Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2014-12-27   PMB 4.1.3 - (Authenticated) SQL Injection 32 WEB xd4rker dark
2014-12-27   phpList 3.0.6/3.0.10 - SQL Injection 29 WEB Vulnerability-Lab
2014-12-27   Pimcore CMS 2.3.0/3.0 - SQL Injection 32 WEB Vulnerability-Lab
2011-04-16   4Images 1.7.9 - Multiple Remote File Inclusions / SQL Injections 35 WEB KedAns-Dz
2011-04-15   PhoenixCMS 1.7 - Local File Inclusion / SQL Injection 28 WEB KedAns-Dz
2011-04-15   RunCMS Module Partners - 'id' SQL Injection 26 WEB KedAns-Dz
2011-04-14   Qianbo Enterprise Web Site Management System - 'Keyword' Cross-Site Scripting 28 WEB d3c0der
2011-04-15   Agahi Advertisement CMS 4.0 - 'view_ad.php' SQL Injection 24 WEB Sepehr Security Team
2011-04-14   PhpAlbum.net 0.4.1-14_fix06 - 'var3' Remote Command Execution 31 WEB High-Tech Bridge SA
2011-04-12   Website Baker 2.8.1 - Multiple SQL Injections 33 WEB High-Tech Bridge SA
2011-04-12   Plogger 1.0 RC1 - 'gallery_name' Cross-Site Scripting 25 WEB High-Tech Bridge SA
2011-04-12   WordPress Theme The Gazette Edition 2.9.4 - Multiple Vulnerabilities 31 WEB MustLive
2011-04-12   WordPress Plugin Spellchecker 3.1 - '/general.php' Local/Remote File Inclusion 27 WEB Dr Trojan
2014-12-24   Lazarus Guestbook 1.22 - Multiple Vulnerabilities 41 WEB TaurusOmar
2011-04-09   eForum 1.1 - 'eforum.php' Arbitrary File Upload 29 WEB QSecure
2011-04-11   WordPress Theme Live Wire 2.3.1 - Multiple Vulnerabilities 29 WEB MustLive
2011-04-11   Etki Video PRO 2.0 - 'kategori.asp?cat' SQL Injection 27 WEB Kurd-Team
2011-04-11   Etki Video PRO 2.0 - 'izle.asp?id' SQL Injection 29 WEB Kurd-Team
2011-04-11   Dimac CMS 1.3 XS - 'default.asp' SQL Injection 30 WEB KedAns-Dz
2011-04-08   1024 CMS 1.1.0 Beta - Multiple Input Validation Vulnerabilities 31 WEB QSecure & Demetris Papapetrou
2011-04-07   eGroupWare 1.8.1 - 'test.php' Cross-Site Scripting 30 WEB AutoSec Tools
2014-12-23   NetIQ Access Manager 4.0 SP1 - Multiple Vulnerabilities 36 WEB SEC Consult
2014-12-23   SysAid Server - Arbitrary File Disclosure 29 WEB Bernhard Mueller
2014-12-23   PHPMyRecipes 1.2.2 - 'browse.php?category' SQL Injection 30 WEB Manish Tanwar
2014-12-22   Lotus Mail Encryption Server 2.1.0.1 (Protector for Mail) - Local File Inclusion / Remote Code Execu 31 WEB Patrick Webster
2014-12-19   Codiad 2.4.3 - Multiple Vulnerabilities 28 WEB TaurusOmar
2014-12-19   GQ File Manager 0.2.5 - Multiple Vulnerabilities 32 WEB TaurusOmar
2014-12-19   Piwigo 2.7.2 - Multiple Vulnerabilities 28 WEB TaurusOmar
2014-12-19   ProjectSend r561 - Multiple Vulnerabilities 30 WEB TaurusOmar
2014-12-19   MiniBB 3.1 - Blind SQL Injection 31 WEB Kacper Szurek
2014-12-19   Cacti Superlinks Plugin 1.4-2 - SQL Injection / Local File Inclusion 34 WEB Wireghoul
2011-04-07   vTiger CRM 5.2.1 - 'vtigerservice.php' Cross-Site Scripting 31 WEB AutoSec Tools
2011-04-07   Omer Portal 3.220060425 - 'arama_islem.asp' Cross-Site Scripting 36 WEB kurdish hackers team
2011-04-08   PrestaShop 1.3.6 - 'cms.php' Remote File Inclusion 36 WEB KedAns-Dz
2011-04-08   vTiger CRM 5.2.1 - 'sortfieldsjson.php' Local File Inclusion 30 WEB John Leitch
2011-04-06   Redmine 1.0.1/1.1.1 - 'projects/hg-hellowword/news/' Cross-Site Scripting 30 WEB Mesut Timur
2011-04-06   TextPattern 4.2 - 'index.php' Cross-Site Scripting 25 WEB kurdish hackers team
2011-04-04   XOOPS 2.5 - 'banners.php' Multiple Local File Inclusions 29 WEB KedAns-Dz
2011-04-05   UseBB 1.0.11 - 'admin.php' Local File Inclusion 28 WEB High-Tech Bridge SA
2011-04-05   Eleanor CMS - Cross-Site Scripting / Multiple SQL Injections 25 WEB High-Tech Bridge SA
2011-04-04   Yaws-Wiki 1.88-1 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities 28 WEB Michael Brooks
2011-04-04   Gazelle CMS 1.0 - Cross-Site Scripting / SQL Injection 25 WEB kurdish hackers team
2011-04-03   DoceboLms 4.0.4 - 'index.php' Multiple HTML Injection Vulnerabilities 29 WEB LiquidWorm
2011-04-03   WordPress Plugin Placester 0.1 - 'ajax_action' Cross-Site Scripting 26 WEB John Leitch
2011-04-04   WordPress Plugin WPwizz AdWizz Plugin 1.0 - 'link' Cross-Site Scripting 27 WEB John Leitch
2011-04-04   MyBB 1.4/1.6 - Multiple Vulnerabilities 30 WEB MustLive
2011-04-04   PHP-Fusion - 'article_id' SQL Injection 26 WEB KedAns-Dz
2014-12-17   CIK Telecom VoIP Router SVG6000RW - Privilege Escalation / Command Execution 29 WEB Chako
2011-04-01   AWCM 2.x - 'search.php' Cross-Site Scripting 29 WEB Antu Sanadi
2014-12-16   CMS Papoo 6.0.0 Rev. 4701 - Persistent Cross-Site Scripting 27 WEB Steffen Rösemann
2011-03-31   Collabtive 0.6.5 - Multiple Remote Input Validation Vulnerabilities 26 WEB High-Tech Bridge SA
2011-03-31   InTerra Blog Machine 1.84 - 'subject' HTML Injection 30 WEB High-Tech Bridge SA
2011-03-30   ICJobSite 1.1 - 'pid' SQL Injection 27 WEB RoAd_KiLlEr
2014-12-15   WordPress Plugin WP Symposium 14.11 - Arbitrary File Upload 25 WEB Claudio Viviani
2014-12-15   ResourceSpace 6.4.5976 - Cross-Site Scripting / SQL Injection / Insecure Cookie Handling 26 WEB Adler Freiheit
2014-12-15   PHPads 213607 - Authentication Bypass / Password Change 26 WEB Shaker msallm
2014-12-15   WordPress Plugin Download Manager 2.7.4 - Remote Code Execution 28 WEB Claudio Viviani
2014-12-15   Soitec SmartEnergy 1.4 - SCADA Login SQL Injection / Authentication Bypass 34 WEB LiquidWorm
2014-12-15   GLPI 0.85 - Blind SQL Injection 33 WEB Kacper Szurek
2011-03-30   YaCOMAS 0.3.6 OpenCMS - Multiple Cross-Site Scripting Vulnerabilities 32 WEB Pr@fesOr X
2011-03-30   GuppY 4.6.14 - 'lng' Multiple SQL Injections 24 WEB kurdish hackers team
2011-03-29   XOOPS - 'view_photos.php' Cross-Site Scripting 26 WEB KedAns-Dz
2011-03-29   Tracks 1.7.2 - URI Cross-Site Scripting 25 WEB Mesut Timur
2011-03-29   Spitfire 1.0.3x - 'cms_username' Cross-Site Scripting 30 WEB High-Tech Bridge SA
2011-03-29   osCSS 2.1 - Multiple Cross-Site Scripting / Local File Inclusions 29 WEB AutoSec Tools
2011-03-28   Claroline 1.10 - Multiple HTML Injection Vulnerabilities 31 WEB AutoSec Tools
2014-12-10   OpenEMR 4.1.2(7) - Multiple SQL Injections 28 WEB Portcullis
2011-03-28   webEdition CMS 6.1.0.2 - 'DOCUMENT_ROOT' Local File Inclusion 27 WEB eidelweiss
2011-03-28   Alkacon OpenCMS 7.5.x - Multiple Cross-Site Scripting Vulnerabilities 26 WEB antisnatchor
2011-03-27   OrangeHRM 2.6.2 - 'jobVacancy.php' Cross-Site Scripting 25 WEB AutoSec Tools
2014-12-10   Humhub 0.10.0-rc.1 - Multiple Persistent Cross-Site Scripting Vulnerabilities 28 WEB Jos Wetzels_ Emiel Florijn
2014-12-10   Humhub 0.10.0-rc.1 - SQL Injection 25 WEB Jos Wetzels_ Emiel Florijn
2011-03-27   Cetera eCommerce - Multiple Cross-Site Scripting / SQL Injections 28 WEB MustLive
2014-12-09   Flat Calendar 1.1 - HTML Injection 30 WEB ZoRLu Bugrahan
2014-12-09   WordPress Plugin Symposium 14.10 - SQL Injection 25 WEB Kacper Szurek
2011-03-25   Family Connections 2.3.2 - 'subject' HTML Injection 27 WEB Zero Science Lab
2011-03-24   netjukebox 4.01B/5.25 - 'skin' Cross-Site Scripting 25 WEB AutoSec Tools
2011-03-24   Ripe Website Manager 1.1 - Cross-Site Scripting / Multiple SQL Injections 35 WEB High-Tech Bridge SA
2011-03-24   GrapeCity Data Dynamics Reports 1.6.2084.14 - Multiple Cross-Site Scripting Vulnerabilities 26 WEB Dionach
2011-03-24   MC Content Manager 10.1.1 - Multiple Cross-Site Scripting Vulnerabilities 22 WEB MustLive
2014-12-08   WordPress Plugin Ajax Store Locator 1.2 - Arbitrary File Download 26 WEB Claudio Viviani
2014-12-08   Free Article Submissions 1.0 - SQL Injection 25 WEB BarrabravaZ
2014-12-08   PBBoard CMS - Persistent Cross-Site Scripting 24 WEB Manish Tanwar
2014-12-08   IceHrm 7.1 - Multiple Vulnerabilities 26 WEB LiquidWorm
2011-03-21   PluggedOut Blog 1.9.9 - 'year' Cross-Site Scripting 26 WEB kurdish hackers team
2011-03-21   Newsportal 0.37 - 'post.php' Cross-Site Scripting 28 WEB kurdish hackers team
2011-03-21   Online store PHP script - Multiple Cross-Site Scripting / SQL Injections 26 WEB kurdish hackers team
2011-03-19   Web Poll Pro 1.0.3 - 'error' HTML Injection 30 WEB Hector.x90
2011-03-18   XOOPS 2.x - Multiple Cross-Site Scripting Vulnerabilities 25 WEB Aung Khant
2011-03-17   WordPress Plugin Rating-Widget 1.3.1 - Multiple Cross-Site Scripting Vulnerabilities 23 WEB Todor Donev
2011-03-17   WordPress Plugin Sodahead Polls 2.0.2 - Multiple Cross-Site Scripting Vulnerabilities 32 WEB High-Tech Bridge SA
2014-12-05   PBBoard CMS 3.0.1 - SQL Injection 26 WEB Tran Dinh Tien
2011-03-16   AplikaMedia CMS - 'page_info.php' SQL Injection 22 WEB H3X
2011-03-10   Wikiwig 5.01 - Cross-Site Scripting / HTML Injection 28 WEB AutoSec Tools
2011-03-15   SugarCRM 6.1.1 - Information Disclosure 26 WEB RedTeam Pentesting GmbH
2014-12-04   Advertise With Pleasure! (AWP) 6.6 - SQL Injection 25 WEB Robert Cooper
2014-12-04   Technicolor DT5130 2.05.C29GV - Multiple Vulnerabilities 24 WEB Crash
2014-12-03   WordPress Plugin CodeArt Google MP3 Player - File Disclosure Download 24 WEB QK14 Team
2014-12-03   WordPress Plugin Cart66 Lite eCommerce 1.5.1.17 - Blind SQL Injection 28 WEB Kacper Szurek
2011-03-14   BoutikOne - 'rss_top10.php?lang' SQL Injection 27 WEB cdx.security
2011-03-14   BoutikOne - 'rss_promo.php?lang' SQL Injection 30 WEB cdx.security
2011-03-14   BoutikOne - 'rss_flash.php?lang' SQL Injection 24 WEB cdx.security
2011-03-14   BoutikOne - 'rss_news.php?lang' SQL Injection 29 WEB cdx.security
2011-03-14   BoutikOne - 'search.php' Multiple SQL Injections 24 WEB cdx.security
2011-03-14   BoutikOne - 'list.php?path' SQL Injection 21 WEB cdx.security
2011-03-14   BoutikOne - 'categorie.php?path' SQL Injection 20 WEB cdx.security
2014-12-03   WordPress Plugin Google Document Embedder 2.5.16 - 'mysql_real_escpae_string' Bypass SQL Injection 26 WEB Securely (Yoo Hee man)
2011-03-04   Lms Web Ensino - Multiple Input Validation Vulnerabilities 24 WEB waKKu
2014-12-02   TYPO3 Extension ke DomPDF - Remote Code Execution 25 WEB RedTeam Pentesting
2014-12-02   EntryPass N5200 - Credentials Exposure 21 WEB RedTeam Pentesting
2014-12-02   WordPress Plugin Nextend Facebook Connect 1.4.59 - Cross-Site Scripting 27 WEB Kacper Szurek
2011-03-10   Cosmoshop 10.05.00 - Multiple Cross-Site Scripting / SQL Injections 27 WEB High-Tech Bridge SA
2011-03-10   Xinha 0.96 - 'spell-check-savedicts.php' Multiple HTML Injection Vulnerabilities 24 WEB John Leitch
2011-03-10   WordPress Plugin Lazyest Gallery 1.0.26 - 'image' Cross-Site Scripting 26 WEB High-Tech Bridge SA
2011-03-08   Ruubikcms 1.0.3 - 'head.php' Cross-Site Scripting 25 WEB Khashayar Fereidani
2011-03-08   WordPress Plugin 1 Flash Gallery 0.2.5 - Cross-Site Scripting / SQL Injection 29 WEB High-Tech Bridge SA
2011-03-08   WordPress Plugin PhotoSmash Galleries 1.0.x - 'action' Cross-Site Scripting 23 WEB High-Tech Bridge SA
2014-12-02   SQL Buddy 1.3.3 - Remote Code Execution 29 WEB Fady Mohammed Osman
2014-12-02   ProjectSend r-561 - Arbitrary File Upload 24 WEB Fady Mohammed Osman
2014-12-02   Prolink PRN2001 - Multiple Vulnerabilities 24 WEB Herman Groeneveld
2011-03-08   WordPress Plugin Inline Gallery 0.3.9 - 'do' Cross-Site Scripting 26 WEB High-Tech Bridge SA
2011-03-08   WS Interactive Automne 4.1 - '/admin/upload-controler.php' Arbitrary File Upload 23 WEB AutoSec Tools
2011-03-03   Interleave 5.5.0.2 - 'basicstats.php' Multiple Cross-Site Scripting Vulnerabilities 28 WEB AutoSec Tools
2011-03-07   Kodak InSite 5.5.2 - '/Pages/login.aspx?Language' Cross-Site Scripting 29 WEB Dionach
2011-03-07   Kodak InSite 5.5.2 - '/Troubleshooting/DiagnosticReport.asp?HeaderWarning' Cross-Site Scripting 26 WEB Dionach