|
2012-02-20
|
|
F*EX 20100208/20111129-2 - Multiple Cross-Site Scripting Vulnerabilities
|
8 |
WEB
|
muuratsalo
|
|
2012-02-20
|
|
VOXTRONIC Voxlog Professional 3.7.x - 'userlogdetail.php?idclient' SQL Injection
|
7 |
WEB
|
J. Greil
|
|
2012-02-20
|
|
VOXTRONIC Voxlog Professional 3.7.x - 'get.php?v' Arbitrary File Access
|
7 |
WEB
|
J. Greil
|
|
2012-02-18
|
|
Tiki Wiki CMS Groupware - 'url' Open Redirection
|
7 |
WEB
|
sonyy
|
|
2015-04-27
|
|
WordPress Core 4.2 - Persistent Cross-Site Scripting
|
7 |
WEB
|
klikki
|
|
2015-04-27
|
|
OTRS < 3.1.x / < 3.2.x / < 3.3.x - Persistent Cross-Site Scripting
|
7 |
WEB
|
Adam Ziaja
|
|
2012-02-18
|
|
Joomla! Component com_xcomp - Local File Inclusion
|
6 |
WEB
|
KedAns-Dz
|
|
2012-02-18
|
|
Joomla! Component com_x-shop - 'idd' SQL Injection
|
6 |
WEB
|
KedAns-Dz
|
|
2012-02-16
|
|
Impulsio CMS - 'id' SQL Injection
|
6 |
WEB
|
sonyy
|
|
2012-02-17
|
|
JaWiki - 'versionNo' Cross-Site Scripting
|
8 |
WEB
|
sonyy
|
|
2015-04-23
|
|
WordPress Plugin Ultimate Product Catalogue - SQL Injection (2)
|
7 |
WEB
|
Felipe Molina
|
|
2015-04-23
|
|
WordPress Plugin Ultimate Product Catalogue - SQL Injection (1)
|
8 |
WEB
|
Felipe Molina
|
|
2015-04-23
|
|
WebUI 1.5b6 - Remote Code Execution
|
8 |
WEB
|
TUNISIAN CYBER
|
|
2015-04-22
|
|
Wolf CMS 0.8.2 - Arbitrary File Upload
|
8 |
WEB
|
CWH Underground
|
|
2015-04-22
|
|
Open-Letters - Remote PHP Code Injection
|
8 |
WEB
|
TUNISIAN CYBER
|
|
2015-04-21
|
|
BlueDragon CFChart Servlet 7.1.1.17759 - Arbitrary File Retrieval/Deletion
|
10 |
WEB
|
Portcullis
|
|
2015-04-21
|
|
GoAutoDial CE 3.3-1406088000 - Authentication Bypass / Arbitrary File Upload / Command Injection
|
10 |
WEB
|
Chris McCurley
|
|
2015-04-21
|
|
WordPress Plugin Community Events 1.3.5 - SQL Injection
|
6 |
WEB
|
Hannes Trunde
|
|
2015-04-21
|
|
MediaSuite CMS - Artibary File Disclosure
|
8 |
WEB
|
KnocKout inj3ct0r
|
|
2015-04-21
|
|
WordPress Plugin Tune Library 1.5.4 - SQL Injection
|
8 |
WEB
|
Hannes Trunde
|
|
2015-04-21
|
|
WordPress Plugin MiwoFTP 1.0.5 - Arbitrary File Download (2)
|
6 |
WEB
|
dadou dz
|
|
2015-04-21
|
|
WordPress Plugin NEX-Forms < 3.0 - SQL Injection
|
7 |
WEB
|
Claudio Viviani
|
|
2015-04-21
|
|
Photo Manager Pro 4.4.0 iOS - Code Execution
|
8 |
WEB
|
Vulnerability-Lab
|
|
2015-04-21
|
|
Mobile Drive HD 1.8 - Local File Inclusion
|
7 |
WEB
|
Vulnerability-Lab
|
|
2015-04-21
|
|
Photo Manager Pro 4.4.0 iOS - Local File Inclusion
|
7 |
WEB
|
Vulnerability-Lab
|
|
2015-04-21
|
|
Wifi Drive Pro 1.2 iOS - Local File Inclusion
|
5 |
WEB
|
Vulnerability-Lab
|
|
2015-04-21
|
|
SevenIT SevDesk 3.10 - Multiple Web Vulnerabilities
|
6 |
WEB
|
Vulnerability-Lab
|
|
2012-02-17
|
|
ButorWiki 3.0 - 'service' Cross-Site Scripting
|
8 |
WEB
|
sonyy
|
|
2012-02-17
|
|
Pandora FMS 4.0.1 - 'sec2' Local File Inclusion
|
6 |
WEB
|
Ucha Gobejishvili
|
|
2012-02-16
|
|
CMS Faethon 1.3.4 - 'articles.php' Multiple SQL Injections
|
6 |
WEB
|
tempe_mendoan
|
|
2012-02-16
|
|
Tube Ace - 'q' Cross-Site Scripting
|
7 |
WEB
|
Daniel Godoy
|
|
2012-02-15
|
|
LEPTON 1.1.3 - Cross-Site Scripting
|
8 |
WEB
|
High-Tech Bridge SA
|
|
2012-02-15
|
|
11in1 CMS 1.2.1 - Cross-Site Request Forgery (Admin Password)
|
7 |
WEB
|
High-Tech Bridge SA
|
|
2012-02-15
|
|
11in1 CMS 1.2.1 - '/admin/index.php?class' Traversal Local File Inclusion
|
7 |
WEB
|
High-Tech Bridge SA
|
|
2012-02-15
|
|
11in1 CMS 1.2.1 - 'index.php?class' Traversal Local File Inclusion
|
7 |
WEB
|
High-Tech Bridge SA
|
|
2015-04-16
|
|
WordPress Plugin Ajax Store Locator 1.2 - SQL Injection
|
8 |
WEB
|
Claudio Viviani
|
|
2015-04-15
|
|
WordPress Plugin MiwoFTP 1.0.5 - Arbitrary File Download (1)
|
7 |
WEB
|
Necmettin COSKUN
|
|
2012-02-13
|
|
EditWrxLite CMS - 'wrx.cgi' Remote Command Execution
|
6 |
WEB
|
chippy1337
|
|
2012-02-13
|
|
STHS v2 Web Portal - 'team.php?team' SQL Injection
|
6 |
WEB
|
Liyan Oz
|
|
2012-02-13
|
|
STHS v2 Web Portal - 'prospect.php?team' SQL Injection
|
6 |
WEB
|
Liyan Oz
|
|
2012-02-13
|
|
STHS v2 Web Portal - 'prospects.php?team' SQL Injection
|
6 |
WEB
|
Liyan Oz
|
|
2012-02-10
|
|
ProWiki - 'id' Cross-Site Scripting
|
6 |
WEB
|
sonyy
|
|
2012-02-13
|
|
Powie pFile 1.02 - '/pfile/file.php?id' SQL Injection
|
8 |
WEB
|
indoushka
|
|
2012-02-13
|
|
Powie pFile 1.02 - '/pfile/kommentar.php?filecat' Cross-Site Scripting
|
6 |
WEB
|
indoushka
|
|
2012-02-13
|
|
SMW+ 1.5.6 - 'target' HTML Injection
|
8 |
WEB
|
sonyy
|
|
2015-04-14
|
|
WordPress Plugin MiwoFTP 1.0.5 - Cross-Site Request Forgery / Arbitrary File Creation / Remote Code
|
6 |
WEB
|
LiquidWorm
|
|
2015-04-14
|
|
WordPress Plugin MiwoFTP 1.0.5 - Multiple Cross-Site Request Forgery / Cross-Site Scripting Vulnerab
|
6 |
WEB
|
LiquidWorm
|
|
2015-04-14
|
|
WordPress Plugin MiwoFTP 1.0.5 - Cross-Site Request Forgery / Arbitrary File Deletion
|
7 |
WEB
|
LiquidWorm
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_ag_main.php' Crafted Arbitrary File Upload /
|
7 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - '/admin/index.php?base_path' Remote File Inclusion
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - '/admin/base_useradmin.php?base_path' Remote File
|
7 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'index.php?base_path' Remote File Inclusion
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_user.php?base_path' Remote File Inclusion
|
7 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_stat_uaddr.php?base_path' Remote File Inclus
|
7 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_stat_time.php?base_path' Remote File Inclusi
|
7 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_stat_sensor.php?base_path' Remote File Inclu
|
7 |
WEB
|
indoushka
|
|
2015-04-14
|
|
WordPress Plugin Video Gallery 2.8 - SQL Injection
|
8 |
WEB
|
Claudio Viviani
|
|
2015-04-13
|
|
WordPress Plugin N-Media Website Contact Form with File Upload 1.3.4 - Arbitrary File Upload (1)
|
7 |
WEB
|
Claudio Viviani
|
|
2015-04-13
|
|
Traidnt Up 3.0 - SQL Injection
|
7 |
WEB
|
Ali Trixx
|
|
2015-04-13
|
|
WordPress Plugin Duplicator 0.5.14 - SQL Injection / Cross-Site Request Forgery
|
7 |
WEB
|
Claudio Viviani
|
|
2015-04-13
|
|
WordPress Plugin WP Mobile Edition 2.7 - Remote File Disclosure
|
7 |
WEB
|
Khwanchai Kaewyos
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_stat_ports.php?base_path' Remote File Inclus
|
7 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_stat_iplink.php?base_path' Remote File Inclu
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_stat_ipaddr.php?base_path' Remote File Inclu
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_stat_common.php?base_path' Remote File Inclu
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_stat_class.php?base_path' Remote File Inclus
|
5 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_stat_alerts.php?base_path' Remote File Inclu
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_qry_common.php?base_path' Remote File Inclus
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_qry_alert.php?base_path' Remote File Inclusi
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_ag_main.php?base_path' Remote File Inclusion
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - '/setup/setup2.php?ado_inc_PHP' Remote File Inclus
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - '/includes/base_state_common.inc.php?GLOBALS[user_
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - '/setup/base_conf_contents.php' Multiple Remote Fi
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - '/includes/base_state_query.inc.php?base_path' Rem
|
5 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - '/includes/base_state_criteria.inc.php?base_path'
|
5 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - '/includes/base_output_query.inc.php?base_path' Re
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - '/includes/base_output_html.inc.php?base_path' Rem
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - '/includes/base_include.inc.php?base_path' Remote
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - '/includes/base_db.inc.php?base_path' Remote File
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - '/includes/base_cache.inc.php?base_path' Remote Fi
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - '/includes/base_action.inc.php?base_path' Remote F
|
5 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - '/help/base_setup_help.php?base_path' Remote File
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_payload.php?base_path' Remote File Inclusion
|
5 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_maintenance.php?base_path' Remote File Inclu
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_main.php?base_path' Remote File Inclusion
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_logout.php?base_path' Remote File Inclusion
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_local_rules.php?base_path' Remote File Inclu
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_graph_main.php?base_path' Remote File Inclus
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_graph_form.php?base_path' Remote File Inclus
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_graph_display.php?base_path' Remote File Inc
|
6 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_graph_common.php?base_path' Remote File Incl
|
7 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_db_setup.php?base_path' Remote File Inclusio
|
7 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Nova CMS - '/includes/function/usertpl.php?conf[blockfile]' Remote File Inclusion
|
9 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Nova CMS - '/includes/function/gets.php?Filename' Remote File Inclusion
|
9 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Nova CMS - '/optimizer/index.php?fileType' Remote File Inclusion
|
8 |
WEB
|
indoushka
|
|
2012-02-11
|
|
Nova CMS - '/administrator/modules/moduleslist.php?id' Remote File Inclusion
|
9 |
WEB
|
indoushka
|
|
2012-02-13
|
|
Zimbra - 'view' Cross-Site Scripting
|
8 |
WEB
|
sonyy
|
|
2012-02-12
|
|
eFront Community++ 3.6.10 - SQL Injection / Multiple HTML Injection Vulnerabilities
|
9 |
WEB
|
Benjamin Kunz Mejri
|
|
2012-02-10
|
|
RabbitWiki - 'title' Cross-Site Scripting
|
9 |
WEB
|
sonyy
|
|
2015-04-09
|
|
WordPress Plugin Windows Desktop and iPhone Photo Uploader - Arbitrary File Upload
|
8 |
WEB
|
Manish Tanwar
|
|
2000-12-19
|
|
BOA Web Server 0.94.8.2 - Arbitrary File Access
|
9 |
WEB
|
llmora
|
|
2012-02-10
|
|
Zen Cart 1.3.9h - '/path_to_admin/product.php' Cross-Site Request Forgery
|
9 |
WEB
|
DisK0nn3cT
|
|
2012-02-10
|
|
CubeCart 3.0.20 - 'switch.php?r' Arbitrary Site Redirect
|
8 |
WEB
|
Aung Khant
|
|
2012-02-10
|
|
CubeCart 3.0.20 - '/admin/login.php?goto' Arbitrary Site Redirect
|
10 |
WEB
|
Aung Khant
|
|
2012-02-10
|
|
CubeCart 3.0.20 - Multiple Script 'redir' Arbitrary Site Redirects
|
7 |
WEB
|
Aung Khant
|
|
2012-02-10
|
|
LxCenter Kloxo 6.1.10 - Multiple HTML Injection Vulnerabilities
|
10 |
WEB
|
anonymous
|
|
2012-02-10
|
|
Dolibarr ERP/CRM 3.x - '/adherents/fiche.php' SQL Injection
|
8 |
WEB
|
Benjamin Kunz Mejri
|
|
2015-04-08
|
|
Novell ZENworks Configuration Management 11.3.1 - Remote Code Execution
|
6 |
WEB
|
Pedro Ribeiro
|
|
2015-04-08
|
|
WordPress Plugin Traffic Analyzer 3.4.2 - Blind SQL Injection
|
7 |
WEB
|
Dan King
|
|
2015-04-08
|
|
Balero CMS 0.7.2 - Multiple JS/HTML Injection Vulnerabilities
|
8 |
WEB
|
LiquidWorm
|
|
2015-04-08
|
|
Balero CMS 0.7.2 - Multiple Blind SQL Injections
|
8 |
WEB
|
LiquidWorm
|
|
2015-04-08
|
|
WordPress Plugin Shareaholic 7.6.0.3 - Cross-Site Scripting
|
7 |
WEB
|
Kacper Szurek
|
|
2015-04-08
|
|
WordPress Plugin All In One WP Security & Firewall 3.9.0 - SQL Injection
|
8 |
WEB
|
Claudio Viviani
|
|
2012-02-07
|
|
eFront 3.6.10 - 'administrator.php' Cross-Site Scripting
|
7 |
WEB
|
Chokri B.A
|
|
2012-02-07
|
|
ManageEngine ADManager Plus 5.2 Build 5210 - 'domainName' Cross-Site Scripting
|
7 |
WEB
|
LiquidWorm
|
|
2012-02-07
|
|
ManageEngine ADManager Plus 5.2 Build 5210 - 'Operation' Cross-Site Scripting
|
6 |
WEB
|
LiquidWorm
|
|
2012-02-07
|
|
Simple Groupware 0.742 - 'export' Cross-Site Scripting
|
7 |
WEB
|
Infoserve Security Team
|
|
2012-02-06
|
|
Vespa 0.8.6 - 'getid3.php' Local File Inclusion
|
7 |
WEB
|
T0x!c
|
|
2012-02-03
|
|
PHP-Fusion 7.2.4 - 'weblink_id' SQL Injection
|
8 |
WEB
|
Am!r
|
|
2012-02-03
|
|
project-open 3.4.x - 'account-closed.tcl' Cross-Site Scripting
|
8 |
WEB
|
Michail Poultsakis
|
|
2012-02-02
|
|
Joomla! Component Currency Converter 1.0.0 - 'from' Cross-Site Scripting
|
8 |
WEB
|
BHG Security Center
|
|
2012-02-02
|
|
iknSupport 'search' Module - Cross-Site Scripting
|
8 |
WEB
|
Red Security TEAM
|
|
2012-02-02
|
|
Joomla! Component com_bnf - 'seccion_id' SQL Injection
|
6 |
WEB
|
Daniel Godoy
|
|
2012-02-02
|
|
GForge 5.7.1 - Multiple Cross-Site Scripting Vulnerabilities
|
7 |
WEB
|
sonyy
|
|
2012-02-01
|
|
phpLDAPadmin 1.2.0.5-2 - 'server_id' Cross-Site Scripting
|
7 |
WEB
|
andsarmiento
|