Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2015-02-20   Pentaho < 4.5.0 - User Console XML Injection 10 WEB K.d Long
2011-09-12   Papoo CMS Light 4.0 - Multiple Cross-Site Scripting Vulnerabilities 9 WEB Stefan Schurtz
2011-09-08   Pluck CMS 4.7 - Multiple Local File Inclusion / File Disclosure Vulnerabilities 12 WEB Bl4k3
2015-02-19   Piwigo 2.7.3 - Multiple Vulnerabilities 9 WEB Steffen Rösemann
2015-02-19   CrushFTP 7.2.0 - Multiple Vulnerabilities 10 WEB Rehan Ahmed
2015-02-19   Piwigo 2.7.3 - SQL Injection 13 WEB Sven Schleier
2011-09-08   In-link 2.3.4/5.1.3 RC1 - 'cat' SQL Injection 18 WEB SubhashDasyam
2011-09-08   SkaDate - 'blogs.php' Cross-Site Scripting 10 WEB sonyy
2011-09-05   Zikula Application Framework 1.2.7/1.3 - 'themename' Cross-Site Scripting 11 WEB High-Tech Bridge SA
2011-09-06   GeoClassifieds Lite 2.0.x - Multiple Cross-Site Scripting / SQL Injections 10 WEB Yassin Aboukir
2011-09-06   Kisanji - 'gr' Cross-Site Scripting 10 WEB Bl4ck.Viper
2011-09-05   EasyGallery 5 - 'index.php' Multiple SQL Injections 10 WEB Eyup CELIK
2011-09-05   Advanced Image Hosting Script 2.3 - 'report.php' Cross-Site Scripting 14 WEB R3d-D3V!L
2015-02-18   WordPress Plugin Duplicator 0.5.8 - Privilege Escalation 10 WEB Kacper Szurek
2011-09-02   ACal 2.2.6 - 'calendar.php' Cross-Site Scripting 12 WEB T0xic
2011-09-02   Mambo Component N-Myndir - SQL Injection 11 WEB CoBRa_21
2011-09-02   Mambo Component N-Frettir - SQL Injection 12 WEB CoBRa_21
2011-09-02   KaiBB 2.0.1 - SQL Injection / Arbitrary File Upload 12 WEB KedAns-Dz
2011-09-02   Mambo Component N-Press - SQL Injection 10 WEB CoBRa_21
2015-02-18   D-Link DSL-2640B ADSL Router - 'ddnsmngr' Remote DNS Change 11 WEB Todor Donev
2011-09-02   Mambo Component Ahsshop - SQL Injection 9 WEB CoBRa_21
2011-09-02   Mambo Component N-Gallery - SQL Injection 9 WEB CoBRa_21
2015-02-17   GuppY CMS 5.0.9 < 5.00.10 - Multiple Cross-Site Request Forgery Vulnerabilities 10 WEB Brandon Murphy
2015-02-17   Guppy CMS 5.0.9/5.00.10 - Authentication Bypass/Change Email 12 WEB Brandon Murphy
2011-09-02   Mambo Component N-Skyrslur - Cross-Site Scripting 11 WEB CoBRa_21
2011-08-31   Web Professional - 'default.php' SQL Injection 10 WEB The_Exploited
2011-08-31   S9Y Serendipity 1.5.1 - 'research_display.php' SQL Injection 14 WEB The_Exploited
2011-08-31   TinyWebGallery 1.8.4 - Local File Inclusion / SQL Injection 13 WEB KedAns-Dz
2011-08-30   CS-Cart 2.2.1 - 'products.php' SQL Injection 12 WEB Net.Edit0r
2011-08-30   IBM Open Admin Tool 2.71 - Multiple Cross-Site Scripting Vulnerabilities 19 WEB Sumit Kumar Soni
2011-08-29   ClickCMS - Denial of Service / CAPTCHA Bypass 12 WEB MustLive
2015-02-16   eTouch SamePage 4.4.0.0.239 - Multiple Vulnerabilities 15 WEB Brandon Perry
2015-02-16   WordPress Plugin Fancybox 3.0.2 - Persistent Cross-Site Scripting 17 WEB NULLpOint7r
2015-02-16   WordPress Plugin WonderPlugin Audio Player 2.0 - Blind SQL Injection / Cross-Site Scripting 12 WEB Kacper Szurek
2011-08-27   phpWebSite 1.7.1 - 'mod.php' SQL Injection 13 WEB Ehsan_Hp200
2011-08-26   Mambo 4.6.5 - 'index.php' Cross-Site Request Forgery 12 WEB Caddy-Dz
2011-08-25   Simple Machines Forum (SMF) 1.1.14/2.0 - '[img]' BBCode Tag Cross-Site Request Forgery 17 WEB Christian Yerena
2011-08-25   Zazavi 1.2.1 - '/FileManager/Controller.php' Arbitrary File Upload 14 WEB KedAns-Dz
2011-08-24   VicBlog - 'tag' SQL Injection 17 WEB Eyup CELIK
2011-08-24   Tourismscripts Hotel Portal - 'hotel_city' HTML Injection 14 WEB Eyup CELIK
2011-08-24   CommodityRentals Real Estate Script - 'txtsearch' HTML Injection 13 WEB Eyup CELIK
2011-08-23   Open Classifieds 1.7.2 - Multiple Cross-Site Scripting Vulnerabilities 11 WEB Yassin Aboukir
2011-08-22   Concrete 5.4.1 1 - 'rcID' Cross-Site Scripting 10 WEB Aung Khant
2011-08-22   TotalShopUK 1.7.2 - 'index.php' SQL Injection 13 WEB Eyup CELIK
2011-08-22   Pandora FMS 3.x - 'index.php' Cross-Site Scripting 11 WEB mehdi boukazoula
2011-08-21   OneFileCMS 1.1.1 - 'onefilecms.php' Cross-Site Scripting 12 WEB mr.pr0n
2011-08-18   Mantis Bug Tracker 1.1.8 - Cross-Site Scripting / SQL Injection 15 WEB Net.Edit0r
2011-08-18   Adobe ColdFusion - 'probe.cfm' Cross-Site Scripting 10 WEB G.R0b1n
2011-08-17   Code Widgets Multiple Question - Multiple Choice Online Questionnaire SQL Injections 16 WEB L0rd CrusAd3r
2011-08-17   Code Widgets DataBound Collapsible Menu - 'main.asp' SQL Injection 12 WEB Inj3ct0r
2011-08-17   Code Widgets DataBound Index Style Menu - 'category.asp' SQL Injection 12 WEB Inj3ct0r
2011-08-17   Code Widgets Online Job Application - 'admin.asp' Multiple SQL Injections 11 WEB L0rd CrusAd3r
2015-02-13   WordPress Plugin Webdorado Spider Event Calendar 1.4.9 - SQL Injection 11 WEB Mateusz Lach
2015-02-12   Exponent CMS 2.3.1 - Multiple Cross-Site Scripting Vulnerabilities 12 WEB Mayuresh Dani
2015-02-12   WordPress Plugin Video Gallery 2.7.0 - SQL Injection 13 WEB Claudio Viviani
2015-02-11   IBM Endpoint Manager - Persistent Cross-Site Scripting 15 WEB RedTeam Pentesting
2015-02-11   Pandora FMS 5.1 SP1 - SQL Injection 11 WEB Vulnerability-Lab
2015-02-11   WordPress Plugin Survey and Poll 1.1 - Blind SQL Injection 20 WEB Securely (Yoo Hee man)
2011-08-17   WordPress Plugin WP-Stats-Dashboard 2.6.5.1 - Multiple Cross-Site Scripting Vulnerabilities 12 WEB High-Tech Bridge SA
2011-08-17   WordPress Plugin Fast Secure Contact Form 3.0.3.1 - 'index.php' Cross-Site Scripting 12 WEB High-Tech Bridge SA
2011-08-15   phpList 2.10.x - Security Bypass / Information Disclosure 11 WEB Davide Canali
2011-08-15   awiki 20100125 - Multiple Local File Inclusions 10 WEB muuratsalo
2011-08-17   phpWebSite - 'page_id' Cross-Site Scripting 13 WEB Ehsan_Hp200
2011-08-11   PHP Flat File Guestbook 1.0 - 'ffgb_admin.php' Remote File Inclusion 13 WEB RiRes Walid
2015-02-10   WordPress Plugin WP EasyCart - Unrestricted Arbitrary File Upload (Metasploit) 9 WEB Metasploit
2015-02-10   LG DVR LE6016D - Remote File Disclosure 11 WEB Yakir Wizman
2015-02-09   Fork CMS 3.8.5 - SQL Injection 13 WEB Sven Schleier
2015-02-09   Chamilo LMS 1.9.8 - Blind SQL Injection 12 WEB Kacper Szurek
2011-08-10   WordPress Plugin eShop 6.2.8 - Multiple Cross-Site Scripting Vulnerabilities 22 WEB High-Tech Bridge SA
2011-08-08   BlueSoft Rate My Photo Site - 'ty' SQL Injection 12 WEB darkTR
2011-08-08   BlueSoft Banner Exchange - 'referer_id' SQL Injection 11 WEB darkTR
2011-08-09   OpenEMR 4.0 - Multiple Cross-Site Scripting Vulnerabilities 15 WEB Houssam Sahli
2011-08-08   Search Network 2.0 - 'query' Cross-Site Scripting 16 WEB darkTR
2011-08-05   Softbiz Recipes Portal Script - Multiple Cross-Site Scripting Vulnerabilities 12 WEB Net.Edit0r
2015-02-09   StaMPi - Local File Inclusion 16 WEB e . V . E . L
2015-02-09   u5CMS 3.9.3 - Multiple Persistent Cross-Site Scripting / Reflected Cross-Site Scripting Vulnerabilit 11 WEB LiquidWorm
2015-02-09   u5CMS 3.9.3 - 'thumb.php' Local File Inclusion 14 WEB LiquidWorm
2015-02-09   u5CMS 3.9.3 - Multiple SQL Injections 10 WEB LiquidWorm
2015-02-09   u5CMS 3.9.3 - 'deletefile.php' Arbitrary File Deletion 13 WEB LiquidWorm
2015-02-09   RedaxScript CMS 2.2.0 - SQL Injection 10 WEB ITAS Team
2011-08-04   Community Server 2007/2008 - 'TagSelector.aspx' Cross-Site Scripting 15 WEB PontoSec
2011-08-04   WordPress Plugin WP E-Commerce 3.8.6 - 'cart_messages[]' Cross-Site Scripting 11 WEB High-Tech Bridge SA
2011-08-03   HESK 2.2 - Multiple Cross-Site Scripting Vulnerabilities 11 WEB High-Tech Bridge SA
2011-08-03   Joomla! Component com_community - 'userid' SQL Injection 11 WEB Ne0 H4ck3R
2011-08-03   Joomla! Component com_xeslidegalfx - 'id' SQL Injection 13 WEB Ne0 H4ck3R
2011-08-03   Ataccan E-Ticaret Scripti - 'id' SQL Injection 9 WEB Err0R
2011-08-03   BESNI OKUL PORTAL - 'sayfa.asp' Cross-Site Scripting 13 WEB Err0R
2011-08-03   mt LinkDatenbank - 'b' Cross-Site Scripting 12 WEB Err0R
2011-07-11   Gilnet News - 'read_more.php' SQL Injection 11 WEB Err0R
2011-08-02   MyBB MyTabs Plugin - 'tab' SQL Injection 13 WEB AutoRUN & dR.sqL
2011-08-01   Curverider Elgg 1.7.9 - Multiple Cross-Site Scripting Vulnerabilities 11 WEB Aung Khant
2014-12-12   IBM Tivoli Service Automation Manager 7.2.4 - Remote Code Execution 9 WEB Jakub Palaczynski
2011-07-28   Sitecore CMS 6.4.1 - 'url' Open Redirection 12 WEB Tom Neaves
2011-07-28   HP Network Automation 9.10 - SQL Injection 12 WEB anonymous
2011-07-25   CobraScripts Trading Marketplace Script - 'cid' SQL Injection 11 WEB Ehsan_Hp200
2015-02-05   Magento Server MAGMI Plugin - Multiple Vulnerabilities 13 WEB SECUPENT
2015-02-04   Pragyan CMS 3.0 - SQL Injection 10 WEB Steffen Rösemann
2011-07-27   PHPJunkYard GBook 1.6/1.7 - Multiple Cross-Site Scripting Vulnerabilities 13 WEB High-Tech Bridge SA
2011-07-27   MBoard 1.3 - 'url' Open Redirection 13 WEB High-Tech Bridge SA
2011-07-26   Support Incident Tracker (SiT!) 3.63 p1 - 'tasks.php?selected[]' SQL Injection 12 WEB Yuri Goltsev
2011-07-26   Support Incident Tracker (SiT!) 3.63 p1 - 'search.php?search_string' SQL Injection 12 WEB Yuri Goltsev
2011-07-26   Support Incident Tracker (SiT!) 3.63 p1 - 'billable_incidents.php?sites[]' SQL Injection 10 WEB Yuri Goltsev
2011-07-26   Support Incident Tracker (SiT!) 3.63 p1 - 'report_marketing.php?exc[]' SQL Injection 13 WEB Yuri Goltsev
2011-07-25   Joomla! Component com_virtualmoney 1.5 - SQL Injection 10 WEB FL0RiX
2015-02-03   Hewlett-Packard (HP) UCMDB - JMX-Console Authentication Bypass 14 WEB Hans-Martin Muench
2015-02-03   ManageEngine Desktop Central 9 Build 90087 - Cross-Site Request Forgery 13 WEB Mohamed Idris
2011-07-25   Willscript Recipes Website Script Silver Edition - 'viewRecipe.php' SQL Injection 11 WEB Lazmania61
2011-07-25   Online Grades 3.2.5 - Multiple Cross-Site Scripting Vulnerabilities 11 WEB Gjoko Krstic
2011-07-25   Godly Forums - 'id' SQL Injection 15 WEB 3spi0n
2011-07-21   Synergy Software - 'id' SQL Injection 10 WEB Ehsan_Hp200
2011-07-20   Cyberoam UTM - Multiple Cross-Site Scripting Vulnerabilities 14 WEB Patrick Webster
2011-07-20   Tiki Wiki CMS Groupware 7.2 - 'snarf_ajax.php' Cross-Site Scripting 11 WEB High-Tech Bridge SA
2011-07-20   Joomla! < 1.6.5 - Multiple Cross-Site Scripting Vulnerabilities 10 WEB YGN Ethical Hacker Group
2015-02-02   Sefrengo CMS 1.6.1 - Multiple SQL Injections 15 WEB ITAS Team
2011-07-11   WordPress Plugin bSuite 4.0.7 - Multiple HTML Injection Vulnerabilities 11 WEB IHTeam
2011-07-17   BlueSoft Social Networking CMS - SQL Injection 11 WEB Lazmania61
2011-07-18   BlueSoft (Multiple Products) - Multiple SQL Injections 9 WEB Lazmania61
2011-07-15   AJ Classifieds - 'listingid' SQL Injection 22 WEB Lazmania61
2011-07-15   Joomla! Component com_newssearch - SQL Injection 11 WEB Robert Cooper
2011-07-15   Joomla! Component Controller - 'Itemid' SQL Injection 11 WEB SOLVER
2011-07-15   Joomla! Component com_hospital - SQL Injection 10 WEB SOLVER
2011-07-15   Joomla! Component Juicy Gallery - 'picId' SQL Injection 11 WEB SOLVER
2011-07-15   Joomla! Component Foto - 'id_categoria' SQL Injection 15 WEB SOLVER
2011-07-15   Easy Estate Rental - 's_location' SQL Injection 11 WEB Lazmania61
2011-07-15   Auto Web Toolbox - 'id' SQL Injection 10 WEB Lazmania61