2003-10-01
|
|
Atrise Everyfind 5.0.2 - search Cross-Site Scripting
|
2 |
WEB
|
Ezhilan
|
2003-10-01
|
|
DCP-Portal 5.5 - 'lostpassword.php?email' SQL Injection
|
2 |
WEB
|
Lifo Fifo
|
2003-10-01
|
|
DCP-Portal 5.5 - 'advertiser.php?Password' SQL Injection
|
2 |
WEB
|
Lifo Fifo
|
2012-12-07
|
|
m0n0wall 1.33 - Multiple Cross-Site Request Forgery Vulnerabilities
|
2 |
WEB
|
Yann CAM
|
2003-09-29
|
|
Alan Ward A-Cart 2.0 - MSG Cross-Site Scripting
|
2 |
WEB
|
G00db0y
|
2003-09-29
|
|
Geeklog 1.3.x - Cross-Site Scripting
|
1 |
WEB
|
Lorenzo Hernandez Garcia-Hierro
|
2003-09-29
|
|
Geeklog 1.3.x - SQL Injection
|
2 |
WEB
|
Lorenzo Hernandez Garcia-Hierro
|
2003-09-29
|
|
GuppY 2.4 - HTML Injection
|
2 |
WEB
|
David Suzanne
|
2003-09-25
|
|
Software602 602Pro LAN SUITE 2003 - Sensitive User Information Storage
|
2 |
WEB
|
Phuong Nguyen
|
2012-12-06
|
|
Kordil EDms 2.2.60rc3 - SQL Injection
|
2 |
WEB
|
Woody Hughes
|
2003-09-24
|
|
yMonda Thread-IT 1.6 - Multiple HTML Injections
|
2 |
WEB
|
Bahaa Naamneh
|
2003-09-20
|
|
myPHPNuke 1.8.8 - 'auth.inc.php' SQL Injection
|
2 |
WEB
|
Lifo Fifo
|
2003-09-19
|
|
Flying Dog Software Powerslave 4.3 Portalmanager - 'sql_id' Information Disclosure
|
2 |
WEB
|
H Zero Seven
|
2003-09-18
|
|
Mambo Site Server 4.0.14 - 'contact.php' Unauthorized Mail Relay
|
2 |
WEB
|
Lifo Fifo
|
2003-09-18
|
|
Mambo Site Server 4.0.14 - 'emailarticle.php?id' SQL Injection
|
2 |
WEB
|
Lifo Fifo
|
2003-09-18
|
|
Mambo Site Server 4.0.14 - 'banners.php?bid' SQL Injection
|
1 |
WEB
|
Lifo Fifo
|
2003-09-16
|
|
NetWin DBabble 2.5 i - Cross-Site Scripting
|
2 |
WEB
|
dr_insane
|
2003-09-12
|
|
vbPortal 2.0 alpha 8.1 - (Authenticated) SQL Injection
|
1 |
WEB
|
frog
|
2012-12-04
|
|
Advantech Studio 7.0 - SCADA/HMI Directory Traversal
|
1 |
WEB
|
Nin3
|
2003-09-09
|
|
Invision Power Board (IP.Board) 1.x - 'index.php' showtopic Cross-Site Scripting
|
1 |
WEB
|
Boy Bear
|
2003-09-09
|
|
Escapade 0.2.1 Beta Scripting Engine - 'PAGE' Full Path Disclosure
|
1 |
WEB
|
Bahaa Naamneh
|
2003-09-09
|
|
Escapade 0.2.1 Beta Scripting Engine - 'PAGE' Cross-Site Scripting
|
1 |
WEB
|
Bahaa Naamneh
|
2003-09-08
|
|
phpBB 2.0.6 - URL BBCode HTML Injection
|
2 |
WEB
|
keupon_ps2
|
2003-09-08
|
|
ICQ 2003 - Webfront Guestbook Cross-Site Scripting
|
1 |
WEB
|
Donnie Werner
|
2012-12-03
|
|
FirePass SSL VPN - Local File Inclusion
|
2 |
WEB
|
SEC Consult
|
2012-12-03
|
|
Symantec Messaging Gateway 9.5.3-3 - Arbitrary File Download
|
1 |
WEB
|
Ben Williams
|
2012-12-03
|
|
Symantec Messaging Gateway 9.5.3-3 - Cross-Site Request Forgery
|
2 |
WEB
|
Ben Williams
|
2012-12-03
|
|
SchoolCMS - Persistent Cross-Site Scripting
|
2 |
WEB
|
VipVince
|
2012-12-03
|
|
MyBB KingChat Plugin - SQL Injection
|
2 |
WEB
|
Red_Hat
|
2003-09-05
|
|
Digital Scribe 1.x - Error Function Cross-Site Scripting
|
3 |
WEB
|
Secunia
|
2003-09-03
|
|
WebCalendar 0.9.x (Multiple Modules) - SQL Injection
|
2 |
WEB
|
noconflic
|
2003-09-01
|
|
Sitebuilder 1.4 - 'sitebuilder.cgi' Directory Traversal
|
2 |
WEB
|
Zero X
|
2003-09-01
|
|
TSguestbook 2.1 - 'Message' HTML Injection
|
2 |
WEB
|
Trash-80
|
2003-09-01
|
|
Ezboard - 'invitefriends.php3' Cross-Site Scripting
|
1 |
WEB
|
David F. Madrid
|
2003-08-27
|
|
eNdonesia 8.2/8.3 - 'Mod' Cross-Site Scripting
|
2 |
WEB
|
Bahaa Naamneh
|
2003-08-27
|
|
AldWeb MiniPortail 1.9/2.x - 'LNG' Cross-Site Scripting
|
2 |
WEB
|
Bahaa Naamneh
|
2003-08-26
|
|
Attila PHP 3.0 - SQL Injection Unauthorized Privileged Access
|
2 |
WEB
|
frog
|
2003-08-26
|
|
Py-Membres 4.x - 'Pass_done.php' SQL Injection
|
2 |
WEB
|
frog
|
2003-08-26
|
|
Py-Membres 4.x - 'Secure.php' Unauthorized Access
|
2 |
WEB
|
frog
|
2003-08-25
|
|
Netbula Anyboard 9.9.5 6 - Information Disclosure
|
2 |
WEB
|
cyber talon
|
2003-08-25
|
|
newsPHP 216 - Authentication Bypass
|
2 |
WEB
|
Officerrr
|
2003-08-25
|
|
newsPHP 216 - Remote File Inclusion
|
2 |
WEB
|
Officerrr
|
2003-08-23
|
|
IdealBB 1.4.9 Beta - HTML Injection
|
2 |
WEB
|
Scott M
|
2003-08-18
|
|
Fusion News 3.3 - Unauthorized Account Addition
|
2 |
WEB
|
DarkKnight
|
2003-08-16
|
|
MatrikzGB Guestbook 2.0 - Administrative Privilege Escalation
|
2 |
WEB
|
Stephan Sattler
|
2003-08-15
|
|
Poster 2.0 - Unauthorized Privileged User Access
|
1 |
WEB
|
DarkKnight
|
2003-08-13
|
|
Clickcess ChitChat.NET - topic title Cross-Site Scripting
|
2 |
WEB
|
G00db0y
|
2003-08-13
|
|
Clickcess ChitChat.NET - name Cross-Site Scripting
|
2 |
WEB
|
G00db0y
|
2012-11-30
|
|
SilverStripe CMS 3.0.2 - (Multiple Vulnerabilities) Cross-Site Scripting / Cross-Site Request Forger
|
2 |
WEB
|
Sense of Security
|
2012-11-30
|
|
SmartCMS - '/index.php?menuitem' SQL Injection / Cross-Site Scripting
|
2 |
WEB
|
Yakir Wizman
|
2012-11-30
|
|
Free Hosting Manager 2.0 - 'id' SQL Injection
|
2 |
WEB
|
Yakir Wizman
|
2003-08-13
|
|
HolaCMS 1.2.x - 'HTMLtags.php' Local File Inclusion
|
2 |
WEB
|
Virginity Security
|
2003-08-13
|
|
Xoops 1.0/1.3.x - BBCode HTML Injection
|
2 |
WEB
|
frog
|
2003-08-13
|
|
SurgeLDAP 1.0 d - 'User.cgi' Cross-Site Scripting
|
2 |
WEB
|
Ziv Kamir
|
2003-08-12
|
|
Eudora WorldMail 2.0 - Search Cross-Site Scripting
|
2 |
WEB
|
Donnie Werner
|
2003-08-12
|
|
HostAdmin - Full Path Disclosure
|
2 |
WEB
|
G00db0y
|
2003-08-11
|
|
PHPOutsourcing Zorum 3.4 - Full Path Disclosure
|
2 |
WEB
|
Zone-h Security Team
|
2003-08-11
|
|
phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 earch Module - 'PDA_limit' Cross-Site Scripting
|
2 |
WEB
|
Lorenzo Hernandez Garcia-Hierro
|
2003-08-11
|
|
phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 pagemaster Module - 'PAGE_id' Cross-Site Scripting
|
1 |
WEB
|
Lorenzo Hernandez Garcia-Hierro
|
2003-08-11
|
|
phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 fatcat Module - 'fatcat_id' Cross-Site Scripting
|
1 |
WEB
|
Lorenzo Hernandez Garcia-Hierro
|
2003-08-11
|
|
phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 Calendar Module - 'day' Cross-Site Scripting
|
1 |
WEB
|
Lorenzo Hernandez Garcia-Hierro
|
2003-08-11
|
|
PHP Website 0.7.3/0.8.2/0.8.3/0.9.2 Calendar Module - SQL Injection
|
0 |
WEB
|
Lorenzo Hernandez Garcia-Hierro
|
2003-08-11
|
|
News Wizard 2.0 - Full Path Disclosure
|
2 |
WEB
|
G00db0y
|
2003-08-11
|
|
PHPOutSourcing Zorum 3.x - Cross-Site Scripting
|
2 |
WEB
|
G00db0y
|
2003-08-11
|
|
Better Basket Pro 3.0 Store Builder - Full Path Disclosure
|
2 |
WEB
|
G00db0y
|
2003-08-11
|
|
Stellar Docs 1.2 - Full Path Disclosure
|
2 |
WEB
|
G00db0y
|
2003-08-11
|
|
DCForum+ 1.2 - 'Subject' HTML Injection
|
2 |
WEB
|
G00db0y
|
2012-11-29
|
|
FCKEditor Core ASP 2.6.8 - Arbitrary File Upload Protection Bypass
|
2 |
WEB
|
Soroush Dalili
|
2012-11-29
|
|
Oracle OpenSSO 8.0 - Multiple Cross-Site Scripting POST Injection Vulnerabilities
|
2 |
WEB
|
LiquidWorm
|
2003-08-09
|
|
Invision Power Board (IP.Board) 1.0/1.1/1.2 - 'admin.php' Cross-Site Scripting
|
2 |
WEB
|
Boy Bear
|
2003-08-09
|
|
geeeekShop 1.4 - Information Disclosure
|
2 |
WEB
|
G00db0y
|
2003-08-08
|
|
PostNuke 0.6/0.7 web_links Module - TTitle Cross-Site Scripting
|
2 |
WEB
|
Lorenzo Hernandez Garcia-Hierro
|
2003-08-08
|
|
PostNuke 0.6/0.7 Downloads Module - TTitle Cross-Site Scripting
|
2 |
WEB
|
Lorenzo Hernandez Garcia-Hierro
|
2003-08-08
|
|
C-Cart 1.0 - Full Path Disclosure
|
2 |
WEB
|
G00db0y
|
2003-08-07
|
|
IdealBB 1.4.9 - 'error.asp' Cross-Site Scripting
|
1 |
WEB
|
G00db0y
|
2003-08-06
|
|
vBulletin 3.0 - 'register.php' HTML Injection
|
1 |
WEB
|
Ferruh Mavituna
|
2003-08-04
|
|
Macromedia Dreamweaver MX 6.0 - PHP User Authentication Suite Cross-Site Scripting
|
1 |
WEB
|
Lorenzo Hernandez Garcia-Hierro
|
2003-07-31
|
|
MOD Guthabenhack 1.3 For Woltlab Burning Board - SQL Injection
|
2 |
WEB
|
ben.moeckel@badwebmasters.net
|
2012-11-28
|
|
gleamtech filevista/fileultimate 4.6 - Directory Traversal
|
2 |
WEB
|
Soroush Dalili
|
2003-07-28
|
|
Softshoe - Parse-file Cross-Site Scripting
|
2 |
WEB
|
Bahaa Naamneh
|
2003-07-27
|
|
Gallery 1.2/1.3.x - Search Engine Cross-Site Scripting
|
2 |
WEB
|
Larry Nguyen
|
2003-07-28
|
|
PBLang 4.0/4.56 Bulletin Board System - IMG Tag HTML Injection
|
2 |
WEB
|
Quan Van Truong
|
2003-07-25
|
|
e107 Website System 0.554 - HTML Injection
|
2 |
WEB
|
Pete Foster
|
2003-07-24
|
|
e107 Website System 0.555 - 'db.php' Information Disclosure
|
2 |
WEB
|
Artoor Petrovich
|
2003-07-24
|
|
PHP Arena paFileDB 1.1.3/2.1.1/3.0/3.1 - Arbitrary File Upload / Execution
|
2 |
WEB
|
Martin Eiszner
|
2003-07-24
|
|
PHP-Gastebuch 1.60 - Information Disclosure
|
2 |
WEB
|
Jim Pangalos
|
2003-07-21
|
|
MoreGroupWare 0.6.8 - WEBMAIL2_INC_DIR Remote File Inclusion
|
2 |
WEB
|
phil dunn
|
2003-07-21
|
|
WebCalendar 0.9.x - Local File Inclusion Information Disclosure
|
2 |
WEB
|
noconflic
|
2003-07-21
|
|
atomicboard 0.6.2 - Directory Traversal
|
2 |
WEB
|
gr00vy
|
2003-07-21
|
|
Drupal 4.1/4.2 - Cross-Site Scripting
|
1 |
WEB
|
Ferruh Mavituna
|
2012-11-26
|
|
PRADO PHP Framework 3.2.0 - Arbitrary File Read
|
2 |
WEB
|
LiquidWorm
|
2012-11-26
|
|
SmartCMS - 'index.php?idx' SQL Injection
|
2 |
WEB
|
NoGe
|
2012-11-26
|
|
BuyClassifiedScript - PHP Code Injection
|
2 |
WEB
|
d3b4g
|
2003-07-18
|
|
SimpNews 2.0.1/2.13 - 'path_simpnews' Remote File Inclusion
|
2 |
WEB
|
PUPET
|
2003-07-17
|
|
eStore 1.0.1/1.0.2 - 'Settings.inc.php' Full Path Disclosure
|
1 |
WEB
|
Bosen
|
2003-07-16
|
|
Ultimate Bulletin Board 6.0/6.2 - UBBER Cookie HTML Injection
|
2 |
WEB
|
anti_acid
|
2003-07-16
|
|
.netCART Settings.XML - Information Disclosure
|
2 |
WEB
|
G00db0y
|
2003-07-15
|
|
Splatt Forum 3/4 - Post Icon HTML Injection
|
2 |
WEB
|
Lethalman
|
2012-11-25
|
|
ES CmS 0.1 - SQL Injection
|
1 |
WEB
|
hossein beizaee
|
2012-11-25
|
|
jBilling 3.0.2 - Cross-Site Scripting
|
1 |
WEB
|
Woody Hughes
|
2003-07-14
|
|
BlazeBoard 1.0 - Information Disclosure
|
1 |
WEB
|
JackDaniels
|
2003-07-13
|
|
HTMLToNuke - Cross-Site Scripting
|
1 |
WEB
|
JOCANOR
|
2003-07-13
|
|
ASP-DEV Discussion Forum 2.0 - Admin Directory Weak Default Permissions
|
1 |
WEB
|
G00db0y
|
2003-07-10
|
|
Virtual Programming VP-ASP 5.00 - 'shopexd.asp' SQL Injection (2)
|
1 |
WEB
|
Bosen & TioEuy
|
2003-07-10
|
|
Virtual Programming VP-ASP 5.00 - 'shopexd.asp' SQL Injection (1)
|
1 |
WEB
|
TioEuy & AresU
|
2003-07-10
|
|
PHPForum 2.0 RC1 - 'Mainfile.php' Remote File Inclusion
|
1 |
WEB
|
theblacksheep
|
2003-07-09
|
|
ChangshinSoft EZTrans Server - 'download.php' Directory Traversal
|
1 |
WEB
|
SSR Team
|
2003-07-09
|
|
QuadComm Q-Shop 2.5 - Failure To Validate Credentials
|
1 |
WEB
|
G00db0y
|
2012-11-21
|
|
PHP Server Monitor - Persistent Cross-Site Scripting
|
2 |
WEB
|
loneferret
|
2012-11-21
|
|
ManageEngine ServiceDesk 8.0 - Multiple Vulnerabilities
|
2 |
WEB
|
Vulnerability-Lab
|
2012-11-21
|
|
Yii Framework 1.1.8 - Search SQL Injection
|
2 |
WEB
|
Juno_okyo
|
2003-07-07
|
|
CPanel 5.0/5.3/6.x - Admin Interface HTML Injection
|
2 |
WEB
|
Ory Segal
|
2003-07-05
|
|
ProductCart 1.5/1.6/2.0 - File Disclosure
|
2 |
WEB
|
Tri Huynh
|
2003-07-05
|
|
ProductCart 1.5/1.6/2.0 - 'MSG.asp' Cross-Site Scripting
|
2 |
WEB
|
atomix
|
2003-07-04
|
|
ProductCart 1.5/1.6/2.0 - 'login.asp' SQL Injection
|
2 |
WEB
|
Bosen
|
2003-07-04
|
|
ProductCart 1.5/1.6/2.0 - 'Custva.asp' SQL Injection
|
2 |
WEB
|
Bosen
|
2003-07-02
|
|
Verity K2 Toolkit 2.20 Query Builder Search Script - Cross-Site Scripting
|
2 |
WEB
|
SSR Team
|
2012-11-20
|
|
WordPress Plugin Facebook Survey 1.0 - SQL Injection
|
2 |
WEB
|
Vulnerability Research Laboratory
|
2012-11-20
|
|
SonicWALL CDP 5040 6.x - Multiple Vulnerabilities
|
2 |
WEB
|
Vulnerability-Lab
|
2003-07-02
|
|
Verity K2 Toolkit 2.20 - Cross-Site Scripting
|
2 |
WEB
|
SSR Team
|
2003-06-30
|
|
PABox 1.6 - Password Reset
|
1 |
WEB
|
silentscripter
|
2003-06-29
|
|
MegaBook 1.1/2.0/2.1 - Multiple HTML Injection Vulnerabilities
|
1 |
WEB
|
Morning Wood
|
2003-06-29
|
|
CutePHP CuteNews 1.3 - HTML Injection
|
2 |
WEB
|
Peter Winter-Smith
|
2003-06-26
|
|
iXmail 0.2/0.3 - 'iXmail_NetAttach.php' File Deletion
|
2 |
WEB
|
leseulfrog
|
2012-11-19
|
|
weBid 1.0.5 - Directory Traversal
|
2 |
WEB
|
loneferret
|