Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2007-08-07   VietPHP - '/admin/index.php?language' Remote File Inclusion 24 WEB master-of-desastor
2007-08-07   VietPHP - '_functions.php?dirpath' Remote File Inclusion 24 WEB master-of-desastor
2007-08-06   snif 1.5.2 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 28 WEB r0t
2007-08-04   J! Reactions 1.8.1 - comPath Remote File Inclusion 25 WEB Yollubunlar.Org
2007-08-03   Next Gen Portfolio Manager - 'default.asp' Multiple SQL Injections 24 WEB Aria-Security Team
2007-08-03   Lanius CMS 1.2.14 GALLERY Module - 'gid' SQL Injection 21 WEB k1tk4t
2007-08-03   Lanius CMS 1.2.14 EZSHOPINGCART Module - 'cid' SQL Injection 26 WEB k1tk4t
2007-08-03   Lanius CMS 1.2.14 FAQ Module - 'mid' SQL Injection 30 WEB k1tk4t
2007-08-02   Hunkaray Okul Portali 1.1 - 'Duyuruoku.asp' SQL Injection 24 WEB Yollubunlar.Org
2007-08-02   Joomla! Component Tour de France Pool 1.0.1 Module - MosConfig_absolute_path Remote File Inclusion 24 WEB Yollubunlar.Org
2013-12-23   WordPress Theme Persuasion 2.x - Arbitrary File Download / File Deletion 23 WEB Interference Security
2007-08-01   WebDirector - 'index.php' Cross-Site Scripting 23 WEB r0t
2007-07-31   WebEvent 4.03 - 'Webevent.cgi' Cross-Site Scripting 22 WEB d3hydr8
2007-07-30   Global Centre Aplomb Poll 1.1 - 'admin.php?Madoa' Remote File Inclusion 23 WEB ilker Kandemir
2007-07-30   Global Centre Aplomb Poll 1.1 - 'vote.php?Madoa' Remote File Inclusion 21 WEB ilker Kandemir
2007-07-30   Global Centre Aplomb Poll 1.1 - 'index.php?Madoa' Remote File Inclusion 21 WEB ilker Kandemir
2007-07-30   IT!CMS 0.2 - 'titletext-ed.php?wndtitle' Cross-Site Scripting 23 WEB Aria-Security Team
2007-07-30   IT!CMS 0.2 - 'menu-ed.php?wndtitle' Cross-Site Scripting 27 WEB Aria-Security Team
2007-07-30   IT!CMS 0.2 - 'lang-en.php?wndtitle' Cross-Site Scripting 24 WEB Aria-Security Team
2007-07-28   phpCoupon - Remote Payment Bypass 22 WEB freeprotect.net
2007-07-28   Real Estate Listing Website Application Template Login Dialog - SQL Injection 23 WEB Aria-Security Team
2007-07-28   Pay Roll Time Sheet and Punch Card Application With Web UI - 'login.asp' SQL Injection 22 WEB Aria-Security Team
2007-07-28   Message Board / Threaded Discussion Forum - 'Sign_In.aspx' SQL Injection 27 WEB Aria-Security Team
2007-07-28   Online Store Application Template - 'Sign_In.aspx' SQL Injection 26 WEB Aria-Security Team
2007-07-28   Berthanas Ziyaretci Defteri 2.0 - 'Yonetici.asp' SQL Injection 24 WEB Yollubunlar
2007-07-27   Metyus Forum Portal 1.0 - 'Philboard_Forum.asp' SQL Injection 26 WEB Cr@zy_King
2013-12-21   Cisco EPC3925 - Persistent Cross-Site Scripting 24 WEB Jeroen - IT Nerdbox
2013-12-18   SonarQube Jenkins Plugin - Plain Text Password 26 WEB Christian Catalano
2013-12-18   Jenkins 1.523 - Persistent HTML Code 23 WEB Christian Catalano
2007-07-27   Bandersnatch 0.4 - Multiple Input Validation Vulnerabilities 26 WEB Tim Brown
2007-07-26   WordPress Plugin WP-FeedStats 2.1 - HTML Injection 23 WEB David Kierznowski
2007-07-26   Nukedit 4.9.x - 'login.asp' Cross-Site Scripting 21 WEB d3hydr8
2013-12-17   InstantCMS 1.10.3 - Blind SQL Injection 24 WEB High-Tech Bridge SA
2013-12-17   Ditto Forensic FieldStation 2013Oct15a - Multiple Vulnerabilities 22 WEB Martin Wundram
2007-07-26   PHPHostBot 1.05 - 'Authorize.php' Remote File Inclusion 23 WEB S4M3K
2007-07-26   BSM Store Dependent Forums 1.02 - 'Username' SQL Injection 25 WEB Aria-Security Team
2007-07-25   iFoto 1.0 - 'index.php' Directory Traversal 23 WEB Lostmon
2007-07-25   Vikingboard 0.1.2 - 'cp.php' Information Disclosure 24 WEB Lostmon
2007-07-25   Vikingboard 0.1.2 - 'forum.php' Information Disclosure 23 WEB Lostmon
2007-07-25   Vikingboard 0.1.2 - 'topic.php' Cross-Site Scripting 25 WEB Lostmon
2007-07-25   Vikingboard 0.1.2 - 'post.php' Cross-Site Scripting 21 WEB Lostmon
2007-07-25   Vikingboard 0.1.2 - 'user.php' Cross-Site Scripting 23 WEB Lostmon
2007-07-25   Vikingboard 0.1.2 - 'cp.php' Cross-Site Scripting 24 WEB Lostmon
2007-07-25   W1L3D4 philboard 0.3 - Cross-Site Scripting 23 WEB GeFORC3
2007-07-24   cPanel 10.9.1 - 'Resname' Cross-Site Scripting 23 WEB Aria-Security Team
2007-07-24   Webbler CMS 3.1.3 - Mail A Friend Open Email Relay 26 WEB Adrian Pastor
2007-07-24   Webbler CMS 3.1.3 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 24 WEB Adrian Pastor
2013-12-17   FileMaster SY-IT 3.1 iOS - Multiple Web Vulnerabilities 26 WEB Vulnerability-Lab
2007-07-23   Alstrasoft Affiliate Network Pro 8.0 - 'pgmid' SQL Injection 24 WEB Lostmon
2007-07-23   Alstrasoft Affiliate Network Pro 8.0 - 'temp.php' Cross-Site Scripting 23 WEB Lostmon
2007-07-23   Alstrasoft Affiliate Network Pro 8.0 - 'index.php' Cross-Site Scripting 25 WEB Lostmon
2007-07-23   Alstrasoft Sms Text Messaging Enterprise 2.0 - '/admin/edituser.php?userid' Cross-Site Scripting 27 WEB Lostmon
2007-07-23   Alstrasoft Sms Text Messaging Enterprise 2.0 - '/admin/membersearch.php' Multiple Cross-Site Scripti 26 WEB Lostmon
2007-07-23   Alstrasoft Video Share Enterprise 4.x - Multiple Input Validation Vulnerabilities 26 WEB Lostmon
2013-12-16   Penny Auction 5 - SQL Injection 24 WEB 3spi0n
2013-12-16   Lowest Unique Bid Auction - SQL Injection 26 WEB 3spi0n
2013-12-16   Cisco EPC3925 - Cross-Site Request Forgery 26 WEB Jeroen - IT Nerdbox
2013-12-16   Beetel TC1-450 Airtel Wireless Router - Multiple Cross-Site Request Forgery Vulnerabilities 21 WEB Samandeep Singh
2013-12-16   UPC Ireland Cisco EPC 2425 Router / Horizon Box - WPA-PSK Handshake Information 24 WEB Matt O'Connor
2013-12-16   iScripts MultiCart 2.4 - Persistent Cross-Site Scripting / Cross-Site Request Forgery / Cross-Site S 28 WEB Saadi Siddiqui
2013-12-16   Wallpaper Script 3.5.0082 - Persistent Cross-Site Scripting 26 WEB null pointer
2007-07-23   PHMe 0.0.2 - 'Function_List.php' Local File Inclusion 21 WEB You_You
2007-07-23   Image Racer - 'searchresults.asp' SQL Injection 23 WEB Aria-Security Team
2007-07-23   ASP cvmatik 1.1 - Multiple HTML Injection Vulnerabilities 22 WEB GeFORC3
2007-07-23   Alisveris Sitesi Scripti - 'index.asp' Cross-Site Scripting 24 WEB GeFORC3
2013-12-16   Gitlab 6.0 - Persistent Cross-Site Scripting 24 WEB hellok
2007-07-23   Alisveris Sitesi Scripti - 'index.asp' SQL Injection 28 WEB GeFORC3
2007-07-23   Dora Emlak 1.0 Script - Multiple Input Validation Vulnerabilities 24 WEB GeFORC3
2007-07-20   UseBB 1.0.7 - '/install/upgrade-0-3.php?PHP_SELF' Cross-Site Scripting 21 WEB s4mi
2007-07-20   UseBB 1.0.7 - '/install/upgrade-0-2-3.php?PHP_SELF' Cross-Site Scripting 21 WEB s4mi
2007-07-19   GeoBlog MOD_1.0 - 'deleteblog.php?id' Arbitrary Blog Deletion 25 WEB joseph.giron13
2007-07-19   GeoBlog MOD_1.0 - 'deletecomment.php?id' Arbitrary Comment Deletion 24 WEB joseph.giron13
2007-07-17   Insanely Simple Blog 0.4/0.5 - Cross-Site Scripting 24 WEB joseph.giron13
2007-07-17   Insanely Simple Blog 0.4/0.5 - 'index.php' SQL Injection 23 WEB joseph.giron13
2007-07-17   husrevforum 1.0.1/2.0.1 - 'Philboard_forum.asp' SQL Injection 26 WEB GeFORC3
2007-07-16   TBDev.NET DR - 'TakeProfEdit.php' HTML Injection 24 WEB PescaoDeth
2007-07-14   Citadel WebCit 7.02/7.10 - 'showuser?who' Cross-Site Scripting 22 WEB Christopher Schwardt
2013-12-15   Phone Drive Eightythree 4.1.1 iOS - Multiple Vulnerabilities 24 WEB Vulnerability-Lab
2013-12-15   Piwigo CMS 2.5.3 - Multiple Web Vulnerabilities 24 WEB sajith
2007-07-13   Dating Gold 3.0.5 - 'secure.admin.php?int_path' Remote File Inclusion 25 WEB mostafa_ragab
2007-07-13   Dating Gold 3.0.5 - 'footer.php?int_path' Remote File Inclusion 22 WEB mostafa_ragab
2007-07-13   Dating Gold 3.0.5 - 'header.php?int_path' Remote File Inclusion 21 WEB mostafa_ragab
2007-03-23   MzK Blog - 'Katgoster.asp' SQL Injection 26 WEB GeFORC3
2007-07-13   ActiveWeb Contentserver CMS 5.6.2929 - Client-Side Filtering Bypass 26 WEB RedTeam Pentesting
2007-07-13   contentserver 5.6.2929 - '/errors/transaction.asp?msg' Cross-Site Scripting 23 WEB RedTeam Pentesting
2007-07-13   contentserver 5.6.2929 - '/errors/rights.asp?msg' Cross-Site Scripting 26 WEB RedTeam Pentesting
2007-07-13   ActiveWeb Contentserver 5.6.2929 - 'Picture_Real_Edit.asp' SQL Injection 25 WEB RedTeam Pentesting
2007-07-12   Inmostore 4.0 - 'index.php' SQL Injection 23 WEB Keniobats
2007-07-12   Helma 1.5.3 - Search Script Cross-Site Scripting 26 WEB Hanno Boeck
2007-07-11   IBM Proventia Sensor Appliance - Multiple Input Validation Vulnerabilities 22 WEB Alex Hernandez
2007-07-11   EnViVo!CMS - 'default.asp?ID' SQL Injection 23 WEB durito
2007-07-10   ImgSvr 0.6 - 'Template' Local File Inclusion 28 WEB Tim Brown
2007-07-09   SquirrelMail G/PGP Encryption Plugin 2.0/2.1 - Multiple Remote Command Execution Vulnerabilities 24 WEB Stefan Esser
2007-07-07   Levent Veysi Portal 1.0 - 'Oku.asp' SQL Injection 27 WEB GeFORC3
2007-07-05   Maia Mailguard 1.0.2 - 'login.php' Multiple Local File Inclusions 24 WEB Adriel T. Desautels
2007-07-04   OpManager 6/7 - '/admin/DeviceAssociation.do' Multiple Cross-Site Scripting Vulnerabilities 25 WEB Lostmon
2007-07-04   OpManager 6/7 - 'admin/ServiceConfiguration.do?Operation' Cross-Site Scripting 24 WEB Lostmon
2007-07-04   OpManager 6/7 - reports/ReportViewAction.do Multiple Cross-Site Scripting Vulnerabilities 24 WEB Lostmon
2007-07-04   OpManager 6/7 - 'traceRoute.do?name' Cross-Site Scripting 23 WEB Lostmon
2007-07-04   OpManager 6/7 - 'ping.do?name' Cross-Site Scripting 23 WEB Lostmon
2007-07-04   NetFlow Analyzer 5 - '/jspui/customReport.jsp?rtype' Cross-Site Scripting 23 WEB Lostmon
2007-07-04   NetFlow Analyzer 5 - '/jspui/selectDevice.jsp?rtype' Cross-Site Scripting 24 WEB Lostmon
2007-07-04   NetFlow Analyzer 5 - 'netflow/jspui/index.jsp?view' Cross-Site Scripting 24 WEB Lostmon
2007-07-04   NetFlow Analyzer 5 - '/jspui/appConfig.jsp?task' Cross-Site Scripting 24 WEB Lostmon
2007-07-04   NetFlow Analyzer 5 - '/jspui/applicationList.jsp?alpha' Cross-Site Scripting 26 WEB Lostmon
2007-07-03   Oliver - Multiple Cross-Site Scripting Vulnerabilities 25 WEB A. R.
2007-07-02   Liesbeth Base CMS - Information Disclosure 29 WEB durito
2007-07-02   Moodle 1.7.1 - 'index.php' Cross-Site Scripting 21 WEB MustLive
2007-07-02   Yoggie Pico and Pico Pro Backticks - Remote Code Execution 25 WEB Cody Brocious
2007-07-02   Claroline 1.8.3 - '$_SERVER['PHP_SELF']' Multiple Cross-Site Scripting Vulnerabilities 26 WEB munozferna
2007-06-27   ETicket 1.5.5 - 'Open.php' Multiple Cross-Site Scripting Vulnerabilities 25 WEB Jesper Jurcenoks
2006-12-02   DUClassmate 1.x - 'ICity' SQL Injection 23 WEB Aria-Security Team
2007-06-27   Papoo 1.0.3 - 'Plugin.php' Authentication Bypass 27 WEB Nico Leidecker
2013-12-12   Pentagram Cerberus P 6363 DSL Router - Multiple Vulnerabilities 23 WEB condis
2013-12-12   WHMCompleteSolution (WHMCS) 4.x/5.x - Multiple Web Vulnerabilities 22 WEB AhwAk20o0 --
2013-12-12   Cythosia 2.x Botnet (C2 Web Panel) - SQL Injection 28 WEB GalaxyAndroid
2013-12-12   KikChat - Local File Inclusion / Remote Code Execution 23 WEB cr4wl3r
2007-06-25   Calendarix 0.7.20070307 - Multiple SQL Injections 26 WEB Jesper Jurcenoks
2007-06-25   Calendarix 0.7.20070307 - Multiple Cross-Site Scripting Vulnerabilities 25 WEB Jesper Jurcenoks
2007-06-25   MyNews 0.10 - AuthACC SQL Injection 23 WEB netVigilance
2007-06-22   Joomla! / Mambo Component Mod_Forum - 'PHPBB_Root.php' Remote File Inclusion 24 WEB spymeta
2007-06-22   eNdonesia 8.4 - 'banners.php?click Action bid' SQL Injection 26 WEB laurent gaffie
2007-06-22   eNdonesia 8.4 - 'mod.php?viewarticle Action artid' SQL Injection 22 WEB laurent gaffie
2007-06-21   NetClassifieds 1.9.7 - Multiple Input Validation Vulnerabilities 26 WEB laurent gaffie
2007-06-21   PHPAccounts 0.5 - 'index.php' Multiple SQL Injections 23 WEB r0t