Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2012-01-09   Marinet CMS - 'room2.php?roomid' SQL Injection 14 WEB H4ckCity Security Team
2012-01-09   Clipbucket 2.6 - 'channels.php?time' SQL Injection 20 WEB YaDoY666
2012-01-09   Clipbucket 2.6 - 'videos.php?time' SQL Injection 17 WEB YaDoY666
2012-01-09   Clipbucket 2.6 - 'view_item.php?type' Cross-Site Scripting 22 WEB YaDoY666
2012-01-09   Clipbucket 2.6 - 'view_collection.php?type' Cross-Site Scripting 26 WEB YaDoY666
2012-01-09   Clipbucket 2.6 - 'videos.php?cat' Cross-Site Scripting 21 WEB YaDoY666
2012-01-09   Clipbucket 2.6 - 'search_result.php?query' Cross-Site Scripting 16 WEB YaDoY666
2012-01-09   Clipbucket 2.6 - 'groups.php?cat' Cross-Site Scripting 16 WEB YaDoY666
2012-01-09   Clipbucket 2.6 - 'collections.php?cat' Cross-Site Scripting 17 WEB YaDoY666
2012-01-09   Clipbucket 2.6 - 'channels.php?cat' Cross-Site Scripting 19 WEB YaDoY666
2012-01-07   Atar2b CMS 4.0.1 - 'pageE.php?id' SQL Injection 15 WEB BHG Security Center
2012-01-07   Atar2b CMS 4.0.1 - 'pageH.php?id' SQL Injection 19 WEB BHG Security Center
2012-01-07   Atar2b CMS 4.0.1 - 'gallery_e.php?id' SQL Injection 17 WEB BHG Security Center
2015-03-27   Berta CMS - Arbitrary File Upload 20 WEB Simon Waters
2012-01-07   DIGIT CMS 1.0.7 - Cross-Site Scripting / SQL Injection 22 WEB BHG Security Center
2012-01-06   eFront 3.6.10 - 'download' Directory Traversal 17 WEB Chokri B.A
2012-01-05   SQLiteManager 1.2.4 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 16 WEB Stefan Schurtz
2012-01-05   SQLiteManager 1.2.4 - 'main.php?dbsel' Cross-Site Scripting 19 WEB Stefan Schurtz
2012-01-05   VertrigoServ 2.25 - 'extensions.php' Script Cross-Site Scripting 16 WEB Stefan Schurtz
2015-03-26   pfSense 2.2 - Multiple Vulnerabilities 19 WEB High-Tech Bridge SA
2012-01-04   StatIt 4 - 'statistik.php' Multiple Cross-Site Scripting Vulnerabilities 18 WEB sonyy
2012-01-05   Yaws-Wiki 1.88 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities 17 WEB SiteWatch
2012-01-04   UBBCentral UBB.Threads 7.5.6 - 'Username' Cross-Site Scripting 18 WEB sonyy
2011-12-29   Pligg CMS 1.1.4 - 'SERVER[php_self]' Cross-Site Scripting 14 WEB SiteWatch
2011-12-29   Pligg CMS 1.1.2 - 'status' SQL Injection 16 WEB SiteWatch
2012-01-04   Limny 3.0.1 - 'login.php' Script Cross-Site Scripting 18 WEB Gjoko Krstic
2012-01-04   Orchard 1.3.9 - 'ReturnUrl' Open Redirection 14 WEB Mesut Timur
2012-01-04   GraphicsClone Script - 'term' Cross-Site Scripting 20 WEB Mr.PaPaRoSSe
2015-03-25   WordPress Plugin Marketplace 2.4.0 - Remote Code Execution (Add Admin) 20 WEB Claudio Viviani
2012-01-04   TextPattern 4.4.1 - 'ddb' Cross-Site Scripting 14 WEB Jonathan Claudius
2012-01-03   WordPress Plugin WHOIS 1.4.2 3 - 'domain' Cross-Site Scripting 18 WEB Atmon3r
2012-01-03   WordPress Plugin Comment Rating 2.9.20 - 'path' Cross-Site Scripting 15 WEB The Evil Thinker
2012-01-03   Tienda Virtual - 'art_detalle.php' SQL Injection 18 WEB Arturo Zamora
2012-01-02   FuseTalk Forums 3.2 - 'windowed' Cross-Site Scripting 15 WEB sonyy
2011-01-01   PHPB2B 4.1 - 'q' Cross-Site Scripting 19 WEB H4ckCity Security Team
2012-01-01   WordPress Plugin WP Live.php 1.2.1 - 's' Cross-Site Scripting 16 WEB H4ckCity Security Team
2012-01-01   Siena CMS 1.242 - 'err' Cross-Site Scripting 16 WEB Net.Edit0r
2011-12-31   WordPress Plugin TheCartPress 1.6 - 'OptionsPostsList.php' Cross-Site Scripting 15 WEB 6Scan
2015-03-24   WordPress Plugin InBoundio Marketing 1.0 - Arbitrary File Upload 16 WEB KedAns-Dz
2011-12-21   epesi BIM 1.2 rev 8154 - Multiple Cross-Site Scripting Vulnerabilities 19 WEB High-Tech Bridge SA
2011-12-20   Cyberoam UTM 10 - 'tableid' SQL Injection 16 WEB Benjamin Kunz Mejri
2011-12-20   Joomla! Component com_caproductprices - 'id' SQL Injection 14 WEB CoBRa_21
2011-12-20   PHPShop CMS 3.4 - Multiple Cross-Site Scripting / SQL Injections 18 WEB High-Tech Bridge SA
2011-12-20   Tiki Wiki CMS Groupware 8.1 - 'show_errors' HTML Injection 17 WEB Stefan Schurtz
2011-12-20   Joomla! Component com_tsonymf - 'idofitem' SQL Injection 14 WEB CoBRa_21
2011-12-19   PHP Booking Calendar 10e - 'page_info_message' Cross-Site Scripting 20 WEB G13
2015-03-22   WordPress Plugin Marketplace 2.4.0 - Arbitrary File Download 19 WEB Kacper Szurek
2015-03-22   Joomla! Component Spider FAQ - SQL Injection 16 WEB Manish Tanwar
2015-03-21   Telescope 0.9.2 - Markdown Persistent Cross-Site Scripting 18 WEB shubs
2011-12-18   Video Community Portal - 'userID' SQL Injection 19 WEB Lazmania61
2011-12-17   Social Network Community 2 - 'userID' SQL Injection 18 WEB Lazmania61
2011-12-17   Flirt-Projekt 4.8 - 'rub' SQL Injection 18 WEB Lazmania61
2011-12-15   Websense 7.6 Products - 'favorites.exe' Authentication Bypass 15 WEB Ben Williams
2011-12-15   Websense 7.6 Triton - 'ws_irpt.exe' Remote Command Execution 16 WEB Ben Williams
2011-12-15   Websense 7.6 - Triton Report Management Interface Cross-Site Scripting 16 WEB Ben Williams
2011-12-15   Owl Intranet Engine 1.00 - 'userid' Authentication Bypass 19 WEB RedTeam Pentesting GmbH
2011-12-14   BrowserCRM 5.100.1 - 'login[]' Cross-Site Scripting 16 WEB High-Tech Bridge SA
2011-12-14   BrowserCRM 5.100.1 - 'clients.php' Cross-Site Scripting 21 WEB High-Tech Bridge SA
2011-12-14   BrowserCRM 5.100.1 - 'framed' Cross-Site Scripting 17 WEB High-Tech Bridge SA
2011-12-14   BrowserCRM 5.100.1 - URI Cross-Site Scripting 23 WEB High-Tech Bridge SA
2011-12-14   BrowserCRM 5.100.1 - 'contact_id' SQL Injection 23 WEB High-Tech Bridge SA
2011-12-14   BrowserCRM 5.100.1 - 'parent_id' SQL Injection 18 WEB High-Tech Bridge SA
2011-12-14   Pulse Pro 1.7.2 - Multiple Cross-Site Scripting Vulnerabilities 19 WEB Avram Marius
2011-12-16   Fork CMS 3.1.5 - Multiple Cross-Site Scripting Vulnerabilities 17 WEB Avram Marius
2011-12-31   WordPress Plugin The Welcomizer 1.3.9.4 - 'twiz-index.php' Cross-Site Scripting 18 WEB Am!r
2011-12-13   WordPress Plugin flash-album-gallery - 'flagshow.php' Cross-Site Scripting 17 WEB Am!r
2015-03-19   Citrix Nitro SDK - Command Injection 17 WEB Han Sahin
2015-03-19   Citrix Command Center - Credential Disclosure 21 WEB Han Sahin
2015-03-19   EMC M&R (Watch4net) - Directory Traversal 24 WEB Han Sahin
2015-03-19   Joomla! Component ECommerce-WD 1.2.5 - SQL Injection 22 WEB Brandon Perry
2015-03-19   EMC M&R (Watch4net) - Credential Disclosure 16 WEB Han Sahin
2015-03-19   Chamilo LMS 1.9.10 - Multiple Vulnerabilities 16 WEB Rehan Ahmed
2011-12-12   WordPress Plugin GRAND FlAGallery 1.57 - 'flagshow.php' Cross-Site Scripting 18 WEB Am!r
2011-12-09   Pet Listing - 'preview.php' Cross-Site Scripting 22 WEB Mr.PaPaRoSSe
2015-03-18   Websense Appliance Manager - Command Injection 20 WEB Han Sahin
2015-03-17   Metasploit Project < 4.11.1 - Initial User Creation Cross-Site Request Forgery (Metasploit) 21 WEB Mohamed Abdelbaset Elnoby
2015-03-17   Moodle 2.5.9/2.6.8/2.7.5/2.8.3 - Block Title Handler Cross-Site Scripting 19 WEB LiquidWorm
2015-03-16   WordPress Plugin WPML 3.1.9 - Multiple Vulnerabilities 24 WEB Jouko Pynnonen
2015-03-16   WordPress Plugin SEO by Yoast 1.7.3.3 - Blind SQL Injection 24 WEB Ryan Dewhurst
2011-12-06   Simple Machines Forum (SMF) 1.1.15 - 'fckeditor' Arbitrary File Upload 20 WEB HELLBOY
2011-12-06   WordPress Plugin Pretty Link 1.5.2 - 'pretty-bar.php' Cross-Site Scripting 23 WEB Am!r
2011-12-05   Elxis CMS 2009 - 'administrator/index.php' URI Cross-Site Scripting 19 WEB Ewerson Guimaraes
2011-12-05   Elxis CMS 2009 - 'index.php?task' Cross-Site Scripting 24 WEB Ewerson Guimaraes
2011-12-01   Hero 3.69 - 'month' Cross-Site Scripting 24 WEB Gjoko Krstic
2011-12-01   AtMail 1.04 - 'func' Multiple Cross-Site Scripting Vulnerabilities 21 WEB Dognædis
2015-03-16   Smart PHP Poll - Authentication Bypass 21 WEB Mr.tro0oqy yemen
2015-03-16   Joomla! Component com_simplephotogallery 1.0 - SQL Injection 21 WEB Moneer Masoud
2011-11-30   SugarCRM Community Edition 6.3.0RC1 - 'index.php' Multiple SQL Injections 24 WEB High-Tech Bridge SA
2011-11-30   WordPress Plugin flash-album-gallery - 'facebook.php' Cross-Site Scripting 24 WEB Am!r
2011-11-30   WordPress Plugin 1-jquery-photo-gallery-Slideshow-flash 1.01 - Cross-Site Scripting 24 WEB Am!r
2011-11-30   OrangeHRM 2.6.11 - '/lib/controllers/CentralController.php?id' SQL Injection 19 WEB High-Tech Bridge SA
2011-11-30   OrangeHRM 2.6.11 - 'lib/controllers/CentralController.php' URI Cross-Site Scripting 23 WEB High-Tech Bridge SA
2011-11-30   OrangeHRM 2.6.11 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 23 WEB High-Tech Bridge SA
2011-11-29   Virtual Vertex Muster 6.1.6 - Web Interface Directory Traversal 17 WEB Nick Freeman
2015-03-08   WordPress Plugin Reflex Gallery 3.1.3 - Arbitrary File Upload 18 WEB CrashBandicot
2015-03-10   Joomla! Component com_simplephotogallery 1.0 - Arbitrary File Upload 18 WEB CrashBandicot
2015-03-04   WordPress Theme DesignFolio Plus 1.2 - Arbitrary File Upload 20 WEB CrashBandicot
2015-03-12   Codiad 2.5.3 - Local File Inclusion 22 WEB TUNISIAN CYBER
2015-03-12   Citrix Netscaler NS10.5 - WAF Bypass (Via HTTP Header Pollution) 23 WEB BGA Security
2015-03-13   WoltLab Community Gallery - Persistent Cross-Site Scripting 21 WEB ITAS Team
2011-11-28   Manx 1.0.1 - '/admin/admin_pages.php?Filename' Traversal Arbitrary File Access 23 WEB LiquidWorm
2011-11-28   Manx 1.0.1 - '/admin/admin_blocks.php?Filename' Traversal Arbitrary File Access 20 WEB LiquidWorm
2011-11-28   Manx 1.0.1 - '/admin/tiny_mce/plugins/ajaxfilemanager_OLD/ajax_get_file_listing.php' Multiple Cross- 18 WEB LiquidWorm
2011-11-28   Manx 1.0.1 - '/admin/tiny_mce/plugins/ajaxfilemanager/ajax_get_file_listing.php' Multiple Cross-Site 23 WEB LiquidWorm
2011-11-28   WordPress Plugin Skysa App Bar - 'idnews' Cross-Site Scripting 20 WEB Amir
2011-11-26   eSyndiCat Pro 2.3.5 - Multiple Cross-Site Scripting Vulnerabilities 20 WEB d3v1l
2015-03-11   CS-Cart 4.2.4 - Cross-Site Request Forgery 21 WEB Luis Santana
2011-11-24   HP Network Node Manager (NMM) i 9.10 - 'nnm/protected/traceroute.jsp?nodename' Cross-Site Scripting 25 WEB anonymous
2011-11-24   HP Network Node Manager (NMM) i 9.10 - 'nnm/protected/statuspoll.jsp?nodename' Cross-Site Scripting 24 WEB anonymous
2011-11-24   HP Network Node Manager (NMM) i 9.10 - 'nnm/protected/ping.jsp?nodename' Cross-Site Scripting 23 WEB anonymous
2011-11-24   HP Network Node Manager (NMM) i 9.10 - 'nnm/protected/configurationpoll.jsp?nodename' Cross-Site Scr 22 WEB anonymous
2011-11-24   HP Network Node Manager (NMM) i 9.10 - '/nnm/mibdiscover?node' Cross-Site Scripting 23 WEB anonymous
2011-11-24   Balitbang CMS 3.3 - 'alumni.php?hal' SQL Injection 23 WEB X-Cisadane
2011-11-24   Balitbang CMS 3.3 - 'index.php?hal' SQL Injection 22 WEB X-Cisadane
2011-11-24   AdaptCMS 2.0 - SQL Injection 23 WEB X-Cisadane
2011-11-23   Pro Clan Manager 0.4.2 - SQL Injection 19 WEB anonymous
2011-11-22   Hastymail2 - 'rs' Cross-Site Scripting 21 WEB HTrovao
2011-11-23   Zen Cart CMS 1.3.9h - Multiple Cross-Site Scripting Vulnerabilities 22 WEB RPinto
2011-11-23   Prestashop 1.4.4.1 - 'displayImage.php' HTTP Response Splitting 23 WEB RGouveia
2011-11-23   PrestaShop 1.4.4.1 - '/admin/ajaxfilemanager/ajax_save_text.php' Multiple Cross-Site Scripting Vulne 25 WEB Prestashop
2011-11-23   PrestaShop 1.4.4.1 - '/modules/mondialrelay/kit_mondialrelay/SuiviExpedition_ajax.php?Expedition' Cr 19 WEB Prestashop
2011-11-23   PrestaShop 1.4.4.1 - '/modules/mondialrelay/googlemap.php' Multiple Cross-Site Scripting Vulnerabili 23 WEB Prestashop
2011-11-23   PrestaShop 1.4.4.1 mondialrelay (kit_mondialrelay) - Multiple Cross-Site Scripting Vulnerabilities 23 WEB Prestashop
2011-11-23   WordPress Plugin NewsLetter Meenews 5.1 - 'idnews' Cross-Site Scripting 24 WEB Amir
2011-11-23   WordPress Plugin Featurific For WordPress 1.6.2 - 'snum' Cross-Site Scripting 23 WEB Amir