Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2014-06-18   Cacti Superlinks Plugin 1.4-2 - SQL Injection 4 WEB Napsterakos
2014-06-18   ZTE WXV10 W300 - Multiple Vulnerabilities 4 WEB Osanda Malith Jayathissa
2010-03-24   Joomla! Component com_jresearch - 'Controller' Local File Inclusion 4 WEB Chip d3 bi0s
2010-03-23   Joomla! Component com_cb - 'cat' SQL Injection 5 WEB DevilZ TM
2010-03-23   Joomla! Component com_aml_2 - 'art' SQL Injection 5 WEB Metropolis
2010-03-23   SpringSource (Multiple Products) - Multiple HTML Injection Vulnerabilities 4 WEB Aaron Kulick
2010-03-23   Kasseler CMS News Module - 'id' SQL Injection 5 WEB Palyo34
2014-06-17   Motorola SBG901 Wireless Modem - Cross-Site Request Forgery 4 WEB Blessen Thomas
2010-03-23   PHPAuthent 0.2.1 - 'useradd.php' Multiple HTML Injection Vulnerabilities 5 WEB Yoyahack
2010-03-23   RepairShop2 - 'index.php?Prod' Cross-Site Scripting 5 WEB kaMtiEz
2010-03-23   agXchange ESM - 'ucquerydetails.jsp' Cross-Site Scripting 4 WEB Lament
2010-03-19   vBulletin 4.0.2 - Search Cross-Site Scripting 5 WEB 5ubzer0
2010-03-22   PHPKIT 1.6.x - 'b-day.php' Addon SQL Injection 5 WEB n3w7u
2010-03-23   Lussumo Vanilla 1.1.10 - 'definitions.php' Multiple Remote File Inclusions 7 WEB eidelweiss
2010-03-22   agXchange ESM - 'ucschcancelproc.jsp' Open Redirection 5 WEB Lament
2010-03-19   PHPWind 6.0 - Multiple Cross-Site Scripting Vulnerabilities 5 WEB Liscker
2010-03-18   Kempt SiteDone 2.0 - '/detail.php' Cross-Site Scripting / SQL Injection 6 WEB d3v1l
2010-03-18   tenfourzero.net Shutter 0.1.4 - 'admin.html' Multiple SQL Injections 6 WEB blake
2010-03-17   PHPBB2 Plus 1.53 - 'kb.php' SQL Injection 4 WEB Gamoscu
2010-03-17   Joomla! Component com_alert - 'q_item' SQL Injection 5 WEB N2n-Hacker
2010-03-17   eFront 3.5.5 - 'langname' Local File Inclusion 6 WEB 7Safe
2010-03-16   Joomla! Component com_as - 'catid' SQL Injection 6 WEB N2n-Hacker
2010-03-15   Dojo Toolkit 1.4.1 - '/doh/runner.html' Multiple Cross-Site Scripting Vulnerabilities 5 WEB Adam Bixby
2010-03-15   Dojo Toolkit 1.4.1 - '/dijit/tests/_testCommon.js?theme' Cross-Site Scripting 5 WEB Adam Bixby
2010-03-15   Domain Verkaus & Auktions Portal - 'index.php' SQL Injection 5 WEB Easy Laster
2010-03-15   Andromeda 1.9.2 - 's' Cross-Site Scripting / Session Fixation 5 WEB indoushka
2010-03-15   Pars CMS - 'RP' Multiple SQL Injections 5 WEB Isfahan
2010-03-15   (Multiple Products) - 'banner.swf' Cross-Site Scripting 5 WEB MustLive
2010-03-14   DirectAdmin 1.33.6 - 'CMD_DB_VIEW' Cross-Site Scripting 4 WEB r0t
2010-03-15   Zigurrat Farsi CMS - '/manager/textbox.asp' SQL Injection 5 WEB Isfahan
2010-03-13   Joomla! Component com_d-greinar - 'maintree' Cross-Site Scripting 4 WEB DevilZ TM
2010-03-13   Joomla! Component com_seek - 'id' SQL Injection 6 WEB DevilZ TM
2010-03-12   pMyAdmin 3.3.5.1 - 'db_create.php' Cross-Site Scripting 5 WEB Liscker
2010-03-12   Easynet4u Forum Host - 'topic.php' SQL Injection 6 WEB Pr0T3cT10n
2010-03-11   CodeIgniter 1.0 - 'BASEPATH' Multiple Remote File Inclusions 6 WEB eidelweiss
2010-03-11   ARTIS ABTON CMS - Multiple SQL Injections 5 WEB MustLive
2010-03-11   AneCMS 1.0 - 'index.php' Multiple HTML Injection Vulnerabilities 6 WEB pratul agrawal
2014-06-13   ZeroCMS 1.0 - 'zero_transact_user.php' Handling Privilege Escalation 6 WEB Tiago Carvalho
2014-06-13   Yealink VoIP Phone SIP-T38G - Local File Inclusion 4 WEB Mr.Un1k0d3r
2014-06-13   Plesk 10.4.4/11.0.9 - SSO XML External Entity / Cross-Site Scripting Injection 5 WEB BLacK ZeRo
2010-03-10   DDL CMS 2.1 - 'blacklist.php' Cross-Site Scripting 5 WEB ITSecTeam
2010-03-10   60cycleCMS - 'select.php' Multiple HTML Injection Vulnerabilities 5 WEB pratul agrawal
2010-03-10   Friendly Technologies TR-069 ACS 2.8.9 - Login SQL Injection 4 WEB Yaniv Miron
2010-03-10   Max Network Technology BBSMAX 4.2 - 'threadid' Cross-Site Scripting 4 WEB Liscker
2010-03-09   IBM ENOVIA SmarTeam - 'LoginPage.aspx' Cross-Site Scripting 4 WEB Lament
2010-02-16   wh-em.com upload 7.0 - Insecure Cookie Authentication Bypass 5 WEB indoushka
2010-03-09   TikiWik < 4.2 - Multiple Vulnerabilities 4 WEB Mateusz Drygas
2010-03-07   OpenCart 1.3.2 - 'page' SQL Injection 4 WEB Andrés Gómez
2010-03-08   KDPics 1.18 - '/admin/index.php' Authentication Bypass 4 WEB snakespc
2010-03-08   ASPCode CMS 1.5.8 - 'default.asp' Multiple Cross-Site Scripting Vulnerabilities 3 WEB Alberto Fontanella
2010-03-08   Max Network Technology BBSMAX 4.2 - 'post.aspx' Cross-Site Scripting 4 WEB Liscker
2010-03-08   Pre E-Learning Portal - 'search_result.asp' SQL Injection 4 WEB NoGe
2010-03-06   phpCOIN 1.2.1 - 'mod' Local File Inclusion 4 WEB _mlk_
2010-03-05   Six Apart Vox - 'search' Page Cross-Site Scripting 4 WEB Phenom
2010-03-05   Saskia's ShopSystem - 'id' Local File Inclusion 4 WEB cr4wl3r
2010-03-05   Spectrum Software WebManager CMS - 'pojam' Cross-Site Scripting 4 WEB hacker@sr.gov.yu
2014-06-11   SHOUTcast DNAS 2.2.1 - Persistent Cross-Site Scripting 4 WEB rob222
2010-03-05   Natychmiast CMS - Multiple Cross-Site Scripting / SQL Injections 4 WEB Maciej Gojny
2010-03-04   Drupal < 5.22/6.16 - Multiple Vulnerabilities 4 WEB David Rothstein
2010-03-04   BBSXP 2008 - 'ShowPost.asp' Cross-Site Scripting 4 WEB Liscker
2014-06-10   ZeroCMS 1.0 - 'zero_view_article.php' SQL Injection 4 WEB LiquidWorm
2014-06-09   DevExpress ASPxFileManager 10.2 < 13.2.8 - Directory Traversal 4 WEB RedTeam Pentesting
2014-06-09   WebTitan 4.01 (Build 68) - Multiple Vulnerabilities 5 WEB SEC Consult
2014-06-09   eFront 3.6.14.4 - 'surname' Persistent Cross-Site Scripting 4 WEB shyamkumar somana
2010-03-04   Comptel Provisioning and Activation - 'index.jsp?error_msg_parameter' Cross-Site Scripting 5 WEB thebluegenius
2010-03-02   Discuz! 6.0 - 'uid' Cross-Site Scripting 5 WEB lis cker
2010-03-02   Sparta Systems TrackWise EQms - Multiple Cross-Site Scripting Vulnerabilities 4 WEB Yaniv Miron
2010-03-01   DeDeCMS 5.5 - '_SESSION[dede_admin_id]' Authentication Bypass 4 WEB Wolves Security Team
2010-03-01   Blax Blog 0.1 - 'girisyap.php' SQL Injection 5 WEB cr4wl3r
2010-03-01   Article Friendly - 'Filename' Local File Inclusion 5 WEB pratul agrawal
2010-02-27   SLAED CMS 4 - Installation Script Unauthorized Access 4 WEB indoushka
2010-02-28   Open Educational System 0.1 Beta - 'CONF_INCLUDE_PATH' Multiple Remote File Inclusions 4 WEB cr4wl3r
2010-02-28   TRUC 0.11 - 'login_reset_password_page.php' Cross-Site Scripting 4 WEB snakespc
2010-02-26   ARISg 5.0 - 'wflogin.jsp' Cross-Site Scripting 4 WEB Yaniv Miron
2010-02-25   Newbie CMS 0.0.2 - Insecure Cookie Authentication Bypass 4 WEB JIKO
2010-02-25   IBM (Multiple Products) - Login Page Cross-Site Scripting 4 WEB Oren Hafif
2010-02-24   OpenInferno OI.Blogs 1.0 - Multiple Local File Inclusions 4 WEB JIKO
2010-02-24   Joomla! Component HD FLV Player - 'id' SQL Injection 4 WEB kaMtiEz
2010-02-24   MySmartBB 1.7 - Multiple Cross-Site Scripting Vulnerabilities 4 WEB indoushka
2010-02-23   Softbiz Jobs - 'sbad_type' Cross-Site Scripting 6 WEB pratul agrawal
2010-02-22   Galerie Dezign-Box - Multiple Input Validation Vulnerabilities 6 WEB indoushka
2010-02-20   vBulletin 4.0.2 - Multiple Cross-Site Scripting Vulnerabilities 4 WEB indoushka
2010-02-20   Joomla! Component com_recipe - Multiple SQL Injections 4 WEB FL0RiX
2010-02-19   Social Web CMS 2 - 'index.php' Cross-Site Scripting 4 WEB GoLdeN-z3r0
2010-02-18   Subex Nikira Fraud Management System GUI - 'message' Cross-Site Scripting 4 WEB thebluegenius
2010-02-18   XlentProjects SphereCMS 1.1 - 'archive.php' SQL Injection 4 WEB AmnPardaz Security Research Team
2014-06-06   Madness Pro 1.14 - SQL Injection 5 WEB bwall
2014-06-06   Madness Pro 1.14 - Persistent Cross-Site Scripting 4 WEB bwall
2010-02-18   New-CMS 1.08 - Multiple Local File Inclusion / HTML Injection Vulnerabilities 4 WEB Alberto Fontanella
2010-02-16   EziScript Google Page Rank 1.1 - Cross-Site Scripting 4 WEB sarabande
2010-02-16   Extreme Mobster - 'login' Cross-Site Scripting 4 WEB indoushka
2010-02-16   BGSvetionik BGS CMS - 'search' Cross-Site Scripting 4 WEB hacker@sr.gov.yu
2010-02-16   Portrait Software Portrait Campaign Manager 4.6.1.22 - Multiple Cross-Site Scripting Vulnerabilities 4 WEB Roel Schouten
2009-12-31   Joomla! Component MS Comment 0.8.0b - Security Bypass / Cross-Site Scripting 5 WEB Jeff Channell
2010-02-12   Basic-CMS - 'nav_id' Cross-Site Scripting 4 WEB Red-D3v1L
2010-02-12   CMS Made Simple 1.6.6 - Local File Inclusion / Cross-Site Scripting 3 WEB Beenu Arora
2009-09-17   Joomla! Component F!BB 1.5.96 RC - SQL Injection / HTML Injection 5 WEB Jeff Channell
2009-09-17   Joomla! Component EasyBook 2.0.0rc4 - Multiple HTML Injection Vulnerabilities 3 WEB Jeff Channell
2009-11-15   Joomla! Component Webee Comments 1.1/1.2 - Multiple BBCode Tags Cross-Site Scripting Vulnerabilities 4 WEB Jeff Channell
2009-11-15   Joomla! Component Webee Comments 1.1/1.2 - 'index2.php' articleId SQL Injection 3 WEB Jeff Channell
2010-02-03   Interspire Knowledge Manager 5 - 'callback.snipshot.php' Arbitrary File Creation 4 WEB Cory Marsh
2010-02-11   CommodityRentals CD Rental Software - 'index.php' SQL Injection 4 WEB Don Tukulesto
2014-06-03   IPSwitch IMail Server WEB client 12.4 - Persistent Cross-Site Scripting 4 WEB Peru
2014-06-03   Bluetooth Photo-File Share 2.1 iOS - Multiple Vulnerabilities 4 WEB Vulnerability-Lab
2014-06-03   AllReader 1.0 iOS - Multiple Vulnerabilities 2 WEB Vulnerability-Lab
2014-06-03   TigerCom My Assistant 1.1 iOS - Local File Inclusion 4 WEB Vulnerability-Lab
2014-06-03   Privacy Pro 1.2 HZ iOS - Local File Inclusion 4 WEB Vulnerability-Lab
2014-06-03   Files Desk Pro 1.4 iOS - Local File Inclusion 4 WEB Vulnerability-Lab
2014-06-03   NG WifiTransfer Pro 1.1 - Local File Inclusion 5 WEB Vulnerability-Lab
2014-06-03   PHPBTTracker+ 2.2 - SQL Injection 4 WEB BackBox Linux Team
2010-02-11   vBulletin 3.5.4 - Multiple Cross-Site Scripting Vulnerabilities 4 WEB ROOT_EGY
2010-02-09   vBulletin Adsense Component - 'viewpage.php' SQL Injection 5 WEB JIKO
2010-02-08   VideoDB 3.0.3 - 'login.php' Cross-Site Scripting 4 WEB vr
2010-02-08   Zen Time Tracking 2.2 - Multiple SQL Injections 5 WEB cr4wl3r
2010-02-08   Aflam Online 1.0 - 'index.php' SQL Injection 5 WEB alnjm33
2014-06-02   WordPress Plugin Participants Database 1.5.4.8 - SQL Injection 5 WEB Yarubo Research Team
2010-02-05   ASCET Interactive Huski Retail - Multiple SQL Injections 4 WEB Wireghoul
2010-02-05   ASCET Interactive Huski CMS - 'i' Local File Inclusion 4 WEB Wireghoul
2010-02-05   LANDesk Management Gateway 4.x - Multiple Vulnerabilities 4 WEB Aureliano Calvo
2010-02-05   evalSMSI 2.1.3 - Multiple Input Validation Vulnerabilities 4 WEB ekse
2010-02-04   Data 1 Systems UltraBB 1.17 - 'view_post.php' Cross-Site Scripting 4 WEB s4r4d0
2010-02-04   KnowGate hipergate 4.0.12 - Multiple Cross-Site Scripting Vulnerabilities 4 WEB Nahuel Grisolia
2010-02-04   Interspire Knowledge Manager < 5.1.3 - Multiple Remote Vulnerabilities 4 WEB Cory Marsh
2010-02-01   Joomla! Component AutartiTarot - Directory Traversal 4 WEB B-HUNT3|2
2010-02-01   Joomla! Component com_gambling - 'gamblingEvent' SQL Injection 4 WEB md.r00t