Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2012-11-16   Friends in War The FAQ Manager - 'question' SQL Injection 3 WEB unsuprise
2012-11-19   Omni-Secure - 'dir' Multiple File Disclosure Vulnerabilities 3 WEB HaCkeR_EgY
2012-07-19   WebKit Cross-Site Scripting Filter - 'Cross-Site ScriptingAuditor.cpp' Security Bypass 5 WEB Tushar Dalvi
2012-11-16   WordPress Plugin Tagged Albums - 'id' SQL Injection 4 WEB Ashiyane Digital Security Team
2012-11-16   WordPress Theme Dailyedition-mouss - 'id' SQL Injection 4 WEB Ashiyane Digital Security Team
2012-11-09   WordPress Plugin Eco-annu - 'eid' SQL Injection 5 WEB Ashiyane Digital Security Team
2012-11-09   WordPress Plugin PHP Event Calendar - 'cid' SQL Injection 4 WEB Ashiyane Digital Security Team
2012-11-09   WordPress Theme Kakao - 'ID' SQL Injection 3 WEB sil3nt
2012-11-09   ESRI ArcGIS for Server - 'where' SQL Injection 4 WEB anonymous
2012-11-08   AR Web Content Manager (AWCM) - 'cookie_gen.php' Arbitrary Cookie Generation 4 WEB Sooel Son
2012-11-07   WordPress Plugin FLV Player - 'id' SQL Injection 8 WEB Ashiyane Digital Security Team
2012-11-07   OrangeHRM - 'sortField' SQL Injection 4 WEB High-Tech Bridge
2012-11-06   VeriCentre - Multiple SQL Injections 4 WEB Cory Eubanks
2012-11-04   AWAuctionScript CMS - Multiple Remote Vulnerabilities 6 WEB X-Cisadane
2012-11-03   Joomla! Component Parcoauto - 'idVeicolo' SQL Injection 5 WEB Andrea Bocchetti
2012-11-02   DCForum - 'auth_user_file.txt' File Multiple Information Disclosure Vulnerabilities 5 WEB r45c4l
2012-10-31   BloofoxCMS 0.3.5 - Multiple Cross-Site Scripting Vulnerabilities 5 WEB Canberk BOLAT
2015-08-29   Samsung SyncThruWeb 2.01.00.26 - SMB Hash Disclosure 7 WEB Shad Malloy
2015-08-28   Pluck CMS 4.7.3 - Multiple Vulnerabilities 4 WEB smash
2015-08-28   Wolf CMS - Arbitrary File Upload / Execution 4 WEB Narendra Bhati
2015-08-28   Jenkins 1.626 - Cross-Site Request Forgery / Code Execution 4 WEB smash
2015-08-28   WordPress Plugin Responsive Thumbnail Slider 1.0 - Arbitrary File Upload 3 WEB Arash Khazaei
2012-10-31   SolarWinds Orion IP Address Manager (IPAM) - 'search.aspx' Cross-Site Scripting 5 WEB Anthony Trummer
2012-10-31   NetCat CMS - Multiple Cross-Site Scripting Vulnerabilities 4 WEB Security Effect Team
2012-10-30   Joomla! Component com_quiz - SQL Injection 5 WEB Daniel Barragan
2012-10-28   CorePlayer - 'callback' Cross-Site Scripting 4 WEB MustLive
2012-10-16   WANem - Multiple Cross-Site Scripting Vulnerabilities 4 WEB Brendan Coles
2015-08-27   Invision Power Board (IP.Board) 4.x - Persistent Cross-Site Scripting 5 WEB snop
2012-10-26   EasyITSP - 'customers_edit.php' Authentication Bypass 4 WEB Michal Blaszczak
2012-10-29   TP-Link TL-WR841N Router - Local File Inclusion 4 WEB Matan Azugi
2012-10-26   VicBlog - Multiple SQL Injections 5 WEB Geek
2012-10-25   Gramophone - 'rs' Cross-Site Scripting 4 WEB G13
2015-08-26   Magento eCommerce - Remote Code Execution 4 WEB Manish Tanwar
2012-10-26   Inventory - Multiple Cross-Site Scripting / SQL Injections 4 WEB G13
2012-10-23   SMF - 'view' Cross-Site Scripting 4 WEB Am!r
2012-10-22   WHMCompleteSolution (WHMCS) 4.5.2 - 'googlecheckout.php' SQL Injection 4 WEB Starware Security Team
2012-10-18   WordPress Plugin Wordfence Security - Cross-Site Scripting 4 WEB MustLive
2012-10-19   CMS Mini 0.2.2 - 'index.php' Script Cross-Site Scripting 4 WEB Netsparker
2015-08-25   Keeper IP Camera 3.2.2.10 - Authentication Bypass 4 WEB RAT - ThiefKing
2012-10-18   Amateur Photographer's Image Gallery - 'fullscreen.php?albumid' SQL Injection 4 WEB cr4wl3r
2012-10-18   Amateur Photographer's Image Gallery - 'plist.php?albumid' Cross-Site Scripting 4 WEB cr4wl3r
2012-10-18   Amateur Photographer's Image Gallery - 'plist.php?albumid' SQL Injection 4 WEB cr4wl3r
2012-10-18   Amateur Photographer's Image Gallery - 'force-download.php?File' Information Disclosure 4 WEB cr4wl3r
2012-10-18   BSW Gallery - 'uploadpic.php' Arbitrary File Upload 4 WEB cr4wl3r
2015-08-24   WordPress Theme GeoPlaces3 - Arbitrary File Upload 4 WEB Mdn_Newbie
2015-08-24   Pligg CMS 2.0.2 - Cross-Site Request Forgery (Add Admin) 4 WEB Arash Khazaei
2012-10-17   jCore - '/admin/index.php?path' Cross-Site Scripting 5 WEB High-Tech Bridge
2012-10-17   WordPress Plugin Slideshow - Multiple Cross-Site Scripting Vulnerabilities 5 WEB waraxe
2012-10-15   WordPress Plugin Crayon Syntax Highlighter - 'wp_load' Remote File Inclusion 4 WEB Charlie Eriksen
2012-10-15   SilverStripe CMS 2.4.x - 'BackURL' Open Redirection 4 WEB Aung Khant
2012-06-16   vBSEO - 'u' Cross-Site Scripting 3 WEB MegaMan
2012-10-20   WebTitan - 'logs-x.php' Directory Traversal 4 WEB Richard Conner
2012-01-06   SenseSites CommonSense CMS - 'article.php?id' SQL Injection 4 WEB H4ckCity Security Team
2012-01-06   SenseSites CommonSense CMS - 'special.php?id' SQL Injection 3 WEB H4ckCity Security Team
2012-01-06   SenseSites CommonSense CMS - 'id' SQL Injection 3 WEB H4ckCity Security Team
2012-08-11   FileContral - Local File Inclusion / Local File Disclosure 3 WEB Ashiyane Digital Security Team
2012-10-10   OpenX 2.8.10 - 'plugin-index.php' Cross-Site Scripting 4 WEB High-Tech Bridge
2012-10-06   Open Realty - 'select_users_lang' Local File Inclusion 4 WEB L0n3ly-H34rT
2012-10-08   Interspire Email Marketer - Cross-Site Scripting / HTML Injection / SQL Injection 4 WEB Ibrahim El-Sayed
2012-10-05   WordPress Plugin Shopp - Multiple Vulnerabilities 5 WEB T0x!c
2015-08-21   Netsweeper 4.0.8 - Authentication Bypass (via New Profile Creation) 3 WEB Anastasios Monachos
2015-08-21   Netsweeper 4.0.8 - Arbitrary File Upload / Execution 4 WEB Anastasios Monachos
2015-08-21   Netsweeper 3.0.6 - Authentication Bypass 3 WEB Anastasios Monachos
2015-08-21   Netsweeper 4.0.9 - Arbitrary File Upload / Execution 4 WEB Anastasios Monachos
2015-08-21   Netsweeper 4.0.8 - Authentication Bypass (via Disabling of IP Quarantine) 4 WEB Anastasios Monachos
2015-08-21   Netsweeper 4.0.8 - SQL Injection / Authentication Bypass 5 WEB Anastasios Monachos
2015-08-21   Netsweeper 4.0.4 - SQL Injection 3 WEB Anastasios Monachos
2015-08-21   Netsweeper 2.6.29.8 - SQL Injection 3 WEB Anastasios Monachos
2015-08-21   WordPress Plugin MDC Private Message 1.0.0 - Persistent Cross-Site Scripting 4 WEB Chris Kellum
2015-08-21   WordPress Plugin Googmonify 0.8.1 - Cross-Site Scripting / Cross-Site Request Forgery 4 WEB Ehsan Hosseini
2012-10-01   Omnistar Mailer - Multiple SQL Injections / HTML Injection Vulnerabilities 4 WEB Vulnerability Laboratory
2012-10-02   ZenPhoto - 'admin-news-articles.php' Cross-Site Scripting 4 WEB Scott Herbert
2012-10-01   WordPress Plugin Akismet - Multiple Cross-Site Scripting Vulnerabilities 4 WEB Tapco Security
2012-09-30   AlamFifa CMS - 'user_name_cookie' SQL Injection 5 WEB L0n3ly-H34rT
2012-10-02   Switchvox - Multiple HTML Injection Vulnerabilities 5 WEB Ibrahim El-Sayed
2012-09-26   WordPress Plugin ABC Test - 'id' Cross-Site Scripting 4 WEB Scott Herbert
2015-08-20   Pligg CMS 2.0.2 - Arbitrary Code Execution 4 WEB Arash Khazaei
2015-08-20   Vifi Radio 1.0 - Cross-Site Request Forgery 4 WEB KnocKout
2015-08-20   Aruba Mobility Controller 6.4.2.8 - Multiple Vulnerabilities 4 WEB Itzik Chen
2015-08-19   up.time 7.5.0 - Upload and Execute 4 WEB LiquidWorm
2015-08-19   up.time 7.5.0 - Arbitrary File Disclose and Delete 4 WEB LiquidWorm
2015-08-19   up.time 7.5.0 - Cross-Site Scripting / Cross-Site Request Forgery (Add Admin) 4 WEB LiquidWorm
2015-08-19   up.time 7.5.0 - Superadmin Privilege Escalation 4 WEB LiquidWorm
2011-12-30   Neturf eCommerce Shopping Cart - 'searchFor' Cross-Site Scripting 5 WEB farbodmahini
2012-09-22   WordPress Plugin Sexy Add Template - Cross-Site Request Forgery 4 WEB the_cyber_nuxbie
2012-09-25   WordPress Plugin Token Manager - 'tid' Cross-Site Scripting 4 WEB TheCyberNuxbie
2012-09-22   WordPress Core 3.4.2 - Cross-Site Request Forgery 5 WEB AkaStep
2012-09-21   YCommerce - Multiple SQL Injections 6 WEB Ricardo Almeida
2012-09-24   ZEN Load Balancer - Multiple Vulnerabilities 4 WEB Brendan Coles
2012-09-20   WordPress Plugin MF Gig Calendar - Cross-Site Scripting 4 WEB Chris Cooper
2012-09-20   Poweradmin - 'index.php' Cross-Site Scripting 4 WEB Siavash
2012-09-07   WordPress Theme Purity - Multiple Cross-Site Scripting Vulnerabilities 4 WEB Matan Azugi
2012-09-18   WordPress Core 3.4.2 - Multiple Path Disclosure Vulnerabilities 3 WEB AkaStep
2015-08-18   WordPress Plugin WP Symposium 15.1 - 'get_album_item.php' SQL Injection 4 WEB PizzaHatHacker
2015-08-18   WordPress Plugin WP Symposium 15.1 - Blind SQL Injection 3 WEB dxw
2015-08-18   BigTree CMS 4.2.3 - (Authenticated) SQL Injection 4 WEB Curesec Research Team
2015-08-18   CodoForum 3.3.1 - Multiple SQL Injections 4 WEB Curesec Research Team
2015-08-18   PHPfileNavigator 2.3.3 - Privilege Escalation 4 WEB hyp3rlinx
2015-08-18   PHPfileNavigator 2.3.3 - Cross-Site Request Forgery 5 WEB hyp3rlinx
2015-08-18   PHPfileNavigator 2.3.3 - Cross-Site Scripting 4 WEB hyp3rlinx
2015-08-18   Cisco Unified Communications Manager - Multiple Vulnerabilities 5 WEB Bernhard Mueller
2015-08-18   vBulletin < 4.2.2 - Memcache Remote Code Execution 4 WEB Joshua Rogers
2015-08-18   Magento CE < 1.9.0.1 - (Authenticated) Remote Code Execution 5 WEB Ebrietas0
2015-08-17   Nuts CMS - PHP Remote Code Injection / Execution 5 WEB Yakir Wizman
2012-09-18   vBulletin 4.1.12 - 'blog_plugin_useradmin.php' SQL Injection 5 WEB Am!r
2012-09-18   AxisInternet VoIP Manager - Multiple Cross-Site Scripting Vulnerabilities 4 WEB Benjamin Kunz Mejri
2012-09-18   TAGWORX.CMS - 'cid' SQL Injection 4 WEB Crim3R
2012-09-17   minimal Gallery - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 5 WEB ayastar
2012-09-15   IFOBS - 'regclientprint.jsp' Multiple HTML Injection Vulnerabilities 5 WEB MustLive
2015-08-17   Sagemcom F@ST 3864 V2 - Get Admin Password 6 WEB Cade Bull
2012-09-12   Atlassian Confluence 3.4.x - Error Page Cross-Site Scripting 5 WEB D. Niedermaier
2012-09-11   FBDj - 'id' SQL Injection 5 WEB TUNISIAN CYBER
2012-09-06   OpenFiler 2.3 - Multiple Cross-Site Scripting / Information Disclosure Vulnerabilities 4 WEB Brendan Coles
2012-08-30   WordPress Plugin Download Monitor - 'dlsearch' Cross-Site Scripting 4 WEB Chris Cooper
2012-09-10   DELTAScripts PHP Links - Multiple SQL Injections 4 WEB L0n3ly-H34rT
2012-09-10   VICIDIAL Call Center Suite - Multiple SQL Injections 4 WEB Ertebat Gostar Co
2012-09-08   Pinterestclones - Security Bypass / HTML Injection 4 WEB DaOne
2012-09-06   web@all - Local File Inclusion / Multiple Arbitrary File Upload Vulnerabilities 4 WEB KedAns-Dz
2012-09-05   Extcalendar 2.0 - Multiple SQL Injections / HTML Injection Vulnerabilities 4 WEB Ashiyane Digital Security Team
2012-09-05   Flogr - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 4 WEB High-Tech Bridge
2015-08-15   Security IP Camera Star Vision DVR - Authentication Bypass 4 WEB Meisam Monsef
2015-08-15   Joomla! Component com_informations - SQL Injection 4 WEB Omar
2015-08-15   Joomla! Component com_memorix - SQL Injection 3 WEB Omar
2015-08-15   TOTOLINK Routers - Backdoor / Remote Code Execution 3 WEB MadMouse
2015-08-15   Gkplugins Picasaweb - Download File 3 WEB TMT zno