Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2014-11-11   Subex Fms 7.4 - SQL Injection 26 WEB Anastasios Monachos
2014-11-10   WordPress Plugin / Joomla! Component XCloner - Multiple Vulnerabilities 24 WEB Larry W. Cashdollar
2014-11-10   Password Manager Pro / Pro MSP - Blind SQL Injection 29 WEB Pedro Ribeiro
2014-11-10   ManageEngine OpManager / Social IT Plus / IT360 - Multiple Vulnerabilities 27 WEB Pedro Ribeiro
2014-11-10   Barracuda - Multiple Unauthentication Logfile Downloads 25 WEB 4CKnowLedge
2014-11-10   PHP-Fusion 7.02.07 - SQL Injection 27 WEB XLabs Security
2014-11-10   WordPress Plugin Another WordPress Classifieds Plugin - SQL Injection 29 WEB dill
2014-11-10   ZTE ZXDSL 831CII - Insecure Direct Object Reference 29 WEB Paulos Yibelo
2014-11-10   phpSound Music Sharing Platform 1.0.5 - Multiple Cross-Site Scripting Vulnerabilities 30 WEB Halil Dalabasmaz
2014-11-10   Serenity Client Management Portal 1.0.1 - Multiple Vulnerabilities 26 WEB Halil Dalabasmaz
2014-11-10   vldPersonals 2.7 - Multiple Vulnerabilities 25 WEB Mr T
2011-01-11   CMS Tovar - 'tovar.php' SQL Injection 23 WEB jos_ali_joe
2011-01-08   Joostina 1.3 - 'index.php' Cross-Site Scripting 25 WEB MustLive
2011-01-10   WikLink 0.1.3 - Multiple SQL Injections 30 WEB Aliaksandr Hartsuyeu
2011-01-04   WonderCMS 0.3.3 - 'editText.php' Cross-Site Scripting 24 WEB High-Tech Bridge SA
2014-11-06   Symantec Endpoint Protection 12.1.4023.4080 - Multiple Vulnerabilities 26 WEB SEC Consult
2011-01-06   PHP MicroCMS 1.0.1 - 'page_text' Cross-Site Scripting 28 WEB High-Tech Bridge SA
2011-01-05   Openfire 3.6.4 - Multiple Cross-Site Scripting Vulnerabilities 32 WEB Walikar Riyaz Ahemed Dawalmalik
2011-01-05   BlogEngine.NET 1.6 - Directory Traversal / Information Disclosure 31 WEB Deniz Cevik
2011-01-06   Joomla! 1.0.x - 'ordering' Cross-Site Scripting 23 WEB Aung Khant
2011-01-05   WikLink 0.1.3 - 'getURL.php' SQL Injection 26 WEB Aliaksandr Hartsuyeu
2014-11-05   Mouse Media Script 1.6 - Persistent Cross-Site Scripting 25 WEB Halil Dalabasmaz
2014-11-05   MODx CMS 2.2.14 - Cross-Site Request Forgery Bypass / Reflected Cross-Site Scripting / Persistent Cr 26 WEB Narendra Bhati
2010-12-28   Coppermine Photo Gallery 1.5.10 - 'searchnew.php' Cross-Site Scripting 22 WEB waraxe
2010-12-28   Coppermine Photo Gallery 1.5.10 - 'help.php' Cross-Site Scripting 27 WEB waraxe
2010-12-26   CruxCMS 3.0 - Multiple Input Validation Vulnerabilities 29 WEB ToXiC
2014-11-03   Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Remote Code Execution) 30 WEB Stefan Horst
2010-12-27   LiveZilla 3.2.0.2 - 'Track' Module 'server.php' Cross-Site Scripting 24 WEB Ulisses Castro
2014-11-03   PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection 25 WEB Ryan King (Starfall)
2010-12-27   Pligg CMS 1.1.3 - 'range' SQL Injection 26 WEB Dr.NeT
2010-12-28   HotWeb Scripts HotWeb Rentals - 'PageId' SQL Injection 25 WEB non customers
2010-12-23   Social Share - 'search' Cross-Site Scripting 31 WEB Aliaksandr Hartsuyeu
2010-12-23   MyBB 1.6 - 'private.php?keywords' SQL Injection 27 WEB Aung Khant
2010-12-23   MyBB 1.6 - 'search.php?keywords' SQL Injection 25 WEB Aung Khant
2014-11-02   Esotalk CMS 1.0.0g4 - Cross-Site Scripting 26 WEB evi1m0
2010-12-10   Social Share - 'vote.php' HTTP Response Splitting 25 WEB Aliaksandr Hartsuyeu
2010-12-22   WordPress Plugin Accept Signups 0.1 - 'email' Cross-Site Scripting 29 WEB clshack
2010-12-22   Joomla! Component Classified - SQL Injection 28 WEB R4dc0re
2010-12-21   ImpressCMS 1.2.x - 'quicksearch_ContentContent' HTML Injection 25 WEB High-Tech Bridge SA
2010-12-21   WordPress Plugin Mediatricks Viva Thumbs - Multiple Information Disclosure Vulnerabilities 23 WEB Richard Brain
2010-12-21   Social Share - 'Username' SQL Injection 24 WEB Aliaksandr Hartsuyeu
2014-10-31   Who's Who Script - Cross-Site Request Forgery (Add Admin) 25 WEB ZoRLu Bugrahan
2014-10-31   ZTE Modem ZXDSL 531BIIV7.3.0f_D09_IN - Persistent Cross-Site Scripting 23 WEB Ravi Rajput
2014-10-31   Progress OpenEdge 11.2 - Directory Traversal 27 WEB XLabs Security
2010-12-21   Habari 0.6.5 - Multiple Cross-Site Scripting Vulnerabilities 27 WEB High-Tech Bridge SA
2010-12-21   OpenFiler - 'device' Cross-Site Scripting 30 WEB db.pub.mail
2010-12-21   FreeNAS 0.7.2.5543 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 24 WEB db.pub.mail
2010-12-20   Mafya Oyun Scrpti - 'profil.php' SQL Injection 26 WEB DeadLy DeMon
2010-12-20   Social Share - 'postid' SQL Injection 23 WEB Aliaksandr Hartsuyeu
2010-12-17   Social Share - Multiple Cross-Site Scripting Vulnerabilities 25 WEB Aliaksandr Hartsuyeu
2010-12-17   Radius Manager 3.6 - Multiple Cross-Site Scripting Vulnerabilities 27 WEB Rodrigo Rubira Branco
2010-12-16   PHPRS - 'model-kits.php' SQL Injection 24 WEB KnocKout
2010-12-15   Blog:CMS 4.2.1 e - Multiple HTML Injections / Cross-Site Scripting 25 WEB High-Tech Bridge SA
2010-12-15   HP Insight Diagnostics Online Edition 8.4 - 'search.php' Cross-Site Scripting 29 WEB Richard Brain
2014-10-29   MAARCH 1.4 - SQL Injection 26 WEB Adrien Thierry
2014-10-29   MAARCH 1.4 - Arbitrary File Upload 25 WEB Adrien Thierry
2010-12-15   slickMsg - Cross-Site Scripting / HTML Injection 26 WEB Aliaksandr Hartsuyeu
2010-12-14   BlogCFC 5.9.6.001 - Multiple Cross-Site Scripting Vulnerabilities 24 WEB Richard Brain
2010-12-13   PHP TopSites 2.1 - '/rate.php' Cross-Site Scripting / SQL Injection 28 WEB c0de Hunters
2010-12-12   MyBB 1.4.10 - 'tags.php' Cross-Site Scripting 24 WEB TEAMELITE
2010-12-13   Mura CMS - Multiple Cross-Site Scripting Vulnerabilities 28 WEB Richard Brain
2010-12-11   Cetera eCommerce - 'banner.php' Cross-Site Scripting 24 WEB MustLive
2014-10-28   Tapatalk for vBulletin 4.x - Blind SQL Injection 25 WEB tintinweb
2014-10-28   Enalean Tuleap 7.4.99.5 - Remote Command Execution 27 WEB Portcullis
2014-10-28   Enalean Tuleap 7.2 - XML External Entity File Disclosure 26 WEB Portcullis
2014-10-28   Enalean Tuleap 7.4.99.5 - Blind SQL Injection 30 WEB Portcullis
2010-12-13   Joomla! Component com_redirect 1.5.19 - Local File Inclusion 26 WEB jos_ali_joe
2010-12-10   Joomla! Component com_mailto - Multiple Cross-Site Scripting Vulnerabilities 26 WEB MustLive
2010-12-10   slickMsg 0.7-alpha - 'top.php' Cross-Site Scripting 28 WEB Aliaksandr Hartsuyeu
2010-12-10   BizDir 05.10 - 'f_srch' Cross-Site Scripting 25 WEB Aliaksandr Hartsuyeu
2010-12-10   ManageEngine EventLog Analyzer 6.1 - Multiple Cross-Site Scripting Vulnerabilities 27 WEB Rob Kraus
2010-12-10   Joomla! Component JExtensions Property Finder - 'sf_id' SQL Injection 29 WEB FL0RiX
2010-12-09   Joomla! Component Jeformcr - 'id' SQL Injection 29 WEB FL0RiX
2010-12-09   PHP State - 'id' SQL Injection 28 WEB jos_ali_joe
2010-12-09   net2ftp 0.98 (stable) - '/admin1.template.php' Local/Remote File Inclusion 26 WEB Marcin Ressel
2010-12-09   WWWThread 5.0.8 Pro - 'showflat.pl' Cross-Site Scripting 26 WEB Aliaksandr Hartsuyeu
2010-12-07   WordPress Plugin Twitter Feed - 'url' Cross-Site Scripting 31 WEB John Leitch
2014-10-27   Folder Plus 2.5.1 iOS - Persistent Cross-Site Scripting 29 WEB Vulnerability-Lab
2014-10-27   WebDisk+ 2.1 iOS - Code Execution 28 WEB Vulnerability-Lab
2014-10-27   Incredible PBX 2.0.6.5.0 - Remote Command Execution 26 WEB Simo Ben Youssef
2014-10-27   Mulesoft ESB Runtime 3.5.1 - Privilege Escalation 25 WEB Brandon Perry
2014-10-27   HP Operations Agent - Cross-Site Scripting iFrame Injection 26 WEB Matt Schmidt
2014-10-27   CBN CH6640E/CG6640E Wireless Gateway Series - Multiple Vulnerabilities 25 WEB LiquidWorm
2014-10-27   WordPress Plugin CP Multi View Event Calendar 1.01 - SQL Injection 26 WEB Claudio Viviani
2010-12-08   Drupal Module Embedded Media Field/Media 6.x : Video Flotsam/Media: Audio Flotsam - Multiple Vulnera 29 WEB Justin Klein Keane
2010-12-08   WordPress Plugin Safe Search - 'v1' Cross-Site Scripting 26 WEB John Leitch
2010-12-08   WordPress Plugin Processing Embed 0.5 - 'pluginurl' Cross-Site Scripting 28 WEB John Leitch
2010-12-07   SolarWinds Orion Network Performance Monitor (NPM) 10.1 - Multiple Cross-Site Scripting Vulnerabilit 30 WEB x0skel
2010-12-07   Zimplit CMS - 'English_manual_version_2.php?client' Cross-Site Scripting 29 WEB High-Tech Bridge SA
2010-12-07   Zimplit CMS - 'zimplit.php?File' Cross-Site Scripting 31 WEB High-Tech Bridge SA
2010-12-07   Aigaion 1.3.4 - 'ID' SQL Injection 24 WEB KnocKout
2014-10-25   WordPress Plugin 0.9.7 / Joomla! Component 2.0.0 Creative Contact Form - Arbitrary File Upload 27 WEB Claudio Viviani
2014-10-25   Dell EqualLogic Storage - Directory Traversal 25 WEB XLabs Security
2014-10-25   Magento Server MAGMI Plugin 0.7.17a - Remote File Inclusion 28 WEB Parvinder Bhasin
2010-12-06   Alguest 1.1 - 'start' SQL Injection 32 WEB Aliaksandr Hartsuyeu
2010-12-04   Techno Dreams FAQ Manager Package 1.0 - 'faqlist.asp' SQL Injection 29 WEB R4dc0re
2010-12-04   Techno Dreams Articles & Papers Package 2.0 - 'ArticlesTablelist.asp' SQL Injection 28 WEB R4dc0re
2014-10-23   Dell SonicWALL Gms 7.2.x - Code Injection 28 WEB Vulnerability-Lab
2014-10-23   Axway Secure Transport 5.1 SP2 - Arbitrary File Upload (via Cross-Site Request Forgery) 28 WEB Emmanuel Law
2010-12-03   DotNetNuke 5.5.1 - 'InstallWizard.aspx' Cross-Site Scripting 27 WEB Richard Brain
2010-12-03   Alguest 1.1 - Multiple Cookie Authentication Bypass Vulnerabilities 25 WEB Aliaksandr Hartsuyeu
2010-12-02   Contenido CMS 4.8.12 - Multiple Cross-Site Scripting Vulnerabilities 25 WEB High-Tech Bridge SA
2014-10-23   Feng Office 1.7.4 - Cross-Site Scripting 27 WEB AutoSec Tools
2014-10-23   Feng Office 1.7.4 - Arbitrary File Upload 24 WEB AutoSec Tools
2014-10-22   DotNetNuke DNNspot Store 3.0.0 - Arbitrary File Upload (Metasploit) 29 WEB Glafkos Charalambous
2014-10-22   File Manager 4.2.10 iOS - Code Execution 27 WEB Vulnerability-Lab
2014-10-22   iFunBox Free 1.1 iOS - Local File Inclusion 25 WEB Vulnerability-Lab
2010-12-02   Joomla! Component Annuaire - 'index.php?id' SQL Injection 25 WEB Ashiyane Digital Security Team
2010-11-30   AWStats 6.x - Apache Tomcat Configuration File Arbitrary Command Execution 27 WEB StenoPlasma
2010-11-30   BugTracker.NET 3.4.4 - SQL Injection / Cross-Site Scripting 26 WEB BugTracker.NET
2010-11-26   SmartBox - 'page_id' SQL Injection 22 WEB KnocKout
2010-11-26   E-lokaler CMS 2 - Admin Login Multiple SQL Injections 27 WEB ali_err0r
2010-11-30   Joomla! Component com_storedirectory - 'id' SQL Injection 23 WEB XroGuE
2010-11-29   Car Portal 2.0 - 'car_make' Cross-Site Scripting 27 WEB Underground Stockholm
2010-11-30   Joomla! Component Catalogue - SQL Injection / Local File Inclusion 29 WEB XroGuE
2010-11-29   Wernhart Guestbook 2001.03.28 - Multiple SQL Injections 26 WEB Aliaksandr Hartsuyeu
2010-11-29   4homepages 4Images 1.7.x - 'categories.php' SQL Injection 25 WEB Ahmed Atif
2010-11-26   Easy Banner 2009.05.18 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 30 WEB Aliaksandr Hartsuyeu
2010-11-26   Easy Banner 2009.05.18 - '/member.php' Multiple SQL Injection / Authentication Bypass 26 WEB Aliaksandr Hartsuyeu
2010-11-24   SimpLISTic SQL 2.0 - 'email.cgi' Cross-Site Scripting 28 WEB Aliaksandr Hartsuyeu
2010-11-23   ZYXEL P-660R-T1 V2 - 'HomeCurrent_Date' Cross-Site Scripting 26 WEB Usman Saeed
2010-11-22   Hot Links SQL 3.2 - 'report.cgi' SQL Injection 28 WEB Aliaksandr Hartsuyeu
2010-11-18   CompactCMS 1.4.1 - Multiple Cross-Site Scripting Vulnerabilities (1) 27 WEB High-Tech Bridge SA
2010-11-16   Raised Eyebrow CMS - 'venue.php' SQL Injection 25 WEB Cru3l.b0y
2010-11-16   Simea CMS - 'index.php' SQL Injection 26 WEB Cru3l.b0y