|
2011-07-02
|
|
Paliz Portal - Cross-Site Scripting / Multiple SQL Injections
|
8 |
WEB
|
Net.Edit0r
|
|
2011-07-05
|
|
Joomla! Component com_jr_tfb - 'Controller' Local File Inclusion
|
7 |
WEB
|
FL0RiX
|
|
2014-11-11
|
|
WordPress Plugin Photo Gallery 1.2.5 - Unrestricted Arbitrary File Upload
|
8 |
WEB
|
Kacper Szurek
|
|
2015-01-26
|
|
Symantec Data Center Security - Multiple Vulnerabilities
|
9 |
WEB
|
SEC Consult
|
|
2015-01-26
|
|
ferretCMS 1.0.4-alpha - Multiple Vulnerabilities
|
8 |
WEB
|
Steffen Rösemann
|
|
2015-01-26
|
|
jclassifiedsmanager - Multiple Vulnerabilities
|
9 |
WEB
|
Sarath Nair
|
|
2015-01-26
|
|
ManageEngine EventLog Analyzer 9.0 - Directory Traversal / Cross-Site Scripting
|
13 |
WEB
|
Ertebat Gostar Co
|
|
2015-01-26
|
|
SWFupload 2.5.0 - Cross Frame Scripting (XFS)
|
8 |
WEB
|
MindCracker
|
|
2015-01-26
|
|
PHP Webquest 2.6 - SQL Injection
|
6 |
WEB
|
jordan root
|
|
2015-01-26
|
|
ManageEngine ServiceDesk Plus 9.0 < Build 9031 - User Privileges Management
|
8 |
WEB
|
Rewterz - Research Group
|
|
2015-01-26
|
|
Barracuda Networks Cloud Series - Filter Bypass
|
7 |
WEB
|
Vulnerability-Lab
|
|
2015-01-26
|
|
Mangallam CMS - SQL Injection
|
8 |
WEB
|
Vulnerability-Lab
|
|
2011-06-28
|
|
Flatpress 0.1010.1 - Multiple Cross-Site Scripting Vulnerabilities
|
8 |
WEB
|
High-Tech Bridge SA
|
|
2011-06-28
|
|
Joomla! 1.6.3 - Multiple Cross-Site Scripting Vulnerabilities
|
8 |
WEB
|
Aung Khant
|
|
2011-06-27
|
|
WordPress Plugin Pretty Link Lite 1.4.56 - Multiple SQL Injections
|
9 |
WEB
|
MaKyOtOx
|
|
2015-01-22
|
|
ManageEngine ServiceDesk Plus 9.0 - User Enumeration
|
8 |
WEB
|
Muhammad Ahmed Siddiqui
|
|
2015-01-22
|
|
ManageEngine ServiceDesk Plus 9.0 - SQL Injection
|
8 |
WEB
|
Muhammad Ahmed Siddiqui
|
|
2011-06-27
|
|
Mambo 4.6.x - Multiple Cross-Site Scripting Vulnerabilities
|
7 |
WEB
|
Aung Khant
|
|
2011-06-27
|
|
Joomla! Component com_morfeoshow - 'idm' SQL Injection
|
8 |
WEB
|
Th3.xin0x
|
|
2011-06-23
|
|
Nodesforum - '_nodesforum_node' SQL Injection
|
7 |
WEB
|
Andrea Bocchetti
|
|
2015-01-19
|
|
WordPress Plugin Cforms 14.7 - Remote Code Execution
|
9 |
WEB
|
Zakhar
|
|
2015-01-22
|
|
ecommerceMajor - SQL Injection / Authentication Bypass
|
8 |
WEB
|
Manish Tanwar
|
|
2011-06-23
|
|
Sitemagic CMS - 'SMTpl' Directory Traversal
|
7 |
WEB
|
Andrea Bocchetti
|
|
2011-06-22
|
|
FanUpdate 3.0 - 'pageTitle' Cross-Site Scripting
|
9 |
WEB
|
High-Tech Bridge SA
|
|
2011-06-22
|
|
Eshop Manager - Multiple SQL Injections
|
7 |
WEB
|
Number 7
|
|
2011-06-22
|
|
H3C ER5100 - Authentication Bypass
|
8 |
WEB
|
128bit
|
|
2011-06-21
|
|
Sitemagic CMS 2010.04.17 - 'SMExt' Cross-Site Scripting
|
9 |
WEB
|
Gjoko Krstic
|
|
2011-06-18
|
|
Taha Portal 3.2 - 'sitemap.php' Cross-Site Scripting
|
7 |
WEB
|
Bl4ck.Viper
|
|
2011-06-18
|
|
Immophp 1.1.1 - Cross-Site Scripting / SQL Injection
|
7 |
WEB
|
KedAns-Dz
|
|
2011-06-19
|
|
Nibbleblog 3 - Multiple SQL Injections
|
7 |
WEB
|
KedAns-Dz
|
|
2011-06-15
|
|
MyBloggie 2.1.6 - HTML Injection / SQL Injection
|
7 |
WEB
|
Robin Verton
|
|
2011-06-15
|
|
miniblog 1.0 - Multiple Cross-Site Scripting Vulnerabilities
|
8 |
WEB
|
High-Tech Bridge SA
|
|
2011-06-14
|
|
vBTube 1.2.9 - 'vBTube.php' Multiple Cross-Site Scripting Vulnerabilities
|
8 |
WEB
|
Mr.ThieF
|
|
2015-01-20
|
|
vBulletin vBSSO Single Sign-On 1.4.14 - SQL Injection
|
7 |
WEB
|
Technidev
|
|
2015-01-21
|
|
ArticleFR CMS 3.0.5 - Arbitrary File Upload
|
9 |
WEB
|
TranDinhTien
|
|
2015-01-21
|
|
ArticleFR CMS 3.0.5 - SQL Injection
|
7 |
WEB
|
TranDinhTien
|
|
2011-06-13
|
|
PHP-Nuke 8.3 - 'upload.php' Arbitrary File Upload (2)
|
6 |
WEB
|
pentesters.ir
|
|
2011-06-13
|
|
PHP-Nuke 8.3 - 'upload.php' Arbitrary File Upload (1)
|
8 |
WEB
|
pentesters.ir
|
|
2011-06-13
|
|
Microsoft Lync Server 2010 - 'ReachJoin.aspx' Remote Command Injection
|
8 |
WEB
|
Mark Lachniet
|
|
2011-06-13
|
|
WebFileExplorer 3.6 - 'user' / 'pass' SQL Injection
|
8 |
WEB
|
pentesters.ir
|
|
2015-01-20
|
|
WordPress Plugin Pixarbay Images 2.3 - Multiple Vulnerabilities
|
7 |
WEB
|
Hans-Martin Muench
|
|
2015-01-20
|
|
RedaxScript 2.1.0 - Privilege Escalation
|
7 |
WEB
|
shyamkumar somana
|
|
2011-06-13
|
|
Joomla! Component Minitek FAQ Book 1.3 - 'id' SQL Injection
|
7 |
WEB
|
kaMtiEz
|
|
2011-06-10
|
|
Tolinet Agencia - 'id' SQL Injection
|
7 |
WEB
|
Andrea Bocchetti
|
|
2011-06-07
|
|
The Pacer Edition CMS 2.1 - 'email' Cross-Site Scripting
|
6 |
WEB
|
LiquidWorm
|
|
2011-06-08
|
|
WordPress Plugin GD Star Rating - 'votes' SQL Injection
|
6 |
WEB
|
anonymous
|
|
2011-06-07
|
|
Blog:CMS 4.2 - Multiple Cross-Site Scripting Vulnerabilities
|
6 |
WEB
|
Stefan Schurtz
|
|
2011-06-07
|
|
Xataface 1.x - 'action' Local File Inclusion
|
6 |
WEB
|
ITSecTeam
|
|
2011-06-06
|
|
Squiz Matrix 4 - 'colour_picker.php' Cross-Site Scripting
|
6 |
WEB
|
Patrick Webster
|
|
2011-06-06
|
|
PopScript - 'index.php' Multiple Input Validation Vulnerabilities
|
6 |
WEB
|
NassRawI
|
|
2011-06-06
|
|
Multiple WordPress WooThemes Themes - 'test.php' Cross-Site Scripting
|
6 |
WEB
|
MustLive
|
|
2011-06-06
|
|
Nakid CMS 1.0.2 - 'CKEditorFuncNum' Cross-Site Scripting
|
7 |
WEB
|
AutoSec Tools
|
|
2011-06-06
|
|
Joomla! Component CCBoard - SQL Injection / Arbitrary File Upload
|
7 |
WEB
|
KedAns-Dz
|
|
2011-06-06
|
|
vBulletin vBExperience 3 - 'sortorder' Cross-Site Scripting
|
7 |
WEB
|
Mr.ThieF
|
|
2015-01-16
|
|
WordPress Plugin Pie Register 2.0.13 - Privilege Escalation
|
6 |
WEB
|
Kacper Szurek
|
|
2011-06-02
|
|
Ushahidi 2.0.1 - 'range' SQL Injection
|
6 |
WEB
|
Gjoko Krstic
|
|
2011-06-01
|
|
ARSC Really Simple Chat 3.3-rc2 - Cross-Site Scripting / Multiple SQL Injections
|
6 |
WEB
|
High-Tech Bridge SA
|
|
2011-06-01
|
|
PikaCMS - Multiple Local File Disclosure Vulnerabilities
|
6 |
WEB
|
KnocKout
|
|
2011-06-01
|
|
TEDE Simplificado 1.01/S2.04 - Multiple SQL Injections
|
6 |
WEB
|
KnocKout
|
|
2011-05-31
|
|
S9Y Serendipity Freetag-plugin 3.21 - 'index.php' Cross-Site Scripting
|
6 |
WEB
|
Stefan Schurtz
|
|
2011-05-31
|
|
Kentico CMS 5.5R2.23 - 'userContextMenu_Parameter' Cross-Site Scripting
|
6 |
WEB
|
LiquidWorm
|
|
2011-05-30
|
|
Cotonti 0.9.2 - Multiple SQL Injections
|
7 |
WEB
|
KedAns-Dz
|
|
2011-05-25
|
|
BlackBoard Learn 8.0 - 'keywordraw' Cross-Site Scripting
|
7 |
WEB
|
Matt Jezorek
|
|
2011-05-25
|
|
Kryn.cms 0.9 - '_kurl' Cross-Site Scripting
|
8 |
WEB
|
AutoSec Tools
|
|
2011-05-25
|
|
Joomla! Component com_shop - SQL Injection
|
8 |
WEB
|
ThunDEr HeaD
|
|
2011-05-25
|
|
MidiCMS Website Builder - Local File Inclusion / Arbitrary File Upload
|
7 |
WEB
|
KedAns-Dz
|
|
2011-05-24
|
|
Ajax Chat 1.0 - 'ajax-chat.php' Cross-Site Scripting
|
8 |
WEB
|
High-Tech Bridge SA
|
|
2011-05-24
|
|
phpScheduleIt 1.2.12 - Multiple Cross-Site Scripting Vulnerabilities
|
5 |
WEB
|
High-Tech Bridge SA
|
|
2011-05-23
|
|
Joomla! Component Map Locator - 'cid' SQL Injection
|
6 |
WEB
|
FL0RiX
|
|
2011-05-19
|
|
LimeSurvey 1.85+ - 'admin.php' Cross-Site Scripting
|
6 |
WEB
|
Juan Manuel Garcia
|
|
2015-01-14
|
|
Ansible Tower 2.0.2 - Multiple Vulnerabilities
|
12 |
WEB
|
SEC Consult
|
|
2011-05-19
|
|
Andy's PHP KnowledgeBase 0.95.4 - 'step5.php' PHP Remote Code Execution
|
7 |
WEB
|
AutoSec Tools
|
|
2011-05-19
|
|
Room Juice 0.3.3 - 'display.php' Cross-Site Scripting
|
6 |
WEB
|
AutoSec Tools
|
|
2011-05-18
|
|
CiscoWorks Common Services 3.1.1 - Auditing Directory Traversal
|
6 |
WEB
|
Sense of Security
|
|
2015-01-13
|
|
Foxit MobilePDF 4.4.0 iOS - Multiple Vulnerabilities
|
6 |
WEB
|
Vulnerability-Lab
|
|
2015-01-13
|
|
Dell iDRAC IPMI 1.5 - Insufficient Session ID Randomness
|
8 |
WEB
|
Yong Chuan_ Koh
|
|
2015-01-13
|
|
Gecko CMS 2.3 - Multiple Vulnerabilities
|
9 |
WEB
|
LiquidWorm
|
|
2011-05-18
|
|
TWiki 5.0.1 - 'origurl' Cross-Site Scripting
|
9 |
WEB
|
Mesut Timur
|
|
2011-05-17
|
|
PHP Calendar Basic 2.3 - Multiple Cross-Site Scripting Vulnerabilities
|
9 |
WEB
|
High-Tech Bridge SA
|
|
2011-05-16
|
|
eFront 3.6.9 - 'submitScore.php' Cross-Site Scripting
|
8 |
WEB
|
John Leitch
|
|
2011-05-16
|
|
Mitel Audio and Web Conferencing 4.4.3.0 - Multiple Cross-Site Scripting Vulnerabilities
|
8 |
WEB
|
Richard Brain
|
|
2011-05-16
|
|
eFront 3.6.9 - 'scripts.php' Local File Inclusion
|
12 |
WEB
|
AutoSec Tools
|
|
2011-05-16
|
|
openQRM 4.8 - 'source_tab' Cross-Site Scripting
|
9 |
WEB
|
AutoSec Tools
|
|
2011-05-12
|
|
DocMGR 1.1.2 - 'history.php' Cross-Site Scripting
|
10 |
WEB
|
AutoSec Tools
|
|
2011-05-16
|
|
allocPSA 1.7.4 - '/login/login.php' Cross-Site Scripting
|
9 |
WEB
|
AutoSec Tools
|
|
2011-05-16
|
|
Mambo Component Docman 1.3.0 - Multiple SQL Injections
|
10 |
WEB
|
KedAns-Dz
|
|
2015-01-11
|
|
D-Link DSL-2730B Modem - 'Lancfg2get.cgi Persistent Cross-Site Scripting
|
9 |
WEB
|
XLabs Security
|
|
2015-01-11
|
|
D-Link DSL-2730B Modem - Cross-Site Scripting Injection Stored DnsProxy.cmd
|
10 |
WEB
|
XLabs Security
|
|
2015-01-11
|
|
D-Link DSL-2730B Modem - Cross-Site Scripting Injection Stored Wlsecrefresh.wl & Wlsecurity.wl
|
10 |
WEB
|
XLabs Security
|
|
2011-05-16
|
|
Joomla! Component com_cbcontact - 'contact_id' SQL Injection
|
9 |
WEB
|
KedAns-Dz
|
|
2011-05-13
|
|
Flash Tag Cloud And MT-Cumulus Plugin - 'tagcloud' Cross-Site Scripting
|
8 |
WEB
|
MustLive
|
|
2011-05-12
|
|
Argyle Social - Multiple Cross-Site Scripting Vulnerabilities
|
9 |
WEB
|
High-Tech Bridge SA
|
|
2011-05-10
|
|
Calendarix 0.8.20080808 - Multiple Cross-Site Scripting / SQL Injections
|
8 |
WEB
|
High-Tech Bridge SA
|
|
2011-05-10
|
|
poMMo Aardvark PR16.1 - Multiple Cross-Site Scripting Vulnerabilities
|
8 |
WEB
|
High-Tech Bridge SA
|
|
2011-05-09
|
|
ZAPms 1.22 - 'nick' SQL Injection
|
8 |
WEB
|
KedAns-Dz
|
|
2015-01-09
|
|
vBulletin MicroCART 1.1.4 - Arbitrary Files Deletion / SQL Injection / Cross-Site Scripting
|
9 |
WEB
|
Technidev
|
|
2015-01-08
|
|
WordPress Plugin Shopping Cart 3.0.4 - Unrestricted Arbitrary File Upload
|
10 |
WEB
|
Kacper Szurek
|
|
2011-05-09
|
|
Keyfax Customer Response Management 3.2.2.6 - Multiple Cross-Site Scripting Vulnerabilities
|
9 |
WEB
|
Richard Brain
|
|
2011-05-09
|
|
HOMEPIMA Design - 'filedown.php' Local File Disclosure
|
10 |
WEB
|
KnocKout
|
|
2011-05-07
|
|
Getsimple CMS 3.0 - 'set' Local File Inclusion
|
10 |
WEB
|
AutoSec Tools
|
|
2011-05-09
|
|
EmbryoCore 1.03 - 'index.php' SQL Injection
|
9 |
WEB
|
KedAns-Dz
|
|
2011-05-01
|
|
TCExam 11.1.29 - 'tce_xml_user_results.php' Multiple SQL Injections
|
11 |
WEB
|
AutoSec Tools
|
|
2015-01-07
|
|
Sefrengo CMS 1.6.0 - SQL Injection
|
10 |
WEB
|
Steffen Rösemann
|
|
2015-01-07
|
|
Pirelli ADSL2/2+ Wireless Router P.DGA4001N - Information Disclosure
|
10 |
WEB
|
Eduardo Novella
|
|
2015-01-07
|
|
Microweber CMS 0.95 - SQL Injection
|
10 |
WEB
|
Pham Kien Cuong
|
|
2011-05-09
|
|
phpWebSite 1.7.1 - 'upload.php' Arbitrary File Upload
|
10 |
WEB
|
AutoSec Tools
|
|
2011-05-09
|
|
Gelsheet 1.02 - 'index.php' Cross-Site Scripting
|
10 |
WEB
|
AutoSec Tools
|
|
2011-05-09
|
|
Exponent CMS 2.0.0 Beta 1.1 - Local File Inclusion / Arbitrary File Upload
|
10 |
WEB
|
AutoSec Tools
|
|
2011-05-09
|
|
Ampache 3.5.4 - 'login.php' Cross-Site Scripting
|
10 |
WEB
|
AutoSec Tools
|
|
2011-05-09
|
|
encoder 0.4.10 - 'edit.php' Cross-Site Scripting
|
9 |
WEB
|
AutoSec Tools
|
|
2011-05-08
|
|
FestOS 2.3c - 'upload.php' Arbitrary File Upload
|
10 |
WEB
|
KedAns-Dz
|
|
2015-01-06
|
|
AdaptCMS 3.0.3 - Multiple Vulnerabilities
|
9 |
WEB
|
LiquidWorm
|
|
2011-05-07
|
|
e107 0.7.25 - 'news.php' SQL Injection
|
8 |
WEB
|
KedAns-Dz
|
|
2011-05-05
|
|
PHPDug 2.0 - Multiple Cross-Site Scripting Vulnerabilities
|
8 |
WEB
|
High-Tech Bridge SA
|
|
2011-05-05
|
|
BMC Dashboards 7.6.01 - Cross-Site Scripting / Information Disclosure
|
9 |
WEB
|
Richard Brain
|
|
2011-05-05
|
|
BMC Remedy Knowledge Management 7.5.00 - Default Account / Multiple Cross-Site Scripting Vulnerabili
|
8 |
WEB
|
Richard Brain
|
|
2011-05-05
|
|
PHP Directory Listing Script 3.1 - 'index.php' Cross-Site Scripting
|
10 |
WEB
|
High-Tech Bridge SA
|
|
2011-05-05
|
|
WordPress Plugin WP Ajax Calendar 1.0 - 'example.php' Cross-Site Scripting
|
13 |
WEB
|
High-Tech Bridge SA
|
|
2011-05-03
|
|
GoT.MY (Multiple Products) - 'theme_dir' Cross-Site Scripting
|
8 |
WEB
|
Hector.x90
|
|
2011-05-03
|
|
SelectaPix 1.4.1 - 'uploadername' Cross-Site Scripting
|
8 |
WEB
|
High-Tech Bridge SA
|
|
2011-05-03
|
|
YaPiG 0.95 - Multiple Cross-Site Scripting Vulnerabilities
|
7 |
WEB
|
High-Tech Bridge SA
|
|
2011-05-03
|
|
E2 Photo Gallery 0.9 - 'index.php' Cross-Site Scripting
|
10 |
WEB
|
High-Tech Bridge SA
|
|
2011-05-03
|
|
Proofpoint Protection Server 5.5.5 - 'process.cgi' Cross-Site Scripting
|
8 |
WEB
|
Karan Khosla
|
|
2011-05-03
|
|
Web Auction 0.3.6 - 'lang' Cross-Site Scripting
|
9 |
WEB
|
AutoSec Tools
|
|
2015-01-04
|
|
Crea8Social 2.0 - Cross-Site Scripting Change Interface
|
10 |
WEB
|
Yudhistira B W
|