Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2010-01-31   Joomla! Component com_rsgallery2 2.0 - 'catid' SQL Injection 4 WEB snakespc
2009-07-16   XAMPP 1.6.x - 'showcode.php' Local File Inclusion 5 WEB MustLive
2010-01-28   CommonSpot Server - '/utilities/longproc.cfm' Cross-Site Scripting 4 WEB Richard Brain
2010-01-27   Discuz! 6.0 - 'tid' Cross-Site Scripting 4 WEB s4r4d0
2010-01-26   Joomla! Component 3D Cloud - 'tagcloud.swf' Cross-Site Scripting 5 WEB MustLive
2009-10-24   Jetty 6.1.x - JSP Snoop Page Multiple Cross-Site Scripting Vulnerabilities 6 WEB aScii
2010-01-22   OpenX 2.6.1 - SQL Injection 4 WEB AndySoon
2010-01-21   cPanel and WHM 11.25 - 'failurl' HTTP Response Splitting 5 WEB Trancer
2014-05-28   Sharetronix 3.3 - Multiple Vulnerabilities 3 WEB High-Tech Bridge SA
2014-05-28   AuraCMS 3.0 - Multiple Vulnerabilities 4 WEB Mustafa ALTINKAYNAK
2010-01-20   PHPMySpace Gold 8.0 - 'gid' SQL Injection 5 WEB Ctacok
2010-01-19   VisualShapers EZContents 2.0.3 - Authentication Bypass / Multiple SQL Injections 4 WEB AmnPardaz Security Research Team
2010-01-18   vBulletin 4.0.1 - 'misc.php' SQL Injection 4 WEB indoushka
2010-01-18   Easysitenetwork Jokes Complete Website - 'searchingred' Cross-Site Scripting 4 WEB indoushka
2010-01-18   Easysitenetwork Jokes Complete Website - 'id' Cross-Site Scripting 4 WEB indoushka
2010-01-19   DataLife Engine 8.3 - '/engine/ajax/addcomments.php?_REQUEST[skin]' Remote File Inclusion 4 WEB indoushka
2010-01-19   DataLife Engine 8.3 - '/engine/ajax/pm.php?config[lang]' Remote File Inclusion 4 WEB indoushka
2010-01-19   DataLife Engine 8.3 - '/engine/inc/help.php?config[langs]' Remote File Inclusion 4 WEB indoushka
2010-01-19   DataLife Engine 8.3 - '/engine/inc/include/init.php?selected_language' Remote File Inclusion 5 WEB indoushka
2010-01-18   TestLink 1.8.5 - 'order_by_login_dir' Cross-Site Scripting 4 WEB Prashant Khandelwal
2010-01-15   LetoDms 1.4.x - 'lang' Local File Inclusion 4 WEB D. Fabian
2010-01-14   Joomla! Component com_marketplace 1.2 - 'catid' Cross-Site Scripting 4 WEB ViRuSMaN
2010-01-14   Xforum 1.4 - 'nbpageliste' Cross-Site Scripting 5 WEB ViRuSMaN
2010-01-14   Technology for Solutions 1.0 - 'id' Cross-Site Scripting 4 WEB PaL-D3v1L
2014-05-26   D-Link Routers - Multiple Vulnerabilities 6 WEB Kyle Lovett
2014-05-26   ZYXEL P-660HW-T1 3 Wireless Router - Cross-Site Request Forgery 4 WEB Mustafa ALTINKAYNAK
2014-05-26   Videos Tube 1.0 - Multiple SQL Injections 4 WEB Mustafa ALTINKAYNAK
2010-01-14   Zenoss 2.3.3 - Multiple SQL Injections 4 WEB nGenuity Information Services
2010-01-13   Tribisur - 'cat' Cross-Site Scripting 3 WEB ViRuSMaN
2010-01-13   Joomla! Component com_tienda - 'categoria' Cross-Site Scripting 4 WEB FL0RiX
2010-01-12   Simple PHP Blog 0.5.x - 'search.php' Cross-Site Scripting 4 WEB Sora
2010-01-12   Docmint 1.0/2.1 - 'id' Cross-Site Scripting 4 WEB Red-D3v1L
2014-05-24   Web Terra 1.1 - 'books.cgi' Remote Command Execution 4 WEB felipe andrian
2014-05-24   Mayan-EDms Web-Based Document Management OS System - Multiple Persistent Cross-Site Scripting Vulner 5 WEB Dolev Farhi
2010-01-11   Active Calendar 1.2 - '$_SERVER['PHP_SELF']' Multiple Cross-Site Scripting Vulnerabilities 4 WEB Martin Barbella
2010-01-12   PHPepperShop 2.5 - 'USER_ARTIKEL_HANDLING_AUFRUF.php' Cross-Site Scripting 4 WEB Crux
2010-01-11   @lex Guestbook 5.0 - Multiple Cross-Site Scripting Vulnerabilities 5 WEB D3V!L FUCKER
2010-01-11   Jamit Job Board - 'post_id' Cross-Site Scripting 5 WEB Crux
2010-01-11   DELTAScripts PHP Links 1.0 - 'email' Cross-Site Scripting 5 WEB Crux
2010-01-10   DigitalHive - 'mt' Cross-Site Scripting 5 WEB ViRuSMaN
2010-01-08   Joomla! Component Jobads - 'type' SQL Injection 4 WEB N0KT4
2010-01-07   Calendarix 0.7 - 'calpath' Remote File Inclusion 3 WEB Saywhat
2010-01-07   dotProject 2.1.3 - Multiple SQL Injections / HTML Injection Vulnerabilities 5 WEB Justin C. Klein Keane
2010-01-07   Joomla! Component DM Orders - 'id' SQL Injection 4 WEB NoGe
2010-01-06   Roundcube Webmail 0.2 - Cross-Site Scripting 6 WEB j4ck & Globus
2010-01-05   LineWeb 1.0.5 - Multiple Remote Vulnerabilities 6 WEB Ignacio Garrido
2010-01-05   LXR 0.9.x - Cross Referencer Multiple Cross-Site Scripting Vulnerabilities 4 WEB Dan Rosenberg
2010-01-04   MercuryBoard 1.1.5 - 'index.php' Cross-Site Scripting 3 WEB indoushka
2010-01-04   WMNews - '/admin/wmnews.php' Cross-Site Scripting 3 WEB indoushka
2010-01-04   pL-PHP 0.9 - 'index.php' Cross-Site Scripting 4 WEB indoushka
2010-01-03   SLAED CMS 2.0 - 'stop' Cross-Site Scripting 5 WEB indoushka
2010-01-03   Discuz! 2.0 - Multiple Cross-Site Scripting Vulnerabilities 4 WEB indoushka
2010-01-01   VisionGate 1.6 - 'login.php' Cross-Site Scripting 4 WEB indoushka
2010-01-01   VirtuaSystems VirtuaNews Pro 1.0.4 - 'admin.php' Cross-Site Scripting 6 WEB indoushka
2010-01-01   PHPCart 3.1.2 - 'search.php' Cross-Site Scripting 4 WEB indoushka
2010-01-01   Reamday Enterprises Magic News Plus 1.0.2 - Cross-Site Scripting 5 WEB indoushka
2009-12-31   DieselPay 1.6 - Cross-Site Scripting / Directory Traversal 5 WEB indoushka
2009-12-31   Discuz! 1.0 - 'referer' Cross-Site Scripting 5 WEB indoushka
2009-12-31   PhotoKorn 1.542 - Cross-Site Scripting / Remote File Inclusion 5 WEB indoushka
2009-12-31   StarDevelop Live Help 2.6 - 'SERVER' Multiple Cross-Site Scripting Vulnerabilities 5 WEB indoushka
2014-05-21   Binatone DT 850W Wireless Router - Multiple Cross-Site Request Forgery Vulnerabilities 5 WEB Samandeep Singh
2009-12-31   Imagevue r16 - 'amount' Cross-Site Scripting 5 WEB indoushka
2009-12-31   BosClassifieds 1.20 - 'recent.php' Cross-Site Scripting 7 WEB indoushka
2009-12-31   SendStudio 4.0.1 - Cross-Site Scripting / Security Bypass 6 WEB indoushka
2009-12-31   PHPMyCart 1.3 - Cross-Site Scripting / Authentication Bypass 5 WEB indoushka
2009-12-29   AzDGDatingMedium 1.9.3 - 'l' Multiple Cross-Site Scripting Vulnerabilities 5 WEB indoushka
2009-12-29   FreeWebShop 2.2.9 R2 - Multiple Remote Vulnerabilities 4 WEB Akita Software Security
2009-12-25   Barbo91 - 'upload.php' Cross-Site Scripting 4 WEB indoushka
2009-12-26   PHPInstantGallery 1.1 - 'admin.php' Cross-Site Scripting 4 WEB indoushka
2009-12-28   FreePBX 2.5.2 - Zap Channel Addition Description Parameter Cross-Site Scripting 4 WEB Global-Evolution
2009-12-28   FreePBX 2.5.2 - '/admin/config.php?tech' Cross-Site Scripting 5 WEB Global-Evolution
2009-12-28   Joomla! Component Joomulus 2.0 - 'tagcloud.swf' Cross-Site Scripting 4 WEB MustLive
2009-12-29   Joomla! Component iF Portfolio Nexus - 'Controller' Remote File Inclusion 4 WEB F10riX
2009-12-24   MyBB 1.4.10 - 'myps.php' Cross-Site Scripting 5 WEB Steven Abbagnaro
2009-12-23   webMathematica 3 - 'MSP' Script Cross-Site Scripting 6 WEB Floyd Fuh
2009-12-21   PHP-Calendar 1.1 - 'update10.php?configfile' Traversal Local File Inclusion 6 WEB Juan Galiana Lara
2009-12-21   PHP-Calendar 1.1 - 'update08.php?configfile' Traversal Local File Inclusion 7 WEB Juan Galiana Lara
2009-12-22   ClarkConnect Linux 5.0 - 'proxy.php' Cross-Site Scripting 5 WEB Edgard Chammas
2014-05-19   HP Release Control - (Authenticated) XML External Entity (Metasploit) 6 WEB Brandon Perry
2014-05-19   SafeNet Sentinel Protection Server 7.0 < 7.4 / Sentinel Keys Server 1.0.3 < 1.0.4 - Directory Traver 6 WEB Matt Schmidt
2014-05-19   SPIP CMS < 2.0.23/ 2.1.22/3.0.9 - Privilege Escalation 5 WEB Gregory Draperi
2009-12-21   Kasseler CMS 1.3.4 Lite - Multiple Cross-Site Scripting Vulnerabilities 6 WEB Gamoscu
2009-12-20   JBC Explorer 7.20 - 'arbre.php' Cross-Site Scripting 5 WEB Metropolis
2009-12-18   Ampache 3.4.3 - 'login.php' Multiple SQL Injections 4 WEB R3d-D3V!L
2009-12-18   F3Site 2009 - '/mod/new.php?GLOBALS[nlang]' Traversal Local File Inclusion 6 WEB cr4wl3r
2009-12-18   F3Site 2009 - '/mod/poll.php?GLOBALS[nlang]' Traversal Local File Inclusion 6 WEB cr4wl3r
2009-12-17   Joomla! Component com_joomportfolio - 'secid' SQL Injection 6 WEB Fl0riX & Snakespc
2009-12-17   cPanel 11.x - 'fileop' Multiple Cross-Site Scripting Vulnerabilities 5 WEB RENO
2009-12-17   QuiXplorer 2.x - 'lang' Local File Inclusion 5 WEB Juan Galiana Lara
2009-12-17   Pluxml-Blog 4.2 - '/core/admin/auth.php' Cross-Site Scripting 5 WEB Metropolis
2009-12-16   iSupport 1.8 - 'index.php?which' Cross-Site Scripting 6 WEB Stink & Essandre
2009-12-16   iSupport 1.8 - 'ticket_function.php' Multiple Cross-Site Scripting Vulnerabilities 5 WEB Stink & Essandre
2009-12-16   Drupal Module Sections 5.x-1.2/6.x-1.2 - HTML Injection 4 WEB Justin C. Klein Keane
2009-12-16   Article Directory - 'login.php' SQL Injection 5 WEB R3d D3v!L
2009-12-15   Horde 3.3.5 - '/Administration Interface admin/sqlshell.php?PATH_INFO' Cross-Site Scripting 5 WEB Juan Galiana Lara
2009-12-15   Horde 3.3.5 - '/Administration Interface admin/cmdshell.php?PATH_INFO' Cross-Site Scripting 4 WEB Juan Galiana Lara
2009-12-15   Horde 3.3.5 - Cross-Site Scripting 6 WEB Juan Galiana Lara
2009-12-14   phpFaber CMS 1.3.36 - 'module.php' Cross-Site Scripting 5 WEB bi0
2009-12-14   Million Pixel Script 3 - 'pa' Cross-Site Scripting 5 WEB bi0
2009-12-14   Ez Cart - 'sid' Cross-Site Scripting 6 WEB anti-gov
2009-12-10   Zeeways ZeeJobsite - 'basic_search_result.php' Cross-Site Scripting 5 WEB bi0
2009-12-09   Invision Power Board (IP.Board) 3.0.3 - '.txt' MIME-Type Cross-Site Scripting 5 WEB Xacker
2009-12-04   Joomla! Component You!Hostit! 1.0.1 Template - Cross-Site Scripting 6 WEB andresg888
2009-12-04   Joomla! Component YOOtheme Warp5 - 'yt_color' Cross-Site Scripting 6 WEB andresg888
2009-12-07   Advanced Image Hosting Script 2.x - 'search.php' Cross-Site Scripting 6 WEB aBo MoHaMeD
2009-12-04   WordPress Plugin Yoast Google Analytics 3.2.4 - 404 Error Page Cross-Site Scripting 7 WEB intern0t
2014-05-16   eGroupWare 1.8.006 - Multiple Vulnerabilities 5 WEB High-Tech Bridge SA
2009-12-01   phpMyFAQ < 2.5.4 - Multiple Cross-Site Scripting Vulnerabilities 5 WEB Amol Naik
2009-11-30   Elxis - 'Filename' Directory Traversal 6 WEB cr4wl3r
2009-11-30   SmartMedia Module 0.85 Beta for XOOPS - 'categoryId' Cross-Site Scripting 6 WEB SoldierOfAllah
2009-11-30   Content Module 0.5 for XOOPS - 'id' SQL Injection 5 WEB s4r4d0
2008-02-16   Power Phlogger 2.2.x - Cross-Site Scripting 5 WEB MustLive
2009-11-23   Joomla! 1.5.x - 404 Error Page Cross-Site Scripting 6 WEB MustLive
2009-11-16   Joomla! Component ProofReader 1.0 RC9 - Cross-Site Scripting 6 WEB MustLive
2009-11-24   klinza Professional CMS 5.0.1 - 'menulast.php' Local File Inclusion 6 WEB klinza
2009-11-24   Quick.Cart 3.4 / Quick.CMS 2.4 - Delete Function Cross-Site Request Forgery 6 WEB Alice Kaerast
2009-11-21   Cacti 0.8.x - 'graph.php' Multiple Cross-Site Scripting Vulnerabilities 5 WEB Moritz Naumann
2009-11-16   WordPress Plugin Subscribe to Comments 2.0 - Multiple Cross-Site Scripting Vulnerabilities 4 WEB MustLive
2009-11-13   WordPress Plugin Fuctweb CapCC 1.0 CAPTCHA - Security Bypass 5 WEB MustLive
2009-11-09   WordPress Plugin WP-Cumulus 1.x - 'tagcloud.swf' Cross-Site Scripting 8 WEB MustLive
2014-05-15   ElasticSearch - Remote Code Execution 5 WEB Jeff Geiger
2009-11-24   WordPress Plugin Firestats 1.0.2 - Multiple Cross-Site Scripting / Authentication Bypass Vulnerabili 5 WEB MustLive
2009-11-24   WordPress Plugin Firestats 1.0.2 - Multiple Cross-Site Scripting / Authentication Bypass Vulnerabili 5 WEB MustLive
2009-11-15   WordPress Plugin Trashbin 0.1 - 'mtb_undelete' Cross-Site Scripting 6 WEB MustLive
2009-11-29   WordPress Plugin WP-phpList 2.10.2 - 'unsubscribeemail' Cross-Site Scripting 5 WEB MustLive