|
2011-05-02
|
|
LDAP Account Manager 3.4.0 - 'selfserviceSaveOk' Cross-Site Scripting
|
9 |
WEB
|
AutoSec Tools
|
|
2011-05-02
|
|
LANSA aXes Web Terminal TN5250 - 'axes_default.css' Cross-Site Scripting
|
9 |
WEB
|
Patrick Webster
|
|
2011-04-30
|
|
Tine 2.0 - 'vbook.php' Cross-Site Scripting
|
9 |
WEB
|
AutoSec Tools
|
|
2011-04-28
|
|
ClanSphere 2011.0 - Local File Inclusion / Arbitrary File Upload
|
8 |
WEB
|
KedAns-Dz
|
|
2015-01-03
|
|
e107 2 Bootstrap CMS - Cross-Site Scripting
|
11 |
WEB
|
Ahmet Agar / 0x97
|
|
2011-04-28
|
|
phpGraphy 0.9.13b - 'theme_dir' Cross-Site Scripting
|
8 |
WEB
|
High-Tech Bridge SA
|
|
2011-04-25
|
|
eyeOS 1.9.0.2 - Image File Handling HTML Injection
|
8 |
WEB
|
Alberto Ortega
|
|
2011-04-28
|
|
BackupPC 3.x - 'index.cgi' Multiple Cross-Site Scripting Vulnerabilities
|
10 |
WEB
|
High-Tech Bridge SA
|
|
2011-04-27
|
|
Kusaba X 0.9 - Multiple Cross-Site Scripting Vulnerabilities
|
10 |
WEB
|
Emilio Pinna
|
|
2011-04-28
|
|
WordPress Plugin WP Photo Album 1.5.1 - 'id' Cross-Site Scripting
|
8 |
WEB
|
High-Tech Bridge SA
|
|
2011-04-28
|
|
WordPress Plugin Daily Maui Photo Widget 0.2 - Multiple Cross-Site Scripting Vulnerabilities
|
11 |
WEB
|
High-Tech Bridge SA
|
|
2011-04-27
|
|
Cisco Unified Communications Manager 8.5 - 'xmldirectorylist.jsp' Multiple SQL Injections
|
9 |
WEB
|
Alberto Revelli
|
|
2015-01-01
|
|
Absolut Engine 1.73 - Multiple Vulnerabilities
|
9 |
WEB
|
Steffen Rösemann
|
|
2011-04-27
|
|
up.time Software 5 - Administration Interface Remote Authentication Bypass
|
10 |
WEB
|
James Burton
|
|
2011-04-27
|
|
Joostina (Multiple Components) - SQL Injection
|
8 |
WEB
|
KedAns-Dz
|
|
2011-04-26
|
|
Football Website Manager 1.1 - SQL Injection / Multiple HTML Injection Vulnerabilities
|
8 |
WEB
|
RoAd_KiLlEr
|
|
2011-04-26
|
|
PHP F1 Max's Photo Album - 'showimage.php' Cross-Site Scripting
|
8 |
WEB
|
High-Tech Bridge SA
|
|
2011-04-26
|
|
phpList 2.10.x - 'email' Cross-Site Scripting
|
8 |
WEB
|
High-Tech Bridge SA
|
|
2011-04-26
|
|
WordPress Plugin WP Ajax Recent Posts 1.0.1 - 'do' Cross-Site Scripting
|
8 |
WEB
|
High-Tech Bridge SA
|
|
2011-04-26
|
|
Noah's Classifieds 5.0.4 - 'index.php' Multiple HTML Injection Vulnerabilities
|
9 |
WEB
|
High-Tech Bridge SA
|
|
2014-12-31
|
|
Social Microblogging PRO 1.5 - Persistent Cross-Site Scripting
|
10 |
WEB
|
Halil Dalabasmaz
|
|
2011-04-26
|
|
html-edit CMS 3.1.x - 'html_output' Cross-Site Scripting
|
10 |
WEB
|
KedAns-Dz
|
|
2011-04-26
|
|
WordPress Plugin Sermon Browser 0.43 - Cross-Site Scripting / SQL Injection
|
9 |
WEB
|
Ma3sTr0-Dz
|
|
2011-04-25
|
|
TemaTres 1.3 - '_search_expresion' Cross-Site Scripting
|
11 |
WEB
|
AutoSec Tools
|
|
2011-04-22
|
|
Nuke Evolution Xtreme 2.0 - Local File Inclusion / SQL Injection
|
12 |
WEB
|
KedAns-Dz
|
|
2011-04-22
|
|
Dolibarr ERP/CRM 3.0 - Local File Inclusion / Cross-Site Scripting
|
10 |
WEB
|
AutoSec Tools
|
|
2011-04-21
|
|
LightNEasy 3.2.3 - 'userhandle' Cookie SQL Injection
|
9 |
WEB
|
AutoSec Tools
|
|
2011-04-22
|
|
todoyu 2.0.8 - 'lang' Cross-Site Scripting
|
8 |
WEB
|
AutoSec Tools
|
|
2011-04-21
|
|
ZenPhoto 1.4.0.3 - '_zp_themeroot' Multiple Cross-Site Scripting Vulnerabilities
|
8 |
WEB
|
High-Tech Bridge SA
|
|
2011-04-21
|
|
SyCtel Design - 'menu' Multiple Local File Inclusions
|
9 |
WEB
|
Ashiyane Digital Security Team
|
|
2011-04-20
|
|
Automagick Tube Script 1.4.4 - 'module' Cross-Site Scripting
|
10 |
WEB
|
Kurd-Team
|
|
2011-04-19
|
|
webSPELL 4.2.2a - Multiple Cross-Site Scripting Vulnerabilities
|
11 |
WEB
|
High-Tech Bridge SA
|
|
2011-04-19
|
|
ChatLakTurk PHP Botlu Video - 'ara.php' Cross-Site Scripting
|
9 |
WEB
|
kurdish hackers team
|
|
2011-04-19
|
|
Dalbum 1.43 - 'editini.php' Cross-Site Scripting
|
7 |
WEB
|
High-Tech Bridge SA
|
|
2011-04-19
|
|
WordPress Plugin WP-StarsRateBox 1.1 - 'j' SQL Injection
|
9 |
WEB
|
High-Tech Bridge SA
|
|
2011-04-19
|
|
Ultra Marketing Enterprises CMS and Cart - Multiple SQL Injections
|
11 |
WEB
|
eXeSoul
|
|
2011-04-18
|
|
XOOPS 2.5 - 'imagemanager.php' Local File Inclusion
|
10 |
WEB
|
KedAns-Dz
|
|
2011-04-19
|
|
CRESUS - 'recette_detail.php' SQL Injection
|
11 |
WEB
|
GrayHatz Security Group
|
|
2011-04-18
|
|
Joomla! Component com_phocadownload - Local File Inclusion
|
9 |
WEB
|
KedAns-Dz
|
|
2011-04-16
|
|
ChillyCMS 1.2.1 - Multiple Remote File Inclusions
|
10 |
WEB
|
KedAns-Dz
|
|
2014-12-27
|
|
Easy File Sharing Web Server 6.8 - Persistent Cross-Site Scripting
|
9 |
WEB
|
Sick Psycko
|
|
2014-12-27
|
|
PMB 4.1.3 - (Authenticated) SQL Injection
|
11 |
WEB
|
xd4rker dark
|
|
2014-12-27
|
|
phpList 3.0.6/3.0.10 - SQL Injection
|
10 |
WEB
|
Vulnerability-Lab
|
|
2014-12-27
|
|
Pimcore CMS 2.3.0/3.0 - SQL Injection
|
10 |
WEB
|
Vulnerability-Lab
|
|
2011-04-16
|
|
4Images 1.7.9 - Multiple Remote File Inclusions / SQL Injections
|
10 |
WEB
|
KedAns-Dz
|
|
2011-04-15
|
|
PhoenixCMS 1.7 - Local File Inclusion / SQL Injection
|
8 |
WEB
|
KedAns-Dz
|
|
2011-04-15
|
|
RunCMS Module Partners - 'id' SQL Injection
|
8 |
WEB
|
KedAns-Dz
|
|
2011-04-14
|
|
Qianbo Enterprise Web Site Management System - 'Keyword' Cross-Site Scripting
|
10 |
WEB
|
d3c0der
|
|
2011-04-15
|
|
Agahi Advertisement CMS 4.0 - 'view_ad.php' SQL Injection
|
8 |
WEB
|
Sepehr Security Team
|
|
2011-04-14
|
|
PhpAlbum.net 0.4.1-14_fix06 - 'var3' Remote Command Execution
|
8 |
WEB
|
High-Tech Bridge SA
|
|
2011-04-12
|
|
Website Baker 2.8.1 - Multiple SQL Injections
|
11 |
WEB
|
High-Tech Bridge SA
|
|
2011-04-12
|
|
Plogger 1.0 RC1 - 'gallery_name' Cross-Site Scripting
|
8 |
WEB
|
High-Tech Bridge SA
|
|
2011-04-12
|
|
WordPress Theme The Gazette Edition 2.9.4 - Multiple Vulnerabilities
|
8 |
WEB
|
MustLive
|
|
2011-04-12
|
|
WordPress Plugin Spellchecker 3.1 - '/general.php' Local/Remote File Inclusion
|
9 |
WEB
|
Dr Trojan
|
|
2014-12-24
|
|
Lazarus Guestbook 1.22 - Multiple Vulnerabilities
|
9 |
WEB
|
TaurusOmar
|
|
2011-04-09
|
|
eForum 1.1 - 'eforum.php' Arbitrary File Upload
|
9 |
WEB
|
QSecure
|
|
2011-04-11
|
|
WordPress Theme Live Wire 2.3.1 - Multiple Vulnerabilities
|
9 |
WEB
|
MustLive
|
|
2011-04-11
|
|
Etki Video PRO 2.0 - 'kategori.asp?cat' SQL Injection
|
8 |
WEB
|
Kurd-Team
|
|
2011-04-11
|
|
Etki Video PRO 2.0 - 'izle.asp?id' SQL Injection
|
9 |
WEB
|
Kurd-Team
|
|
2011-04-11
|
|
Dimac CMS 1.3 XS - 'default.asp' SQL Injection
|
8 |
WEB
|
KedAns-Dz
|
|
2011-04-08
|
|
1024 CMS 1.1.0 Beta - Multiple Input Validation Vulnerabilities
|
10 |
WEB
|
QSecure & Demetris Papapetrou
|
|
2011-04-07
|
|
eGroupWare 1.8.1 - 'test.php' Cross-Site Scripting
|
9 |
WEB
|
AutoSec Tools
|
|
2014-12-23
|
|
NetIQ Access Manager 4.0 SP1 - Multiple Vulnerabilities
|
8 |
WEB
|
SEC Consult
|
|
2014-12-23
|
|
SysAid Server - Arbitrary File Disclosure
|
10 |
WEB
|
Bernhard Mueller
|
|
2014-12-23
|
|
PHPMyRecipes 1.2.2 - 'browse.php?category' SQL Injection
|
8 |
WEB
|
Manish Tanwar
|
|
2014-12-22
|
|
Lotus Mail Encryption Server 2.1.0.1 (Protector for Mail) - Local File Inclusion / Remote Code Execu
|
12 |
WEB
|
Patrick Webster
|
|
2014-12-19
|
|
Codiad 2.4.3 - Multiple Vulnerabilities
|
9 |
WEB
|
TaurusOmar
|
|
2014-12-19
|
|
GQ File Manager 0.2.5 - Multiple Vulnerabilities
|
10 |
WEB
|
TaurusOmar
|
|
2014-12-19
|
|
Piwigo 2.7.2 - Multiple Vulnerabilities
|
9 |
WEB
|
TaurusOmar
|
|
2014-12-19
|
|
ProjectSend r561 - Multiple Vulnerabilities
|
9 |
WEB
|
TaurusOmar
|
|
2014-12-19
|
|
MiniBB 3.1 - Blind SQL Injection
|
11 |
WEB
|
Kacper Szurek
|
|
2014-12-19
|
|
Cacti Superlinks Plugin 1.4-2 - SQL Injection / Local File Inclusion
|
10 |
WEB
|
Wireghoul
|
|
2011-04-07
|
|
vTiger CRM 5.2.1 - 'vtigerservice.php' Cross-Site Scripting
|
10 |
WEB
|
AutoSec Tools
|
|
2011-04-07
|
|
Omer Portal 3.220060425 - 'arama_islem.asp' Cross-Site Scripting
|
11 |
WEB
|
kurdish hackers team
|
|
2011-04-08
|
|
PrestaShop 1.3.6 - 'cms.php' Remote File Inclusion
|
10 |
WEB
|
KedAns-Dz
|
|
2011-04-08
|
|
vTiger CRM 5.2.1 - 'sortfieldsjson.php' Local File Inclusion
|
10 |
WEB
|
John Leitch
|
|
2011-04-06
|
|
Redmine 1.0.1/1.1.1 - 'projects/hg-hellowword/news/' Cross-Site Scripting
|
10 |
WEB
|
Mesut Timur
|
|
2011-04-06
|
|
TextPattern 4.2 - 'index.php' Cross-Site Scripting
|
10 |
WEB
|
kurdish hackers team
|
|
2011-04-04
|
|
XOOPS 2.5 - 'banners.php' Multiple Local File Inclusions
|
10 |
WEB
|
KedAns-Dz
|
|
2011-04-05
|
|
UseBB 1.0.11 - 'admin.php' Local File Inclusion
|
10 |
WEB
|
High-Tech Bridge SA
|
|
2011-04-05
|
|
Eleanor CMS - Cross-Site Scripting / Multiple SQL Injections
|
10 |
WEB
|
High-Tech Bridge SA
|
|
2011-04-04
|
|
Yaws-Wiki 1.88-1 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
|
11 |
WEB
|
Michael Brooks
|
|
2011-04-04
|
|
Gazelle CMS 1.0 - Cross-Site Scripting / SQL Injection
|
10 |
WEB
|
kurdish hackers team
|
|
2011-04-03
|
|
DoceboLms 4.0.4 - 'index.php' Multiple HTML Injection Vulnerabilities
|
12 |
WEB
|
LiquidWorm
|
|
2011-04-03
|
|
WordPress Plugin Placester 0.1 - 'ajax_action' Cross-Site Scripting
|
11 |
WEB
|
John Leitch
|
|
2011-04-04
|
|
WordPress Plugin WPwizz AdWizz Plugin 1.0 - 'link' Cross-Site Scripting
|
11 |
WEB
|
John Leitch
|
|
2011-04-04
|
|
MyBB 1.4/1.6 - Multiple Vulnerabilities
|
12 |
WEB
|
MustLive
|
|
2011-04-04
|
|
PHP-Fusion - 'article_id' SQL Injection
|
10 |
WEB
|
KedAns-Dz
|
|
2014-12-17
|
|
CIK Telecom VoIP Router SVG6000RW - Privilege Escalation / Command Execution
|
13 |
WEB
|
Chako
|
|
2011-04-01
|
|
AWCM 2.x - 'search.php' Cross-Site Scripting
|
11 |
WEB
|
Antu Sanadi
|
|
2014-12-16
|
|
CMS Papoo 6.0.0 Rev. 4701 - Persistent Cross-Site Scripting
|
12 |
WEB
|
Steffen Rösemann
|
|
2011-03-31
|
|
Collabtive 0.6.5 - Multiple Remote Input Validation Vulnerabilities
|
11 |
WEB
|
High-Tech Bridge SA
|
|
2011-03-31
|
|
InTerra Blog Machine 1.84 - 'subject' HTML Injection
|
13 |
WEB
|
High-Tech Bridge SA
|
|
2011-03-30
|
|
ICJobSite 1.1 - 'pid' SQL Injection
|
12 |
WEB
|
RoAd_KiLlEr
|
|
2014-12-15
|
|
WordPress Plugin WP Symposium 14.11 - Arbitrary File Upload
|
10 |
WEB
|
Claudio Viviani
|
|
2014-12-15
|
|
ResourceSpace 6.4.5976 - Cross-Site Scripting / SQL Injection / Insecure Cookie Handling
|
10 |
WEB
|
Adler Freiheit
|
|
2014-12-15
|
|
PHPads 213607 - Authentication Bypass / Password Change
|
13 |
WEB
|
Shaker msallm
|
|
2014-12-15
|
|
WordPress Plugin Download Manager 2.7.4 - Remote Code Execution
|
11 |
WEB
|
Claudio Viviani
|
|
2014-12-15
|
|
Soitec SmartEnergy 1.4 - SCADA Login SQL Injection / Authentication Bypass
|
13 |
WEB
|
LiquidWorm
|
|
2014-12-15
|
|
GLPI 0.85 - Blind SQL Injection
|
11 |
WEB
|
Kacper Szurek
|
|
2011-03-30
|
|
YaCOMAS 0.3.6 OpenCMS - Multiple Cross-Site Scripting Vulnerabilities
|
10 |
WEB
|
Pr@fesOr X
|
|
2011-03-30
|
|
GuppY 4.6.14 - 'lng' Multiple SQL Injections
|
9 |
WEB
|
kurdish hackers team
|
|
2011-03-29
|
|
XOOPS - 'view_photos.php' Cross-Site Scripting
|
8 |
WEB
|
KedAns-Dz
|
|
2011-03-29
|
|
Tracks 1.7.2 - URI Cross-Site Scripting
|
9 |
WEB
|
Mesut Timur
|
|
2011-03-29
|
|
Spitfire 1.0.3x - 'cms_username' Cross-Site Scripting
|
9 |
WEB
|
High-Tech Bridge SA
|
|
2011-03-29
|
|
osCSS 2.1 - Multiple Cross-Site Scripting / Local File Inclusions
|
10 |
WEB
|
AutoSec Tools
|
|
2011-03-28
|
|
Claroline 1.10 - Multiple HTML Injection Vulnerabilities
|
12 |
WEB
|
AutoSec Tools
|
|
2014-12-10
|
|
OpenEMR 4.1.2(7) - Multiple SQL Injections
|
11 |
WEB
|
Portcullis
|
|
2011-03-28
|
|
webEdition CMS 6.1.0.2 - 'DOCUMENT_ROOT' Local File Inclusion
|
10 |
WEB
|
eidelweiss
|
|
2011-03-28
|
|
Alkacon OpenCMS 7.5.x - Multiple Cross-Site Scripting Vulnerabilities
|
10 |
WEB
|
antisnatchor
|
|
2011-03-27
|
|
OrangeHRM 2.6.2 - 'jobVacancy.php' Cross-Site Scripting
|
9 |
WEB
|
AutoSec Tools
|
|
2014-12-10
|
|
Humhub 0.10.0-rc.1 - Multiple Persistent Cross-Site Scripting Vulnerabilities
|
9 |
WEB
|
Jos Wetzels_ Emiel Florijn
|
|
2014-12-10
|
|
Humhub 0.10.0-rc.1 - SQL Injection
|
7 |
WEB
|
Jos Wetzels_ Emiel Florijn
|
|
2011-03-27
|
|
Cetera eCommerce - Multiple Cross-Site Scripting / SQL Injections
|
10 |
WEB
|
MustLive
|
|
2014-12-09
|
|
Flat Calendar 1.1 - HTML Injection
|
10 |
WEB
|
ZoRLu Bugrahan
|
|
2014-12-09
|
|
WordPress Plugin Symposium 14.10 - SQL Injection
|
8 |
WEB
|
Kacper Szurek
|
|
2011-03-25
|
|
Family Connections 2.3.2 - 'subject' HTML Injection
|
9 |
WEB
|
Zero Science Lab
|
|
2011-03-24
|
|
netjukebox 4.01B/5.25 - 'skin' Cross-Site Scripting
|
9 |
WEB
|
AutoSec Tools
|
|
2011-03-24
|
|
Ripe Website Manager 1.1 - Cross-Site Scripting / Multiple SQL Injections
|
10 |
WEB
|
High-Tech Bridge SA
|
|
2011-03-24
|
|
GrapeCity Data Dynamics Reports 1.6.2084.14 - Multiple Cross-Site Scripting Vulnerabilities
|
9 |
WEB
|
Dionach
|
|
2011-03-24
|
|
MC Content Manager 10.1.1 - Multiple Cross-Site Scripting Vulnerabilities
|
7 |
WEB
|
MustLive
|
|
2014-12-08
|
|
WordPress Plugin Ajax Store Locator 1.2 - Arbitrary File Download
|
8 |
WEB
|
Claudio Viviani
|
|
2014-12-08
|
|
Free Article Submissions 1.0 - SQL Injection
|
8 |
WEB
|
BarrabravaZ
|
|
2014-12-08
|
|
PBBoard CMS - Persistent Cross-Site Scripting
|
8 |
WEB
|
Manish Tanwar
|
|
2014-12-08
|
|
IceHrm 7.1 - Multiple Vulnerabilities
|
7 |
WEB
|
LiquidWorm
|