Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2012-03-10   PHP Address Book 6.2.12 - Multiple Vulnerabilities 1 WEB Stefan Schurtz
2012-03-08   RazorCMS 1.2.1 Stable - Cross-Site Request Forgery (Delete Web Pages) 1 WEB Ivano Binetti
2012-03-08   RazorCMS 1.2.1 STABLE - Arbitrary File Upload 1 WEB i2sec_Hyo jun Oh
2012-03-07   promise webpam 2.2.0.13 - Multiple Vulnerabilities 1 WEB LiquidWorm
2012-03-07   HomeSeer HS2 and HomeSeer PRO - Multiple Vulnerabilities 0 WEB Silent_Dream
2012-03-07   Iciniti Store - SQL Injection 1 WEB Sense of Security
2012-03-02   Drupal 7.12 - Multiple Vulnerabilities 1 WEB Ivano Binetti
2012-02-21   Fork CMS 3.2.5 - Multiple Vulnerabilities 1 WEB Ivano Binetti
2012-03-05   lizard cart - 'search.php' SQL Injection 1 WEB Number 7
2012-03-05   Symfony2 - Local File Disclosure 1 WEB Sense of Security
2012-03-04   AneCMS 2e2c583 - Local File Inclusion 1 WEB I2sec-Jong Hwan Park
2012-03-04   DZCP (deV!L_z Clanportal) Witze Addon 0.9 - SQL Injection 1 WEB Easy Laster
2012-03-03   Endian UTM Firewall 2.4.x < 2.5.0 - Multiple Web Vulnerabilities 1 WEB Vulnerability-Lab
2012-03-03   Timesheet Next Gen 1.5.2 - Multiple SQL Injections 1 WEB G13
2012-03-03   Rivettracker 1.03 - Multiple SQL Injections 1 WEB Ali Raheem
2012-03-02   phxEventManager 2.0 Beta 5 - 'search.php' search_terms SQL Injection 2 WEB skysbsb
2012-02-29   Wolf CMS 0.7.5 - Multiple Vulnerabilities 1 WEB longrifle0x
2012-02-29   ImgPals Photo Host 1.0 - Admin Account Disactivation 2 WEB CorryL
2012-02-29   Yealink VOIP Phone - Persistent Cross-Site Scripting 2 WEB Narendra Shinde
2012-02-28   WebfolioCMS 1.1.4 - Cross-Site Request Forgery (Add Admin/Modify Pages) 2 WEB Ivano Binetti
2012-02-26   ContaoCMS (aka TYPOlight) 2.11 - Cross-Site Request Forgery (Delete Admin / Delete Article) 2 WEB Ivano Binetti
2012-02-25   YVS Image Gallery - SQL Injection 1 WEB CorryL
2012-02-25   webgrind 1.0 - 'file' Local File Inclusion 1 WEB LiquidWorm
2012-02-25   cPassMan 1.82 - Remote Command Execution 1 WEB ls
2012-02-24   PHP Gift Registry 1.5.5 - SQL Injection 1 WEB G13
2012-02-23   The Uploader 2.0.4 (English/Italian) - Arbitrary File Upload / Remote Code Execution (Metasploit) 2 WEB Danny Moules
2012-02-23   Snom IP Phone - Privilege Escalation 2 WEB Sense of Security
2012-02-23   phpDenora 1.4.6 - Multiple SQL Injections 2 WEB Patrick de Brouwer
2012-02-22   DFLabs PTK 1.0.5 - Steal Authentication Credentials 2 WEB Ivano Binetti
2012-02-22   D-Link DSL-2640B ADSL Router - Authentication Bypass 2 WEB Ivano Binetti
2012-02-22   WebcamXP and webcam 7 - Directory Traversal 2 WEB Silent_Dream
2012-02-22   D-Link DCS Series - Cross-Site Request Forgery (Change Admin Password) 1 WEB rigan
2012-02-22   LimeSurvey (PHPSurveyor 1.91+ stable) - Blind SQL Injection 2 WEB TorTukiTu
2012-02-22   Brim < 2.0.0 - SQL Injection 1 WEB ifnull
2012-02-22   Sagem F@ST 2604 ADSL Router - Cross-Site Request Forgery 2 WEB KinG Of PiraTeS
2012-02-21   Cisco Linksys WAG54GS - Cross-Site Request Forgery (Change Admin Password) 2 WEB Ivano Binetti
2012-02-20   Plume CMS 1.2.4 - Cross-Site Request Forgery 1 WEB Ivano Binetti
2012-02-20   D-Link DSL-2640B ADSL Router - Cross-Site Request Forgery 1 WEB Ivano Binetti
2012-02-19   SyndeoCMS 3.0 - Cross-Site Request Forgery 2 WEB Ivano Binetti
2012-02-19   4PSA CMS - SQL Injection 2 WEB BHG Security Center
2012-02-18   almnzm 2.4 - Cross-Site Request Forgery (Add Admin) 2 WEB HaNniBaL KsA
2012-02-17   Pandora Fms 4.0.1 - Local File Inclusion 2 WEB Vulnerability-Lab
2012-02-16   SocialCMS 1.0.2 - Cross-Site Request Forgery 2 WEB Ivano Binetti
2012-02-12   Fork CMS 3.2.4 - Local File Inclusion / Cross-Site Scripting 1 WEB Avram Marius
2012-02-10   Dolibarr ERP/CRM 3.2.0 < Alpha - File Inclusion 2 WEB Vulnerability-Lab
2012-02-08   Cyberoam Central Console 2.00.2 - Remote File Inclusion 2 WEB Vulnerability-Lab
2012-02-08   Gazelle CMS 1.0 - Update Statement SQL Injection 2 WEB hackme
2012-02-07   Flyspray 0.9.9.6 - Cross-Site Request Forgery 2 WEB Vaibhav Gupta
2012-02-06   XRayCMS 1.1.1 - SQL Injection 2 WEB chap0
2012-02-06   Tube Ace (Adult PHP Tube Script) - SQL Injection 2 WEB Daniel Godoy
2012-02-06   BASE 1.4.5 - 'base_qry_main.php?t_view' SQL Injection 2 WEB a.kadir altan
2012-02-05   GAzie 5.20 - Cross-Site Request Forgery 2 WEB Giuseppe D'Inverno
2012-02-02   Achievo 1.4.3 - Multiple Web Vulnerabilities 1 WEB Vulnerability-Lab
2012-02-02   osCommerce 3.0.2 - Persistent Cross-Site Scripting 1 WEB Vulnerability-Lab
2012-02-02   Apache Struts - Multiple Persistent Cross-Site Scripting Vulnerabilities 1 WEB SecPod Research
2012-02-02   Sphinix Mobile Web Server 3.1.2.47 - Multiple Persistent Cross-Site Scripting Vulnerabilities 1 WEB SecPod Research
2012-01-13   MailEnable Webmail - Cross-Site Scripting 1 WEB Sajjad Pourali
2012-02-01   sit! support incident tracker 3.64 - Multiple Vulnerabilities 1 WEB High-Tech Bridge SA
2012-02-01   swDesk - Multiple Vulnerabilities 1 WEB Red Security TEAM
2012-01-31   Vastal I-Tech Agent Zone - 'search.php' Blind SQL Injection 0 WEB Cagri Tepebasili
2012-01-31   PragmaMX 1.2.10 - Persistent Cross-Site Scripting 1 WEB HauntIT
2012-01-31   Ez Album - Blind SQL Injection 1 WEB Red Security TEAM
2012-01-31   phpShowtime - Directory Traversal 1 WEB Red Security TEAM
2012-01-31   Snort Report 1.3.2 - SQL Injection 1 WEB a.kadir altan
2012-01-30   phux Download Manager - Blind SQL Injection 1 WEB Red Security TEAM
2012-01-30   Ajax Upload - Arbitrary File Upload 1 WEB Daniel Godoy
2012-01-30   Campaign Enterprise 11.0.421 - SQL Injection 0 WEB Craig Freyman
2012-01-30   4Images 1.7.6-9 - Cross-Site Request Forgery / PHP Code Injection 1 WEB Or4nG.M4N
2012-01-30   HostBill App 2.3 - Remote Code Injection 1 WEB Dr.DaShEr
2012-01-27   vBSEO 3.6.0 - 'proc_deutf()' Remote PHP Code Injection (Metasploit) 2 WEB EgiX
2012-01-26   Peel Shopping 2.8/ 2.9 - Cross-Site Scripting / SQL Injections 2 WEB Cyber-Crystal
2012-01-26   phpList 2.10.9 - Cross-Site Request Forgery / Cross-Site Scripting 1 WEB Cyber-Crystal
2012-01-26   VR GPub 4.0 - Cross-Site Request Forgery 1 WEB Cyber-Crystal
2012-01-25   WordPress Core 3.3.1 - Multiple Vulnerabilities 1 WEB Trustwave's SpiderLabs
2012-01-24   stoneware webnetwork6 - Multiple Vulnerabilities 2 WEB Jacob Holcomb
2012-01-23   SpamTitan Application 5.08x - SQL Injection 2 WEB Vulnerability-Lab
2012-01-23   WordPress Plugin Kish Guest Posting 1.0 - Arbitrary File Upload 2 WEB EgiX
2012-01-22   MiniCMS 1.0/2.0 - PHP Code Injection 2 WEB Or4nG.M4N
2012-01-22   WordPress Plugin AllWebMenus < 1.1.9 Menu Plugin - Arbitrary File Upload 2 WEB 6Scan
2012-01-21   ARYADAD - Multiple Vulnerabilities 2 WEB Red Security TEAM
2012-01-21   iSupport 1.x - Cross-Site Request Forgery / HTML Code Injection (Add Admin) 2 WEB Or4nG.M4N
2012-01-21   Nova CMS - Directory Traversal 2 WEB Red Security TEAM
2012-01-21   PHP iReport 1.0 - Remote Html Code Injection 2 WEB Or4nG.M4N
2012-01-20   WhatsApp - Remote Change Status 1 WEB emgent
2012-01-20   EasyPage - SQL Injection 1 WEB Red Security TEAM
2012-01-20   ICTimeAttendance - Authentication Bypass 1 WEB v3n0m
2012-01-19   appRain CMF 0.1.5 - 'Uploadify.php' Unrestricted Arbitrary File Upload 1 WEB EgiX
2012-01-19   WordPress Plugin ucan post 1.0.09 - Persistent Cross-Site Scripting 2 WEB Gianluca Brindisi
2012-01-19   Drupal Module CKEditor 3.0 < 3.6.2 - Persistent EventHandler Cross-Site Scripting 2 WEB MaXe
2012-01-18   DZCP (deV!L_z Clanportal) 1.5.5 Moviebase Addon - Blind SQL Injection 2 WEB Easy Laster
2012-01-18   DZCP (deV!L_z Clanportal) Gamebase Addon - SQL Injection 2 WEB Easy Laster
2012-01-18   PHPBridges Blog System - 'members.php' SQL Injection 1 WEB 3spi0n
2012-01-18   pGB 2.12 - 'kommentar.php' SQL Injection 2 WEB 3spi0n
2012-01-17   Joomla! Component com_discussions - SQL Injection 2 WEB Red Security TEAM
2012-01-16   PHPDomainRegister 0.4a-RC2-dev - Multiple Vulnerabilities 1 WEB Or4nG.M4N
2012-01-15   Cloupia End-to-end FlexPod Management - Directory Traversal 2 WEB Chris Rock
2012-01-14   phpMyAdmin 3.3.x/3.4.x - Local File Inclusion via XML External Entity Injection (Metasploit) 1 WEB Marco Batista
2012-01-13   Pragyan CMS 2.6.1 - Arbitrary File Upload 2 WEB Dr.KroOoZ
2012-01-13   Tine 2.0 - Maischa Multiple Cross-Site Scripting Vulnerabilities 2 WEB Vulnerability-Lab
2012-01-12   WordPress Plugin Count Per Day - Multiple Vulnerabilities 2 WEB 6Scan
2012-01-12   WordPress Plugin wp-autoyoutube - Blind SQL Injection 2 WEB longrifle0x
2012-01-12   Advanced Image Hosting Script - SQL Injection 2 WEB Robert Cooper
2012-01-10   WordPress Plugin Age Verification 0.4 - Open Redirect 2 WEB Gianluca Brindisi
2012-01-10   w-CMS 2.01 - Multiple Vulnerabilities 2 WEB th3.g4m3_0v3r
2012-01-10   Pragyan CMS 3.0 - Remote File Disclosure 2 WEB Or4nG.M4N
2012-01-10   RazorCMS 1.2 - Directory Traversal 2 WEB chap0
2012-01-09   Enigma2 Webinterface 1.5.x/1.6.x/1.7.x (Linux) - Remote File Disclosure 2 WEB Todor Donev
2012-01-09   SAPID 1.2.3 Stable - Remote File Inclusion 2 WEB Opa Yong
2012-01-09   Clipbucket 2.6 - Multiple Vulnerabilities 1 WEB YaDoY666
2012-01-09   Paddelberg Topsite Script - Authentication Bypass 2 WEB Christian Inci
2012-01-08   phpMyDirectory.com 1.3.3 - SQL Injection 2 WEB Serseri
2012-01-08   MangosWeb - SQL Injection 2 WEB Hood3dRob1n
2012-01-06   WordPress Plugin Pay with Tweet 1.1 - Multiple Vulnerabilities 1 WEB Gianluca Brindisi
2012-01-06   Apache Struts 2 < 2.3.1 - Multiple Vulnerabilities 2 WEB SEC Consult
2012-01-06   TinyWebGallery 1.8.3 - Remote Command Execution 1 WEB Expl0!Ts
2012-01-04   Posse Softball Director CMS - 'team.php' Blind SQL Injection 1 WEB Easy Laster
2012-01-04   Posse Softball Director CMS - SQL Injection 1 WEB H4ckCity Security Team
2012-01-04   Typo3 4.5 < 4.7 - Remote Code Execution / Local File Inclusion / Remote File Inclusion 1 WEB MaXe
2012-01-02   MyPHPDating 1.0 - SQL Injection 3 WEB ITTIHACK
2012-01-02   PHP-X-Links Script - SQL Injection 2 WEB H4ckCity Security Team
2012-01-02   WSN Links Script 2.3.4 - SQL Injection 2 WEB H4ckCity Security Team
2011-12-30   Akiva WebBoard 8.x - SQL Injection 2 WEB Alexander Fuchs
2011-12-30   Dede CMS - SQL Injection 1 WEB CWH & Nafsh
2011-12-29   Winn Guestbook 2.4.8c - Persistent Cross-Site Scripting 1 WEB G13
2011-12-29   DIY-CMS blog mod - SQL Injection 2 WEB snup