Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2014-07-24   Lian Li NAS - Multiple Vulnerabilities 28 WEB pws
2014-07-24   WordPress Plugin Video Gallery 2.5 - Multiple Vulnerabilities 22 WEB Claudio Viviani
2010-06-18   Joomla! Component Gallery XML 1.1 - SQL Injection / Local File Inclusion 21 WEB jdc
2010-06-17   Firebook - Multiple Cross-Site Scripting / Directory Traversal Vulnerabilities 21 WEB MustLive
2010-06-27   Ceica-GW - 'login.php' Cross-Site Scripting 22 WEB indoushka
2010-06-16   2DayBiz ybiz Network Community Script - SQL Injection / Cross-Site Scripting 22 WEB Sid3^effects
2014-07-23   Netgear DGN2200 1.0.0.29_1.7.29_HotS - Password Disclosure 26 WEB Dolev Farhi
2014-07-23   Barracuda Networks #35 Web Firewall 610 6.0.1 - Filter Bypass / Persistent 20 WEB Vulnerability-Lab
2010-06-06   JForum 2.1.8 - 'Username' Cross-Site Scripting 20 WEB Adam Baldwin
2010-06-15   Sell@Site PHP Online Jobs Login - Multiple SQL Injections 15 WEB L0rd CrusAd3r
2010-06-14   MODx 1.0.3 - 'index.php' Multiple SQL Injections 18 WEB High-Tech Bridge SA
2010-06-11   AneCMS 1.x - '/modules/blog/index.php' SQL Injection 19 WEB High-Tech Bridge SA
2010-06-11   AneCMS 1.x - '/modules/blog/index.php' HTML Injection 21 WEB High-Tech Bridge SA
2010-06-14   VideoWhisper PHP 2 Way Video Chat - 'r' Cross-Site Scripting 18 WEB Sid3^effects
2010-06-21   Plesk Server Administrator (PSA) - 'locale' Local File Inclusion 20 WEB Pouya Daneshmand
2014-07-21   Raritan PowerIQ 4.1.0 - SQL Injection (Metasploit) 23 WEB Brandon Perry
2014-07-21   MTS MBlaze Ultra Wi-Fi / ZTE AC3633 - Multiple Vulnerabilities 23 WEB Ajin Abraham
2010-06-10   Arab Portal 2.2 - 'members.php' SQL Injection 19 WEB SwEET-DeViL
2014-07-20   WordPress Plugin WP BackupPlus - Database and Files Backup Download 18 WEB pSyCh0_3D
2010-01-18   Bits Video Script 2.04/2.05 - 'search.php' Cross-Site Scripting 23 WEB indoushka
2010-01-18   Bits Video Script 2.04/2.05 - '/register.php' Arbitrary File Upload / Arbitrary PHP Code Execution 26 WEB indoushka
2010-01-18   Bits Video Script 2.04/2.05 - '/addvideo.php' Arbitrary File Upload / Arbitrary PHP Code Execution 19 WEB indoushka
2010-01-18   Hitmaaan Gallery 1.3 - Multiple Cross-Site Scripting Vulnerabilities 22 WEB indoushka
2010-01-18   Bits Video Script 2.05 Gold Beta - 'showcase2search.php?rowptem[template]' Remote File Inclusion 22 WEB indoushka
2010-01-18   Bits Video Script 2.05 Gold Beta - 'showcasesearch.php?rowptem[template]' Remote File Inclusion 22 WEB indoushka
2010-06-09   SilverStripe CMS 2.4 - File Renaming Security Bypass 23 WEB John Leitch
2010-06-09   (GREEZLE) Global Real Estate Agent Login - Multiple SQL Injections 21 WEB L0rd CrusAd3r
2010-06-09   PGAUTOPro - SQL Injection / Cross-Site Scripting (2) 24 WEB Sid3^effects
2010-06-03   log1 CMS 2.0 - Session Handling Remote Security Bypass / Remote File Inclusion 21 WEB High-Tech Bridge SA
2009-01-08   PRTG Traffic Grapher 6.2.1 - 'url' Cross-Site Scripting 20 WEB Patrick Webster
2010-06-07   BoastMachine 3.1 - 'key' Cross-Site Scripting 23 WEB High-Tech Bridge SA
2010-06-07   cPanel 11.25 Image Manager - 'target' Local File Inclusion 25 WEB AnTi SeCuRe
2014-07-18   WordPress Plugin Gallery Objects 0.4 - SQL Injection 30 WEB Claudio Viviani
2014-07-18   Barracuda Networks Message Archiver 650 - Persistent Cross-Site Scripting 21 WEB Vulnerability-Lab
2014-07-17   Omeka 2.2 - Cross-Site Request Forgery / Persistent Cross-Site Scripting 22 WEB LiquidWorm
2010-06-06   CuteSITE CMS 1.x - '/manage/main.php?fld_path' Cross-Site Scripting 29 WEB High-Tech Bridge SA
2010-06-06   CuteSITE CMS 1.x - '/manage/add_user.php?user_id' SQL Injection 24 WEB High-Tech Bridge SA
2010-01-15   PonVFTP - 'login.php' SQL Injection 25 WEB S2K9
2010-06-06   JForum 2.1.8 - 'bookmarks' Module Multiple HTML Injection Vulnerabilities 19 WEB Adam Baldwin
2010-01-04   Pay Per Minute Video Chat Script 2.x - SQL Injection / Multiple Cross-Site Scripting Vulnerabilities 20 WEB R3d-D3V!L
2014-07-16   Bilboplanet 2.0 - Multiple Cross-Site Scripting Vulnerabilities 21 WEB Vivek N
2014-07-16   Joomla! Component Youtube Gallery 4.1.7 - SQL Injection 23 WEB Pham Van Khanh
2014-07-16   BitDefender GravityZone 5.1.5.386 - Multiple Vulnerabilities 24 WEB SEC Consult
2010-06-04   WordPress Plugin Gigya Socialize 1.0/1.1.x - Cross-Site Scripting 21 WEB MustLive
2010-01-06   L2Web LineWeb 1.0.5 - Multiple Input Validation Vulnerabilities 21 WEB Ignacio Garrido
2009-12-30   Western Digital My Book World Edition 1.1.16 - 'lang' Cross-Site Scripting 22 WEB emgent
2010-01-02   Obsession-Design Image-Gallery 1.1 - 'display.php' Cross-Site Scripting 21 WEB kaMtiEz
2010-01-06   KubeLabs PHPDug 2.0 - 'upcoming.php' Cross-Site Scripting 18 WEB indoushka
2010-06-03   MoinMoin 1.x - 'PageEditor.py' Cross-Site Scripting 21 WEB anonymous
2010-01-06   Sniggabo CMS 2.21 - 'search.php' Cross-Site Scripting 21 WEB Sora
2010-06-02   PHP City Portal 1.3 - 'cms_data.php' Cross-Site Scripting 19 WEB Red-D3v1L
2010-06-02   TPO Duyuru Scripti - Insecure Cookie Authentication Bypass 17 WEB Septemb0x
2010-06-02   TCExam 10.1.7 - '/admin/code/tce_functions_tcecode_editor.php' Arbitrary File Upload 22 WEB John Leitch
2010-06-01   Hexjector 1.0.7.2 - 'hexjector.php' Cross-Site Scripting 22 WEB hexon
2010-06-02   Joomla! Component com_sar_news - 'id' SQL Injection 20 WEB LynX
2010-01-07   Datetopia Match Agency BiZ - Multiple Cross-Site Scripting Vulnerabilities 20 WEB R3d-D3V!L
2010-01-01   CMS Made Simple 1.x - Cross-Site Scripting / Cross-Site Request Forgery 17 WEB Truong Thao Nguyen
2010-01-10   Smart Statistics 1.0 - 'smart_Statistics_admin.php' Cross-Site Scripting 18 WEB R3d-D3V!L
2014-07-14   Shopizer 1.1.5 - Multiple Vulnerabilities 19 WEB SEC Consult
2010-05-31   wsCMS - 'news.php' Cross-Site Scripting 20 WEB cyberlog
2010-05-28   CMScout 2.08 - Cross-Site Scripting 21 WEB XroGuE
2010-05-30   GR Board 1.8.6 - 'page.php' Remote File Inclusion 23 WEB eidelweiss
2010-05-28   ImpressPages CMS 1.0x - 'admin.php' Multiple SQL Injections 19 WEB High-Tech Bridge SA
2010-05-28   osCommerce Visitor Web Stats AddOn - 'Accept-Language' Header SQL Injection 20 WEB Christopher Schramm
2010-05-27   BackLinkSpider 1.3.1774 - 'cat_id' SQL Injection 20 WEB sniper ip
2010-05-26   md5 Encryption Decryption PHP Script - 'index.php' Cross-Site Scripting 16 WEB indoushka
2010-05-24   360 Web Manager 3.0 - 'webpages-form-led-edit.php' SQL Injection 19 WEB High-Tech Bridge SA
2010-05-24   Ruubikcms 1.0.3 - 'index.php' Cross-Site Scripting 22 WEB High-Tech Bridge SA
2010-05-24   Getsimple CMS 2.01 - 'components.php' Cross-Site Scripting 22 WEB High-Tech Bridge SA
2010-05-24   RazorCMS 1.0 - '/admin/index.php' HTML Injection 20 WEB High-Tech Bridge SA
2014-07-12   Aerohive HiveOS 5.1r5 < 6.1r5 - Multiple Vulnerabilities 19 WEB DearBytes
2010-05-23   OpenForum 2.2 b005 - 'saveAsAttachment()' Method Arbitrary File Creation 19 WEB John Leitch
2010-05-22   cyberhost - 'default.asp' SQL Injection 18 WEB redst0rm
2010-05-20   NPDS REvolution 10.02 - 'admin.php' Cross-Site Request Forgery 24 WEB High-Tech Bridge SA
2010-05-18   gpEasy CMS 1.6.2 - 'editing_files.php' Cross-Site Scripting 23 WEB High-Tech Bridge SA
2014-07-10   Infoblox 6.8.2.11 - OS Command Injection 22 WEB Nate Kettlewell
2010-05-21   Specialized Data Systems Parent Connect 2010.04.11 - Multiple SQL Injections 17 WEB epixoip
2014-07-10   C99Shell (Web Shell) - 'c99.php' Authentication Bypass 22 WEB Mandat0ry
2010-01-15   Triburom - 'forum.php' Cross-Site Scripting 20 WEB ViRuSMaN
2010-05-20   Lisk CMS 4.4 - 'id' Multiple Cross-Site Scripting / SQL Injections 20 WEB High-Tech Bridge SA
2010-01-13   StivaSoft Stiva SHOPPING CART 1.0 - 'demo.php' Cross-Site Scripting 24 WEB PaL-D3v1L
2010-05-19   Joomla! Component com_horses - 'id' SQL Injection 19 WEB Kernel Security Group
2010-05-20   Snipe Gallery 3.1 - 'image.php?cfg_admin_path' Remote File Inclusion 19 WEB Sn!pEr.S!Te Hacker
2010-05-20   Snipe Gallery 3.1 - 'gallery.php?cfg_admin_path' Remote File Inclusion 21 WEB Sn!pEr.S!Te Hacker
2010-05-19   SoftDirec 1.05 - 'delete_confirm.php' Cross-Site Scripting 22 WEB indoushka
2010-05-08   Web 2.0 Social Network Freunde Community System - 'user.php' SQL Injection 22 WEB Easy Laster
2010-05-19   Caucho Resin Professional 3.1.5 - '/resin-admin/digest.php' Multiple Cross-Site Scripting Vulnerabil 23 WEB xuanmumu
2010-05-19   Shopzilla Affiliate Script PHP - 'search.php' Cross-Site Scripting 21 WEB Andrea Bocchetti
2010-05-19   Joomla! Component Percha Multicategory Article 0.6 - 'Controller' Arbitrary File Access 21 WEB AntiSecurity
2014-07-08   Dolibarr ERP/CRM 3.5.3 - Multiple Vulnerabilities 21 WEB Deepak Rathore
2010-05-19   Joomla! Component Percha Gallery 1.6 Beta - 'Controller' Traversal Arbitrary File Access 25 WEB AntiSecurity
2010-05-19   Joomla! Component Percha Downloads Attach 1.1 - 'Controller' Traversal Arbitrary File Access 20 WEB AntiSecurity
2010-05-19   Joomla! Component Percha Fields Attach 1.0 - 'Controller' Traversal Arbitrary File Access 19 WEB AntiSecurity
2010-05-19   Joomla! Component Percha Image Attach 1.1 - 'Controller' Traversal Arbitrary File Access 21 WEB AntiSecurity
2010-01-18   Serialsystem 1.0.4 Beta - 'list' Cross-Site Scripting 20 WEB indoushka
2010-01-18   Mobile Chat 2.0.2 - 'chatsmileys.php' Cross-Site Scripting 21 WEB indoushka
2010-05-18   Joomla! Component JComments 2.1 - 'ComntrNam' Cross-Site Scripting 24 WEB High-Tech Bridge SA
2010-05-18   NPDS REvolution 10.02 - 'download.php' Cross-Site Scripting 25 WEB High-Tech Bridge SA
2014-07-07   Photo Org WonderApplications 8.3 iOS - Local File Inclusion 21 WEB Vulnerability-Lab
2010-01-19   Blaze Apps 1.x - SQL Injection / HTML Injection 20 WEB AmnPardaz Security Research Team
2010-05-17   PonVFTP - Insecure Cookie Authentication Bypass 20 WEB SkuLL-HackeR
2010-05-14   Planet Script 1.x - 'idomains.php' Cross-Site Scripting 21 WEB Mr.ThieF
2010-05-17   Platnik 8.1.1 - Multiple SQL Injections 22 WEB podatnik386
2010-01-03   PHP Banner Exchange 1.2 - 'signupconfirm.php' Cross-Site Scripting 23 WEB indoushka
2010-01-03   PHP File Uploader - Arbitrary File Upload 21 WEB indoushka
2010-05-13   NPDS REvolution 10.02 - 'topic' Cross-Site Scripting 24 WEB High-Tech Bridge SA
2014-07-07   Netgear WNR1000v3 - Password Recovery Credential Disclosure (Metasploit) 23 WEB c1ph04
2014-07-06   Frog CMS 0.9.5 - Arbitrary File Upload 22 WEB Javid Hussain
2010-05-13   NPDS REvolution 10.02 - 'download.php' SQL Injection 21 WEB High-Tech Bridge SA
2010-05-19   C99Shell 1.0 Pre-Release build 16 (Web Shell) - 'ch99.php' Cross-Site Scripting 18 WEB indoushka
2010-05-12   TomatoCMS 2.0.x - SQL Injection 21 WEB Russ McRee
2010-05-11   Saurus CMS 4.7 - 'edit.php' Cross-Site Scripting 20 WEB High-Tech Bridge SA
2010-05-11   Affiliate Store Builder - 'edit_cms.php' Multiple SQL Injections 15 WEB High-Tech Bridge SA
2010-05-10   Advanced Poll 2.0 - 'mysql_host' Cross-Site Scripting 20 WEB High-Tech Bridge SA
2010-05-10   EasyPublish CMS 23.04.2010 - URI Cross-Site Scripting 19 WEB High-Tech Bridge SA
2010-05-09   eFront 3.x - 'ask_chat.php' SQL Injection 18 WEB Stefan Esser
2010-01-20   Chipmunk NewsLetter 2.0 - Multiple Cross-Site Scripting Vulnerabilities 18 WEB b0telh0
2010-05-07   ECShop 2.7.2 - 'category.php' SQL Injection 17 WEB Liscker
2010-05-07   Consona - 'n6plugindestructor.asp' Cross-Site Scripting 20 WEB Ruben Santamarta
2010-05-06   Digital Factory Publique! 2.3 - 'sid' SQL Injection 18 WEB Christophe de la Fuente
2010-01-20   kloNews 2.0 - 'cat.php' Cross-Site Scripting 17 WEB cr4wl3r
2014-07-02   Kerio Control 8.3.1 - Blind SQL Injection 19 WEB Khashayar Fereidani
2014-07-02   Zurmo CRM - Persistent Cross-Site Scripting 20 WEB Provensec
2010-01-31   HAWHAW - 'newsread.php' SQL Injection 18 WEB s4r4d0
2010-01-31   Site Manager 3.0 - 'id' SQL Injection 21 WEB Sec Attack Team