2005-11-15
|
|
PHPWCMS 1.2.5 -DEV - 'imgdir' Traversal Arbitrary File Access
|
1 |
WEB
|
Stefan Lochbihler
|
2005-11-15
|
|
PHPWCMS 1.2.5 -DEV - 'login.php?form_lang' Traversal Arbitrary File Access
|
1 |
WEB
|
Stefan Lochbihler
|
2005-11-15
|
|
Pearl Forums 2.0 - 'index.php' Local File Inclusion
|
1 |
WEB
|
abducter_minds@yahoo.com
|
2005-11-15
|
|
Pearl Forums 2.0 - 'index.php' Multiple SQL Injections
|
1 |
WEB
|
abducter_minds@yahoo.com
|
2005-11-15
|
|
Walla TeleSite 3.0 - 'ts.cgi' File Existence Enumeration
|
1 |
WEB
|
Rafi Nahum
|
2005-11-15
|
|
Walla TeleSite 3.0 - 'ts.exe?sug' SQL Injection
|
1 |
WEB
|
Rafi Nahum
|
2005-11-15
|
|
Walla TeleSite 3.0 - 'ts.exe?sug' Cross-Site Scripting
|
1 |
WEB
|
Rafi Nahum
|
2005-11-15
|
|
Walla TeleSite 3.0 - 'ts.exe?tsurl' Arbitrary Article Access
|
1 |
WEB
|
Rafi Nahum
|
2005-11-14
|
|
Codegrrl - 'Protection.php' Code Execution
|
1 |
WEB
|
Robin Verton
|
2005-11-14
|
|
Wizz Forum - 'forumreply.php?TopicID' SQL Injection
|
1 |
WEB
|
HACKERS PAL
|
2005-11-14
|
|
Wizz Forum - 'ForumAuthDetails.php?AuthID' SQL Injection
|
1 |
WEB
|
HACKERS PAL
|
2005-11-14
|
|
Help Center Live 1.0/1.2/2.0 - 'module.php' Local File Inclusion
|
1 |
WEB
|
HACKERS PAL
|
2005-11-12
|
|
ActiveCampaign 1-2-All Broadcast Email 4.0 - Admin Control Panel 'Username' SQL Injection
|
1 |
WEB
|
bhs_team
|
2005-11-12
|
|
PHPWebThings 1.4 - 'download.php?File' SQL Injection
|
1 |
WEB
|
A.1.M
|
2005-11-11
|
|
PHPSysInfo 2.x - Multiple Input Validation Vulnerabilities
|
1 |
WEB
|
anonymous
|
2013-06-30
|
|
eFile Wifi Transfer Manager 1.0 - Multiple Vulnerabilities
|
1 |
WEB
|
Vulnerability-Lab
|
2005-11-09
|
|
TikiWiki 1.9 - 'Tiki-view_forum_thread.php' Cross-Site Scripting
|
1 |
WEB
|
Moritz Naumann
|
2005-11-09
|
|
SAP Web Application Server 6.x/7.0 - Open Redirection
|
1 |
WEB
|
Leandro Meiners
|
2005-11-09
|
|
SAP Web Application Server 6.x/7.0 - 'frameset.htm?sap-syscmd' Cross-Site Scripting
|
1 |
WEB
|
Leandro Meiners
|
2005-11-09
|
|
SAP Web Application Server 6.x/7.0 - Error Page Cross-Site Scripting
|
1 |
WEB
|
Leandro Meiners
|
2005-11-07
|
|
PHPList Mailing List Manager 2.x - '/admin/users.php?find' Cross-Site Scripting
|
1 |
WEB
|
Tobias Klein
|
2005-11-07
|
|
PHPList Mailing List Manager 2.x - '/admin/configure.php?id' Cross-Site Scripting
|
1 |
WEB
|
Tobias Klein
|
2005-11-07
|
|
PHPList Mailing List Manager 2.x - '/admin/eventlog.php' Multiple Cross-Site Scripting Vulnerabiliti
|
0 |
WEB
|
Tobias Klein
|
2005-11-07
|
|
PHPList Mailing List Manager 2.x - '/admin/editattributes.php?id' SQL Injection
|
0 |
WEB
|
Tobias Klein
|
2005-11-07
|
|
PHPList Mailing List Manager 2.x - '/admin/admin.php?id' SQL Injection
|
1 |
WEB
|
Tobias Klein
|
2005-11-07
|
|
ToendaCMS 0.6.1 - 'admin.php' Directory Traversal
|
1 |
WEB
|
Bernhard Mueller
|
2005-11-07
|
|
Invision Power Board (IP.Board) 2.1 - 'admin.php' Multiple Cross-Site Scripting Vulnerabilities
|
1 |
WEB
|
benjilenoob
|
2005-11-07
|
|
XMB Forum 1.9.3 - 'u2u.php' Cross-Site Scripting
|
1 |
WEB
|
HACKERS PAL
|
2005-11-07
|
|
OSTE 1.0 - Remote File Inclusion
|
1 |
WEB
|
khc@bsdmail.org
|
2005-11-07
|
|
Asterisk 0.x/1.0/1.2 Voicemail - Unauthorized Access
|
1 |
WEB
|
Adam Pointon
|
2005-11-07
|
|
PHPFM - Arbitrary File Upload
|
1 |
WEB
|
rUnViRuS
|
2005-11-04
|
|
Ocean12 ASP Calendar Manager 1.0 - Authentication Bypass
|
0 |
WEB
|
syst3m_f4ult
|
2005-11-04
|
|
JPortal Web Portal 2.2.1/2.3.1 - 'news.php' SQL Injection
|
1 |
WEB
|
Mousehack
|
2005-11-04
|
|
JPortal Web Portal 2.2.1/2.3.1 - 'comment.php' SQL Injection
|
1 |
WEB
|
Mousehack
|
2005-11-03
|
|
Galerie 2.4 - 'showgallery.php' SQL Injection
|
1 |
WEB
|
abducter_minds@yahoo.com
|
2005-11-03
|
|
PHP Handicapper (2005) - 'Process_signup.php' HTTP Response Splitting
|
1 |
WEB
|
BiPi_HaCk
|
2005-11-02
|
|
CuteNews 1.4.1 - 'template' Traversal Arbitrary File Access
|
1 |
WEB
|
retrogod@aliceposta.it
|
2005-11-02
|
|
CuteNews 1.4.1 - 'show_archives.php' Traversal Arbitrary File Access
|
1 |
WEB
|
retrogod@aliceposta.it
|
2005-11-02
|
|
Simple PHP Blog 0.4 - 'colors.php' Multiple Cross-Site Scripting Vulnerabilities
|
1 |
WEB
|
enji@infosys.tuwien.ac.at
|
2005-11-02
|
|
Simple PHP Blog 0.4 - 'preview_static_cgi.php' Multiple Cross-Site Scripting Vulnerabilities
|
1 |
WEB
|
enji@infosys.tuwien.ac.at
|
2005-11-02
|
|
Simple PHP Blog 0.4 - 'preview_cgi.php' Multiple Cross-Site Scripting Vulnerabilities
|
1 |
WEB
|
enji@infosys.tuwien.ac.at
|
2005-11-02
|
|
PHPWebThings 0.4.4 - 'forum.php' Cross-Site Scripting
|
1 |
WEB
|
Linux_Drox
|
2005-11-02
|
|
News2Net 3.0 - 'index.php' SQL Injection
|
1 |
WEB
|
Mousehack
|
2005-11-01
|
|
XMB Forum 1.9.3 - 'post.php' SQL Injection
|
1 |
WEB
|
almaster
|
2005-11-01
|
|
VUBB - 'index.php' Cross-Site Scripting
|
0 |
WEB
|
Alireza Hassani
|
2013-06-26
|
|
PHP-Charts 1.0 - 'index.php?type' Remote Code Execution
|
0 |
WEB
|
infodox
|
2013-06-26
|
|
e107 Advanced Medal System Plugin - SQL Injection
|
2 |
WEB
|
Life Wasted
|
2005-11-01
|
|
Elite Forum 1.0 - HTML Injection
|
2 |
WEB
|
gladiator
|
2005-11-01
|
|
Belchior Foundry vCard Pro 3.1 - 'Addrbook.php' SQL Injection
|
2 |
WEB
|
almaster
|
2005-10-31
|
|
Comersus Backoffice 4.x/5.0/6.0 - '/comersus/database/comersus.mdb' Direct Request Database Disclosu
|
2 |
WEB
|
_6mO_HaCk
|
2005-10-31
|
|
Comersus Backoffice 4.x/5.0/6.0 - 'comersus_Backoffice_supportError.asp?error' Cross-Site Scripting
|
2 |
WEB
|
_6mO_HaCk
|
2005-10-31
|
|
PHP 4.x - PHPInfo Cross-Site Scripting
|
2 |
WEB
|
Stefan Esser
|
2005-10-31
|
|
OaBoard 1.0 - 'forum.php' Multiple SQL Injections
|
3 |
WEB
|
abducter_minds@yahoo.com
|
2005-10-31
|
|
PHPCafe Tutorial Manager - 'index.php' SQL Injection
|
2 |
WEB
|
almaster
|
2005-10-31
|
|
Snitz Forum 2000 - 'post.asp' Cross-Site Scripting
|
2 |
WEB
|
h4xorcrew
|
2005-10-31
|
|
Invision Gallery 2.0.3 - 'index.php' SQL Injection
|
2 |
WEB
|
almaster
|
2005-10-29
|
|
PHP Advanced Transfer Manager 1.30 - Remote Unauthorized Access
|
2 |
WEB
|
Zeelock
|
2005-10-29
|
|
MG2 0.5.1 - Authentication Bypass
|
2 |
WEB
|
Preben Nylokken
|
2005-10-27
|
|
ASP Fast Forum - 'error.asp' Cross-Site Scripting
|
2 |
WEB
|
syst3m_f4ult
|
2005-10-27
|
|
PBLang 4.65 - Multiple Cross-Site Scripting Vulnerabilities
|
1 |
WEB
|
abducter
|
2005-10-27
|
|
ATutor 1.x - 'print.php?section' Remote File Inclusion
|
1 |
WEB
|
Andreas Sandblad
|
2005-10-27
|
|
ATutor 1.x - 'body_header.inc.php?section' Local File Inclusion
|
1 |
WEB
|
Andreas Sandblad
|
2005-10-27
|
|
ATutor 1.x - 'forum.inc.php' Arbitrary Command Execution
|
2 |
WEB
|
Andreas Sandblad
|
2005-10-27
|
|
Novell ZENworks Patch Management 6.0.52 - '/reports/default.asp' Multiple SQL Injections
|
2 |
WEB
|
Dennis Rand
|
2005-10-27
|
|
Novell ZENworks Patch Management 6.0.52 - '/computers/default.asp?Direction' SQL Injection
|
1 |
WEB
|
Dennis Rand
|
2005-10-26
|
|
PHP-Nuke Search Enhanced Module 1.1/2.0 - HTML Injection
|
2 |
WEB
|
bhfh01
|
2005-10-26
|
|
GCards 1.43 - 'news.php' SQL Injection
|
2 |
WEB
|
svsecurity
|
2005-10-26
|
|
Techno Dreams (Multiple Scripts) - Multiple SQL Injections
|
2 |
WEB
|
farhad koosha
|
2005-10-26
|
|
Woltlab 1.1/2.x - 'Info-DB Info_db.php' Multiple SQL Injections
|
2 |
WEB
|
admin@batznet.com
|
2005-10-26
|
|
Mantis Bug Tracker 0.19.2/1.0 - 'Bug_sponsorship_list_view_inc.php' File Inclusion
|
2 |
WEB
|
Andreas Sandblad
|
2013-06-24
|
|
Elemata CMS RC3.0 - 'global.php?id' SQL Injection
|
2 |
WEB
|
CWH Underground
|
2013-06-24
|
|
Linksys X3000 1.0.03 build 001 - Multiple Vulnerabilities
|
0 |
WEB
|
m-1-k-3
|
2013-06-24
|
|
PodHawk 1.85 - Arbitrary File Upload
|
1 |
WEB
|
CWH Underground
|
2013-06-24
|
|
Collabtive 1.0 - 'manageuser.php' SQL Injection
|
2 |
WEB
|
drone
|
2013-06-24
|
|
phpEventCalendar 0.2.3 - Multiple Vulnerabilities
|
2 |
WEB
|
AtT4CKxT3rR0r1ST
|
2013-06-24
|
|
Alienvault Open Source SIEM (OSSIM) 4.1 - Multiple SQL Injection Vulnerabilities
|
2 |
WEB
|
Glafkos Charalambous
|
2013-06-24
|
|
Top Games Script 1.2 - 'play.php?gid' SQL Injection
|
2 |
WEB
|
AtT4CKxT3rR0r1ST
|
2013-06-24
|
|
TRENDnet TE100-P1U Print Server Firmware 4.11 - Authentication Bypass
|
0 |
WEB
|
Chako
|
2005-10-26
|
|
Flyspray 0.9 - Multiple Cross-Site Scripting Vulnerabilities
|
0 |
WEB
|
Lostmon
|
2005-10-26
|
|
Belchior Foundry VCard 2.9 - Remote File Inclusion
|
0 |
WEB
|
X
|
2005-10-26
|
|
RSA ACE Agent 5.x - Image Cross-Site Scripting
|
0 |
WEB
|
Bernhard Mueller
|
2005-10-26
|
|
IPBProArcade 2.5.2 - 'GameID' SQL Injection
|
0 |
WEB
|
almaster
|
2005-10-26
|
|
MyBulletinBoard (MyBB) 1.0 - 'usercp.php' SQL Injection
|
0 |
WEB
|
Animal
|
2005-10-25
|
|
Basic Analysis and Security Engine (BASE) 1.2 - 'Base_qry_main.php' SQL Injection
|
0 |
WEB
|
Remco Verhoef
|
2005-05-21
|
|
MWChat 6.8 - 'chat.php' SQL Injection
|
0 |
WEB
|
rgod
|
2005-05-20
|
|
phpMyAdmin 2.x - 'server_databases.php' Cross-Site Scripting
|
0 |
WEB
|
Tobias Klein
|
2005-05-20
|
|
phpMyAdmin 2.x - 'queryframe.php' Cross-Site Scripting
|
0 |
WEB
|
Tobias Klein
|
2005-10-24
|
|
SiteTurn Domain Manager Pro - Admin Panel Cross-Site Scripting
|
0 |
WEB
|
farhad koosha
|
2005-10-26
|
|
saPHP Lesson - 'add.php?forumid' SQL Injection
|
0 |
WEB
|
almaster
|
2005-10-24
|
|
Nuked-klaN 1.7 Links Module - 'link_id' SQL Injection
|
0 |
WEB
|
papipsycho
|
2005-10-24
|
|
Nuked-klaN 1.7 Download Module - 'dl_id' SQL Injection
|
0 |
WEB
|
papipsycho
|
2005-10-24
|
|
Nuked-klaN 1.7 Sections Module - 'artid' SQL Injection
|
0 |
WEB
|
papipsycho
|
2005-10-24
|
|
Nuked-klaN 1.7 Forum Module - Multiple SQL Injections
|
0 |
WEB
|
papipsycho
|
2005-10-26
|
|
FlatNuke 2.5.x - 'index.php' Cross-Site Scripting
|
1 |
WEB
|
alex@aleksanet.com
|
2005-10-22
|
|
FlatNuke 2.5.x - 'index.php' Multiple Remote File Inclusions
|
1 |
WEB
|
abducter_minds@yahoo.com
|
2005-10-22
|
|
Zomplog 3.3/3.4 - 'detail.php' HTML Injection
|
2 |
WEB
|
sikikmail
|
2005-10-20
|
|
Chipmunk Directory - 'recommend.php?entryID' Cross-Site Scripting
|
1 |
WEB
|
Alireza Hassani
|
2005-10-20
|
|
Chipmunk Forum - 'recommend.php?ID' Cross-Site Scripting
|
1 |
WEB
|
Alireza Hassani
|
2005-10-20
|
|
Chipmunk Forum - 'quote.php?forumID' Cross-Site Scripting
|
1 |
WEB
|
Alireza Hassani
|
2005-10-20
|
|
Chipmunk Forum - 'newtopic.php?forumID' Cross-Site Scripting
|
1 |
WEB
|
Alireza Hassani
|
2005-10-19
|
|
PHP-Nuke Search Module - 'modules.php' Directory Traversal
|
2 |
WEB
|
sp3x@securityreason.com
|
2005-10-18
|
|
MySource 2.14 - 'mime.php?PEAR_PATH' Remote File Inclusion
|
2 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'mimeDecode.php?PEAR_PATH' Remote File Inclusion
|
2 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'Span.php?PEAR_PATH' Remote File Inclusion
|
2 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'Date.php?PEAR_PATH' Remote File Inclusion
|
2 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'mail.php?PEAR_PATH' Remote File Inclusion
|
2 |
WEB
|
Secunia Research
|
2013-06-21
|
|
GLPI 0.83.8 - Multiple Vulnerabilities
|
1 |
WEB
|
LiquidWorm
|
2005-10-18
|
|
MySource 2.14 - 'Request.php?PEAR_PATH' Remote File Inclusion
|
1 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'Socket.php?PEAR_PATH' Remote File Inclusion
|
1 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'init_mysource.php?INCLUDE_PATH' Remote File Inclusion
|
1 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'new_upgrade_functions.php' Multiple Remote File Inclusions
|
1 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'edit_table_cell_type_wysiwyg.php?Stylesheet' Cross-Site Scripting
|
0 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'edit_table_props.php?bgcolor' Cross-Site Scripting
|
1 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'edit_table_row_props.php?bgcolor' Cross-Site Scripting
|
1 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'header.php?bgcolor' Cross-Site Scripting
|
1 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'edit_table_cell_props.php?bgcolor' Cross-Site Scripting
|
1 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'insert_table.php?bgcolor' Cross-Site Scripting
|
1 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'upgrade_in_progress_backend.php?target_url' Cross-Site Scripting
|
1 |
WEB
|
Secunia Research
|
2005-10-18
|
|
NetFlow Analyzer 4 - Cross-Site Scripting
|
2 |
WEB
|
why@nsfocus.com
|
2005-10-17
|
|
Comersus Backoffice Plus - Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
Lostmon
|
2005-10-15
|
|
PunBB 1.2.x - 'search.php' SQL Injection
|
2 |
WEB
|
Devil_box
|
2005-10-14
|
|
Complete PHP - Counter Cross-Site Scripting
|
2 |
WEB
|
BiPi_HaCk
|
2005-10-14
|
|
Complete PHP Counter - SQL Injection
|
2 |
WEB
|
BiPi_HaCk
|
2005-10-14
|
|
Gallery 2.0 - 'main.php' Directory Traversal
|
2 |
WEB
|
Michael Dipper
|
2005-10-13
|
|
Accelerated Mortgage Manager - 'Password' SQL Injection
|
2 |
WEB
|
imready4chillin
|