Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2009-08-17   Adobe ColdFusion Server 8.0.1 - '/wizards/common/_logintowizard.cfm' Query String Cross-Site Scripti 9 WEB Alexander Polyakov
2009-08-17   Adobe ColdFusion Server 8.0.1 - 'administrator/logviewer/searchlog.cfm?startRow' Cross-Site Scriptin 8 WEB Alexander Polyakov
2009-08-17   Adobe ColdFusion Server 8.0.1 - '/wizards/common/_authenticatewizarduser.cfm' Query String Cross-Sit 8 WEB Alexander Polyakov
2009-08-15   Discuz! 6.0 - '2fly_gift.php' SQL Injection 9 WEB Securitylab.ir
2009-08-10   Papoo 3.x - Upload Images Arbitrary File Upload 9 WEB RedTeam Pentesting GmbH
2014-05-03   Seagate BlackArmor NAS - Multiple Vulnerabilities 9 WEB Shayan S
2009-08-10   ViArt CMS - 'forum_topic_new.php?forum_id' Cross-Site Scripting 9 WEB Moudi
2009-08-10   ViArt CMS - 'forum.php?forum_id' Cross-Site Scripting 10 WEB Moudi
2014-05-03   Crime24 Stealer Panel 1.0 - Multiple Vulnerabilities 8 WEB Daisuke Dan
2009-08-10   ViArt CMS - 'forums.php?category_id' Cross-Site Scripting 8 WEB Moudi
2009-08-10   SQLiteManager 1.2 - 'main.php' Cross-Site Scripting 7 WEB Hadi Kiamarsi
2009-08-10   SupportPRO SupportDesk 3.0 - 'shownews.php' Cross-Site Scripting 9 WEB Moudi
2009-08-07   PhotoPost PHP 3.3.1 - 'cat' Cross-Site Scripting / SQL Injection 9 WEB 599eme Man
2009-08-06   Alkacon OpenCMS 7.x - Multiple Input Validation Vulnerabilities 8 WEB Katie French
2009-08-05   AJ Auction Pro 3.0 - 'txtkeyword' Cross-Site Scripting 9 WEB 599eme Man
2009-08-04   CS-Cart 2.0.5 - 'reward_points.post.php' SQL Injection 8 WEB Ryan Dewhurst
2009-06-29   Censura < 2.1.1 - Multiple Cross-Site Scripting Vulnerabilities 9 WEB mark99
2014-05-01   Netgear DGN2200 1.0.0.29_1.7.29_HotS - Persistent Cross-Site Scripting 9 WEB Dolev Farhi
2014-05-01   Fritz!Box - Remote Command Execution 10 WEB 0x4148
2009-07-30   Softbiz Dating Script 1.0 - 'cat_products.php' SQL Injection 9 WEB MizoZ
2009-06-30   XOOPS 2.3.3 - 'op' Multiple Cross-Site Scripting Vulnerabilities 9 WEB Sense of Security
2009-06-30   NTSOFT BBS E-Market Professional - Multiple Cross-Site Scripting Vulnerabilities (1) 9 WEB Ivan Sanchez
2014-04-30   Beetel 450TC2 Router - Cross-Site Request Forgery (Admin Password) 8 WEB shyamkumar somana
2009-06-29   Miniweb 2.0 Site Builder Module - Multiple Cross-Site Scripting Vulnerabilities 8 WEB Moudi
2009-06-28   Matterdaddy Market 1.x - 'index.php' Cross-Site Scripting 8 WEB Moudi
2009-06-28   Joomla! Component Permis 1.0 (com_groups) - 'id' SQL Injection 10 WEB Prince_Pwn3r
2009-06-27   Joomla! Component com_user - 'view' Open Redirection 9 WEB 599eme Man
2009-06-24   Pilot Group eTraining - 'lessons_login.php' Cross-Site Scripting 8 WEB Moudi
2009-06-24   Pilot Group eTraining - 'news_read.php' Cross-Site Scripting 10 WEB Moudi
2009-06-24   Pilot Group eTraining - 'courses_login.php' Cross-Site Scripting 8 WEB Moudi
2009-06-27   AlmondSoft Classifieds Pro - 'gmap.php?addr' Cross-Site Scripting 8 WEB Moudi
2009-06-27   AlmondSoft Multiple Classifieds Products - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 9 WEB Moudi
2009-06-27   AlmondSoft Multiple Classifieds Products - 'index.php?replid' SQL Injection 9 WEB Moudi
2009-06-27   Joomla! Component Almond Classifieds 7.5 - Cross-Site Scripting / SQL Injection 7 WEB Moudi
2009-06-27   PG Roommate Finder Solution - 'viewprofile.php?part' Cross-Site Scripting 9 WEB Moudi
2009-06-27   PG Roommate Finder Solution - 'quick_search.php?part' Cross-Site Scripting 9 WEB Moudi
2009-06-27   AIOCP 1.4 - 'cp_html2txt.php' Remote File Inclusion 9 WEB Hadi Kiamarsi
2009-06-24   XZeroScripts XZero Community Classifieds 4.97.8 - Multiple Cross-Site Scripting Vulnerabilities 10 WEB Moudi
2009-06-24   PG Matchmaking - 'services.php?show' Cross-Site Scripting 8 WEB Moudi
2009-06-24   PG Matchmaking - 'search.php?show' Cross-Site Scripting 10 WEB Moudi
2009-06-24   PG Matchmaking - 'browse_men.php?show' Cross-Site Scripting 8 WEB Moudi
2009-06-24   PG Matchmaking - 'browse_ladies.php?show' Cross-Site Scripting 11 WEB Moudi
2009-06-23   CommuniGate Pro 5.2.14 - Web Mail URI Parsing HTML Injection 10 WEB Andrea Purificato
2009-06-20   Programs Rating - 'postcomments.php?id' Cross-Site Scripting 8 WEB Moudi
2009-06-20   Programs Rating - 'rate.php?id' Cross-Site Scripting 8 WEB Moudi
2014-04-29   NULL NUKE CMS 2.2 - Multiple Vulnerabilities 8 WEB LiquidWorm
2014-04-29   TRENDnet TEW-634GRU 1.00.23 - Multiple Vulnerabilities 9 WEB SirGod
2009-06-16   PHPLive! 3.2.2 - 'request.php' SQL Injection 7 WEB boom3rang
2009-06-14   Scriptsez Easy Image Downloader - 'id' Cross-Site Scripting 10 WEB Moudi
2014-04-28   WordPress Plugin iMember360 3.8.012 < 3.9.001 - Multiple Vulnerabilities 7 WEB Everett Griffiths
2014-04-28   GeoCore MAX DB Ver. 7.3.3 - Blind SQL Injection 10 WEB Esac
2014-04-28   Adem 0.5.1 - Local File Inclusion 9 WEB JIKO
2014-04-28   ApPHP MicroBlog 1.0.1 - Remote Command Execution 9 WEB LOTFREE
2009-06-06   ClanSphere 2009 - 'text' Cross-Site Scripting 9 WEB 599eme Man
2009-06-05   Horde 3.1 - 'Passwd' Module Cross-Site Scripting 7 WEB anonymous
2009-06-01   Joomla! 1.5.x - Cross-Site Scripting / Information Disclosure 8 WEB Juan Galiana Lara
2009-05-30   phpMyAdmin 3.3.0 - 'db' Cross-Site Scripting 8 WEB r0t
2009-05-26   Aardvark Topsites PHP 5.2 - 'index.php' Cross-Site Scripting 7 WEB anonymous
2009-05-23   Basic Analysis and Security Engine (BASE) 1.2.4 - 'readRoleCookie()' Authentication Bypass 8 WEB Tim Medin
2009-05-19   DirectAdmin 1.33.6 - 'CMD_REDIRECT' Cross-Site Scripting 9 WEB r0t
2009-05-15   Webmedia Explorer 5.0.9/5.10 - Multiple Cross-Site Scripting Vulnerabilities 9 WEB intern0t
2014-04-26   ApPHP MicroBlog 1.0.1 - Multiple Vulnerabilities 9 WEB JIKO
2014-04-25   Depot WiFi 1.0.0 iOS - Multiple Vulnerabilities 8 WEB Vulnerability-Lab
2009-06-03   Joomla! < 1.5.11 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities 8 WEB Airton Torres
2009-06-02   PHP-Nuke 8.0 Downloads Module - 'query' Cross-Site Scripting 8 WEB Schap Security
2014-04-25   miSecureMessages 4.0.1 - Session Management / Authentication Bypass 9 WEB Jared Bird
2009-05-28   Achievo 1.3.4 - Multiple Cross-Site Scripting Vulnerabilities 10 WEB MaXe
2009-05-15   Lussumo Vanilla 1.1.5/1.1.7 - 'updatecheck.php' Cross-Site Scripting 8 WEB Gerendi Sandor Attila
2009-05-27   PHP-Nuke 8.0 - '/main/tracking/userLog.php' SQL Injection 11 WEB Gerendi Sandor Attila
2009-05-22   DotNetNuke 4.9.3 - 'ErrorPage.aspx' Cross-Site Scripting 9 WEB ben hawkes
2009-05-22   LxBlog - Multiple Cross-Site Scripting / SQL Injections 11 WEB Securitylab.ir
2014-04-24   Alienvault 4.3.1 - SQL Injection / Cross-Site Scripting 6 WEB Sasha Zivojinovic
2014-04-24   WD Arkeia Virtual Appliance 10.2.9 - Local File Inclusion 9 WEB SEC Consult
2014-04-24   dompdf 0.6.0 - 'dompdf.php?read' Arbitrary File Read 8 WEB Portcullis
2014-04-24   WordPress Plugin Work-The-Flow 1.2.1 - Arbitrary File Upload 7 WEB nopesled
2009-05-20   Profense 2.2.20/2.4.2 - Web Application Firewall Security Bypass 8 WEB EnableSecurity
2009-05-20   Kingsoft Webshield 1.1.0.62 - Cross-Site Scripting / Remote Command Execution 9 WEB inking
2009-05-15   Cacti 0.8.7 - 'data_input.php' Cross-Site Scripting 8 WEB fgeek
2014-04-24   Bonefire 0.7.1 - Reinstall Admin Account 8 WEB Mehmet Ince
2009-05-11   Dacio's Image Gallery 1.6 - Multiple Remote Vulnerabilities 8 WEB ahmadbady
2009-05-08   MagpieRSS 0.72 - Cross-Site Scripting / HTML Injection 9 WEB Justin Klein Keane
2009-05-08   Claroline 1.8.11 - '/claroline/linker/notfound.php' Cross-Site Scripting 8 WEB Gerendi Sandor Attila
2014-04-23   HP Laser Jet - JavaScript Persistent Cross-Site Scripting via PJL Directory Traversal 9 WEB @0x00string
2009-05-06   Verlihub Control Panel 1.7 - Multiple Cross-Site Scripting Vulnerabilities 9 WEB TEAMELITE
2009-05-05   VerliAdmin 0.3 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 9 WEB TEAMELITE
2009-05-05   IceWarp Merak Mail Server 9.4.1 - 'Forgot Password' Input Validation 8 WEB RedTeam Pentesting GmbH
2009-05-05   IceWarp Merak Mail Server 9.4.1 - 'item.php' Cross-Site Scripting 7 WEB RedTeam Pentesting GmbH
2014-04-22   kitForm CRM Extension 0.43 - 'sorter.ph?sorter_value' SQL Injection 9 WEB chapp
2014-04-22   No-CMS 0.6.6 rev 1 - Admin Account Hijacking / Remote Code Execution via Static Encryption Key 8 WEB Mehmet Ince
2014-04-22   Sixnet Sixview 2.4.1 - Web Console Directory Traversal 9 WEB daniel svartman
2009-05-05   IceWarp Merak Mail Server 9.4.1 - 'cleanHTML()' Cross-Site Scripting 9 WEB RedTeam Pentesting GmbH
2009-05-05   IceWarp Merak Mail Server 9.4.1 Groupware Component - Multiple SQL Injections 9 WEB RedTeam Pentesting
2009-05-03   MyBB 1.4.5 - Multiple Vulnerabilities 9 WEB Jacques Copeau
2009-04-29   Coppermine Photo Gallery 1.4.21 - 'css' Cross-Site Scripting 9 WEB Gerendi Sandor Attila
2009-04-27   Invision Power Board (IP.Board) 3.0 - Multiple HTML Injection / Information Disclosure Vulnerabiliti 9 WEB brain[pillow]
2009-04-27   MataChat - 'input.php' Multiple Cross-Site Scripting Vulnerabilities 8 WEB Am!r
2009-04-24   PuterJam's Blog PJBlog3 3.0.6 - 'action.asp' SQL Injection 8 WEB anonymous
2009-04-23   CS Whois Lookup - 'ip' Remote Command Execution 9 WEB SirGod
2009-04-22   Flat Calendar 1.1 - 'add.php' HTML Injection 8 WEB ZoRLu
2009-04-22   New5starRating 1.0 - '/admin/control_panel_sample.php' SQL Injection 9 WEB zer0day
2014-04-20   Teracom Modem T2-B-Gawv1.4U10Y-BI - Cross-Site Request Forgery 9 WEB Rakesh S
2014-04-19   PTCeffect 4.6 - Local File Inclusion / SQL Injection 9 WEB walid naceri
2009-04-21   Sun Java System Delegated Administrator 6.x - HTTP Response Splitting 9 WEB SCS team
2009-04-20   Online Contact Manager 3.0 - 'delete.php?id' Cross-Site Scripting 8 WEB Vrs-hCk
2009-04-20   Online Contact Manager 3.0 - 'edit.php?id' Cross-Site Scripting 9 WEB Vrs-hCk
2009-04-20   Online Contact Manager 3.0 - 'email.php?id' Cross-Site Scripting 9 WEB Vrs-hCk
2009-04-20   Online Contact Manager 3.0 - 'view.php?id' Cross-Site Scripting 8 WEB Vrs-hCk
2009-04-20   Online Contact Manager 3.0 - 'index.php?showGroup' Cross-Site Scripting 9 WEB Vrs-hCk
2009-04-20   Online Photo Pro 2.0 - 'section' Cross-Site Scripting 9 WEB Vrs-hCk
2014-04-18   CMSimple 4.4/4.4.2 - Remote File Inclusion 9 WEB NoGe
2009-04-17   Malleo 1.2.3 - 'admin.php' Local File Inclusion 8 WEB Drosophila
2009-04-16   BlackBerry Enterprise Server 4.0/4.1 - MDS Connection Service Cross-Site Scripting 9 WEB Ken Millar
2009-04-16   RazorCMS 0.3RC2 - Multiple Vulnerabilities 7 WEB Jeremi Gosney
2009-04-16   Geeklog 1.5.2 - 'usersettings.php' SQL Injection 10 WEB Nine:Situations:Group::bookoo
2009-04-16   Phorum 5.2 - 'versioncheck.php?upgrade_available' Cross-Site Scripting 11 WEB voodoo-labs
2009-04-16   Phorum 5.2 - '/admin/users.php' Multiple Cross-Site Scripting Vulnerabilities 11 WEB voodoo-labs
2009-04-16   Phorum 5.2 - '/admin/banlist.php?curr' Cross-Site Scripting 10 WEB voodoo-labs
2009-04-16   Phorum 5.2 - '/admin/badwords.php?curr' Cross-Site Scripting 10 WEB voodoo-labs
2009-04-15   Novell Teaming 1.0 - User Enumeration / Multiple Cross-Site Scripting Vulnerabilities 9 WEB Michael Kirchner
2009-04-14   IBM Tivoli Continuous Data Protection for Files 3.1.4.0 - Cross-Site Scripting 9 WEB Abdul-Aziz Hariri
2009-04-13   Banshee 1.4.2 DAAP Extension - '/apps/web/vs_diag.cgi' Cross-Site Scripting 11 WEB Anthony de Almeida Lopes
2009-04-13   People-Trak - Login SQL Injection 8 WEB Mormoroth.net
2009-04-09   Absolute Form Processor XE 1.5 - 'login.asp' SQL Injection 10 WEB ThE g0bL!N
2009-04-09   Cisco Subscriber Edge Services Manager - Cross-Site Scripting / HTML Injection 11 WEB Usman Saeed
2009-04-09   IBM Bladecenter Advanced Management Module 1.42 - Cross-Site Request Forgery 11 WEB Henri Lindberg