Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2015-05-04   PhotoWebsite 3.1 iOS - Local File Inclusion 21 WEB Vulnerability-Lab
2012-03-05   Etano 1.20/1.22 - 'photo_view.php?return' Cross-Site Scripting 18 WEB Aung Khant
2012-03-05   Etano 1.20/1.22 - 'photo_search.php' Multiple Cross-Site Scripting Vulnerabilities 19 WEB Aung Khant
2012-03-05   Etano 1.20/1.22 - 'search.php' Multiple Cross-Site Scripting Vulnerabilities 23 WEB Aung Khant
2012-03-04   LastGuru ASP Guestbook - 'View.asp' SQL Injection 20 WEB demonalex
2012-03-02   starCMS - 'q' URI Cross-Site Scripting 22 WEB Am!r
2012-02-28   Fork CMS 3.x - '/backend/modules/error/actions/index.php?parse()' Multiple Error Display Cross-Site 24 WEB anonymous
2012-02-28   Fork CMS 3.x - '/private/en/locale/index?name' Cross-Site Scripting 27 WEB anonymous
2012-02-29   Traidnt Topics Viewer 2.0 - 'main.php' Cross-Site Request Forgery 24 WEB Green Hornet
2012-02-29   Dotclear 2.4.1.2 - '/admin/plugin.php?page' Cross-Site Scripting 23 WEB High-Tech Bridge SA
2012-02-29   Dotclear 2.4.1.2 - '/admin/comments.php' Multiple Cross-Site Scripting Vulnerabilities 23 WEB High-Tech Bridge SA
2012-02-29   Dotclear 2.4.1.2 - '/admin/blogs.php?nb' Cross-Site Scripting 23 WEB High-Tech Bridge SA
2012-02-29   Dotclear 2.4.1.2 - '/admin/auth.php?login_data' Cross-Site Scripting 25 WEB High-Tech Bridge SA
2012-02-27   OSQA's CMS - Multiple HTML Injection Vulnerabilities 23 WEB Ucha Gobejishvili
2012-02-27   Bontq - 'user/' URI Cross-Site Scripting 25 WEB sonyy
2012-02-26   Webglimpse 2.x - Multiple Cross-Site Scripting Vulnerabilities 23 WEB MustLive
2012-02-26   MyJobList 0.1.3 - 'eid' SQL Injection 22 WEB Red Security TEAM
2012-02-23   Mobile Mp3 Search Script 2.0 - 'dl.php' HTTP Response Splitting 25 WEB Corrado Liotta
2012-02-22   Oxwall 1.1.1 - 'plugin' Cross-Site Scripting 18 WEB Ariko-Security
2012-02-22   Chyrp 2.1.2 - '/includes/error.php?body' Cross-Site Scripting 23 WEB High-Tech Bridge SA
2012-02-22   Chyrp 2.1.1 - 'ajax.php' HTML Injection 20 WEB High-Tech Bridge SA
2012-02-22   Dolibarr ERP/CRM 3.2 Alpha - Multiple Directory Traversal Vulnerabilities 24 WEB Benjamin Kunz Mejri
2012-02-22   ContentLion Alpha 1.3 - 'login.php' Cross-Site Scripting 21 WEB Stefan Schurtz
2012-02-21   CPG Dragonfly CMS 9.3.3.0 - Multiple Multiple Cross-Site Scripting Vulnerabilities 25 WEB Ariko-Security
2012-02-21   Xavi 7968 ADSL Router - '/webconfig/lan/lan_config.html/local_lan_config?host_name_txtbox' Cross-Sit 33 WEB Busindre
2012-02-20   Joomla! Component Machine - Multiple SQL Injections 21 WEB the_cyber_nuxbie
2015-04-29   OS Solution OSProperty 2.8.0 - SQL Injection 25 WEB Brandon Perry
2015-04-29   Wing FTP Server Admin 4.4.5 - Multiple Vulnerabilities 20 WEB hyp3rlinx
2015-04-29   WordPress Plugin TheCartPress 1.3.9 - Multiple Vulnerabilities 19 WEB High-Tech Bridge SA
2012-02-18   Joomla! Component com_xvs - 'Controller' Local File Inclusion 25 WEB KedAns-Dz
2012-02-21   Dolphin 7.0.x - 'explanation.php?explain' Cross-Site Scripting 25 WEB Aung Khant
2012-02-21   Dolphin 7.0.x - 'viewFriends.php' Multiple Cross-Site Scripting Vulnerabilities 20 WEB Aung Khant
2012-02-20   TestLink - Multiple SQL Injections 18 WEB Juan M. Natal
2012-02-20   F*EX 20100208/20111129-2 - Multiple Cross-Site Scripting Vulnerabilities 21 WEB muuratsalo
2012-02-20   VOXTRONIC Voxlog Professional 3.7.x - 'userlogdetail.php?idclient' SQL Injection 21 WEB J. Greil
2012-02-20   VOXTRONIC Voxlog Professional 3.7.x - 'get.php?v' Arbitrary File Access 16 WEB J. Greil
2012-02-18   Tiki Wiki CMS Groupware - 'url' Open Redirection 19 WEB sonyy
2015-04-27   WordPress Core 4.2 - Persistent Cross-Site Scripting 16 WEB klikki
2015-04-27   OTRS < 3.1.x / < 3.2.x / < 3.3.x - Persistent Cross-Site Scripting 18 WEB Adam Ziaja
2012-02-18   Joomla! Component com_xcomp - Local File Inclusion 16 WEB KedAns-Dz
2012-02-18   Joomla! Component com_x-shop - 'idd' SQL Injection 16 WEB KedAns-Dz
2012-02-16   Impulsio CMS - 'id' SQL Injection 15 WEB sonyy
2012-02-17   JaWiki - 'versionNo' Cross-Site Scripting 19 WEB sonyy
2015-04-23   WordPress Plugin Ultimate Product Catalogue - SQL Injection (2) 19 WEB Felipe Molina
2015-04-23   WordPress Plugin Ultimate Product Catalogue - SQL Injection (1) 20 WEB Felipe Molina
2015-04-23   WebUI 1.5b6 - Remote Code Execution 20 WEB TUNISIAN CYBER
2015-04-22   Wolf CMS 0.8.2 - Arbitrary File Upload 22 WEB CWH Underground
2015-04-22   Open-Letters - Remote PHP Code Injection 19 WEB TUNISIAN CYBER
2015-04-21   BlueDragon CFChart Servlet 7.1.1.17759 - Arbitrary File Retrieval/Deletion 22 WEB Portcullis
2015-04-21   GoAutoDial CE 3.3-1406088000 - Authentication Bypass / Arbitrary File Upload / Command Injection 20 WEB Chris McCurley
2015-04-21   WordPress Plugin Community Events 1.3.5 - SQL Injection 18 WEB Hannes Trunde
2015-04-21   MediaSuite CMS - Artibary File Disclosure 18 WEB KnocKout inj3ct0r
2015-04-21   WordPress Plugin Tune Library 1.5.4 - SQL Injection 17 WEB Hannes Trunde
2015-04-21   WordPress Plugin MiwoFTP 1.0.5 - Arbitrary File Download (2) 16 WEB dadou dz
2015-04-21   WordPress Plugin NEX-Forms < 3.0 - SQL Injection 17 WEB Claudio Viviani
2015-04-21   Photo Manager Pro 4.4.0 iOS - Code Execution 18 WEB Vulnerability-Lab
2015-04-21   Mobile Drive HD 1.8 - Local File Inclusion 14 WEB Vulnerability-Lab
2015-04-21   Photo Manager Pro 4.4.0 iOS - Local File Inclusion 18 WEB Vulnerability-Lab
2015-04-21   Wifi Drive Pro 1.2 iOS - Local File Inclusion 16 WEB Vulnerability-Lab
2015-04-21   SevenIT SevDesk 3.10 - Multiple Web Vulnerabilities 17 WEB Vulnerability-Lab
2012-02-17   ButorWiki 3.0 - 'service' Cross-Site Scripting 23 WEB sonyy
2012-02-17   Pandora FMS 4.0.1 - 'sec2' Local File Inclusion 17 WEB Ucha Gobejishvili
2012-02-16   CMS Faethon 1.3.4 - 'articles.php' Multiple SQL Injections 16 WEB tempe_mendoan
2012-02-16   Tube Ace - 'q' Cross-Site Scripting 21 WEB Daniel Godoy
2012-02-15   LEPTON 1.1.3 - Cross-Site Scripting 20 WEB High-Tech Bridge SA
2012-02-15   11in1 CMS 1.2.1 - Cross-Site Request Forgery (Admin Password) 18 WEB High-Tech Bridge SA
2012-02-15   11in1 CMS 1.2.1 - '/admin/index.php?class' Traversal Local File Inclusion 22 WEB High-Tech Bridge SA
2012-02-15   11in1 CMS 1.2.1 - 'index.php?class' Traversal Local File Inclusion 20 WEB High-Tech Bridge SA
2015-04-16   WordPress Plugin Ajax Store Locator 1.2 - SQL Injection 18 WEB Claudio Viviani
2015-04-15   WordPress Plugin MiwoFTP 1.0.5 - Arbitrary File Download (1) 20 WEB Necmettin COSKUN
2012-02-13   EditWrxLite CMS - 'wrx.cgi' Remote Command Execution 18 WEB chippy1337
2012-02-13   STHS v2 Web Portal - 'team.php?team' SQL Injection 21 WEB Liyan Oz
2012-02-13   STHS v2 Web Portal - 'prospect.php?team' SQL Injection 22 WEB Liyan Oz
2012-02-13   STHS v2 Web Portal - 'prospects.php?team' SQL Injection 23 WEB Liyan Oz
2012-02-10   ProWiki - 'id' Cross-Site Scripting 18 WEB sonyy
2012-02-13   Powie pFile 1.02 - '/pfile/file.php?id' SQL Injection 18 WEB indoushka
2012-02-13   Powie pFile 1.02 - '/pfile/kommentar.php?filecat' Cross-Site Scripting 20 WEB indoushka
2012-02-13   SMW+ 1.5.6 - 'target' HTML Injection 17 WEB sonyy
2015-04-14   WordPress Plugin MiwoFTP 1.0.5 - Cross-Site Request Forgery / Arbitrary File Creation / Remote Code 18 WEB LiquidWorm
2015-04-14   WordPress Plugin MiwoFTP 1.0.5 - Multiple Cross-Site Request Forgery / Cross-Site Scripting Vulnerab 17 WEB LiquidWorm
2015-04-14   WordPress Plugin MiwoFTP 1.0.5 - Cross-Site Request Forgery / Arbitrary File Deletion 15 WEB LiquidWorm
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_ag_main.php' Crafted Arbitrary File Upload / 22 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - '/admin/index.php?base_path' Remote File Inclusion 16 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - '/admin/base_useradmin.php?base_path' Remote File 19 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'index.php?base_path' Remote File Inclusion 18 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_user.php?base_path' Remote File Inclusion 22 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_stat_uaddr.php?base_path' Remote File Inclus 25 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_stat_time.php?base_path' Remote File Inclusi 17 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_stat_sensor.php?base_path' Remote File Inclu 16 WEB indoushka
2015-04-14   WordPress Plugin Video Gallery 2.8 - SQL Injection 18 WEB Claudio Viviani
2015-04-13   WordPress Plugin N-Media Website Contact Form with File Upload 1.3.4 - Arbitrary File Upload (1) 31 WEB Claudio Viviani
2015-04-13   Traidnt Up 3.0 - SQL Injection 21 WEB Ali Trixx
2015-04-13   WordPress Plugin Duplicator 0.5.14 - SQL Injection / Cross-Site Request Forgery 18 WEB Claudio Viviani
2015-04-13   WordPress Plugin WP Mobile Edition 2.7 - Remote File Disclosure 24 WEB Khwanchai Kaewyos
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_stat_ports.php?base_path' Remote File Inclus 20 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_stat_iplink.php?base_path' Remote File Inclu 20 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_stat_ipaddr.php?base_path' Remote File Inclu 16 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_stat_common.php?base_path' Remote File Inclu 19 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_stat_class.php?base_path' Remote File Inclus 17 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_stat_alerts.php?base_path' Remote File Inclu 20 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_qry_common.php?base_path' Remote File Inclus 25 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_qry_alert.php?base_path' Remote File Inclusi 17 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_ag_main.php?base_path' Remote File Inclusion 17 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - '/setup/setup2.php?ado_inc_PHP' Remote File Inclus 19 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - '/includes/base_state_common.inc.php?GLOBALS[user_ 21 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - '/setup/base_conf_contents.php' Multiple Remote Fi 20 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - '/includes/base_state_query.inc.php?base_path' Rem 26 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - '/includes/base_state_criteria.inc.php?base_path' 19 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - '/includes/base_output_query.inc.php?base_path' Re 16 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - '/includes/base_output_html.inc.php?base_path' Rem 19 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - '/includes/base_include.inc.php?base_path' Remote 20 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - '/includes/base_db.inc.php?base_path' Remote File 18 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - '/includes/base_cache.inc.php?base_path' Remote Fi 20 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - '/includes/base_action.inc.php?base_path' Remote F 25 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - '/help/base_setup_help.php?base_path' Remote File 18 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_payload.php?base_path' Remote File Inclusion 14 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_maintenance.php?base_path' Remote File Inclu 17 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_main.php?base_path' Remote File Inclusion 16 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_logout.php?base_path' Remote File Inclusion 19 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_local_rules.php?base_path' Remote File Inclu 17 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_graph_main.php?base_path' Remote File Inclus 20 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_graph_form.php?base_path' Remote File Inclus 19 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_graph_display.php?base_path' Remote File Inc 14 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_graph_common.php?base_path' Remote File Incl 17 WEB indoushka
2012-02-11   Basic Analysis and Security Engine (BASE) 1.4.5 - 'base_db_setup.php?base_path' Remote File Inclusio 16 WEB indoushka