2012-03-10
|
|
PHP Address Book 6.2.12 - Multiple Vulnerabilities
|
1 |
WEB
|
Stefan Schurtz
|
2012-03-08
|
|
RazorCMS 1.2.1 Stable - Cross-Site Request Forgery (Delete Web Pages)
|
1 |
WEB
|
Ivano Binetti
|
2012-03-08
|
|
RazorCMS 1.2.1 STABLE - Arbitrary File Upload
|
1 |
WEB
|
i2sec_Hyo jun Oh
|
2012-03-07
|
|
promise webpam 2.2.0.13 - Multiple Vulnerabilities
|
1 |
WEB
|
LiquidWorm
|
2012-03-07
|
|
HomeSeer HS2 and HomeSeer PRO - Multiple Vulnerabilities
|
0 |
WEB
|
Silent_Dream
|
2012-03-07
|
|
Iciniti Store - SQL Injection
|
1 |
WEB
|
Sense of Security
|
2012-03-02
|
|
Drupal 7.12 - Multiple Vulnerabilities
|
1 |
WEB
|
Ivano Binetti
|
2012-02-21
|
|
Fork CMS 3.2.5 - Multiple Vulnerabilities
|
1 |
WEB
|
Ivano Binetti
|
2012-03-05
|
|
lizard cart - 'search.php' SQL Injection
|
1 |
WEB
|
Number 7
|
2012-03-05
|
|
Symfony2 - Local File Disclosure
|
1 |
WEB
|
Sense of Security
|
2012-03-04
|
|
AneCMS 2e2c583 - Local File Inclusion
|
1 |
WEB
|
I2sec-Jong Hwan Park
|
2012-03-04
|
|
DZCP (deV!L_z Clanportal) Witze Addon 0.9 - SQL Injection
|
1 |
WEB
|
Easy Laster
|
2012-03-03
|
|
Endian UTM Firewall 2.4.x < 2.5.0 - Multiple Web Vulnerabilities
|
1 |
WEB
|
Vulnerability-Lab
|
2012-03-03
|
|
Timesheet Next Gen 1.5.2 - Multiple SQL Injections
|
1 |
WEB
|
G13
|
2012-03-03
|
|
Rivettracker 1.03 - Multiple SQL Injections
|
1 |
WEB
|
Ali Raheem
|
2012-03-02
|
|
phxEventManager 2.0 Beta 5 - 'search.php' search_terms SQL Injection
|
2 |
WEB
|
skysbsb
|
2012-02-29
|
|
Wolf CMS 0.7.5 - Multiple Vulnerabilities
|
1 |
WEB
|
longrifle0x
|
2012-02-29
|
|
ImgPals Photo Host 1.0 - Admin Account Disactivation
|
2 |
WEB
|
CorryL
|
2012-02-29
|
|
Yealink VOIP Phone - Persistent Cross-Site Scripting
|
2 |
WEB
|
Narendra Shinde
|
2012-02-28
|
|
WebfolioCMS 1.1.4 - Cross-Site Request Forgery (Add Admin/Modify Pages)
|
2 |
WEB
|
Ivano Binetti
|
2012-02-26
|
|
ContaoCMS (aka TYPOlight) 2.11 - Cross-Site Request Forgery (Delete Admin / Delete Article)
|
2 |
WEB
|
Ivano Binetti
|
2012-02-25
|
|
YVS Image Gallery - SQL Injection
|
1 |
WEB
|
CorryL
|
2012-02-25
|
|
webgrind 1.0 - 'file' Local File Inclusion
|
1 |
WEB
|
LiquidWorm
|
2012-02-25
|
|
cPassMan 1.82 - Remote Command Execution
|
1 |
WEB
|
ls
|
2012-02-24
|
|
PHP Gift Registry 1.5.5 - SQL Injection
|
1 |
WEB
|
G13
|
2012-02-23
|
|
The Uploader 2.0.4 (English/Italian) - Arbitrary File Upload / Remote Code Execution (Metasploit)
|
2 |
WEB
|
Danny Moules
|
2012-02-23
|
|
Snom IP Phone - Privilege Escalation
|
2 |
WEB
|
Sense of Security
|
2012-02-23
|
|
phpDenora 1.4.6 - Multiple SQL Injections
|
2 |
WEB
|
Patrick de Brouwer
|
2012-02-22
|
|
DFLabs PTK 1.0.5 - Steal Authentication Credentials
|
2 |
WEB
|
Ivano Binetti
|
2012-02-22
|
|
D-Link DSL-2640B ADSL Router - Authentication Bypass
|
2 |
WEB
|
Ivano Binetti
|
2012-02-22
|
|
WebcamXP and webcam 7 - Directory Traversal
|
2 |
WEB
|
Silent_Dream
|
2012-02-22
|
|
D-Link DCS Series - Cross-Site Request Forgery (Change Admin Password)
|
1 |
WEB
|
rigan
|
2012-02-22
|
|
LimeSurvey (PHPSurveyor 1.91+ stable) - Blind SQL Injection
|
2 |
WEB
|
TorTukiTu
|
2012-02-22
|
|
Brim < 2.0.0 - SQL Injection
|
1 |
WEB
|
ifnull
|
2012-02-22
|
|
Sagem F@ST 2604 ADSL Router - Cross-Site Request Forgery
|
2 |
WEB
|
KinG Of PiraTeS
|
2012-02-21
|
|
Cisco Linksys WAG54GS - Cross-Site Request Forgery (Change Admin Password)
|
2 |
WEB
|
Ivano Binetti
|
2012-02-20
|
|
Plume CMS 1.2.4 - Cross-Site Request Forgery
|
1 |
WEB
|
Ivano Binetti
|
2012-02-20
|
|
D-Link DSL-2640B ADSL Router - Cross-Site Request Forgery
|
1 |
WEB
|
Ivano Binetti
|
2012-02-19
|
|
SyndeoCMS 3.0 - Cross-Site Request Forgery
|
2 |
WEB
|
Ivano Binetti
|
2012-02-19
|
|
4PSA CMS - SQL Injection
|
2 |
WEB
|
BHG Security Center
|
2012-02-18
|
|
almnzm 2.4 - Cross-Site Request Forgery (Add Admin)
|
2 |
WEB
|
HaNniBaL KsA
|
2012-02-17
|
|
Pandora Fms 4.0.1 - Local File Inclusion
|
2 |
WEB
|
Vulnerability-Lab
|
2012-02-16
|
|
SocialCMS 1.0.2 - Cross-Site Request Forgery
|
2 |
WEB
|
Ivano Binetti
|
2012-02-12
|
|
Fork CMS 3.2.4 - Local File Inclusion / Cross-Site Scripting
|
1 |
WEB
|
Avram Marius
|
2012-02-10
|
|
Dolibarr ERP/CRM 3.2.0 < Alpha - File Inclusion
|
2 |
WEB
|
Vulnerability-Lab
|
2012-02-08
|
|
Cyberoam Central Console 2.00.2 - Remote File Inclusion
|
2 |
WEB
|
Vulnerability-Lab
|
2012-02-08
|
|
Gazelle CMS 1.0 - Update Statement SQL Injection
|
2 |
WEB
|
hackme
|
2012-02-07
|
|
Flyspray 0.9.9.6 - Cross-Site Request Forgery
|
2 |
WEB
|
Vaibhav Gupta
|
2012-02-06
|
|
XRayCMS 1.1.1 - SQL Injection
|
2 |
WEB
|
chap0
|
2012-02-06
|
|
Tube Ace (Adult PHP Tube Script) - SQL Injection
|
2 |
WEB
|
Daniel Godoy
|
2012-02-06
|
|
BASE 1.4.5 - 'base_qry_main.php?t_view' SQL Injection
|
2 |
WEB
|
a.kadir altan
|
2012-02-05
|
|
GAzie 5.20 - Cross-Site Request Forgery
|
2 |
WEB
|
Giuseppe D'Inverno
|
2012-02-02
|
|
Achievo 1.4.3 - Multiple Web Vulnerabilities
|
1 |
WEB
|
Vulnerability-Lab
|
2012-02-02
|
|
osCommerce 3.0.2 - Persistent Cross-Site Scripting
|
1 |
WEB
|
Vulnerability-Lab
|
2012-02-02
|
|
Apache Struts - Multiple Persistent Cross-Site Scripting Vulnerabilities
|
1 |
WEB
|
SecPod Research
|
2012-02-02
|
|
Sphinix Mobile Web Server 3.1.2.47 - Multiple Persistent Cross-Site Scripting Vulnerabilities
|
1 |
WEB
|
SecPod Research
|
2012-01-13
|
|
MailEnable Webmail - Cross-Site Scripting
|
1 |
WEB
|
Sajjad Pourali
|
2012-02-01
|
|
sit! support incident tracker 3.64 - Multiple Vulnerabilities
|
1 |
WEB
|
High-Tech Bridge SA
|
2012-02-01
|
|
swDesk - Multiple Vulnerabilities
|
1 |
WEB
|
Red Security TEAM
|
2012-01-31
|
|
Vastal I-Tech Agent Zone - 'search.php' Blind SQL Injection
|
0 |
WEB
|
Cagri Tepebasili
|
2012-01-31
|
|
PragmaMX 1.2.10 - Persistent Cross-Site Scripting
|
1 |
WEB
|
HauntIT
|
2012-01-31
|
|
Ez Album - Blind SQL Injection
|
1 |
WEB
|
Red Security TEAM
|
2012-01-31
|
|
phpShowtime - Directory Traversal
|
1 |
WEB
|
Red Security TEAM
|
2012-01-31
|
|
Snort Report 1.3.2 - SQL Injection
|
1 |
WEB
|
a.kadir altan
|
2012-01-30
|
|
phux Download Manager - Blind SQL Injection
|
1 |
WEB
|
Red Security TEAM
|
2012-01-30
|
|
Ajax Upload - Arbitrary File Upload
|
1 |
WEB
|
Daniel Godoy
|
2012-01-30
|
|
Campaign Enterprise 11.0.421 - SQL Injection
|
0 |
WEB
|
Craig Freyman
|
2012-01-30
|
|
4Images 1.7.6-9 - Cross-Site Request Forgery / PHP Code Injection
|
1 |
WEB
|
Or4nG.M4N
|
2012-01-30
|
|
HostBill App 2.3 - Remote Code Injection
|
1 |
WEB
|
Dr.DaShEr
|
2012-01-27
|
|
vBSEO 3.6.0 - 'proc_deutf()' Remote PHP Code Injection (Metasploit)
|
2 |
WEB
|
EgiX
|
2012-01-26
|
|
Peel Shopping 2.8/ 2.9 - Cross-Site Scripting / SQL Injections
|
2 |
WEB
|
Cyber-Crystal
|
2012-01-26
|
|
phpList 2.10.9 - Cross-Site Request Forgery / Cross-Site Scripting
|
1 |
WEB
|
Cyber-Crystal
|
2012-01-26
|
|
VR GPub 4.0 - Cross-Site Request Forgery
|
1 |
WEB
|
Cyber-Crystal
|
2012-01-25
|
|
WordPress Core 3.3.1 - Multiple Vulnerabilities
|
1 |
WEB
|
Trustwave's SpiderLabs
|
2012-01-24
|
|
stoneware webnetwork6 - Multiple Vulnerabilities
|
2 |
WEB
|
Jacob Holcomb
|
2012-01-23
|
|
SpamTitan Application 5.08x - SQL Injection
|
2 |
WEB
|
Vulnerability-Lab
|
2012-01-23
|
|
WordPress Plugin Kish Guest Posting 1.0 - Arbitrary File Upload
|
2 |
WEB
|
EgiX
|
2012-01-22
|
|
MiniCMS 1.0/2.0 - PHP Code Injection
|
2 |
WEB
|
Or4nG.M4N
|
2012-01-22
|
|
WordPress Plugin AllWebMenus < 1.1.9 Menu Plugin - Arbitrary File Upload
|
2 |
WEB
|
6Scan
|
2012-01-21
|
|
ARYADAD - Multiple Vulnerabilities
|
2 |
WEB
|
Red Security TEAM
|
2012-01-21
|
|
iSupport 1.x - Cross-Site Request Forgery / HTML Code Injection (Add Admin)
|
2 |
WEB
|
Or4nG.M4N
|
2012-01-21
|
|
Nova CMS - Directory Traversal
|
2 |
WEB
|
Red Security TEAM
|
2012-01-21
|
|
PHP iReport 1.0 - Remote Html Code Injection
|
2 |
WEB
|
Or4nG.M4N
|
2012-01-20
|
|
WhatsApp - Remote Change Status
|
1 |
WEB
|
emgent
|
2012-01-20
|
|
EasyPage - SQL Injection
|
1 |
WEB
|
Red Security TEAM
|
2012-01-20
|
|
ICTimeAttendance - Authentication Bypass
|
1 |
WEB
|
v3n0m
|
2012-01-19
|
|
appRain CMF 0.1.5 - 'Uploadify.php' Unrestricted Arbitrary File Upload
|
1 |
WEB
|
EgiX
|
2012-01-19
|
|
WordPress Plugin ucan post 1.0.09 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Gianluca Brindisi
|
2012-01-19
|
|
Drupal Module CKEditor 3.0 < 3.6.2 - Persistent EventHandler Cross-Site Scripting
|
2 |
WEB
|
MaXe
|
2012-01-18
|
|
DZCP (deV!L_z Clanportal) 1.5.5 Moviebase Addon - Blind SQL Injection
|
2 |
WEB
|
Easy Laster
|
2012-01-18
|
|
DZCP (deV!L_z Clanportal) Gamebase Addon - SQL Injection
|
2 |
WEB
|
Easy Laster
|
2012-01-18
|
|
PHPBridges Blog System - 'members.php' SQL Injection
|
1 |
WEB
|
3spi0n
|
2012-01-18
|
|
pGB 2.12 - 'kommentar.php' SQL Injection
|
2 |
WEB
|
3spi0n
|
2012-01-17
|
|
Joomla! Component com_discussions - SQL Injection
|
2 |
WEB
|
Red Security TEAM
|
2012-01-16
|
|
PHPDomainRegister 0.4a-RC2-dev - Multiple Vulnerabilities
|
1 |
WEB
|
Or4nG.M4N
|
2012-01-15
|
|
Cloupia End-to-end FlexPod Management - Directory Traversal
|
2 |
WEB
|
Chris Rock
|
2012-01-14
|
|
phpMyAdmin 3.3.x/3.4.x - Local File Inclusion via XML External Entity Injection (Metasploit)
|
1 |
WEB
|
Marco Batista
|
2012-01-13
|
|
Pragyan CMS 2.6.1 - Arbitrary File Upload
|
2 |
WEB
|
Dr.KroOoZ
|
2012-01-13
|
|
Tine 2.0 - Maischa Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
Vulnerability-Lab
|
2012-01-12
|
|
WordPress Plugin Count Per Day - Multiple Vulnerabilities
|
2 |
WEB
|
6Scan
|
2012-01-12
|
|
WordPress Plugin wp-autoyoutube - Blind SQL Injection
|
2 |
WEB
|
longrifle0x
|
2012-01-12
|
|
Advanced Image Hosting Script - SQL Injection
|
2 |
WEB
|
Robert Cooper
|
2012-01-10
|
|
WordPress Plugin Age Verification 0.4 - Open Redirect
|
2 |
WEB
|
Gianluca Brindisi
|
2012-01-10
|
|
w-CMS 2.01 - Multiple Vulnerabilities
|
2 |
WEB
|
th3.g4m3_0v3r
|
2012-01-10
|
|
Pragyan CMS 3.0 - Remote File Disclosure
|
2 |
WEB
|
Or4nG.M4N
|
2012-01-10
|
|
RazorCMS 1.2 - Directory Traversal
|
2 |
WEB
|
chap0
|
2012-01-09
|
|
Enigma2 Webinterface 1.5.x/1.6.x/1.7.x (Linux) - Remote File Disclosure
|
2 |
WEB
|
Todor Donev
|
2012-01-09
|
|
SAPID 1.2.3 Stable - Remote File Inclusion
|
2 |
WEB
|
Opa Yong
|
2012-01-09
|
|
Clipbucket 2.6 - Multiple Vulnerabilities
|
1 |
WEB
|
YaDoY666
|
2012-01-09
|
|
Paddelberg Topsite Script - Authentication Bypass
|
2 |
WEB
|
Christian Inci
|
2012-01-08
|
|
phpMyDirectory.com 1.3.3 - SQL Injection
|
2 |
WEB
|
Serseri
|
2012-01-08
|
|
MangosWeb - SQL Injection
|
2 |
WEB
|
Hood3dRob1n
|
2012-01-06
|
|
WordPress Plugin Pay with Tweet 1.1 - Multiple Vulnerabilities
|
1 |
WEB
|
Gianluca Brindisi
|
2012-01-06
|
|
Apache Struts 2 < 2.3.1 - Multiple Vulnerabilities
|
2 |
WEB
|
SEC Consult
|
2012-01-06
|
|
TinyWebGallery 1.8.3 - Remote Command Execution
|
1 |
WEB
|
Expl0!Ts
|
2012-01-04
|
|
Posse Softball Director CMS - 'team.php' Blind SQL Injection
|
1 |
WEB
|
Easy Laster
|
2012-01-04
|
|
Posse Softball Director CMS - SQL Injection
|
1 |
WEB
|
H4ckCity Security Team
|
2012-01-04
|
|
Typo3 4.5 < 4.7 - Remote Code Execution / Local File Inclusion / Remote File Inclusion
|
1 |
WEB
|
MaXe
|
2012-01-02
|
|
MyPHPDating 1.0 - SQL Injection
|
3 |
WEB
|
ITTIHACK
|
2012-01-02
|
|
PHP-X-Links Script - SQL Injection
|
2 |
WEB
|
H4ckCity Security Team
|
2012-01-02
|
|
WSN Links Script 2.3.4 - SQL Injection
|
2 |
WEB
|
H4ckCity Security Team
|
2011-12-30
|
|
Akiva WebBoard 8.x - SQL Injection
|
2 |
WEB
|
Alexander Fuchs
|
2011-12-30
|
|
Dede CMS - SQL Injection
|
1 |
WEB
|
CWH & Nafsh
|
2011-12-29
|
|
Winn Guestbook 2.4.8c - Persistent Cross-Site Scripting
|
1 |
WEB
|
G13
|
2011-12-29
|
|
DIY-CMS blog mod - SQL Injection
|
2 |
WEB
|
snup
|