Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2016-10-19   CNDSOFT 2.3 - Cross-Site Request Forgery / Arbitrary File Upload 11 WEB Besim
2016-10-18   Cgiemail 1.6 - Source Code Disclosure 18 WEB Finbar Crago
2016-10-18   ManageEngine ServiceDesk Plus 9.2 Build 9207 - Unauthorized Information Disclosure 13 WEB p0z
2016-10-18   Pluck CMS 4.7.3 - Cross-Site Request Forgery (Add Page) 14 WEB Ahsan Tahir
2016-10-17   PHP Business Directory - Multiple Vulnerabilities 16 WEB larrycompress
2016-10-14   School Full CBT 0.1 - SQL Injection 17 WEB lahilote
2016-10-16   PHP NEWS 1.3.0 - Cross-Site Request Forgery (Add Admin) 14 WEB Meryem AKDOĞAN
2016-10-14   Simple Shopping Cart Application 0.1 - SQL Injection 14 WEB lahilote
2016-10-16   PHP Image Database - Multiple Vulnerabilities 13 WEB larrycompress
2016-10-17   Subrion CMS 4.0.5 - Cross-Site Request Forgery Bypass / Persistent Cross-Site Scripting 13 WEB Ahsan Tahir
2016-10-16   PHP Telephone Directory - Multiple Vulnerabilities 15 WEB larrycompress
2016-10-14   Health Record System 0.1 - Authentication Bypass 17 WEB lahilote
2016-10-14   Fashion Shopping Cart 0.1 - SQL Injection 16 WEB lahilote
2016-10-14   Learning Management System 0.1 - Authentication Bypass 14 WEB lahilote
2016-10-14   Simple Dynamic Web 0.1 - SQL Injection 13 WEB lahilote
2016-10-14   Web Based Alumni Tracking System 0.1 - SQL Injection 15 WEB lahilote
2016-10-14   Student Information System (SIS) 0.1 - Authentication Bypass 19 WEB lahilote
2016-10-14   YouTube Automated CMS 1.0.7 - Cross-Site Request Forgery / Persistent Cross-Site Scripting 13 WEB Arbin Godar
2016-10-14   Simple Forum PHP 2.4 - Cross-Site Request Forgery (Edit Options) 15 WEB Ehsan Hosseini
2016-10-14   Simple Forum PHP 2.4 - SQL Injection 14 WEB Ehsan Hosseini
2016-10-13   JonhCMS 4.5.1 - SQL Injection 13 WEB Besim
2016-10-13   RSS News AutoPilot Script 1.0.1/3.1.0 - Admin Panel Authentication Bypass 13 WEB Arbin Godar
2016-10-13   Colorful Blog - Cross-Site Request Forgery (Change Admin Password) 17 WEB Besim
2016-10-13   Colorful Blog - Persistent Cross-Site Scripting 15 WEB Besim
2016-10-13   Thatware 0.4.6 - SQL Injection 14 WEB Besim
2016-10-13   Simple Blog PHP 2.0 - SQL Injection 14 WEB Ehsan Hosseini
2016-10-13   Simple Blog PHP 2.0 - Multiple Vulnerabilities 14 WEB Ehsan Hosseini
2016-10-12   ApPHP MicroCMS 3.9.5 - Cross-Site Request Forgery (Add Admin) 14 WEB Besim
2016-10-12   ApPHP MicroCMS 3.9.5 - Persistent Cross-Site Scripting 16 WEB Besim
2016-10-12   OpenCimetiere 3.0.0-a5 - Blind SQL Injection 16 WEB Wadeek
2016-10-12   NetBilletterie 2.8 - Multiple Vulnerabilities 13 WEB Wadeek
2016-10-12   Categorizator 0.3.1 - SQL Injection 14 WEB Wadeek
2016-10-11   ApPHP MicroBlog 1.0.2 - Cross-Site Request Forgery (Add New Author) 16 WEB Besim
2016-10-11   ApPHP MicroBlog 1.0.2 - Persistent Cross-Site Scripting 14 WEB Besim
2016-10-11   RSA Enterprise Compromise Assessment Tool 4.1.0.1 - XML External Entity Injection 14 WEB SEC Consult
2016-10-11   AVTECH IP Camera / NVR / DVR Devices - Multiple Vulnerabilities 16 WEB Gergely Eberhardt
2016-10-11   phpEnter 4.2.7 - Cross-Site Request Forgery (Add New Post) 14 WEB Besim
2016-10-11   BirdBlog 1.4.0 - Cross-Site Request Forgery (Add New Post) 13 WEB Besim
2016-10-10   Spacemarc News - Cross-Site Request Forgery (Add New Post) 14 WEB Besim
2016-10-10   Maian Weblog 4.0 - Cross-Site Request Forgery (Add New Post) 13 WEB Besim
2016-10-09   PHP Press Release - Persistent Cross-Site Scripting 16 WEB Besim
2016-10-09   PHP Press Release - Cross-Site Request Forgery (Add Admin) 15 WEB Besim
2016-09-19   ShoreTel Connect ONSITE - Blind SQL Injection 17 WEB Iraklis Mathiopoulos
2016-10-09   miniblog 1.0.1 - Cross-Site Request Forgery (Add New Post) 14 WEB Besim
2016-10-07   Entrepreneur Job Portal Script 2.06 - SQL Injection 12 WEB OoN_Boy
2016-10-07   Simple PHP Blog 0.8.4 - Cross-Site Request Forgery (Add Admin) 15 WEB Besim
2016-10-06   Just Dial Clone Script - 'fid' SQL Injection 13 WEB OoN_Boy
2016-10-06   MLM Unilevel Plan Script 1.0.2 - SQL Injection 15 WEB N4TuraL
2016-10-06   B2B Portal Script - Blind SQL Injection 23 WEB OoN_Boy
2016-10-06   PHP Classifieds Rental Script - Blind SQL Injection 13 WEB OoN_Boy
2016-10-06   Advance MLM Script - SQL Injection 12 WEB OoN_Boy
2016-10-05   Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusion 12 WEB KoreLogic
2016-10-05   Cisco Firepower Threat Management Console 6.0.1 - Remote Command Execution 13 WEB KoreLogic
2016-10-05   Witbe - Remote Code Execution 13 WEB BeLmar
2016-10-05   Picosafe Web GUI - Multiple Vulnerabilities 15 WEB Shahab Shamsi
2016-09-28   Symantec Messaging Gateway 10.6.1 - Directory Traversal 14 WEB R-73eN
2016-09-27   TP-Link Archer CR-700 - Cross-Site Scripting 15 WEB Ayushman Dutta
2016-09-26   Joomla! Component Event Booking 2.10.1 - SQL Injection 17 WEB Persian Hack Team
2016-09-22   Matrimonial Website Script 1.0.2 - SQL Injection 18 WEB N4TuraL
2016-09-22   Kerio Control Unified Threat Management 9.1.0 build 1087/9.1.1 build 1324 - Multiple Vulnerabilities 19 WEB SEC Consult
2016-09-22   Joomla! Component com_videogallerylite 1.0.9 - SQL Injection 13 WEB Larry W. Cashdollar
2016-09-22   Exponent CMS 2.3.9 - Blind SQL Injection 16 WEB Manuel García Cárdenas
2016-09-22   Microix Timesheet Module - SQL Injection 17 WEB Anthony Cole
2016-09-20   Dolphin 7.3.0 - Error-Based SQL Injection 17 WEB Kacper Szurek
2016-09-20   VegaDNS 0.13.2 - Remote Command Injection 19 WEB Wireghoul
2016-09-19   ZineBasic 1.1 - Arbitrary File Disclosure 18 WEB bd0rk
2016-09-19   MuM MapEdit 3.2.6.0 - Multiple Vulnerabilities 14 WEB Paul Baade & Sven Krewitt
2016-09-19   MyBB 1.8.6 - SQL Injection 16 WEB Curesec Research Team
2016-09-19   Kajona 4.7 - Cross-Site Scripting / Directory Traversal 17 WEB Curesec Research Team
2016-09-19   WordPress Plugin Order Export Import for WooCommerce - Order Information Disclosure 20 WEB david-peltier
2016-09-19   BuilderEngine 3.5.0 - Arbitrary File Upload 15 WEB metanubix
2016-09-16   AnoBBS 1.0.1 - Remote File Inclusion 15 WEB bd0rk
2016-09-15   Cisco EPC 3925 - Multiple Vulnerabilities 18 WEB Patryk Bogdan
2016-09-13   Open-Xchange App Suite 7.8.2 - Cross-Site Scripting 13 WEB Jakub A>>oczek
2016-09-13   Open-Xchange Guard 2.4.2 - Multiple Cross-Site Scripting Vulnerabilities 16 WEB Benjamin Daniel Mussler
2016-09-13   ASUS DSL-X11 ADSL Router - DNS Change 17 WEB Todor Donev
2016-09-13   COMTREND ADSL Router CT-5367 C01_R12 / CT-5624 C01_R03 - DNS Change 17 WEB Todor Donev
2016-09-13   Tenda ADSL2/2+ Modem 963281TAN - DNS Change 20 WEB Todor Donev
2016-09-13   PLANET VDR-300NU ADSL Router - DNS Change 19 WEB Todor Donev
2016-09-13   PIKATEL 96338WS_ 96338L-2M-8M - DNS Change 16 WEB Todor Donev
2016-09-13   Inteno EG101R1 VoIP Router - DNS Change 15 WEB Todor Donev
2016-09-13   Exper EWM-01 ADSL/MODEM - DNS Change 19 WEB Todor Donev
2016-09-13   Contrexx CMS egov Module 1.0.0 - SQL Injection 20 WEB hamidreza borghei
2016-09-13   wdCalendar 2 - SQL Injection 27 WEB Alfonso Castillo Angel
2016-09-13   Cherry Music 0.35.1 - Arbitrary File Disclosure 20 WEB feedersec
2016-09-09   Airmail 3.0.2 - Cross-Site Scripting 21 WEB redrain
2016-09-09   Vodafone Mobile Wifi - Reset Admin Password 16 WEB Daniele Linguaglossa
2016-09-08   Zabbix 2.0 < 3.0.3 - SQL Injection 18 WEB Zzzians
2016-09-08   Jobberbase 2.0 - Multiple Vulnerabilities 23 WEB Ross Marks
2016-09-07   Adobe ColdFusion < 11 Update 10 - XML External Entity Injection 17 WEB Dawid Golunski
2016-09-07   FreePBX 13.0.x < 13.0.154 - Remote Command Execution 15 WEB i-Hmx
2016-09-07   CumulusClips 2.4.1 - Multiple Vulnerabilities 18 WEB kor3k
2016-09-06   PHPIPAM 1.2.1 - Multiple Vulnerabilities 14 WEB Saeed reza Zamanian
2016-09-05   WordPress Plugin RB Agency 2.4.7 - Local File Disclosure 18 WEB Persian Hack Team
2016-09-04   Belkin F9K1122v1 1.00.30 - Buffer Overflow (via Cross-Site Request Forgery) 19 WEB b1ack0wl
2016-08-31   ZKTeco ZKAccess Security System 5.3.1 - Persistent Cross-Site Scripting 19 WEB LiquidWorm
2016-08-31   ZKTeco ZKBioSecurity 3.0 - 'visLogin.jsp' Local Authentication Bypass 17 WEB LiquidWorm
2016-08-31   ZKTeco ZKBioSecurity 3.0 - Directory Traversal 18 WEB LiquidWorm
2016-08-31   ZKTeco ZKBioSecurity 3.0 - Cross-Site Request Forgery (Add Superadmin) 23 WEB LiquidWorm
2016-08-31   ZKTeco ZKBioSecurity 3.0 - Hard-Coded Credentials SYSTEM Remote Code Execution 19 WEB LiquidWorm
2016-08-29   FreePBX 13.0.35 - SQL Injection 20 WEB i-Hmx
2016-08-29   PLC Wireless Router GPN2.4P21-C-CN - Arbitrary File Disclosure 17 WEB Rahul Raz
2016-08-29   Intellinet IP Camera INT-L100M20N - Unauthorized Admin Credential Change 19 WEB Todor Donev
2016-08-29   HelpDeskZ 1.0.2 - Arbitrary File Upload 17 WEB Lars Morgenroth
2016-08-29   FreePBX 13.0.35 - Remote Command Execution 15 WEB 0x4148
2016-08-24   WordPress Plugin CYSTEME Finder 1.3 - Arbitrary File Disclosure/Arbitrary File Upload 15 WEB T0w3ntum
2016-08-23   chatNow - Multiple Vulnerabilities 15 WEB HaHwul
2016-08-23   SimplePHPQuiz - Blind SQL Injection 16 WEB HaHwul
2016-08-23   WordPress Plugin Mail Masta 1.0 - Local File Inclusion 20 WEB Guillermo Garcia Marcos
2016-08-22   WordPress Core 4.5.3 - Directory Traversal / Denial of Service 20 WEB Yorick Koster
2016-08-22   Sakai 10.7 - Multiple Vulnerabilities 17 WEB LiquidWorm
2016-08-22   Ocomon 2.0 - SQL Injection 15 WEB Jonatas Fil
2016-08-22   VideoIQ Camera - Local File Disclosure 16 WEB Yakir Wizman
2016-08-22   Honeywell IP-Camera HICC-1100PT - Local File Disclosure 13 WEB Yakir Wizman
2016-08-22   JVC IP-Camera VN-T216VPRU - Local File Disclosure 14 WEB Yakir Wizman
2016-08-22   Vanderbilt IP-Camera CCPW3025-IR / CVMW3025-IR - Local File Disclosure 15 WEB Yakir Wizman
2016-08-19   tcPbX - 'tcpbx_lang' Local File Inclusion 14 WEB 0x4148
2016-08-19   MESSOA IP Cameras (Multiple Models) - Password Change 13 WEB Todor Donev
2016-08-19   Fortigate Firewalls - 'EGREGIOUSBLUNDER' Remote Code Execution 14 WEB Shadow Brokers
2016-08-19   TOPSEC Firewalls - 'ELIGIBLEBOMBSHELL' Remote Code Execution 13 WEB Shadow Brokers
2016-08-19   TOPSEC Firewalls - 'ELIGIBLECANDIDATE' Remote Code Execution 15 WEB Shadow Brokers
2016-08-19   TOPSEC Firewalls - 'ELIGIBLECONTESTANT' Remote Code Execution 13 WEB Shadow Brokers
2016-08-19   ZYCOO IP Phone System - Remote Command Execution 14 WEB 0x4148
2016-08-19   MESSOA IP-Camera NIC990 - Authentication Bypass / Configuration Download 13 WEB Todor Donev
2016-08-19   TOSHIBA IP-Camera IK-WP41A - Authentication Bypass / Configuration Download 13 WEB Todor Donev