Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2011-03-31   InTerra Blog Machine 1.84 - 'subject' HTML Injection 24 WEB High-Tech Bridge SA
2011-03-30   ICJobSite 1.1 - 'pid' SQL Injection 20 WEB RoAd_KiLlEr
2014-12-15   WordPress Plugin WP Symposium 14.11 - Arbitrary File Upload 19 WEB Claudio Viviani
2014-12-15   ResourceSpace 6.4.5976 - Cross-Site Scripting / SQL Injection / Insecure Cookie Handling 18 WEB Adler Freiheit
2014-12-15   PHPads 213607 - Authentication Bypass / Password Change 21 WEB Shaker msallm
2014-12-15   WordPress Plugin Download Manager 2.7.4 - Remote Code Execution 21 WEB Claudio Viviani
2014-12-15   Soitec SmartEnergy 1.4 - SCADA Login SQL Injection / Authentication Bypass 27 WEB LiquidWorm
2014-12-15   GLPI 0.85 - Blind SQL Injection 27 WEB Kacper Szurek
2011-03-30   YaCOMAS 0.3.6 OpenCMS - Multiple Cross-Site Scripting Vulnerabilities 26 WEB Pr@fesOr X
2011-03-30   GuppY 4.6.14 - 'lng' Multiple SQL Injections 16 WEB kurdish hackers team
2011-03-29   XOOPS - 'view_photos.php' Cross-Site Scripting 19 WEB KedAns-Dz
2011-03-29   Tracks 1.7.2 - URI Cross-Site Scripting 17 WEB Mesut Timur
2011-03-29   Spitfire 1.0.3x - 'cms_username' Cross-Site Scripting 24 WEB High-Tech Bridge SA
2011-03-29   osCSS 2.1 - Multiple Cross-Site Scripting / Local File Inclusions 24 WEB AutoSec Tools
2011-03-28   Claroline 1.10 - Multiple HTML Injection Vulnerabilities 23 WEB AutoSec Tools
2014-12-10   OpenEMR 4.1.2(7) - Multiple SQL Injections 22 WEB Portcullis
2011-03-28   webEdition CMS 6.1.0.2 - 'DOCUMENT_ROOT' Local File Inclusion 22 WEB eidelweiss
2011-03-28   Alkacon OpenCMS 7.5.x - Multiple Cross-Site Scripting Vulnerabilities 19 WEB antisnatchor
2011-03-27   OrangeHRM 2.6.2 - 'jobVacancy.php' Cross-Site Scripting 19 WEB AutoSec Tools
2014-12-10   Humhub 0.10.0-rc.1 - Multiple Persistent Cross-Site Scripting Vulnerabilities 23 WEB Jos Wetzels_ Emiel Florijn
2014-12-10   Humhub 0.10.0-rc.1 - SQL Injection 20 WEB Jos Wetzels_ Emiel Florijn
2011-03-27   Cetera eCommerce - Multiple Cross-Site Scripting / SQL Injections 22 WEB MustLive
2014-12-09   Flat Calendar 1.1 - HTML Injection 22 WEB ZoRLu Bugrahan
2014-12-09   WordPress Plugin Symposium 14.10 - SQL Injection 19 WEB Kacper Szurek
2011-03-25   Family Connections 2.3.2 - 'subject' HTML Injection 19 WEB Zero Science Lab
2011-03-24   netjukebox 4.01B/5.25 - 'skin' Cross-Site Scripting 19 WEB AutoSec Tools
2011-03-24   Ripe Website Manager 1.1 - Cross-Site Scripting / Multiple SQL Injections 25 WEB High-Tech Bridge SA
2011-03-24   GrapeCity Data Dynamics Reports 1.6.2084.14 - Multiple Cross-Site Scripting Vulnerabilities 21 WEB Dionach
2011-03-24   MC Content Manager 10.1.1 - Multiple Cross-Site Scripting Vulnerabilities 14 WEB MustLive
2014-12-08   WordPress Plugin Ajax Store Locator 1.2 - Arbitrary File Download 19 WEB Claudio Viviani
2014-12-08   Free Article Submissions 1.0 - SQL Injection 18 WEB BarrabravaZ
2014-12-08   PBBoard CMS - Persistent Cross-Site Scripting 17 WEB Manish Tanwar
2014-12-08   IceHrm 7.1 - Multiple Vulnerabilities 18 WEB LiquidWorm
2011-03-21   PluggedOut Blog 1.9.9 - 'year' Cross-Site Scripting 22 WEB kurdish hackers team
2011-03-21   Newsportal 0.37 - 'post.php' Cross-Site Scripting 19 WEB kurdish hackers team
2011-03-21   Online store PHP script - Multiple Cross-Site Scripting / SQL Injections 20 WEB kurdish hackers team
2011-03-19   Web Poll Pro 1.0.3 - 'error' HTML Injection 19 WEB Hector.x90
2011-03-18   XOOPS 2.x - Multiple Cross-Site Scripting Vulnerabilities 18 WEB Aung Khant
2011-03-17   WordPress Plugin Rating-Widget 1.3.1 - Multiple Cross-Site Scripting Vulnerabilities 18 WEB Todor Donev
2011-03-17   WordPress Plugin Sodahead Polls 2.0.2 - Multiple Cross-Site Scripting Vulnerabilities 22 WEB High-Tech Bridge SA
2014-12-05   PBBoard CMS 3.0.1 - SQL Injection 18 WEB Tran Dinh Tien
2011-03-16   AplikaMedia CMS - 'page_info.php' SQL Injection 17 WEB H3X
2011-03-10   Wikiwig 5.01 - Cross-Site Scripting / HTML Injection 21 WEB AutoSec Tools
2011-03-15   SugarCRM 6.1.1 - Information Disclosure 21 WEB RedTeam Pentesting GmbH
2014-12-04   Advertise With Pleasure! (AWP) 6.6 - SQL Injection 19 WEB Robert Cooper
2014-12-04   Technicolor DT5130 2.05.C29GV - Multiple Vulnerabilities 18 WEB Crash
2014-12-03   WordPress Plugin CodeArt Google MP3 Player - File Disclosure Download 18 WEB QK14 Team
2014-12-03   WordPress Plugin Cart66 Lite eCommerce 1.5.1.17 - Blind SQL Injection 22 WEB Kacper Szurek
2011-03-14   BoutikOne - 'rss_top10.php?lang' SQL Injection 21 WEB cdx.security
2011-03-14   BoutikOne - 'rss_promo.php?lang' SQL Injection 20 WEB cdx.security
2011-03-14   BoutikOne - 'rss_flash.php?lang' SQL Injection 17 WEB cdx.security
2011-03-14   BoutikOne - 'rss_news.php?lang' SQL Injection 19 WEB cdx.security
2011-03-14   BoutikOne - 'search.php' Multiple SQL Injections 17 WEB cdx.security
2011-03-14   BoutikOne - 'list.php?path' SQL Injection 14 WEB cdx.security
2011-03-14   BoutikOne - 'categorie.php?path' SQL Injection 16 WEB cdx.security
2014-12-03   WordPress Plugin Google Document Embedder 2.5.16 - 'mysql_real_escpae_string' Bypass SQL Injection 20 WEB Securely (Yoo Hee man)
2011-03-04   Lms Web Ensino - Multiple Input Validation Vulnerabilities 19 WEB waKKu
2014-12-02   TYPO3 Extension ke DomPDF - Remote Code Execution 17 WEB RedTeam Pentesting
2014-12-02   EntryPass N5200 - Credentials Exposure 14 WEB RedTeam Pentesting
2014-12-02   WordPress Plugin Nextend Facebook Connect 1.4.59 - Cross-Site Scripting 20 WEB Kacper Szurek
2011-03-10   Cosmoshop 10.05.00 - Multiple Cross-Site Scripting / SQL Injections 20 WEB High-Tech Bridge SA
2011-03-10   Xinha 0.96 - 'spell-check-savedicts.php' Multiple HTML Injection Vulnerabilities 19 WEB John Leitch
2011-03-10   WordPress Plugin Lazyest Gallery 1.0.26 - 'image' Cross-Site Scripting 19 WEB High-Tech Bridge SA
2011-03-08   Ruubikcms 1.0.3 - 'head.php' Cross-Site Scripting 18 WEB Khashayar Fereidani
2011-03-08   WordPress Plugin 1 Flash Gallery 0.2.5 - Cross-Site Scripting / SQL Injection 21 WEB High-Tech Bridge SA
2011-03-08   WordPress Plugin PhotoSmash Galleries 1.0.x - 'action' Cross-Site Scripting 18 WEB High-Tech Bridge SA
2014-12-02   SQL Buddy 1.3.3 - Remote Code Execution 21 WEB Fady Mohammed Osman
2014-12-02   ProjectSend r-561 - Arbitrary File Upload 19 WEB Fady Mohammed Osman
2014-12-02   Prolink PRN2001 - Multiple Vulnerabilities 17 WEB Herman Groeneveld
2011-03-08   WordPress Plugin Inline Gallery 0.3.9 - 'do' Cross-Site Scripting 21 WEB High-Tech Bridge SA
2011-03-08   WS Interactive Automne 4.1 - '/admin/upload-controler.php' Arbitrary File Upload 18 WEB AutoSec Tools
2011-03-03   Interleave 5.5.0.2 - 'basicstats.php' Multiple Cross-Site Scripting Vulnerabilities 18 WEB AutoSec Tools
2011-03-07   Kodak InSite 5.5.2 - '/Pages/login.aspx?Language' Cross-Site Scripting 21 WEB Dionach
2011-03-07   Kodak InSite 5.5.2 - '/Troubleshooting/DiagnosticReport.asp?HeaderWarning' Cross-Site Scripting 21 WEB Dionach
2011-03-04   InterPhoto Image Gallery 2.4.2 - 'IPLANG' Local File Inclusion 19 WEB AutoSec Tools
2011-03-03   Pragyan CMS 3.0 Beta - Multiple Cross-Site Scripting Vulnerabilities 22 WEB High-Tech Bridge SA
2011-03-03   xtcModified 1.05 - Multiple HTML Injection / Cross-Site Scripting Vulnerabilities 22 WEB High-Tech Bridge SA
2011-03-03   phpWebSite 1.7.1 - 'local' Cross-Site Scripting 18 WEB AutoSec Tools
2011-03-03   Support Incident Tracker (SiT!) 3.62 - Multiple Cross-Site Scripting Vulnerabilities 19 WEB AutoSec Tools
2011-03-02   VidiScript - 'vp' Cross-Site Scripting 23 WEB NassRawI
2011-03-02   Forritun - Multiple SQL Injections 21 WEB eXeSoul
2011-02-28   SnapProof - 'retPageID' Cross-Site Scripting 23 WEB difficult 511
2011-02-28   WordPress Plugin BackWPup 1.4 - Multiple Information Disclosure Vulnerabilities 23 WEB Danilo Massa
2011-02-23   Drupal Module Cumulus 5.x-1.1/6.x-1.4 - 'tagcloud' Cross-Site Scripting 19 WEB MustLive
2014-11-28   xEpan 1.0.4 - Multiple Vulnerabilities 17 WEB Parikesit _ Kurawa
2011-02-23   WordPress Plugin YT-Audio 1.7 - 'v' Cross-Site Scripting 21 WEB AutoSec Tools
2011-02-23   WordPress Plugin ComicPress Manager 1.4.9 - 'lang' Cross-Site Scripting 18 WEB AutoSec Tools
2011-02-23   WordPress Plugin IGIT Posts Slider Widget 1.0 - 'src' Cross-Site Scripting 17 WEB AutoSec Tools
2011-02-25   glFusion 1.1.x/1.2.1 - 'users.php' SQL Injection 17 WEB H3X
2011-02-25   phpShop 0.8.1 - 'page' Cross-Site Scripting 19 WEB Aung Khant
2014-11-26   WordPress Plugin Slider REvolution 3.0.95 / Showbiz Pro 1.7.1 - Arbitrary File Upload 21 WEB Simo Ben Youssef
2014-11-26   Device42 WAN Emulator 2.3 - Ping Command Injection (Metasploit) 19 WEB Brandon Perry
2014-11-26   Device42 WAN Emulator 2.3 - Traceroute Command Injection (Metasploit) 20 WEB Brandon Perry
2014-11-26   xEpan 1.0.1 - Cross-Site Request Forgery 19 WEB High-Tech Bridge SA
2014-11-26   WordPress Plugin DB Backup - Arbitrary File Download 25 WEB Ashiyane Digital Security Team
2011-02-16   mySeatXT 0.164 - 'lang' Local File Inclusion 21 WEB AutoSec Tools
2011-02-22   Vanilla Forums 2.0.17.x - 'p' Cross-Site Scripting 20 WEB Aung Khant
2011-02-22   IBM Lotus Sametime Server 8.0 - 'stcenter.nsf' Cross-Site Scripting 23 WEB andrew
2011-02-22   WordPress Plugin GD Star Rating 1.9.7 - 'wpfn' Cross-Site Scripting 19 WEB High-Tech Bridge SA
2014-11-25   Arris VAP2500 - Authentication Bypass 20 WEB HeadlessZeke
2014-11-25   WordPress Plugin Google Document Embedder 2.5.14 - SQL Injection 18 WEB Kacper Szurek
2014-11-25   Crea8Social 1.3 - Persistent Cross-Site Scripting 19 WEB Halil Dalabasmaz
2014-11-25   PHPMyRecipes 1.2.2 - 'dosearch.php?words_exact' SQL Injection 19 WEB bard
2011-02-21   Batavi 1.0 - Multiple Local File Inclusion / Cross-Site Scripting Vulnerabilities 17 WEB AutoSec Tools
2011-02-18   WSN Guest 1.24 - 'wsnuser' Cookie SQL Injection 21 WEB Aliaksandr Hartsuyeu
2014-11-24   Advantech EKI-6340 - Command Injection 20 WEB Core Security
2011-02-15   Getsimple CMS 2.03 - 'upload-ajax.php' Arbitrary File Upload 20 WEB s3rg3770 & Chuzz
2011-02-15   Photopad 1.2 - Multiple Cross-Site Scripting Vulnerabilities 18 WEB High-Tech Bridge SA
2011-02-15   Wikipad 1.6.0 - Cross-Site Scripting / HTML Injection / Information Disclosure 17 WEB High-Tech Bridge SA
2011-02-15   Gollos 2.8 - Multiple Cross-Site Scripting Vulnerabilities 18 WEB High-Tech Bridge SA
2011-02-15   MG2 0.5.1 - Multiple Cross-Site Scripting Vulnerabilities 19 WEB LiquidWorm
2011-02-12   Dokeos 1.8.6 2 - 'style' Cross-Site Scripting 15 WEB AutoSec Tools
2014-11-24   WordPress Plugin DukaPress 2.5.2 - Directory Traversal 21 WEB Kacper Szurek
2014-11-24   RobotStats 1.0 - 'robot' SQL Injection 17 WEB ZoRLu Bugrahan
2011-02-09   Smarty Template Engine 2.6.9 - '$smarty.template' PHP Code Injection 19 WEB jonieske
2014-11-24   WordPress Plugin wpDataTables 1.5.3 - Arbitrary File Upload 19 WEB Claudio Viviani
2014-11-24   WordPress Plugin wpDataTables 1.5.3 - SQL Injection 17 WEB Claudio Viviani
2011-02-12   TaskFreak! 0.6.4 - 'rss.php' HTTP Referer Header Cross-Site Scripting 17 WEB LiquidWorm
2011-02-12   TaskFreak! 0.6.4 - 'print_list.php' Multiple Cross-Site Scripting Vulnerabilities 20 WEB LiquidWorm
2011-02-12   TaskFreak! 0.6.4 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 18 WEB LiquidWorm
2011-02-11   Drupal Module CAPTCHA - Security Bypass 15 WEB anonymous
2011-02-10   RunCMS 2.2.2 - 'register.php' SQL Injection 16 WEB High-Tech Bridge SA
2011-02-10   webERP 4.0.1 - 'InputSerialItemsFile.php' Arbitrary File Upload 18 WEB AutoSec Tools
2011-02-10   Dolphin 7.0.4 - Multiple Cross-Site Scripting Vulnerabilities 19 WEB AutoSec Tools
2011-02-10   ManageEngine ADSelfService Plus 4.4 - 'EmployeeSearch.cc' Multiple Cross-Site Scripting Vulnerabilit 16 WEB Core Security