Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2015-02-11   Pandora FMS 5.1 SP1 - SQL Injection 26 WEB Vulnerability-Lab
2015-02-11   WordPress Plugin Survey and Poll 1.1 - Blind SQL Injection 34 WEB Securely (Yoo Hee man)
2011-08-17   WordPress Plugin WP-Stats-Dashboard 2.6.5.1 - Multiple Cross-Site Scripting Vulnerabilities 25 WEB High-Tech Bridge SA
2011-08-17   WordPress Plugin Fast Secure Contact Form 3.0.3.1 - 'index.php' Cross-Site Scripting 27 WEB High-Tech Bridge SA
2011-08-15   phpList 2.10.x - Security Bypass / Information Disclosure 26 WEB Davide Canali
2011-08-15   awiki 20100125 - Multiple Local File Inclusions 25 WEB muuratsalo
2011-08-17   phpWebSite - 'page_id' Cross-Site Scripting 28 WEB Ehsan_Hp200
2011-08-11   PHP Flat File Guestbook 1.0 - 'ffgb_admin.php' Remote File Inclusion 26 WEB RiRes Walid
2015-02-10   WordPress Plugin WP EasyCart - Unrestricted Arbitrary File Upload (Metasploit) 25 WEB Metasploit
2015-02-10   LG DVR LE6016D - Remote File Disclosure 27 WEB Yakir Wizman
2015-02-09   Fork CMS 3.8.5 - SQL Injection 27 WEB Sven Schleier
2015-02-09   Chamilo LMS 1.9.8 - Blind SQL Injection 27 WEB Kacper Szurek
2011-08-10   WordPress Plugin eShop 6.2.8 - Multiple Cross-Site Scripting Vulnerabilities 34 WEB High-Tech Bridge SA
2011-08-08   BlueSoft Rate My Photo Site - 'ty' SQL Injection 29 WEB darkTR
2011-08-08   BlueSoft Banner Exchange - 'referer_id' SQL Injection 32 WEB darkTR
2011-08-09   OpenEMR 4.0 - Multiple Cross-Site Scripting Vulnerabilities 28 WEB Houssam Sahli
2011-08-08   Search Network 2.0 - 'query' Cross-Site Scripting 28 WEB darkTR
2011-08-05   Softbiz Recipes Portal Script - Multiple Cross-Site Scripting Vulnerabilities 29 WEB Net.Edit0r
2015-02-09   StaMPi - Local File Inclusion 33 WEB e . V . E . L
2015-02-09   u5CMS 3.9.3 - Multiple Persistent Cross-Site Scripting / Reflected Cross-Site Scripting Vulnerabilit 29 WEB LiquidWorm
2015-02-09   u5CMS 3.9.3 - 'thumb.php' Local File Inclusion 30 WEB LiquidWorm
2015-02-09   u5CMS 3.9.3 - Multiple SQL Injections 24 WEB LiquidWorm
2015-02-09   u5CMS 3.9.3 - 'deletefile.php' Arbitrary File Deletion 26 WEB LiquidWorm
2015-02-09   RedaxScript CMS 2.2.0 - SQL Injection 26 WEB ITAS Team
2011-08-04   Community Server 2007/2008 - 'TagSelector.aspx' Cross-Site Scripting 26 WEB PontoSec
2011-08-04   WordPress Plugin WP E-Commerce 3.8.6 - 'cart_messages[]' Cross-Site Scripting 26 WEB High-Tech Bridge SA
2011-08-03   HESK 2.2 - Multiple Cross-Site Scripting Vulnerabilities 26 WEB High-Tech Bridge SA
2011-08-03   Joomla! Component com_community - 'userid' SQL Injection 29 WEB Ne0 H4ck3R
2011-08-03   Joomla! Component com_xeslidegalfx - 'id' SQL Injection 30 WEB Ne0 H4ck3R
2011-08-03   Ataccan E-Ticaret Scripti - 'id' SQL Injection 27 WEB Err0R
2011-08-03   BESNI OKUL PORTAL - 'sayfa.asp' Cross-Site Scripting 28 WEB Err0R
2011-08-03   mt LinkDatenbank - 'b' Cross-Site Scripting 26 WEB Err0R
2011-07-11   Gilnet News - 'read_more.php' SQL Injection 27 WEB Err0R
2011-08-02   MyBB MyTabs Plugin - 'tab' SQL Injection 26 WEB AutoRUN & dR.sqL
2011-08-01   Curverider Elgg 1.7.9 - Multiple Cross-Site Scripting Vulnerabilities 25 WEB Aung Khant
2014-12-12   IBM Tivoli Service Automation Manager 7.2.4 - Remote Code Execution 23 WEB Jakub Palaczynski
2011-07-28   Sitecore CMS 6.4.1 - 'url' Open Redirection 26 WEB Tom Neaves
2011-07-28   HP Network Automation 9.10 - SQL Injection 28 WEB anonymous
2011-07-25   CobraScripts Trading Marketplace Script - 'cid' SQL Injection 24 WEB Ehsan_Hp200
2015-02-05   Magento Server MAGMI Plugin - Multiple Vulnerabilities 26 WEB SECUPENT
2015-02-04   Pragyan CMS 3.0 - SQL Injection 28 WEB Steffen Rösemann
2011-07-27   PHPJunkYard GBook 1.6/1.7 - Multiple Cross-Site Scripting Vulnerabilities 26 WEB High-Tech Bridge SA
2011-07-27   MBoard 1.3 - 'url' Open Redirection 25 WEB High-Tech Bridge SA
2011-07-26   Support Incident Tracker (SiT!) 3.63 p1 - 'tasks.php?selected[]' SQL Injection 28 WEB Yuri Goltsev
2011-07-26   Support Incident Tracker (SiT!) 3.63 p1 - 'search.php?search_string' SQL Injection 26 WEB Yuri Goltsev
2011-07-26   Support Incident Tracker (SiT!) 3.63 p1 - 'billable_incidents.php?sites[]' SQL Injection 23 WEB Yuri Goltsev
2011-07-26   Support Incident Tracker (SiT!) 3.63 p1 - 'report_marketing.php?exc[]' SQL Injection 28 WEB Yuri Goltsev
2011-07-25   Joomla! Component com_virtualmoney 1.5 - SQL Injection 26 WEB FL0RiX
2015-02-03   Hewlett-Packard (HP) UCMDB - JMX-Console Authentication Bypass 30 WEB Hans-Martin Muench
2015-02-03   ManageEngine Desktop Central 9 Build 90087 - Cross-Site Request Forgery 28 WEB Mohamed Idris
2011-07-25   Willscript Recipes Website Script Silver Edition - 'viewRecipe.php' SQL Injection 29 WEB Lazmania61
2011-07-25   Online Grades 3.2.5 - Multiple Cross-Site Scripting Vulnerabilities 26 WEB Gjoko Krstic
2011-07-25   Godly Forums - 'id' SQL Injection 28 WEB 3spi0n
2011-07-21   Synergy Software - 'id' SQL Injection 24 WEB Ehsan_Hp200
2011-07-20   Cyberoam UTM - Multiple Cross-Site Scripting Vulnerabilities 26 WEB Patrick Webster
2011-07-20   Tiki Wiki CMS Groupware 7.2 - 'snarf_ajax.php' Cross-Site Scripting 23 WEB High-Tech Bridge SA
2011-07-20   Joomla! < 1.6.5 - Multiple Cross-Site Scripting Vulnerabilities 28 WEB YGN Ethical Hacker Group
2015-02-02   Sefrengo CMS 1.6.1 - Multiple SQL Injections 30 WEB ITAS Team
2011-07-11   WordPress Plugin bSuite 4.0.7 - Multiple HTML Injection Vulnerabilities 25 WEB IHTeam
2011-07-17   BlueSoft Social Networking CMS - SQL Injection 28 WEB Lazmania61
2011-07-18   BlueSoft (Multiple Products) - Multiple SQL Injections 22 WEB Lazmania61
2011-07-15   AJ Classifieds - 'listingid' SQL Injection 36 WEB Lazmania61
2011-07-15   Joomla! Component com_newssearch - SQL Injection 24 WEB Robert Cooper
2011-07-15   Joomla! Component Controller - 'Itemid' SQL Injection 26 WEB SOLVER
2011-07-15   Joomla! Component com_hospital - SQL Injection 28 WEB SOLVER
2011-07-15   Joomla! Component Juicy Gallery - 'picId' SQL Injection 24 WEB SOLVER
2011-07-15   Joomla! Component Foto - 'id_categoria' SQL Injection 28 WEB SOLVER
2011-07-15   Easy Estate Rental - 's_location' SQL Injection 26 WEB Lazmania61
2011-07-15   Auto Web Toolbox - 'id' SQL Injection 25 WEB Lazmania61
2015-01-24   NPDS CMS REvolution-13 - SQL Injection 25 WEB Narendra Bhati
2011-07-29   Chyrp 2.x swfupload Extension - 'upload_handler.php' Arbitrary File Upload / Arbitrary PHP Code Exec 28 WEB Wireghoul
2011-07-29   Chyrp 2.x - '/includes/lib/gz.php?File' Traversal Arbitrary File Access 24 WEB Wireghoul
2011-07-29   Chyrp 2.x - 'action' Traversal Local File Inclusion 28 WEB Wireghoul
2011-07-13   Chyrp 2.x - '/includes/JavaScript.php?action' Cross-Site Scripting 28 WEB Wireghoul
2011-07-13   Chyrp 2.x - '/admin/help.php' Multiple Cross-Site Scripting Vulnerabilities 27 WEB Wireghoul
2011-07-13   TCExam 11.2.x - Multiple Cross-Site Scripting Vulnerabilities 27 WEB Gjoko Krstic
2011-07-12   Flowplayer 3.2.7 - 'linkUrl' Cross-Site Scripting 25 WEB Szymon Gruszecki
2011-07-12   Sphider 1.3.x - Admin Panel Multiple SQL Injections 25 WEB Karthik R
2015-01-29   ManageEngine Firewall Analyzer 8.0 - Directory Traversal / Cross-Site Scripting 30 WEB Ertebat Gostar Co
2011-07-11   ICMusic 1.2 - 'music_id' SQL Injection 29 WEB kaMtiEz
2011-07-11   Prontus CMS - 'page' Cross-Site Scripting 26 WEB Zerial
2011-07-08   Joomla! Component com_voj - SQL Injection 26 WEB CoBRa_21
2011-07-05   Classified Script - c-BrowseClassified Cross-Site Scripting 26 WEB Raghavendra Karthik D
2011-07-03   eTAWASOL - 'id' SQL Injection 22 WEB Bl4ck.Viper
2011-07-02   Paliz Portal - Cross-Site Scripting / Multiple SQL Injections 29 WEB Net.Edit0r
2011-07-05   Joomla! Component com_jr_tfb - 'Controller' Local File Inclusion 27 WEB FL0RiX
2014-11-11   WordPress Plugin Photo Gallery 1.2.5 - Unrestricted Arbitrary File Upload 26 WEB Kacper Szurek
2015-01-26   Symantec Data Center Security - Multiple Vulnerabilities 23 WEB SEC Consult
2015-01-26   ferretCMS 1.0.4-alpha - Multiple Vulnerabilities 29 WEB Steffen Rösemann
2015-01-26   jclassifiedsmanager - Multiple Vulnerabilities 28 WEB Sarath Nair
2015-01-26   ManageEngine EventLog Analyzer 9.0 - Directory Traversal / Cross-Site Scripting 34 WEB Ertebat Gostar Co
2015-01-26   SWFupload 2.5.0 - Cross Frame Scripting (XFS) 27 WEB MindCracker
2015-01-26   PHP Webquest 2.6 - SQL Injection 25 WEB jordan root
2015-01-26   ManageEngine ServiceDesk Plus 9.0 < Build 9031 - User Privileges Management 29 WEB Rewterz - Research Group
2015-01-26   Barracuda Networks Cloud Series - Filter Bypass 31 WEB Vulnerability-Lab
2015-01-26   Mangallam CMS - SQL Injection 26 WEB Vulnerability-Lab
2011-06-28   Flatpress 0.1010.1 - Multiple Cross-Site Scripting Vulnerabilities 25 WEB High-Tech Bridge SA
2011-06-28   Joomla! 1.6.3 - Multiple Cross-Site Scripting Vulnerabilities 26 WEB Aung Khant
2011-06-27   WordPress Plugin Pretty Link Lite 1.4.56 - Multiple SQL Injections 27 WEB MaKyOtOx
2015-01-22   ManageEngine ServiceDesk Plus 9.0 - User Enumeration 30 WEB Muhammad Ahmed Siddiqui
2015-01-22   ManageEngine ServiceDesk Plus 9.0 - SQL Injection 25 WEB Muhammad Ahmed Siddiqui
2011-06-27   Mambo 4.6.x - Multiple Cross-Site Scripting Vulnerabilities 31 WEB Aung Khant
2011-06-27   Joomla! Component com_morfeoshow - 'idm' SQL Injection 26 WEB Th3.xin0x
2011-06-23   Nodesforum - '_nodesforum_node' SQL Injection 28 WEB Andrea Bocchetti
2015-01-19   WordPress Plugin Cforms 14.7 - Remote Code Execution 27 WEB Zakhar
2015-01-22   ecommerceMajor - SQL Injection / Authentication Bypass 24 WEB Manish Tanwar
2011-06-23   Sitemagic CMS - 'SMTpl' Directory Traversal 21 WEB Andrea Bocchetti
2011-06-22   FanUpdate 3.0 - 'pageTitle' Cross-Site Scripting 29 WEB High-Tech Bridge SA
2011-06-22   Eshop Manager - Multiple SQL Injections 27 WEB Number 7
2011-06-22   H3C ER5100 - Authentication Bypass 25 WEB 128bit
2011-06-21   Sitemagic CMS 2010.04.17 - 'SMExt' Cross-Site Scripting 24 WEB Gjoko Krstic
2011-06-18   Taha Portal 3.2 - 'sitemap.php' Cross-Site Scripting 29 WEB Bl4ck.Viper
2011-06-18   Immophp 1.1.1 - Cross-Site Scripting / SQL Injection 24 WEB KedAns-Dz
2011-06-19   Nibbleblog 3 - Multiple SQL Injections 27 WEB KedAns-Dz
2011-06-15   MyBloggie 2.1.6 - HTML Injection / SQL Injection 25 WEB Robin Verton
2011-06-15   miniblog 1.0 - Multiple Cross-Site Scripting Vulnerabilities 23 WEB High-Tech Bridge SA
2011-06-14   vBTube 1.2.9 - 'vBTube.php' Multiple Cross-Site Scripting Vulnerabilities 26 WEB Mr.ThieF
2015-01-20   vBulletin vBSSO Single Sign-On 1.4.14 - SQL Injection 23 WEB Technidev
2015-01-21   ArticleFR CMS 3.0.5 - Arbitrary File Upload 25 WEB TranDinhTien
2015-01-21   ArticleFR CMS 3.0.5 - SQL Injection 25 WEB TranDinhTien
2011-06-13   PHP-Nuke 8.3 - 'upload.php' Arbitrary File Upload (2) 23 WEB pentesters.ir
2011-06-13   PHP-Nuke 8.3 - 'upload.php' Arbitrary File Upload (1) 23 WEB pentesters.ir
2011-06-13   Microsoft Lync Server 2010 - 'ReachJoin.aspx' Remote Command Injection 24 WEB Mark Lachniet
2011-06-13   WebFileExplorer 3.6 - 'user' / 'pass' SQL Injection 24 WEB pentesters.ir
2015-01-20   WordPress Plugin Pixarbay Images 2.3 - Multiple Vulnerabilities 26 WEB Hans-Martin Muench