Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2012-08-21   JPM Article Blog Script 6 - 'tid' Cross-Site Scripting 15 WEB Mr.0c3aN
2012-08-17   LISTSERV 16 - 'SHOWTPL' Cross-Site Scripting 16 WEB Jose Carlos de Arriba
2012-08-17   Elastix 2.2.0 - 'graph.php' Local File Inclusion 17 WEB cheki
2012-08-02   WordPress Theme ShopperPress - SQL Injection / Cross-Site Scripting 17 WEB Benjamin Kunz Mejri
2012-08-10   GalaxyScripts Mini File Host and DaddyScripts Daddy's File Host - Local File Inclusion 18 WEB L0n3ly-H34rT
2012-08-11   MindTouch DekiWiki - Multiple Local/Remote File Inclusions 15 WEB L0n3ly-H34rT
2012-08-10   mIRC - 'projects.php' Cross-Site Scripting 15 WEB TayfunBasoglu
2012-08-13   Total Shop UK eCommerce CodeIgniter - Multiple Cross-Site Scripting Vulnerabilities 14 WEB Chris Cooper
2012-08-09   Hotel Booking Portal 0.1 - Multiple SQL Injections / Cross-Site Scripting 14 WEB Yakir Wizman
2015-07-17   WordPress Plugin BuddyPress Activity Plus 1.5 - Cross-Site Request Forgery 21 WEB Tom Adams
2015-07-16   8 TOTOLINK Router Models - Backdoor Access / Remote Code Execution 19 WEB Pierre Kim
2015-07-16   4 TOTOLINK Router Models - Backdoor Credentials 20 WEB Pierre Kim
2015-07-16   4 TOTOLINK Router Models - Cross-Site Request Forgery / Cross-Site Scripting 19 WEB Pierre Kim
2015-07-16   15 TOTOLINK Router Models - Multiple Remote Code Execution Vulnerabilities 21 WEB Pierre Kim
2015-07-16   WordPress Plugin Download Manager Free 2.7.94 & Pro 4 - (Authenticated) Persistent Cross-Site Script 19 WEB Filippos Mastrogiannis
2015-07-15   Kaseya Virtual System Administrator (VSA) - Multiple Vulnerabilities (1) 15 WEB Pedro Ribeiro
2015-07-15   Joomla! Component com_docman - Multiple Vulnerabilities 20 WEB Hugo Santiago
2012-08-08   dirLIST 0.3.0 - Local File Inclusion 16 WEB L0n3ly-H34rT
2012-08-08   PBBoard - 'admin.php?xml_name' Arbitrary PHP Code Execution 16 WEB High-Tech Bridge
2012-08-08   PBBoard - 'member_id' Validation Password Manipulation 16 WEB High-Tech Bridge
2012-08-08   PBBoard - 'index.php' Multiple SQL Injections 17 WEB High-Tech Bridge
2012-08-08   phpList 2.10.18 - 'index.php' SQL Injection 14 WEB High-Tech Bridge SA
2015-07-14   sysPass 1.0.9 - SQL Injection 15 WEB SySS GmbH
2015-07-14   Pimcore CMS Build 3450 - Directory Traversal 19 WEB Portcullis
2015-07-13   SO Planning 1.32 - Multiple Vulnerabilities 16 WEB Huy-Ngoc DAU
2015-07-13   WordPress Plugin CP Contact Form with Paypal 1.1.5 - Multiple Vulnerabilities 14 WEB Nitin Venkatesh
2015-07-13   ZenPhoto 1.4.8 - Multiple Vulnerabilities 17 WEB Tim Coen
2015-07-13   WordPress Plugin Swim Team 1.44.10777 - Arbitrary File Download 19 WEB Larry W. Cashdollar
2015-07-13   ArticleFR 3.0.6 - Multiple Vulnerabilities 16 WEB LiquidWorm
2015-07-13   phpVibe - Arbitrary File Disclosure 15 WEB ali ahmady
2015-07-13   Arab Portal 3 - SQL Injection 19 WEB ali ahmady
2015-07-13   FreiChat 9.6 - SQL Injection 19 WEB Kacper Szurek
2012-08-08   AraDown - 'id' SQL Injection 16 WEB G-B
2012-08-08   phpList 2.10.18 - 'unconfirmed' Cross-Site Scripting 19 WEB High-Tech Bridge SA
2012-08-08   ConcourseSuite - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities 20 WEB Matthew Joyce
2015-07-13   phpSQLiteCMS - Multiple Vulnerabilities 16 WEB hyp3rlinx
2012-08-07   Getsimple CMS 3.1.2 - 'path' Local File Inclusion 18 WEB PuN!Sh3r
2012-08-07   PBBoard - Authentication Bypass 18 WEB i-Hmx
2012-08-07   TCExam 11.2.x - '/admin/code/tce_edit_question.php?subject_module_id' SQL Injection 17 WEB Chris Cooper
2012-08-07   TCExam 11.2.x - '/admin/code/tce_edit_answer.php' Multiple SQL Injections 17 WEB Chris Cooper
2012-08-06   YT-Videos Script - 'id' SQL Injection 16 WEB 3spi0n
2012-08-05   Mibew Messenger 1.6.4 - 'threadid' SQL Injection 16 WEB Ucha Gobejishvili
2012-08-07   Dir2web - '/system/src/dispatcher.php?oid' SQL Injection 16 WEB Daniel Correa
2012-08-04   Open Constructor - 'confirm.php?q' Cross-Site Scripting 18 WEB Lorenzo Cantoni
2012-08-04   Open Constructor - '/data/file/edit.php?result' Cross-Site Scripting 17 WEB Lorenzo Cantoni
2012-08-04   Open Constructor - '/users/users.php?keyword' Cross-Site Scripting 16 WEB Lorenzo Cantoni
2012-08-05   PolarisCMS - 'WebForm_OnSubmit()' Cross-Site Scripting 14 WEB Gjoko Krstic
2012-08-06   Joomla! Component com_photo - Multiple SQL Injections 20 WEB Chokri Ben Achor
2012-08-06   Worksforweb iAuto - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities 15 WEB Benjamin Kunz Mejri
2012-08-03   Elefant CMS - 'id' Cross-Site Scripting 16 WEB PuN!Sh3r
2012-07-30   Zenoss 3.2.1 - Multiple Vulnerabilities 15 WEB Brendan Coles
2012-07-30   Zenoss 3.2.1 - (Authenticated) Remote Command Execution 19 WEB Brendan Coles
2012-08-03   ntop - 'arbfile' Cross-Site Scripting 21 WEB Marcos Garcia
2012-08-01   tekno.Portal 0.1b - 'link.php' SQL Injection 15 WEB Socket_0x03
2012-08-02   Mahara 1.4.1 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities 18 WEB anonymous
2012-08-01   WordPress Plugin G-Lock Double Opt-in Manager - SQL Injection 16 WEB BEASTIAN
2015-07-10   WordPress Plugin CP Multi View Event Calendar 1.1.7 - SQL Injection 14 WEB i0akiN SEC-LABORATORY
2015-07-10   WordPress Plugin CP Image Store with Slideshow 1.0.5 - Arbitrary File Download 18 WEB i0akiN SEC-LABORATORY
2012-08-01   ManageEngine Applications Manager - Multiple Cross-Site Scripting / SQL Injections 16 WEB Ibrahim El-Sayed
2012-08-01   Distimo Monitor - Multiple Cross-Site Scripting Vulnerabilities 16 WEB Benjamin Kunz Mejri
2012-08-01   ManageEngine Applications Manager - Multiple SQL Injections 15 WEB Ibrahim El-Sayed
2012-07-31   Limny - 'index.php' Multiple SQL Injections 17 WEB L0n3ly-H34rT
2012-07-29   eNdonesia - 'cid' SQL Injection 20 WEB Crim3R
2012-07-29   JW Player - 'playerready' Cross-Site Scripting 16 WEB MustLive
2012-07-28   phpBB - Multiple SQL Injections 18 WEB HauntIT
2012-07-31   DataWatch Monarch Business Intelligence - Multiple Input Validation Vulnerabilities 16 WEB Raymond Rizk
2012-07-30   Scrutinizer 9.0.1.19899 - HTTP Authentication Bypass 18 WEB Mario Ceballos
2012-07-30   Scrutinizer 9.0.1.19899 - Arbitrary File Upload 18 WEB Mario Ceballos
2012-07-30   Scrutinizer 9.0.1.19899 - Multiple Cross-Site Scripting Vulnerabilities 14 WEB Mario Ceballos
2012-07-29   ocPortal 7.1.5 - 'redirect' Open Redirection 15 WEB Aung Khant
2012-07-25   tekno.Portal 0.1b - 'anket.php' SQL Injection 19 WEB Socket_0x03
2012-07-25   Joomla! Component Odudeprofile 2.8 - 'profession' SQL Injection 15 WEB Daniel Barragan
2012-07-24   phpProfiles - Multiple Vulnerabilities 14 WEB L0n3ly-H34rT
2015-07-08   WordPress Plugin Easy2Map 1.24 - SQL Injection 16 WEB Larry W. Cashdollar
2015-07-08   Orchard CMS 1.7.3/1.8.2/1.9.0 - Persistent Cross-Site Scripting 18 WEB Paris Zoumpouloglou
2015-07-08   AirLive (Multiple Products) - OS Command Injection 18 WEB Core Security
2015-07-08   Grandstream GXV3275 < 1.0.3.30 - Multiple Vulnerabilities 19 WEB David Jorm
2015-07-08   WordPress Plugin WP E-Commerce Shop Styling 2.5 - Arbitrary File Download 19 WEB Larry W. Cashdollar
2015-07-08   Centreon 2.5.4 - Multiple Vulnerabilities 17 WEB Huy-Ngoc DAU
2015-07-08   AirLink101 SkyIPCam1620W - OS Command Injection 16 WEB Core Security
2015-07-08   Cradlepoint MBR1400 and MBR1200 - Local File Inclusion 14 WEB Doc_Hak
2012-07-21   WordPress Plugin chenpress - Arbitrary File Upload 14 WEB Am!r
2012-07-19   CodeIgniter 2.1 - 'xss_clean()' Filter Security Bypass 16 WEB Krzysztof Kotowicz
2012-07-20   Maian Survey - '/index.php' URI redirection / Local File Inclusion 21 WEB PuN!Sh3r
2012-07-19   Joomla! Component com_hello - 'Controller' Local File Inclusion 18 WEB AJAX Security Team
2015-07-07   D-Link DSL-2750u / DSL-2730u - (Authenticated) Local File Disclosure 16 WEB SATHISH ARTHAR
2015-07-07   phpLiteAdmin 1.1 - Multiple Vulnerabilities 18 WEB hyp3rlinx
2015-07-07   WordPress Plugin ACF Frontend Display 2.0.5 - Arbitrary File Upload 15 WEB TUNISIAN CYBER
2012-07-17   AVA VoIP - Multiple Vulnerabilities 17 WEB Ibrahim El-Sayed
2012-07-16   EmbryoCore CMS 1.03 - 'loadcss.php' Multiple Directory Traversal Vulnerabilities 19 WEB Sammy FORGIT
2012-07-16   Rama Zeiten CMS - 'download.php' Remote File Disclosure 26 WEB Sammy FORGIT
2012-07-16   web@all - 'name' Cross-Site Scripting 20 WEB Sammy FORGIT
2012-07-16   WordPress Plugin Post Recommendations - 'abspath' Remote File Inclusion 25 WEB Sammy FORGIT
2012-07-16   Simple Machines 2.0.2 - Multiple HTML Injection Vulnerabilities 19 WEB Benjamin Kunz Mejri
2015-07-06   AirDroid - Arbitrary File Upload 21 WEB Parsa Adib
2012-07-16   Event Calender PHP - Multiple Input Validation Vulnerabilities 23 WEB snup
2012-07-15   Elite Bulletin Board - Multiple SQL Injections 21 WEB ToXiC
2012-07-13   WordPress Plugin Generic - Arbitrary File Upload 21 WEB KedAns-Dz
2012-06-17   Funeral Script PHP - Cross-Site Scripting / SQL Injection 19 WEB snup
2012-07-12   Phonalisa - Multiple HTML Injection / Cross-Site Scripting Vulnerabilities 20 WEB Benjamin Kunz Mejri
2012-07-11   Kajona - 'getAllPassedParams()' Multiple Cross-Site Scripting Vulnerabilities 22 WEB High-Tech Bridge SA
2012-07-09   Flogr - 'tag' Multiple Cross-Site Scripting Vulnerabilities 22 WEB Nafsh
2015-07-05   WordPress Plugin S3Bubble Cloud Video With Adverts & Analytics 0.7 - Arbitrary File Download 26 WEB CrashBandicot
2015-07-05   WK UDID 1.0.1 iOS - Command Injection 26 WEB Vulnerability-Lab
2012-07-09   MGB - Multiple Cross-Site Scripting / SQL Injections 25 WEB Stefan Schurtz
2012-07-09   WebsitePanel - 'ReturnUrl' Open Redirection 25 WEB Anastasios Monachos
2012-07-06   sflog! - 'section' Local File Inclusion 23 WEB dun
2012-07-05   WordPress Plugin PHPFreeChat - 'url' Cross-Site Scripting 20 WEB Sammy FORGIT
2012-07-06   WordPress Plugin Knews Multilingual Newsletters - Cross-Site Scripting 22 WEB Sammy FORGIT
2012-07-06   WordPress Plugin church_admin - 'id' Cross-Site Scripting 24 WEB Sammy FORGIT
2012-07-03   WordPress Plugin custom tables - 'key' Cross-Site Scripting 20 WEB Sammy FORGIT
2012-07-06   WordPress Plugin SocialFit - 'msg' Cross-Site Scripting 20 WEB Sammy FORGIT
2012-07-04   Classified Ads Script PHP - 'admin.php' Multiple SQL Injections 20 WEB snup
2012-07-03   PHP MBB - Cross-Site Scripting / SQL Injection 15 WEB TheCyberNuxbie
2015-07-03   CuteNews 2.0.3 - Arbitrary File Upload 18 WEB T0x!c
2012-07-02   Getsimple CMS Items Manager Plugin - 'PHP.php' Arbitrary File Upload 17 WEB Sammy FORGIT
2012-06-29   SWFupload - 'movieName' Cross-Site Scripting 19 WEB Nathan Partlan
2012-06-29   LIOOSYS CMS - SQL Injection / Information Disclosure 19 WEB MustLive
2012-06-29   JAKCMS PRO 2.2.6 - 'uploader.php' Arbitrary File Upload 20 WEB Sammy FORGIT
2012-06-28   TEMENOS T24 - Multiple Cross-Site Scripting Vulnerabilities 18 WEB Rehan Ahmed
2012-06-28   PHP-Fusion Advanced MP3 Player Infusion - 'upload.php' Arbitrary File Upload 19 WEB Sammy FORGIT
2015-07-02   WordPress Plugin Albo Pretorio Online 3.2 - Multiple Vulnerabilities 19 WEB Alessandro Cingolani
2012-06-26   DigPHP - 'dig.php' Script Remote File Disclosure 20 WEB Ryuzaki Lawlet
2012-06-27   Schoolhos CMS - HTML Injection 19 WEB the_cyber_nuxbie
2012-06-25   Umapresence - Local File Inclusion / Arbitrary File Deletion 21 WEB Sammy FORGIT