Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2014-10-28   Enalean Tuleap 7.2 - XML External Entity File Disclosure 15 WEB Portcullis
2014-10-28   Enalean Tuleap 7.4.99.5 - Blind SQL Injection 15 WEB Portcullis
2010-12-13   Joomla! Component com_redirect 1.5.19 - Local File Inclusion 15 WEB jos_ali_joe
2010-12-10   Joomla! Component com_mailto - Multiple Cross-Site Scripting Vulnerabilities 13 WEB MustLive
2010-12-10   slickMsg 0.7-alpha - 'top.php' Cross-Site Scripting 18 WEB Aliaksandr Hartsuyeu
2010-12-10   BizDir 05.10 - 'f_srch' Cross-Site Scripting 16 WEB Aliaksandr Hartsuyeu
2010-12-10   ManageEngine EventLog Analyzer 6.1 - Multiple Cross-Site Scripting Vulnerabilities 13 WEB Rob Kraus
2010-12-10   Joomla! Component JExtensions Property Finder - 'sf_id' SQL Injection 13 WEB FL0RiX
2010-12-09   Joomla! Component Jeformcr - 'id' SQL Injection 17 WEB FL0RiX
2010-12-09   PHP State - 'id' SQL Injection 15 WEB jos_ali_joe
2010-12-09   net2ftp 0.98 (stable) - '/admin1.template.php' Local/Remote File Inclusion 14 WEB Marcin Ressel
2010-12-09   WWWThread 5.0.8 Pro - 'showflat.pl' Cross-Site Scripting 18 WEB Aliaksandr Hartsuyeu
2010-12-07   WordPress Plugin Twitter Feed - 'url' Cross-Site Scripting 22 WEB John Leitch
2014-10-27   Folder Plus 2.5.1 iOS - Persistent Cross-Site Scripting 17 WEB Vulnerability-Lab
2014-10-27   WebDisk+ 2.1 iOS - Code Execution 16 WEB Vulnerability-Lab
2014-10-27   Incredible PBX 2.0.6.5.0 - Remote Command Execution 15 WEB Simo Ben Youssef
2014-10-27   Mulesoft ESB Runtime 3.5.1 - Privilege Escalation 14 WEB Brandon Perry
2014-10-27   HP Operations Agent - Cross-Site Scripting iFrame Injection 15 WEB Matt Schmidt
2014-10-27   CBN CH6640E/CG6640E Wireless Gateway Series - Multiple Vulnerabilities 16 WEB LiquidWorm
2014-10-27   WordPress Plugin CP Multi View Event Calendar 1.01 - SQL Injection 14 WEB Claudio Viviani
2010-12-08   Drupal Module Embedded Media Field/Media 6.x : Video Flotsam/Media: Audio Flotsam - Multiple Vulnera 18 WEB Justin Klein Keane
2010-12-08   WordPress Plugin Safe Search - 'v1' Cross-Site Scripting 17 WEB John Leitch
2010-12-08   WordPress Plugin Processing Embed 0.5 - 'pluginurl' Cross-Site Scripting 19 WEB John Leitch
2010-12-07   SolarWinds Orion Network Performance Monitor (NPM) 10.1 - Multiple Cross-Site Scripting Vulnerabilit 18 WEB x0skel
2010-12-07   Zimplit CMS - 'English_manual_version_2.php?client' Cross-Site Scripting 17 WEB High-Tech Bridge SA
2010-12-07   Zimplit CMS - 'zimplit.php?File' Cross-Site Scripting 18 WEB High-Tech Bridge SA
2010-12-07   Aigaion 1.3.4 - 'ID' SQL Injection 15 WEB KnocKout
2014-10-25   WordPress Plugin 0.9.7 / Joomla! Component 2.0.0 Creative Contact Form - Arbitrary File Upload 17 WEB Claudio Viviani
2014-10-25   Dell EqualLogic Storage - Directory Traversal 17 WEB XLabs Security
2014-10-25   Magento Server MAGMI Plugin 0.7.17a - Remote File Inclusion 19 WEB Parvinder Bhasin
2010-12-06   Alguest 1.1 - 'start' SQL Injection 21 WEB Aliaksandr Hartsuyeu
2010-12-04   Techno Dreams FAQ Manager Package 1.0 - 'faqlist.asp' SQL Injection 16 WEB R4dc0re
2010-12-04   Techno Dreams Articles & Papers Package 2.0 - 'ArticlesTablelist.asp' SQL Injection 15 WEB R4dc0re
2014-10-23   Dell SonicWALL Gms 7.2.x - Code Injection 17 WEB Vulnerability-Lab
2014-10-23   Axway Secure Transport 5.1 SP2 - Arbitrary File Upload (via Cross-Site Request Forgery) 16 WEB Emmanuel Law
2010-12-03   DotNetNuke 5.5.1 - 'InstallWizard.aspx' Cross-Site Scripting 17 WEB Richard Brain
2010-12-03   Alguest 1.1 - Multiple Cookie Authentication Bypass Vulnerabilities 14 WEB Aliaksandr Hartsuyeu
2010-12-02   Contenido CMS 4.8.12 - Multiple Cross-Site Scripting Vulnerabilities 13 WEB High-Tech Bridge SA
2014-10-23   Feng Office 1.7.4 - Cross-Site Scripting 18 WEB AutoSec Tools
2014-10-23   Feng Office 1.7.4 - Arbitrary File Upload 13 WEB AutoSec Tools
2014-10-22   DotNetNuke DNNspot Store 3.0.0 - Arbitrary File Upload (Metasploit) 16 WEB Glafkos Charalambous
2014-10-22   File Manager 4.2.10 iOS - Code Execution 15 WEB Vulnerability-Lab
2014-10-22   iFunBox Free 1.1 iOS - Local File Inclusion 15 WEB Vulnerability-Lab
2010-12-02   Joomla! Component Annuaire - 'index.php?id' SQL Injection 14 WEB Ashiyane Digital Security Team
2010-11-30   AWStats 6.x - Apache Tomcat Configuration File Arbitrary Command Execution 20 WEB StenoPlasma
2010-11-30   BugTracker.NET 3.4.4 - SQL Injection / Cross-Site Scripting 16 WEB BugTracker.NET
2010-11-26   SmartBox - 'page_id' SQL Injection 12 WEB KnocKout
2010-11-26   E-lokaler CMS 2 - Admin Login Multiple SQL Injections 16 WEB ali_err0r
2010-11-30   Joomla! Component com_storedirectory - 'id' SQL Injection 13 WEB XroGuE
2010-11-29   Car Portal 2.0 - 'car_make' Cross-Site Scripting 17 WEB Underground Stockholm
2010-11-30   Joomla! Component Catalogue - SQL Injection / Local File Inclusion 15 WEB XroGuE
2010-11-29   Wernhart Guestbook 2001.03.28 - Multiple SQL Injections 15 WEB Aliaksandr Hartsuyeu
2010-11-29   4homepages 4Images 1.7.x - 'categories.php' SQL Injection 16 WEB Ahmed Atif
2010-11-26   Easy Banner 2009.05.18 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 20 WEB Aliaksandr Hartsuyeu
2010-11-26   Easy Banner 2009.05.18 - '/member.php' Multiple SQL Injection / Authentication Bypass 18 WEB Aliaksandr Hartsuyeu
2010-11-24   SimpLISTic SQL 2.0 - 'email.cgi' Cross-Site Scripting 19 WEB Aliaksandr Hartsuyeu
2010-11-23   ZYXEL P-660R-T1 V2 - 'HomeCurrent_Date' Cross-Site Scripting 15 WEB Usman Saeed
2010-11-22   Hot Links SQL 3.2 - 'report.cgi' SQL Injection 19 WEB Aliaksandr Hartsuyeu
2010-11-18   CompactCMS 1.4.1 - Multiple Cross-Site Scripting Vulnerabilities (1) 18 WEB High-Tech Bridge SA
2010-11-16   Raised Eyebrow CMS - 'venue.php' SQL Injection 14 WEB Cru3l.b0y
2010-11-16   Simea CMS - 'index.php' SQL Injection 18 WEB Cru3l.b0y
2010-11-13   OpenWrt 10.03 - Multiple Cross-Site Scripting Vulnerabilities 13 WEB dave b
2014-10-17   Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (2) 17 WEB Dustin Dörr
2014-10-17   Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User) 19 WEB Claudio Viviani
2010-11-09   Ricoh Web Image Monitor 2.03 - Cross-Site Scripting 18 WEB thelightcosine
2010-11-10   WeBid 0.85P1 - Multiple Input Validation Vulnerabilities 21 WEB John Leitch
2010-11-10   PHPShop 2.1 EE - 'name_new' Cross-Site Scripting 18 WEB MustLive
2014-10-16   Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (1) 15 WEB stopstene
2014-10-15   Indeed Job Search 2.5 iOS API - Multiple Vulnerabilities 16 WEB Vulnerability-Lab
2010-11-08   WordPress Plugin jRSS Widget 1.1.1 - 'url' Information Disclosure 12 WEB John Leitch
2010-11-08   WordPress Plugin Vodpod Video Gallery 3.1.5 - 'vodpod_gallery_thumbs.php' Cross-Site Scripting 16 WEB John Leitch
2010-11-08   WordPress Plugin SEO Tools 3.0 - 'file' Directory Traversal 19 WEB John Leitch
2010-11-08   WordPress Plugin WP Survey And Quiz Tool 1.2.1 - Cross-Site Scripting 14 WEB John Leitch
2010-11-08   WordPress Plugin FeedList 2.61.01 - 'handler_image.php' Cross-Site Scripting 13 WEB John Leitch
2010-11-05   Joomla! Component AutoArticles 3000 - SQL Injection 15 WEB jos_ali_joe
2010-11-05   Angel Learning Management System 7.3 - 'pdaview.asp' Cross-Site Scripting 17 WEB Wesley Kerfoot
2014-10-14   SEO Control Panel 3.6.0 - (Authenticated) SQL Injection 16 WEB Tiago Carvalho
2014-10-14   Tenda A32 Router - Cross-Site Request Forgery 14 WEB zixian
2014-10-14   YourMembers Plugin - Blind SQL Injection 14 WEB TranDinhTien
2014-10-14   Change CMS 3.6.8 - Multiple Cross-Site Request Forgery Vulnerabilities 14 WEB Krusty Hack
2014-10-14   Croogo 2.0.0 - Multiple Persistent Cross-Site Scripting Vulnerabilities 17 WEB LiquidWorm
2014-10-14   Croogo 2.0.0 - Arbitrary PHP Code Execution 14 WEB LiquidWorm
2014-10-14   PayPal Inc BB #85 MB iOS 4.6 - Authentication Bypass 12 WEB Vulnerability-Lab
2014-10-14   Bosch Security Systems DVR 630/650/670 Series - Multiple Vulnerabilities 16 WEB dun
2010-11-05   Joomla! 1.5.x - SQL Error Information Disclosure 14 WEB YGN Ethical Hacker Group
2010-11-02   Online Work Order Suite - Login SQL Injection 16 WEB VSN
2010-11-01   Douran Portal 3.9.7.55 - Arbitrary File Upload / Cross-Site Scripting 13 WEB ITSecTeam
2010-10-30   CMS WebManager-Pro 7.4.3 - Cross-Site Scripting / SQL Injection 15 WEB MustLive
2010-11-01   WordPress Plugin cformsII 11.5/13.1 - 'lib_ajax.php' Multiple Cross-Site Scripting Vulnerabilities 16 WEB Wagner Elias
2010-11-01   SmartOptimizer - Null Character Remote Information Disclosure 21 WEB Francois Harvey
2010-11-01   Elastix 2.0.2 - Multiple Cross-Site Scripting Vulnerabilities 15 WEB dave b
2009-05-25   Intergo Arcade Trade Script 1.0 - 'q' Cross-Site Scripting 16 WEB SmOk3
2009-05-29   212Cafe WebBoard 2.90 Beta - 'view.php' Directory Traversal 16 WEB MrDoug
2010-10-27   W-Agora 4.1.5 - Local File Inclusion / Cross-Site Scripting 17 WEB MustLive
2010-10-28   Feindura CMS Groupware - Multiple Local File Inclusion / Cross-Site Scripting Vulnerabilities 15 WEB Justanotherhacker.com
2009-06-03   i-Gallery 3.4/4.1 - 'streamfile.asp' Multiple Directory Traversal Vulnerabilities 15 WEB Stefano Angaran
2010-10-27   LES PACKS - 'ID' SQL Injection 16 WEB Cru3l.b0y
2010-10-27   Joomla! Component Projects 'com_projects' - SQL Injection / Local File Inclusion 16 WEB jos_ali_joe
2009-06-03   Flatnux 2009-03-27 - Multiple Cross-Site Scripting Vulnerabilities 15 WEB intern0t
2009-06-03   Sitecore CMS 6.0.0 rev. 090120 - 'default.aspx' Cross-Site Scripting 16 WEB intern0t
2014-10-09   Nessus Web UI 2.3.3 - Persistent Cross-Site Scripting 20 WEB Frank Lycops
2014-10-09   DrayTek VigorACS SI 1.3.0 - Multiple Vulnerabilities 19 WEB Digital Misfits
2014-10-09   BMC Track-It! - Multiple Vulnerabilities 18 WEB Pedro Ribeiro
2014-10-08   WordPress Plugin Creative Contact Form 0.9.7 - Arbitrary File Upload 19 WEB Gianni Angelozzi
2014-10-07   HttpCombiner ASP.NET - Remote File Disclosure 13 WEB Le Ngoc Son
2009-07-16   Skybluecanvas 1.1 r237 - 'admin.php' Directory Traversal 14 WEB MaXe
2014-10-06   Ultra Electronics 7.2.0.19/7.4.0.7 - Multiple Vulnerabilities 13 WEB OSI Security
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ibm/wpm/webseal?method' Cross-Site Scripting 14 WEB IBM
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ibm/wpm/user?method' Cross-Site Scripting 14 WEB IBM
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ibm/wpm/rule?method' Cross-Site Scripting 15 WEB IBM
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ibm/wpm/pop?method' Cross-Site Scripting 15 WEB IBM
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ibm/wpm/os?method' Cross-Site Scripting 14 WEB IBM
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ibm/wpm/gsogroup?method' Cross-Site Scripting 14 WEB IBM
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ibm/wpm/gso?method' Cross-Site Scripting 19 WEB IBM
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ibm/wpm/group?method' Cross-Site Scripting 14 WEB IBM
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ibm/wpm/domain?method' Cross-Site Scripting 18 WEB IBM
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ibm/wpm/acl?method' Cross-Site Scripting 22 WEB IBM
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ivt/ivtserver?parm1' Cross-Site Scripting 16 WEB IBM
2010-10-22   W-Agora 4.2.1 - 'search.php?bn' Cross-Site Scripting 13 WEB MustLive
2010-10-22   W-Agora 4.2.1 - 'search.php3?bn' Traversal Local File Inclusion 15 WEB MustLive
2009-08-24   Radvision Scopia - '/entry/index.jsp' Cross-Site Scripting 14 WEB Francesco Bianchino
2009-08-20   PHP Scripts Now Riddles - '/riddles/list.php?catid' SQL Injection 17 WEB Moudi
2009-08-20   PHP Scripts Now Riddles - '/riddles/results.php?searchQuery' Cross-Site Scripting 16 WEB Moudi
2014-10-06   Bash CGI - 'Shellshock' Remote Command Injection (Metasploit) 16 WEB Fady Mohammed Osman
2009-07-20   PHP Scripts Now (Multiple Products) - 'bios.php?rank' SQL Injection 17 WEB 599eme Man