2005-05-20
|
|
phpMyAdmin 2.x - 'queryframe.php' Cross-Site Scripting
|
3 |
WEB
|
Tobias Klein
|
2005-10-24
|
|
SiteTurn Domain Manager Pro - Admin Panel Cross-Site Scripting
|
3 |
WEB
|
farhad koosha
|
2005-10-26
|
|
saPHP Lesson - 'add.php?forumid' SQL Injection
|
2 |
WEB
|
almaster
|
2005-10-24
|
|
Nuked-klaN 1.7 Links Module - 'link_id' SQL Injection
|
3 |
WEB
|
papipsycho
|
2005-10-24
|
|
Nuked-klaN 1.7 Download Module - 'dl_id' SQL Injection
|
2 |
WEB
|
papipsycho
|
2005-10-24
|
|
Nuked-klaN 1.7 Sections Module - 'artid' SQL Injection
|
3 |
WEB
|
papipsycho
|
2005-10-24
|
|
Nuked-klaN 1.7 Forum Module - Multiple SQL Injections
|
3 |
WEB
|
papipsycho
|
2005-10-26
|
|
FlatNuke 2.5.x - 'index.php' Cross-Site Scripting
|
3 |
WEB
|
alex@aleksanet.com
|
2005-10-22
|
|
FlatNuke 2.5.x - 'index.php' Multiple Remote File Inclusions
|
3 |
WEB
|
abducter_minds@yahoo.com
|
2005-10-22
|
|
Zomplog 3.3/3.4 - 'detail.php' HTML Injection
|
4 |
WEB
|
sikikmail
|
2005-10-20
|
|
Chipmunk Directory - 'recommend.php?entryID' Cross-Site Scripting
|
3 |
WEB
|
Alireza Hassani
|
2005-10-20
|
|
Chipmunk Forum - 'recommend.php?ID' Cross-Site Scripting
|
3 |
WEB
|
Alireza Hassani
|
2005-10-20
|
|
Chipmunk Forum - 'quote.php?forumID' Cross-Site Scripting
|
3 |
WEB
|
Alireza Hassani
|
2005-10-20
|
|
Chipmunk Forum - 'newtopic.php?forumID' Cross-Site Scripting
|
3 |
WEB
|
Alireza Hassani
|
2005-10-19
|
|
PHP-Nuke Search Module - 'modules.php' Directory Traversal
|
3 |
WEB
|
sp3x@securityreason.com
|
2005-10-18
|
|
MySource 2.14 - 'mime.php?PEAR_PATH' Remote File Inclusion
|
3 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'mimeDecode.php?PEAR_PATH' Remote File Inclusion
|
3 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'Span.php?PEAR_PATH' Remote File Inclusion
|
3 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'Date.php?PEAR_PATH' Remote File Inclusion
|
3 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'mail.php?PEAR_PATH' Remote File Inclusion
|
3 |
WEB
|
Secunia Research
|
2013-06-21
|
|
GLPI 0.83.8 - Multiple Vulnerabilities
|
2 |
WEB
|
LiquidWorm
|
2005-10-18
|
|
MySource 2.14 - 'Request.php?PEAR_PATH' Remote File Inclusion
|
3 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'Socket.php?PEAR_PATH' Remote File Inclusion
|
3 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'init_mysource.php?INCLUDE_PATH' Remote File Inclusion
|
3 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'new_upgrade_functions.php' Multiple Remote File Inclusions
|
3 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'edit_table_cell_type_wysiwyg.php?Stylesheet' Cross-Site Scripting
|
2 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'edit_table_props.php?bgcolor' Cross-Site Scripting
|
3 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'edit_table_row_props.php?bgcolor' Cross-Site Scripting
|
3 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'header.php?bgcolor' Cross-Site Scripting
|
3 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'edit_table_cell_props.php?bgcolor' Cross-Site Scripting
|
3 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'insert_table.php?bgcolor' Cross-Site Scripting
|
3 |
WEB
|
Secunia Research
|
2005-10-18
|
|
MySource 2.14 - 'upgrade_in_progress_backend.php?target_url' Cross-Site Scripting
|
2 |
WEB
|
Secunia Research
|
2005-10-18
|
|
NetFlow Analyzer 4 - Cross-Site Scripting
|
2 |
WEB
|
why@nsfocus.com
|
2005-10-17
|
|
Comersus Backoffice Plus - Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
Lostmon
|
2005-10-15
|
|
PunBB 1.2.x - 'search.php' SQL Injection
|
2 |
WEB
|
Devil_box
|
2005-10-14
|
|
Complete PHP - Counter Cross-Site Scripting
|
2 |
WEB
|
BiPi_HaCk
|
2005-10-14
|
|
Complete PHP Counter - SQL Injection
|
2 |
WEB
|
BiPi_HaCk
|
2005-10-14
|
|
Gallery 2.0 - 'main.php' Directory Traversal
|
2 |
WEB
|
Michael Dipper
|
2005-10-13
|
|
Accelerated Mortgage Manager - 'Password' SQL Injection
|
2 |
WEB
|
imready4chillin
|
2005-10-13
|
|
YaPiG 0.95b - 'view.php?img_size' Cross-Site Scripting
|
2 |
WEB
|
enji@infosys.tuwien.ac.at
|
2005-10-12
|
|
WebGUI 6.x - Arbitrary Command Execution
|
2 |
WEB
|
David Maciejak
|
2005-10-11
|
|
Accelerated E Solutions - SQL Injection
|
3 |
WEB
|
Andysheh Soltani
|
2005-10-08
|
|
Cyphor 0.19 - 'footer.php?t_login' Cross-Site Scripting
|
3 |
WEB
|
retrogod@aliceposta.it
|
2005-10-08
|
|
Cyphor 0.19 - 'newmsg.php?fid' SQL Injection
|
3 |
WEB
|
retrogod@aliceposta.it
|
2005-10-08
|
|
Cyphor 0.19 - 'lostpwd.php?nick' SQL Injection
|
3 |
WEB
|
rgod
|
2005-10-07
|
|
Aenovo - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
farhad koosha
|
2005-10-07
|
|
Aenovo - '/incs/searchdisplay.asp?strSQL' SQL Injection
|
3 |
WEB
|
farhad koosha
|
2005-10-07
|
|
Aenovo - '/Password/default.asp?Password' SQL Injection
|
3 |
WEB
|
farhad koosha
|
2005-10-07
|
|
Utopia News Pro 1.1.3 - 'footer.php' Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
rgod
|
2005-10-07
|
|
Utopia News Pro 1.1.3 - 'header.php?sitetitle' Cross-Site Scripting
|
3 |
WEB
|
rgod
|
2005-10-05
|
|
TellMe 1.2 - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Donnie Werner
|
2013-06-19
|
|
Monkey CMS - Multiple Vulnerabilities
|
3 |
WEB
|
Yashar shahinzadeh_ Mormoroth
|
2013-06-19
|
|
imacs CMS 0.3.0 - Unrestricted Arbitrary File Upload
|
3 |
WEB
|
CWH Underground
|
2005-09-30
|
|
Merak Mail Server 8.2.4 r - Arbitrary File Deletion
|
2 |
WEB
|
ShineShadow
|
2005-09-30
|
|
EasyGuppy 4.5.4/4.5.5 - 'Printfaq.php' Directory Traversal
|
3 |
WEB
|
Josh Zlatin-Amishav
|
2005-09-30
|
|
IceWarp Web Mail 5.5.1 - 'calendar_w.html?createdataCX' Cross-Site Scripting
|
3 |
WEB
|
ss_contacts
|
2005-09-30
|
|
IceWarp Web Mail 5.5.1 - 'calendar_m.html?createdataCX' Cross-Site Scripting
|
3 |
WEB
|
ss_contacts
|
2005-09-30
|
|
IceWarp Web Mail 5.5.1 - 'calendar_d.html?createdataCX' Cross-Site Scripting
|
3 |
WEB
|
ss_contacts
|
2005-09-30
|
|
IceWarp Web Mail 5.5.1 - 'blank.html?id' Cross-Site Scripting
|
3 |
WEB
|
ss_contacts
|
2005-09-29
|
|
LucidCMS 2.0 - Login SQL Injection
|
3 |
WEB
|
rgod
|
2005-09-29
|
|
SquirrelMail 1.4.2 Address Add Plugin - 'add.php' Cross-Site Scripting
|
3 |
WEB
|
anonymous
|
2005-09-28
|
|
CubeCart 3.0.3 - 'cart.php?redir' Cross-Site Scripting
|
3 |
WEB
|
Lostmon
|
2005-09-28
|
|
CubeCart 3.0.3 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Lostmon
|
2005-09-28
|
|
TWiki TWikiUsers - INCLUDE Function Arbitrary Command Execution
|
3 |
WEB
|
JChristophFuchs
|
2005-09-27
|
|
LucidCMS 2.0 - 'index.php' Cross-Site Scripting
|
3 |
WEB
|
X1ngBox
|
2005-09-26
|
|
CMS Made Simple 0.10 - 'index.php' Cross-Site Scripting
|
3 |
WEB
|
X1ngBox
|
2005-08-23
|
|
PHPMyFAQ 1.5.1 - Logs Unauthorized Access
|
3 |
WEB
|
rgod
|
2005-08-23
|
|
PHPMyFAQ 1.5.1 - Local File Inclusion
|
3 |
WEB
|
rgod
|
2005-09-23
|
|
PHPMyFAQ 1.5.1 - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
rgod
|
2005-08-23
|
|
PHPMyFAQ 1.5.1 - 'Password.php' SQL Injection
|
3 |
WEB
|
retrogod@aliceposta.it
|
2005-08-21
|
|
jPORTAL 2.2.1/2.3.1 - 'download.php' SQL Injection
|
3 |
WEB
|
krasza
|
2005-08-21
|
|
Mall23 - 'AddItem.asp' SQL Injection
|
3 |
WEB
|
SmOk3
|
2005-08-21
|
|
PerlDiver 2.31 - 'Perldiver.cgi' Cross-Site Scripting
|
3 |
WEB
|
Donnie Werner
|
2005-08-21
|
|
Alkalay.Net (Multiple Scripts) - Remote Command Execution
|
3 |
WEB
|
sullo@cirt.net
|
2005-09-20
|
|
PHP Advanced Transfer Manager 1.30 - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
rgod
|
2005-09-20
|
|
PHP Advanced Transfer Manager 1.30 - Multiple Directory Traversal Vulnerabilities
|
3 |
WEB
|
rgod
|
2005-09-20
|
|
Hesk 0.92/0.93 - Session ID Authentication Bypass
|
3 |
WEB
|
Rajesh Sethumadhavan
|
2005-09-19
|
|
MX Shop 3.2 - 'index.php' Multiple SQL Injections
|
3 |
WEB
|
David Sopas Ferreira
|
2005-09-19
|
|
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/template.php' Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
deluxe@security-project.org
|
2005-09-19
|
|
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/modlog.php?orderby' Cross-Site Scripting
|
3 |
WEB
|
deluxe@security-project.org
|
2005-09-19
|
|
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/language.php?goto' Cross-Site Scripting
|
3 |
WEB
|
deluxe@security-project.org
|
2005-09-19
|
|
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/user.php?email' Cross-Site Scripting
|
3 |
WEB
|
deluxe@security-project.org
|
2005-09-19
|
|
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/index.php' Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
deluxe@security-project.org
|
2005-09-19
|
|
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/css.php?group' Cross-Site Scripting
|
2 |
WEB
|
deluxe@security-project.org
|
2005-09-19
|
|
NooToplist 1.0 - 'index.php' Multiple SQL Injections
|
2 |
WEB
|
David Sopas Ferreira
|
2005-09-19
|
|
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/usertools.php?ids' SQL Injection
|
2 |
WEB
|
deluxe@security-project.org
|
2005-09-19
|
|
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/usertitle.php?usertitleid' SQL Injection
|
2 |
WEB
|
deluxe@security-project.org
|
2005-09-19
|
|
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/user.php' Multiple SQL Injections
|
2 |
WEB
|
deluxe@security-project.org
|
2005-09-19
|
|
vBulletin 1.0.1 lite/2.x/3.0 - 'joinrequests.php?request' SQL Injection
|
2 |
WEB
|
deluxe@security-project.org
|
2005-09-19
|
|
EPay Pro 2.0 - 'index.php' Directory Traversal
|
3 |
WEB
|
h4cky0u
|
2005-09-16
|
|
Content2Web 1.0.1 - Multiple Input Validation Vulnerabilities
|
4 |
WEB
|
Security Tester
|
2005-09-15
|
|
DeluxeBB 1.0 - 'newpost.php' SQL Injection
|
3 |
WEB
|
abducter
|
2005-09-15
|
|
DeluxeBB 1.0 - 'pm.php' SQL Injection
|
2 |
WEB
|
abducter
|
2005-09-15
|
|
DeluxeBB 1.0 - 'forums.php' SQL Injection
|
2 |
WEB
|
abducter
|
2005-09-15
|
|
DeluxeBB 1.0 - 'misc.php' SQL Injection
|
2 |
WEB
|
abducter
|
2005-09-15
|
|
DeluxeBB 1.0 - 'topic.php' SQL Injection
|
2 |
WEB
|
abducter
|
2005-09-15
|
|
AEwebworks aeDating 3.2/4.0 - 'search_result.php' SQL Injection
|
2 |
WEB
|
alexsrb
|
2005-09-15
|
|
Digital Scribe 1.4 - Login SQL Injection
|
2 |
WEB
|
rgod
|
2005-09-14
|
|
Noah's Classifieds 1.3 - 'index.php' Cross-Site Scripting
|
1 |
WEB
|
trueend5
|
2005-09-14
|
|
TWiki TWikiUsers - Arbitrary Command Execution
|
3 |
WEB
|
B4dP4nd4
|
2005-09-14
|
|
Noah's Classifieds 1.2/1.3 - 'index.php' SQL Injection
|
3 |
WEB
|
trueend5
|
2005-09-14
|
|
ATutor 1.5.1 - Chat Logs Remote Information Disclosure
|
3 |
WEB
|
rgod
|
2005-09-14
|
|
ATutor 1.5.1 - 'password_reminder.php' SQL Injection
|
3 |
WEB
|
rgod
|
2005-09-14
|
|
MIVA Merchant 5 - Merchant.MVC Cross-Site Scripting
|
3 |
WEB
|
admin@hyperconx.com
|
2005-09-13
|
|
Mail-it Now! Upload2Server 1.5 - Arbitrary File Upload
|
2 |
WEB
|
rgod
|
2005-09-13
|
|
Land Down Under 800/801 - 'plug.php?e' SQL Injection
|
3 |
WEB
|
GroundZero Security Research
|
2005-09-13
|
|
Land Down Under 800/801 - 'auth.php?m' SQL Injection
|
3 |
WEB
|
GroundZero Security Research
|
2005-09-13
|
|
Subscribe Me Pro 2.44 - S.pl Directory Traversal
|
3 |
WEB
|
h4cky0u
|
2005-09-09
|
|
MyBulletinBoard (MyBB) 1.0 - 'RateThread.php' SQL Injection
|
3 |
WEB
|
stranger-killer
|
2013-06-17
|
|
Simple File Manager 024 - Authentication Bypass
|
3 |
WEB
|
Chako
|
2013-06-17
|
|
SPBAS Business Automation Software 2012 - Multiple Vulnerabilities
|
3 |
WEB
|
Christy Philip Mathew
|
2013-06-17
|
|
Havalite CMS 1.1.7 - Unrestricted Arbitrary File Upload
|
3 |
WEB
|
CWH Underground
|
2013-06-17
|
|
Fly-High CMS 2012-07-08 - Unrestricted Arbitrary File Upload
|
3 |
WEB
|
CWH Underground
|
2013-06-17
|
|
WordPress Plugin Ultimate WordPress Auction Plugin 1.0 - Cross-Site Request Forgery
|
3 |
WEB
|
expl0i13r
|
2005-09-08
|
|
AMember Pro 2.3.4 - Remote File Inclusion
|
3 |
WEB
|
NewAngels Team
|
2005-09-08
|
|
Stylemotion WEB//NEWS 1.4 - 'print.php?id' SQL Injection
|
3 |
WEB
|
onkel_fisch
|
2005-09-08
|
|
Stylemotion WEB//NEWS 1.4 - 'news.php' Multiple SQL Injections
|
3 |
WEB
|
onkel_fisch
|
2005-09-08
|
|
Stylemotion WEB//NEWS 1.4 - 'startup.php' Cookie SQL Injection
|
3 |
WEB
|
onkel_fisch
|
2005-09-07
|
|
phpCommunityCalendar 4.0 - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
rgod
|
2005-09-07
|
|
PBLang 4.65 Bulletin Board System - 'SetCookie.php' Directory Traversal
|
3 |
WEB
|
rgod
|
2005-09-07
|
|
phpCommunityCalendar 4.0 - Multiple SQL Injections
|
3 |
WEB
|
rgod
|
2005-09-06
|
|
MyBulletinBoard (MyBB) 1.0 - Multiple SQL Injections
|
3 |
WEB
|
stranger-killer
|
2005-09-06
|
|
MAXdev MD-Pro 1.0.73 - Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
rgod
|
2005-09-06
|
|
MAXdev MD-Pro 1.0.73 - Arbitrary File Upload
|
3 |
WEB
|
rgod
|
2005-09-06
|
|
Unclassified NewsBoard 1.5.3 - 'Description' HTML Injection
|
3 |
WEB
|
retrogod@aliceposta.it
|