Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2004-07-30   PowerPortal 1.1/1.3 - Private Message HTML Injection 2 WEB vampz
2004-07-29   Jaws 0.2/0.3/0.4 - 'ControlPanel.php' SQL Injection 2 WEB Fernando Quintero
2004-07-29   Verylost LostBook 1.1 - Message Entry HTML Injection 2 WEB Joseph Moniz
2004-07-29   Comersus Cart 5.0 - SQL Injection 2 WEB evol@ruiner.halo.nu
2004-07-28   Phorum 5.0.7 - Search Script Cross-Site Scripting 4 WEB vampz
2004-07-28   AntiBoard 0.6/0.7 - 'antiboard.php?feedback' Cross-Site Scripting 2 WEB Josh Gilmour
2004-07-28   AntiBoard 0.6/0.7 - 'antiboard.php' Multiple SQL Injections 2 WEB Josh Gilmour
2004-07-26   PostNuke 0.72/0.75 Reviews Module - Cross-Site Scripting 2 WEB DarkBicho
2013-01-24   SQLiteManager 1.2.4 - Remote PHP Code Injection 2 WEB RealGame
2004-07-26   XLineSoft ASPRunner 1.0/2.x - Database Direct Request Information Disclosure 1 WEB Ferruh Mavituna
2004-07-26   XLineSoft ASPRunner 1.0/2.x - 'export.asp?SQL' Cross-Site Scripting 1 WEB Ferruh Mavituna
2004-07-26   XLineSoft ASPRunner 1.0/2.x - '[TABLE]_list.asp?searchFor' Cross-Site Scripting 1 WEB Ferruh Mavituna
2004-07-26   XLineSoft ASPRunner 1.0/2.x - '[TABLE-NAME]_edit.asp?SQL' Cross-Site Scripting 1 WEB Ferruh Mavituna
2004-07-26   XLineSoft ASPRunner 1.0/2.x - '[TABLE-NAME]_search.asp?Typeen' Cross-Site Scripting 1 WEB Ferruh Mavituna
2004-07-24   EasyIns Stadtportal 4.0 - 'Site' Remote File Inclusion 1 WEB Francisco Alisson
2004-07-24   PostNuke 0.7x - Install Script Administrator Password Disclosure 0 WEB hellsink
2004-07-23   EasyWeb 1.0 FileManager Module - Directory Traversal 1 WEB sullo@cirt.net
2004-07-21   Layton Technology HelpBox 3.0.1 - Multiple SQL Injections 1 WEB Noam Rathaus
2004-07-21   Polar Helpdesk 3.0 - Cookie Based Authentication Bypass 1 WEB Noam Rathaus
2004-07-21   Mensajeitor Tag Board 1.x - Authentication Bypass 1 WEB Jordi Corrales
2004-07-21   Leigh Business Enterprises Web HelpDesk 4.0 - SQL Injection 1 WEB Noam Rathaus
2004-07-21   NetSupport DNA HelpDesk 1.0 Problist Script - SQL Injection 2 WEB Noam Rathaus
2004-07-21   Internet Software Sciences Web+Center 4.0.1 - Cookie Object SQL Injection 2 WEB Noam Rathaus
2004-07-20   Nucleus CMS 3.0 / Blog:CMS 3 / PunBB 1.x - 'Common.php' Remote File Inclusion 2 WEB Radek Hulan
2013-01-22   Adult WebMaster Script - Password Disclosure 2 WEB Dshellnoi Unix
2013-01-22   WordPress Plugin Developer Formatter - Cross-Site Request Forgery 2 WEB Junaid Hussain
2004-07-19   Adam Ismay Print Topic Mod 1.0 - SQL Injection 2 WEB Bartek Nowotarski
2004-07-19   Outblaze Webmail - HTML Injection 2 WEB DarkBicho
2004-07-19   CuteNews 1.3 - Comment HTML Injection 2 WEB DarkBicho
2004-07-19   Artmedic Webdesign Kleinanzeigen Script - Remote File Inclusion 1 WEB Adam Simuntis
2004-07-15   BoardPower Forum - 'ICQ.cgi' Cross-Site Scripting 2 WEB Alexander Antipov
2004-07-15   Gattaca Server 2003 - Cross-Site Scripting 2 WEB dr_insane
2004-07-15   Gattaca Server 2003 - 'Language' Path Exposure 2 WEB dr_insane
2004-07-15   Gattaca Server 2003 - Null Byte Full Path Disclosure 2 WEB dr_insane
2004-07-13   Moodle Help Script 1.x - Cross-Site Scripting 2 WEB morpheus[bd]
2004-07-12   phpBB 2.0.x - 'viewtopic.php' PHP Script Injection 1 WEB sasan hezarkhani
2013-01-21   NConf 1.3 - Arbitrary File Creation 1 WEB haidao
2013-01-21   NConf 1.3 - '/detail.php/detail_admin_items.php?id' SQL Injection 1 WEB haidao
2004-07-07   Comersus Open Technologies Comersus 5.0 - 'comersus_message.asp' Cross-Site Scripting 2 WEB Thomas Ryan
2004-07-07   Comersus Open Technologies Comersus 5.0 - 'comersus_gatewayPayPal.asp' Price Manipulation 1 WEB Thomas Ryan
2004-07-06   Jaws 0.2/0.3 - 'action' Cross-Site Scripting 3 WEB Fernando Quintero
2004-07-06   Jaws 0.2/0.3 - Cookie Manipulation Authentication Bypass 2 WEB Fernando Quintero
2004-07-06   Jaws 0.2/0.3 - 'gadget' Traversal Arbitrary File Access 2 WEB Fernando Quintero
2004-07-05   BasiliX Webmail 1.1 - Email Header HTML Injection 1 WEB Roman Medina-Heigl Hernandez
2004-07-05   Fastream NETFile FTP/Web Server 6.5/6.7 - Directory Traversal 2 WEB Andres Tarasco Acuna
2004-07-05   Symantec Brightmail Anti-Spam 6.0 - Unauthorized Message Disclosure 2 WEB Thomas Springer
2004-07-01   Netegrity IdentityMinder Web Edition 5.6 - Management Interface Cross-Site Scripting 1 WEB vuln@hexview.com
2004-07-01   Netegrity IdentityMinder Web Edition 5.6 - Null Byte Cross-Site Scripting 0 WEB vuln@hexview.com
2004-06-28   PowerPortal 1.1/1.3 - 'modules.php' Traversal Arbitrary Directory Listing 1 WEB DarkBicho
2004-06-28   CuteNews 0.88/1.3 - 'show_archives.php' Cross-Site Scripting 1 WEB DarkBicho
2004-06-28   CuteNews 0.88/1.3 - 'example2.php' Cross-Site Scripting 1 WEB DarkBicho
2004-06-28   CuteNews 0.88/1.3 - 'example1.php' Cross-Site Scripting 1 WEB DarkBicho
2004-06-28   CGIScript.net CSFAQ 1.0 Script - Full Path Disclosure 1 WEB DarkBicho
2004-06-28   McMurtrey/Whitaker & Associates Cart32 2-5 GetLatestBuilds Script - Cross-Site Scripting 1 WEB Dr.Ponidi Haryanto
2004-06-24   ZaireWeb Solutions NewsLetter ZWS - Administrative Interface Authentication Bypass 1 WEB GaMeS
2004-06-24   vBulletin 3.0.1 - 'newreply.php?WYSIWYG_HTML' Cross-Site Scripting 1 WEB Cheng Peng Su
2004-06-23   PHP-Nuke 1.0/2.5/3.0/4.x/5.x/6.x/7.x - Multiple Vulnerabilities 1 WEB Janek Vind
2004-06-22   ArbitroWeb PHP Proxy 0.5/0.6 - Cross-Site Scripting 1 WEB Josh Gilmour
2013-01-19   WordPress Plugin Ripe HD FLV Player - SQL Injection 1 WEB Zikou-16
2013-01-19   Joomla! Component com_collector - Arbitrary File Upload 1 WEB Red Dragon_al
2004-06-21   SqWebMail 4.0.4.20040524 - Email Header HTML Injection 1 WEB Luca Legato
2004-06-21   osTicket STS 1.2 - Attachment Remote Command Execution 1 WEB Guy Pearce
2004-06-15   phpHeaven phpMyChat 0.14.5 - 'admin.php3' Arbitrary File Access 1 WEB HEX
2004-06-15   phpHeaven phpMyChat 0.14.5 - 'edituser.php3?do_not_login' Authentication Bypass 1 WEB HEX
2004-06-15   phpHeaven phpMyChat 0.14.5 - 'usersL.php3' Multiple SQL Injections 1 WEB HEX
2004-06-15   Web Wiz Forums 7.x - 'Registration_Rules.asp' Cross-Site Scripting 0 WEB Ferruh Mavituna
2004-06-15   Pivot 1.0 - 'module_db.php' Remote File Inclusion 1 WEB loofus
2013-01-18   SonicWALL GMS/VIEWPOINT 6.x Analyzer 7.x - Remote Command Execution 2 WEB Nikolas Sotiriu
2013-01-18   SonicWALL GMS/Viewpoint/Analyzer - Authentication Bypass 2 WEB Nikolas Sotiriu
2013-01-18   Linksys WRT54GL Firmware 4.30.15 build 2 - Multiple Vulnerabilities 1 WEB m-1-k-3
2013-01-18   PHP-Charts - Arbitrary PHP Code Execution 1 WEB AkaStep
2004-06-14   Invision Power Board (IP.Board) 1.3 - 'SSI.php' Cross-Site Scripting 2 WEB IMAN Sharafoddin
2004-06-14   Virtual Programming VP-ASP Shoperror Script 4/5 - Cross-Site Scripting 2 WEB Thomas Ryan
2004-06-14   Linksys Web Camera Software 2.10 - 'Next_file' Cross-Site Scripting 1 WEB scriptX
2004-06-11   PHP-Nuke 6.x/7.x Reviews Module - Multiple Cross-Site Scripting Vulnerabilities 1 WEB Janek Vind
2004-06-11   PHP-Nuke 6.x/7.x - Multiple Input Validation Vulnerabilities 2 WEB Janek Vind
2004-06-11   PHP-Nuke 6.x/7.x Reviews Module - 'order' SQL Injection 2 WEB Janek Vind
2004-06-11   PHP-Nuke 6.x/7.x Encyclopedia Module - Multiple Function Cross-Site Scripting Vulnerabilities 2 WEB Janek Vind
2004-06-11   PHP-Nuke 6.x/7.x FAQ Module - 'categories' Cross-Site Scripting 2 WEB Janek Vind
2004-06-10   BlackBoard Learning System 6.0 - Dropbox File Download 2 WEB Maarten Verbeek
2004-06-11   Invision Power Board 1.3 - 'SSI.php' SQL Injection 2 WEB JvdR
2004-06-09   AspDotNetStorefront 3.3 - 'ReturnURL' Cross-Site Scripting 2 WEB Thomas Ryan
2004-06-09   AspDotNetStorefront 3.3 - Access Validation 2 WEB Thomas Ryan
2004-06-09   cPanel 5-9 - Passwd SQL Injection 2 WEB verb0s@virtualnova.net
2013-01-17   Invision Gallery 2.0.5 - SQL Injection 2 WEB Ashiyane Digital Security Team
2004-06-07   NetWin Surgemail 1.8/1.9/2.0 / WebMail 3.1 - Login Form Cross-Site Scripting 2 WEB Donnie Werner
2004-06-07   NetWin Surgemail 1.8/1.9/2.0 / WebMail 3.1 - Error Message Full Path Disclosure 2 WEB Donnie Werner
2004-06-07   Linksys Web Camera Software 2.10 - 'Next_file' File Disclosure 2 WEB John Doe
2004-06-05   cPanel 5-9 - Killacct Script Customer Account DNS Information Deletion 2 WEB qbann targ
2004-06-04   Crafty Syntax Live Help 2.7.3 - Multiple HTML Injection Vulnerabilities 2 WEB HNK Technology Solutions
2004-06-03   Mail Manage EX 3.1.8 MMEX - 'Settings' PHP Remote File Inclusion 1 WEB The Warlock [BhQ]
2004-06-03   SquirrelMail 1.2.x - From Email Header HTML Injection 1 WEB anonymous
2004-06-01   PHP-Nuke 5.x/6.x/7.x - Direct Script Access Security Bypass 1 WEB Squid
2004-06-01   Rit Research Labs TinyWeb 1.9.2 - Unauthorized Script Disclosure 1 WEB Ziv Kamir
2013-01-16   Oracle Application Framework - Diagnostic Mode Bypass 1 WEB Trustwave's SpiderLabs
2013-01-16   Cydia Repo Manager - Cross-Site Request Forgery 0 WEB Ramdan Yantu
2004-05-29   e107 website system 0.6 - 'email article to a friend' Feature Cross-Site Scripting 1 WEB Janek Vind
2004-05-29   e107 website system 0.6 - 'usersettings.php?avmsg' Cross-Site Scripting 1 WEB Janek Vind
2004-05-29   Land Down Under - BBCode HTML Injection 1 WEB Tim De Gier
2004-05-28   jPORTAL 2.2.1 - 'print.php' SQL Injection 1 WEB Maciek Wierciski
2004-05-22   Liferay Enterprise Portal 1.x/2.x/5.0.2 - Multiple Cross-Site Scripting Vulnerabilities 1 WEB Sandeep Giri
2004-05-21   e107 Website System 0.5/0.6 - 'Log.php' HTML Injection 1 WEB Chinchilla
2013-01-15   CMS snews - SQL Injection 1 WEB By onestree
2004-05-18   dsm light Web file browser 2.0 - Directory Traversal 1 WEB Humberto
2004-05-17   PHP-Nuke 6.x/7.x - 'Modpath' File Inclusion 1 WEB waraxe
2004-05-17   osCommerce 2.x - File Manager Directory Traversal 1 WEB Rene
2004-05-17   vBulletin 1.0/2.x/3.0 - 'index.php' User Interface Spoofing 1 WEB p0rk
2004-05-17   TurboTrafficTrader C 1.0 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities 2 WEB Kaloyan Olegov Georgiev
2013-01-14   phpShop 2.0 - SQL Injection 1 WEB By onestree
2004-05-10   Tutorials Manager 1.0 - Multiple SQL Injections 1 WEB Hillel Himovich
2004-05-08   Adam Webb NukeJokes 1.7/2.0 Module - 'modules.php?jokeid' SQL Injection 1 WEB Janek Vind
2004-05-08   Adam Webb NukeJokes 1.7/2.0 Module - Multiple Cross-Site Scripting Vulnerabilities 1 WEB Janek Vind
2004-05-05   SurgeLDAP 1.0 - Web Administration Authentication Bypass 1 WEB GSS IT
2004-05-05   PHPX 3.x - '/forums.php' Cross-Site Request Forgery / Arbitrary Command Execution 2 WEB JeiAr
2004-05-05   PHPX 3.x - '/images.php' Cross-Site Request Forgery / Arbitrary Command Execution 1 WEB JeiAr
2004-05-05   PHPX 3.x - '/user.php' Cross-Site Request Forgery / Arbitrary Command Execution 0 WEB JeiAr
2004-05-05   PHPX 3.x - '/news.php' Cross-Site Request Forgery / Arbitrary Command Execution 1 WEB JeiAr
2004-05-05   PHPX 3.x - '/page.php' Cross-Site Request Forgery / Arbitrary Command Execution 1 WEB JeiAr
2013-01-13   phlyLabs phlyMail Lite 4.03.04 - Full Path Disclosure / Persistent Cross-Site Scripting 1 WEB LiquidWorm
2013-01-13   phlyLabs phlyMail Lite 4.03.04 - 'go' Open Redirect 1 WEB LiquidWorm
2004-05-05   PHPX 3.x - Multiple Cross-Site Scripting Vulnerabilities 1 WEB JeiAr
2004-05-05   Simple Machines Forum (SMF) 1.0 - Size Tag HTML Injection 1 WEB Cheng Peng Su
2004-05-05   E-Zone Media FuzeTalk 2.0 - 'AddUser.cfm' Administrator Command Execution 2 WEB Stuart Jamieson
2004-04-30   Coppermine Photo Gallery 1.2.2b - 'theme.php' Remote File Inclusion 1 WEB Janek Vind
2004-04-30   Coppermine Photo Gallery 1.2.0 RC4 - 'init.inc.php' Remote File Inclusion 1 WEB Janek Vind