Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2012-05-16   LongTail JW Player - 'debug' Cross-Site Scripting 6 WEB gainover
2012-05-15   WordPress Plugin Track That Stat 1.0.8 - Cross-Site Scripting 6 WEB Heine Pedersen
2012-05-15   WordPress Plugin Soundcloud Is Gold 2.1 - 'width' Cross-Site Scripting 6 WEB Heine Pedersen
2012-05-15   WordPress Plugin Share and Follow 1.80.3 - 'admin.php' Cross-Site Scripting 6 WEB Heine Pedersen
2012-05-15   WordPress Plugin Sharebar 1.2.1 - SQL Injection / Cross-Site Scripting 6 WEB Heine Pedersen
2015-06-04   WordPress Plugin zM Ajax Login & Register 1.0.9 - Local File Inclusion 6 WEB Panagiotis Vagenas
2012-05-15   WordPress Plugin Pretty Link Lite 1.5.2 - SQL Injection / Cross-Site Scripting 5 WEB Heine Pedersen
2012-05-15   WordPress Plugin WP Forum Server 1.7.3 - '/fs-admin/fs-admin.php' Multiple Cross-Site Scripting Vuln 6 WEB Heine Pedersen
2012-05-15   WordPress Plugin Mingle Forum 1.0.33 - 'admin.php' Multiple Cross-Site Scripting Vulnerabilities 6 WEB Heine Pedersen
2012-05-15   WordPress Plugin GD Star Rating 1.9.16 - 'tpl_section' Cross-Site Scripting 6 WEB Heine Pedersen
2012-05-15   WordPress Plugin Leaflet Maps Marker 0.0.1 - 'leaflet_marker.php?id' Cross-Site Scripting 6 WEB Heine Pedersen
2012-05-15   WordPress Plugin Leaflet Maps Marker 0.0.1 - 'leaflet_layer.php?id' Cross-Site Scripting 6 WEB Heine Pedersen
2012-05-15   WordPress Plugin LeagueManager 3.7 - Multiple Cross-Site Scripting Vulnerabilities 6 WEB Heine Pedersen
2012-05-15   WordPress Plugin Media Library Categories - Multiple Cross-Site Scripting Vulnerabilities 6 WEB Heine Pedersen
2015-06-03   VFront 0.99.2 - Cross-Site Request Forgery / Persistent Cross-Site Scripting 19 WEB hyp3rlinx
2015-06-03   Seagate Central 2014.0410.0026-F - Remote Facebook Access Token 15 WEB Jeremy Brown
2015-06-02   WordPress Plugin LeagueManager 3.9.11 - SQL Injection 7 WEB javabudd
2012-05-15   WordPress Plugin NewsLetter Manager 1.0 - Multiple Cross-Site Scripting Vulnerabilities 6 WEB Heine Pedersen
2012-05-15   WordPress Plugin iFrame Admin Pages 0.1 - 'main_page.php' Cross-Site Scripting 6 WEB Heine Pedersen
2012-05-15   WordPress Plugin 2 Click Social Media Buttons 0.32.2 - Multiple Cross-Site Scripting Vulnerabilities 6 WEB Heine Pedersen
2012-05-15   WordPress Plugin CataBlog 1.6 - 'admin.php' Cross-Site Scripting 6 WEB Heine Pedersen
2012-05-15   WordPress Plugin PDF & Print Button Joliprint 1.3.0 - Multiple Cross-Site Scripting Vulnerabilities 6 WEB Heine Pedersen
2012-05-15   WordPress Plugin Network Publisher 5.0.1 - 'networkpub_key' Cross-Site Scripting 6 WEB Heine Pedersen
2015-06-01   Aruba ClearPass Policy Manager - Persistent Cross-Site Scripting 6 WEB Cristiano Maruti
2015-06-01   WordPress Plugin dzs-zoomsounds 2.0 - Arbitrary File Upload 6 WEB nabil chris
2012-05-15   WordPress Plugin Dynamic Widgets 1.5.1 - 'themes.php' Cross-Site Scripting 8 WEB Heine Pedersen
2012-05-15   WordPress Plugin GRAND Flash Album Gallery 1.71 - 'admin.php' Cross-Site Scripting 7 WEB Heine Pedersen
2012-05-13   WordPress Plugin WP-FaceThumb 0.1 - 'pagination_wp_facethum' Cross-Site Scripting 8 WEB d3v1l
2015-05-29   ESC 8832 Data Controller - Multiple Vulnerabilities 9 WEB Balazs Makany
2015-05-29   JSPMyAdmin 1.1 - Multiple Vulnerabilities 9 WEB hyp3rlinx
2015-05-29   TCPDF Library 5.9 - Arbitrary File Deletion 8 WEB Filippo Roncari
2012-05-10   Chevereto 1.91 - '/Upload/engine.php?v' Traversal Arbitrary File Enumeration 8 WEB AkaStep
2012-05-10   Chevereto 1.91 - '/Upload/engine.php?v' Cross-Site Scripting 9 WEB AkaStep
2012-05-09   PivotX 2.3.2 - 'ajaxhelper.php' Cross-Site Scripting 8 WEB High-Tech Bridge SA
2012-05-09   OrangeHRM 2.7 RC - 'index.php?URI' Cross-Site Scripting 9 WEB High-Tech Bridge SA
2012-05-09   OrangeHRM 2.7 RC - '/templates/hrfunct/emppop.php?sortOrder1' Cross-Site Scripting 9 WEB High-Tech Bridge SA
2012-05-09   OrangeHRM 2.7 RC - '/plugins/ajaxCalls/haltResumeHsp.php?newHspStatus' Cross-Site Scripting 9 WEB High-Tech Bridge SA
2012-05-09   OrangeHRM 2.7 RC - '/plugins/ajaxCalls/haltResumeHsp.php?hspSummaryId' SQL Injection 9 WEB High-Tech Bridge SA
2012-05-08   PHP Enter 4.1.2 - 'banners.php' PHP Code Injection 7 WEB L3b-r1'z
2012-05-07   JibberBook 2.3 - 'Login_form.php' Authentication Bypass 7 WEB L3b-r1'z
2012-05-07   Ramui Forum Script - 'query' Cross-Site Scripting 6 WEB 3spi0n
2012-05-06   Schneider Electric Telecontrol Kerweb 3.0.0/6.0.0 - 'kw.dll' HTML Injection 8 WEB phocean
2012-05-07   Trombinoscope 3.x - 'photo.php' Server SQL Injection 8 WEB Ramdan Yantu
2012-05-02   iGuard Security Access Control Device Firmware 3.6.7427A - Cross-Site Scripting 5 WEB Usman Saeed
2012-04-27   MySQLDumper 1.24.4 - 'menu.php' PHP Remote Code Execution 6 WEB AkaStep
2012-04-27   MySQLDumper 1.24.4 - 'index.php?page' Cross-Site Scripting 7 WEB AkaStep
2015-05-27   WordPress Plugin Free Counter 1.1 - Persistent Cross-Site Scripting 8 WEB Panagiotis Vagenas
2012-04-27   MySQLDumper 1.24.4 - 'main.php' Multiple Cross-Site Request Forgery Vulnerabilities 8 WEB AkaStep
2012-04-27   MySQLDumper 1.24.4 - Multiple Script Direct Request Information Disclosures 7 WEB AkaStep
2012-04-27   MySQLDumper 1.24.4 - 'filemanagement.php?f' Traversal Arbitrary File Access 6 WEB AkaStep
2012-04-27   MySQLDumper 1.24.4 - 'sql.php' Multiple Cross-Site Scripting Vulnerabilities 7 WEB AkaStep
2012-04-27   MySQLDumper 1.24.4 - 'install.php' Multiple Cross-Site Scripting Vulnerabilities 8 WEB AkaStep
2012-04-27   MySQLDumper 1.24.4 - 'install.php?language' Traversal Arbitrary File Access 8 WEB AkaStep
2012-04-27   MySQLDumper 1.24.4 - 'restore.php?Filename' Cross-Site Scripting 7 WEB AkaStep
2012-04-30   WordPress Plugin WPsc MijnPress - 'rwflush' Cross-Site Scripting 9 WEB Am!r
2012-04-28   Shawn Bradley PHP Volunteer Management 1.0.2 - 'id' SQL Injection 8 WEB eidelweiss
2012-04-27   BBSXP CMS - Multiple SQL Injections 9 WEB Farbod Mahini
2012-04-27   Uiga FanClub - 'p' SQL Injection 8 WEB Farbod Mahini
2012-04-27   XM Forum - 'id' Multiple SQL Injections 9 WEB Farbod Mahini
2012-04-27   SKYUC 3.2.1 - 'encode' Cross-Site Scripting 8 WEB farbodmahini
2012-04-29   Croogo CMS 1.3.4 - Multiple HTML Injection Vulnerabilities 8 WEB Chokri Ben Achor
2012-04-27   SilverStripe CMS 2.4.7 - 'install.php' PHP Code Injection 8 WEB Mehmet Ince
2015-05-26   ClickHeat 1.13+ - Remote Command Execution 8 WEB Calum Hutton
2015-05-26   Sendio ESP - Information Disclosure 8 WEB Core Security
2015-05-26   WordPress Plugin Simple Photo Gallery 1.7.8 - Blind SQL Injection 9 WEB woodspeed
2015-05-26   WordPress Plugin church_admin 0.800 - Persistent Cross-Site Scripting 9 WEB woodspeed
2015-05-26   WordPress Plugin MailChimp Subscribe Forms 1.1 - Remote Code Execution 8 WEB woodspeed
2015-05-26   Apache JackRabbit - WebDAV XML External Entity 10 WEB Mikhail Egorov
2015-05-26   WordPress Plugin GigPress 2.3.8 - SQL Injection 10 WEB Adrián M. F.
2015-05-26   WordPress Plugin Landing Pages 1.8.4 - Multiple Vulnerabilities 8 WEB Adrián M. F.
2015-05-26   WordPress Plugin NewStatPress 0.9.8 - Multiple Vulnerabilities 8 WEB Adrián M. F.
2015-05-26   WordPress Plugin Video Gallery 2.8 - Arbitrary Mail Relay 8 WEB Claudio Viviani
2012-04-26   Quick.CMS 4.0 - 'p' Cross-Site Scripting 7 WEB Jakub Galczyk
2012-04-26   gpEasy 2.3.3 - 'jsoncallback' Cross-Site Scripting 7 WEB Jakub Galczyk
2012-04-26   Concrete5 CMS 5.5.2.1 - Information Disclosure / SQL Injection / Cross-Site Scripting 16 WEB Jakub Galczyk
2012-04-24   Joomla! Component com_videogallery - Local File Inclusion / SQL Injection 8 WEB KedAns-Dz
2012-04-23   Joomla! Component CCNewsLetter 1.0.7 - 'id' SQL Injection 8 WEB E1nzte1N
2012-04-20   Waylu CMS - '/products_xx.php' SQL Injection / HTML Injection 8 WEB TheCyberNuxbie
2012-04-20   Anchor CMS 0.6-14-ga85d0a0 - 'id' Multiple HTML Injection Vulnerabilities 7 WEB Gjoko Krstic
2012-04-20   Pendulab ChatBlazer 8.5 - 'Username' Cross-Site Scripting 7 WEB sonyy
2012-04-18   ownCloud 3.0.0 - 'index.php?redirect_url' Arbitrary Site Redirect 8 WEB Tobias Glemser
2012-04-18   XOOPS 2.5.4 - '/tiny_mce/plugins/xoopsimagemanager/xoopsimagebrowser.php' Multiple Cross-Site Script 7 WEB High-Tech Bridge SA
2012-04-18   XOOPS 2.5.4 - '/modules/pm/pmlite.php?to_userid' Cross-Site Scripting 7 WEB High-Tech Bridge SA
2012-04-17   Acuity CMS 2.6.2 - 'Username' Cross-Site Scripting 9 WEB Aung Khant
2012-04-17   Joomla! Component JA T3 Framework - Directory Traversal 7 WEB indoushka
2012-04-17   TeamPass 2.1.5 - 'login' HTML Injection 8 WEB Marcos Garcia
2012-04-16   WordPress Plugin Yahoo Answer - Multiple Cross-Site Scripting Vulnerabilities 9 WEB Ryuzaki Lawlet
2012-04-15   Seditio CMS 165 - 'plug.php' SQL Injection 9 WEB AkaStep
2012-04-13   Munin 2.0~rc4-1 - Remote Command Injection 8 WEB Helmut Grohne
2012-04-16   Joomla! Plugin Beatz 1.1 - Multiple Cross-Site Scripting Vulnerabilities 7 WEB Aung Khant
2012-04-16   Bioly 1.3 - '/index.php' Cross-Site Scripting / SQL Injection 8 WEB T0xic
2015-05-21   WordPress Plugin WP Symposium 15.1 - '&show=' SQL Injection 8 WEB Hannes Trunde
2015-05-21   Forma LMS 1.3 - Multiple SQL Injections 7 WEB Filippo Roncari
2012-04-11   WordPress Plugin All-in-One Event Calendar 1.4 - 'agenda-widget.php' Multiple Cross-Site Scripting V 6 WEB High-Tech Bridge SA
2012-04-11   WordPress Plugin All-in-One Event Calendar 1.4 - 'save_successful.php?msg' Cross-Site Scripting 7 WEB High-Tech Bridge SA
2012-04-11   WordPress Plugin All-in-One Event Calendar 1.4 - 'box_publish_button.php?button_value' Cross-Site Sc 6 WEB High-Tech Bridge SA
2012-04-11   WordPress Plugin All-in-One Event Calendar 1.4 - 'agenda-widget-form.php?title' Cross-Site Scripting 6 WEB High-Tech Bridge SA
2015-05-21   WordPress Plugin WP Membership 1.2.3 - Multiple Vulnerabilities 7 WEB Panagiotis Vagenas
2012-04-11   BGS CMS 2.2.1 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities 8 WEB LiquidWorm
2012-04-10   Matterdaddy Market 1.1 - 'cat_name' Multiple SQL Injections 8 WEB Chokri B.A
2012-04-09   CitrusDB 2.4.1 - Local File Inclusion / SQL Injection 6 WEB wacky
2012-04-06   WordPress Plugin Uploadify Integration 0.9.6 - Multiple Cross-Site Scripting Vulnerabilities 10 WEB waraxe
2015-05-20   WordPress Plugin FeedWordPress 2015.0426 - SQL Injection 9 WEB Adrián M. F.
2012-04-05   WordPress Plugin TagGator - 'tagid' SQL Injection 6 WEB Am!r
2012-04-04   vBulletin 4.1.10 - 'announcementid' SQL Injection 8 WEB Am!r
2015-05-18   ManageEngine EventLog Analyzer 10.0 Build 10001 - Cross-Site Request Forgery 7 WEB Akash S. Chavan
2015-05-18   OYO File Manager 1.1 (iOS / Android) - Multiple Vulnerabilities 8 WEB Vulnerability-Lab
2015-05-18   Wireless Photo Transfer 3.0 iOS - Local File Inclusion 6 WEB Vulnerability-Lab
2015-05-18   Forma LMS 1.3 - Multiple PHP Object Injection Vulnerabilities 7 WEB Filippo Roncari
2015-05-18   ElasticSearch < 1.4.5 / < 1.5.2 - Directory Traversal 7 WEB pandujar
2015-05-18   Chronosite 5.12 - SQL Injection 7 WEB Wadeek
2012-04-04   osCMax 2.5 - '/admin/stats_monthly_sales.php?status' SQL Injection 7 WEB High-Tech Bridge SA
2012-04-04   osCMax 2.5 - '/admin/login.php?Username' SQL Injection 7 WEB High-Tech Bridge SA
2012-04-04   osCMax 2.5 - '/admin/new_attributes_include.php' Multiple Cross-Site Scripting Vulnerabilities 7 WEB High-Tech Bridge SA
2012-04-04   osCMax 2.5 - '/admin/geo_zones.php?zID' Cross-Site Scripting 8 WEB High-Tech Bridge SA
2012-04-04   osCMax 2.5 - '/admin/information_manager.php?information_id' Cross-Site Scripting 8 WEB High-Tech Bridge SA
2012-04-04   osCMax 2.5 - '/admin/stats_customers.php?sorted' Cross-Site Scripting 8 WEB High-Tech Bridge SA
2012-04-04   osCMax 2.5 - '/admin/stats_monthly_sales.php?status' Cross-Site Scripting 8 WEB High-Tech Bridge SA
2012-04-04   osCMax 2.5 - '/admin/stats_products_purchased.php' Multiple Cross-Site Scripting Vulnerabilities 8 WEB High-Tech Bridge SA
2012-04-04   osCMax 2.5 - '/admin/xsell.php?search' Cross-Site Scripting 8 WEB High-Tech Bridge SA
2012-04-04   osCMax 2.5 - '/admin/htaccess.php' Multiple Cross-Site Scripting Vulnerabilities 5 WEB High-Tech Bridge SA
2012-04-04   osCMax 2.5 - '/admin/login.php?Username' Cross-Site Scripting 8 WEB High-Tech Bridge SA
2012-04-01   FlatnuX CMS - Cross-Site Request Forgery (Add Admin) 9 WEB Vulnerability Laboratory
2012-04-01   FlatnuX CMS - Traversal Arbitrary File Access 9 WEB Vulnerability Laboratory
2012-04-02   JBMC Software DirectAdmin 1.403 - 'domain' Cross-Site Scripting 9 WEB Dawid Golak