017-12-01   Artica Web Proxy 3.06 - Remote Code Execution 14 WEB hyp3rlinx
2017-12-01   MistServer 2.12 - Cross-Site Scripting 9 WEB hyp3rlinx
2017-11-30   Jobs2Careers / Coroflot Clone - SQL Injection 13 WEB 8bitsec
2017-11-28   WordPress Plugin WooCommerce 2.0/3.0 - Directory Traversal 13 WEB Fu2x2000
2017-11-11   osCommerce 2.3.4.1 - Arbitrary File Upload 11 WEB Simon Scannell
2017-11-28   Synology StorageManager 5.2 - Root Remote Command Execution 11 WEB SecuriTeam