Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2015-08-15   Security IP Camera Star Vision DVR - Authentication Bypass 23 WEB Meisam Monsef
2015-08-15   Joomla! Component com_informations - SQL Injection 27 WEB Omar
2015-08-15   Joomla! Component com_memorix - SQL Injection 29 WEB Omar
2015-08-15   TOTOLINK Routers - Backdoor / Remote Code Execution 30 WEB MadMouse
2015-08-15   Gkplugins Picasaweb - Download File 26 WEB TMT zno
2015-08-13   Joomla! Component com_jem 2.1.4 - Multiple Vulnerabilities 24 WEB Martino Sani
2015-08-13   Zend Framework 2.4.2 - PHP FPM XML eXternal Entity Injection 28 WEB Dawid Golunski
2015-08-12   Printer Pro 5.4.3 IOS - Persistent Cross-Site Scripting 32 WEB Taurus Omar
2015-08-12   Geoserver < 2.7.1.1 / < 2.6.4 / < 2.5.5.1 - XML External Entity 26 WEB David Bloom
2015-08-10   WordPress Plugin Candidate Application Form 1.0 - Arbitrary File Download 29 WEB Larry W. Cashdollar
2015-08-10   WordPress Plugin Simple Image Manipulator 1.0 - Arbitrary File Download 34 WEB Larry W. Cashdollar
2015-08-10   WordPress Plugin Recent Backups 0.7 - Arbitrary File Download 30 WEB Larry W. Cashdollar
2015-08-10   WordPress Plugin WPTF Image Gallery 1.03 - Arbitrary File Download 33 WEB Larry W. Cashdollar
2015-08-10   WDS CMS - SQL Injection 29 WEB Ismail Marzouk
2015-08-09   WordPress Plugin Video Gallery 2.7 - SQL Injection 32 WEB Kacper Szurek
2015-08-07   WordPress Plugin Job Manager 0.7.22 - Persistent Cross-Site Scripting 29 WEB Owais Mehtab
2015-08-07   Microweber 1.0.3 - Arbitrary File Upload / Filter Bypass / PHP Remote Code Execution 25 WEB LiquidWorm
2015-08-07   Microweber 1.0.3 - Persistent Cross-Site Scripting / Cross-Site Request Forgery (Add Admin) 30 WEB LiquidWorm
2015-08-07   PHP News Script 4.0.0 - SQL Injection 27 WEB Meisam Monsef
2015-08-07   Froxlor Server Management Panel 0.9.33.1 - MySQL Login Information Disclosure 27 WEB Dustin Dörr
2015-07-31   Netgear ReadyNAS LAN /dbbroker 6.2.4 - Credential Disclosure 22 WEB St0rn
2015-07-29   Tendoo CMS 1.3 - Cross-Site Scripting 30 WEB Arash Khazaei
2015-07-29   JoomShopping - Blind SQL Injection 24 WEB Mormoroth
2015-07-29   2Moons - Multiple Vulnerabilities 27 WEB bRpsd
2015-07-29   phpFileManager 0.9.8 - Cross-Site Request Forgery 26 WEB hyp3rlinx
2015-07-28   phpFileManager 0.9.8 - Remote Command Execution 23 WEB hyp3rlinx
2015-07-27   Xceedium Xsuite - Multiple Vulnerabilities 27 WEB modzero
2015-07-27   WordPress Plugin Count Per Day 3.4 - SQL Injection 25 WEB High-Tech Bridge SA
2015-07-27   WordPress Plugin Unite Gallery Lite 1.4.6 - Multiple Vulnerabilities 28 WEB Nitin Venkatesh
2015-07-27   Hawkeye-G 3.0.1.4912 - Persistent Cross-Site Scripting / Information Leakage 26 WEB hyp3rlinx
2012-09-05   Kayako Fusion - 'download.php' Cross-Site Scripting 30 WEB High-Tech Bridge
2012-09-04   PHPFox 3.0.1 - 'ajax.php' Multiple Cross-Site Scripting Vulnerabilities 24 WEB Crim3R
2012-09-05   Cm3 CMS - 'search.asp' Multiple Cross-Site Scripting Vulnerabilities 28 WEB Crim3R
2012-09-04   Sciretech (Multiple Products) - Multiple SQL Injections 26 WEB AkaStep
2012-08-04   Wiki Web Help - 'configpath' Remote File Inclusion 25 WEB L0n3ly-H34rT
2012-09-03   Sitemax Maestro - SQL Injection / Local File Inclusion 26 WEB AkaStep
2012-08-31   SugarCRM Community Edition - Multiple Information Disclosure Vulnerabilities 28 WEB Brendan Coles
2012-08-30   Crowbar - 'file' Multiple Cross-Site Scripting Vulnerabilities 26 WEB Matthias Weckbecker
2012-08-30   XM Forum - 'search.asp' SQL Injection 29 WEB Crim3R
2012-08-30   TomatoCart - 'example_form.ajax.php' Cross-Site Scripting 28 WEB HauntIT
2015-07-24   Hawkeye-G 3.0.1.4912 - Cross-Site Request Forgery 26 WEB hyp3rlinx
2012-08-29   PrestaShop 1.4.7 - Multiple Cross-Site Scripting Vulnerabilities 27 WEB High-Tech Bridge
2012-08-29   Phorum 5.2.18 - Multiple Cross-Site Scripting Vulnerabilities 25 WEB High-Tech Bridge
2012-08-28   WordPress Plugin Simple:Press Forum - Arbitrary File Upload 26 WEB Iranian Dark Coders
2012-08-28   WordPress Plugin Cloudsafe365 - 'file' Remote File Disclosure 26 WEB Jan Van Niekerk
2012-08-25   Mihalism Multi Host - 'users.php' Cross-Site Scripting 24 WEB Explo!ter
2012-08-25   LibGuides - Multiple Cross-Site Scripting Vulnerabilities 28 WEB Crim3R
2012-08-25   Web Wiz Forums - Multiple Cross-Site Scripting Vulnerabilities 26 WEB Crim3R
2012-08-25   WordPress Plugin Finder - 'order' Cross-Site Scripting 26 WEB Crim3R
2012-08-25   Power-eCommerce - Multiple Cross-Site Scripting Vulnerabilities 30 WEB Crim3R
2012-08-27   Joomla! Component Komento - 'cid' SQL Injection 27 WEB Crim3R
2012-08-24   PHP Web Scripts Text Exchange Pro - 'page' Local File Inclusion 24 WEB Yakir Wizman
2012-08-29   JW Player - 'logo.link' Cross-Site Scripting 25 WEB MustLive
2015-07-21   Joomla! Component Helpdesk Pro < 1.4.0 - Multiple Vulnerabilities 32 WEB Simon Rawet
2015-07-20   AirDroid iOS / Android / Win 3.1.3 - Persistent 32 WEB Vulnerability-Lab
2015-07-20   phpVibe < 4.20 - Persistent Cross-Site Scripting 32 WEB Filippos Mastrogiannis
2012-08-23   PHP Web Scripts Ad Manager Pro - 'page' Local File Inclusion 26 WEB Corrado Liotta
2012-08-22   WordPress Plugin Monsters Editor for WP Super Edit - Arbitrary File Upload 27 WEB Crim3R
2012-08-22   WordPress Plugin Rich Widget - Arbitrary File Upload 30 WEB Crim3R
2012-08-23   KindEditor - 'name' Cross-Site Scripting 26 WEB LiquidWorm
2012-08-23   Monstra CMS 1.2.1 - Multiple HTML Injection Vulnerabilities 24 WEB LiquidWorm
2012-08-22   1024 CMS 2.1.1 - 'p' SQL Injection 30 WEB kallimero
2012-08-23   SiNG cms - 'Password.php' Cross-Site Scripting 26 WEB LiquidWorm
2012-08-22   Joomla! Component CiviCRM - Multiple Arbitrary File Upload Vulnerabilities 26 WEB Crim3R
2012-08-22   Banana Dance - Cross-Site Scripting / SQL Injection 28 WEB Canberk BOLAT
2012-08-22   OrderSys 1.6.4 - Multiple SQL Injections / Multiple Cross-Site Scripting Vulnerabilities 25 WEB Canberk BOLAT
2012-08-22   Jara 1.6 - Multiple SQL Injections / Multiple Cross-Site Scripting Vulnerabilities 25 WEB Canberk BOLAT
2012-08-27   IBM Rational ClearQuest 8.0 - Multiple Vulnerabilities 24 WEB anonymous
2012-08-18   SaltOS - 'download.php' Cross-Site Scripting 26 WEB Stefan Schurtz
2012-08-21   JPM Article Blog Script 6 - 'tid' Cross-Site Scripting 23 WEB Mr.0c3aN
2012-08-17   LISTSERV 16 - 'SHOWTPL' Cross-Site Scripting 25 WEB Jose Carlos de Arriba
2012-08-17   Elastix 2.2.0 - 'graph.php' Local File Inclusion 25 WEB cheki
2012-08-02   WordPress Theme ShopperPress - SQL Injection / Cross-Site Scripting 26 WEB Benjamin Kunz Mejri
2012-08-10   GalaxyScripts Mini File Host and DaddyScripts Daddy's File Host - Local File Inclusion 25 WEB L0n3ly-H34rT
2012-08-11   MindTouch DekiWiki - Multiple Local/Remote File Inclusions 23 WEB L0n3ly-H34rT
2012-08-10   mIRC - 'projects.php' Cross-Site Scripting 26 WEB TayfunBasoglu
2012-08-13   Total Shop UK eCommerce CodeIgniter - Multiple Cross-Site Scripting Vulnerabilities 26 WEB Chris Cooper
2012-08-09   Hotel Booking Portal 0.1 - Multiple SQL Injections / Cross-Site Scripting 22 WEB Yakir Wizman
2015-07-17   WordPress Plugin BuddyPress Activity Plus 1.5 - Cross-Site Request Forgery 30 WEB Tom Adams
2015-07-16   8 TOTOLINK Router Models - Backdoor Access / Remote Code Execution 29 WEB Pierre Kim
2015-07-16   4 TOTOLINK Router Models - Backdoor Credentials 28 WEB Pierre Kim
2015-07-16   4 TOTOLINK Router Models - Cross-Site Request Forgery / Cross-Site Scripting 27 WEB Pierre Kim
2015-07-16   15 TOTOLINK Router Models - Multiple Remote Code Execution Vulnerabilities 29 WEB Pierre Kim
2015-07-16   WordPress Plugin Download Manager Free 2.7.94 & Pro 4 - (Authenticated) Persistent Cross-Site Script 28 WEB Filippos Mastrogiannis
2015-07-15   Kaseya Virtual System Administrator (VSA) - Multiple Vulnerabilities (1) 27 WEB Pedro Ribeiro
2015-07-15   Joomla! Component com_docman - Multiple Vulnerabilities 29 WEB Hugo Santiago
2012-08-08   dirLIST 0.3.0 - Local File Inclusion 28 WEB L0n3ly-H34rT
2012-08-08   PBBoard - 'admin.php?xml_name' Arbitrary PHP Code Execution 25 WEB High-Tech Bridge
2012-08-08   PBBoard - 'member_id' Validation Password Manipulation 24 WEB High-Tech Bridge
2012-08-08   PBBoard - 'index.php' Multiple SQL Injections 28 WEB High-Tech Bridge
2012-08-08   phpList 2.10.18 - 'index.php' SQL Injection 23 WEB High-Tech Bridge SA
2015-07-14   sysPass 1.0.9 - SQL Injection 23 WEB SySS GmbH
2015-07-14   Pimcore CMS Build 3450 - Directory Traversal 33 WEB Portcullis
2015-07-13   SO Planning 1.32 - Multiple Vulnerabilities 27 WEB Huy-Ngoc DAU
2015-07-13   WordPress Plugin CP Contact Form with Paypal 1.1.5 - Multiple Vulnerabilities 24 WEB Nitin Venkatesh
2015-07-13   ZenPhoto 1.4.8 - Multiple Vulnerabilities 26 WEB Tim Coen
2015-07-13   WordPress Plugin Swim Team 1.44.10777 - Arbitrary File Download 28 WEB Larry W. Cashdollar
2015-07-13   ArticleFR 3.0.6 - Multiple Vulnerabilities 26 WEB LiquidWorm
2015-07-13   phpVibe - Arbitrary File Disclosure 24 WEB ali ahmady
2015-07-13   Arab Portal 3 - SQL Injection 26 WEB ali ahmady
2015-07-13   FreiChat 9.6 - SQL Injection 26 WEB Kacper Szurek
2012-08-08   AraDown - 'id' SQL Injection 26 WEB G-B
2012-08-08   phpList 2.10.18 - 'unconfirmed' Cross-Site Scripting 27 WEB High-Tech Bridge SA
2012-08-08   ConcourseSuite - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities 30 WEB Matthew Joyce
2015-07-13   phpSQLiteCMS - Multiple Vulnerabilities 27 WEB hyp3rlinx
2012-08-07   Getsimple CMS 3.1.2 - 'path' Local File Inclusion 27 WEB PuN!Sh3r
2012-08-07   PBBoard - Authentication Bypass 24 WEB i-Hmx
2012-08-07   TCExam 11.2.x - '/admin/code/tce_edit_question.php?subject_module_id' SQL Injection 27 WEB Chris Cooper
2012-08-07   TCExam 11.2.x - '/admin/code/tce_edit_answer.php' Multiple SQL Injections 29 WEB Chris Cooper
2012-08-06   YT-Videos Script - 'id' SQL Injection 23 WEB 3spi0n
2012-08-05   Mibew Messenger 1.6.4 - 'threadid' SQL Injection 30 WEB Ucha Gobejishvili
2012-08-07   Dir2web - '/system/src/dispatcher.php?oid' SQL Injection 26 WEB Daniel Correa
2012-08-04   Open Constructor - 'confirm.php?q' Cross-Site Scripting 28 WEB Lorenzo Cantoni
2012-08-04   Open Constructor - '/data/file/edit.php?result' Cross-Site Scripting 26 WEB Lorenzo Cantoni
2012-08-04   Open Constructor - '/users/users.php?keyword' Cross-Site Scripting 26 WEB Lorenzo Cantoni
2012-08-05   PolarisCMS - 'WebForm_OnSubmit()' Cross-Site Scripting 25 WEB Gjoko Krstic
2012-08-06   Joomla! Component com_photo - Multiple SQL Injections 29 WEB Chokri Ben Achor
2012-08-06   Worksforweb iAuto - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities 23 WEB Benjamin Kunz Mejri
2012-08-03   Elefant CMS - 'id' Cross-Site Scripting 25 WEB PuN!Sh3r
2012-07-30   Zenoss 3.2.1 - Multiple Vulnerabilities 28 WEB Brendan Coles
2012-07-30   Zenoss 3.2.1 - (Authenticated) Remote Command Execution 29 WEB Brendan Coles
2012-08-03   ntop - 'arbfile' Cross-Site Scripting 32 WEB Marcos Garcia
2012-08-01   tekno.Portal 0.1b - 'link.php' SQL Injection 25 WEB Socket_0x03
2012-08-02   Mahara 1.4.1 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities 28 WEB anonymous
2012-08-01   WordPress Plugin G-Lock Double Opt-in Manager - SQL Injection 26 WEB BEASTIAN