2010-12-15
|
|
Pointter PHP Micro-Blogging Social Network - Unauthorized Privilege Escalation
|
2 |
WEB
|
Mark Stanislav
|
2010-12-15
|
|
Pointter PHP Content Management System - Unauthorized Privilege Escalation
|
2 |
WEB
|
Mark Stanislav
|
2010-12-15
|
|
Google Urchin 5.7.03 - Local File Inclusion
|
2 |
WEB
|
Kristian Erik Hermansen
|
2010-12-15
|
|
Mantis Bug Tracker 1.2.3 - 'db_type' Local File Inclusion
|
2 |
WEB
|
LiquidWorm
|
2010-12-15
|
|
Mantis Bug Tracker 1.2.3 - 'db_type' Cross-Site Scripting / Full Path Disclosure
|
1 |
WEB
|
LiquidWorm
|
2010-12-12
|
|
Clear iSpot/Clearspot 2.0.0.0 - Cross-Site Request Forgery
|
2 |
WEB
|
Trustwave's SpiderLabs
|
2010-12-10
|
|
Joomla! Component com_billyportfolio 1.1.2 - Blind SQL Injection
|
2 |
WEB
|
jdc
|
2010-12-10
|
|
Sulata iSoft - 'stream.php' Local File Disclosure
|
2 |
WEB
|
Sudden_death
|
2010-12-09
|
|
Joomla! Component JE Messenger 1.0 - Arbitrary File Upload
|
2 |
WEB
|
Salvatore Fresta
|
2010-12-09
|
|
AJ Matrix DNA - SQL Injection
|
2 |
WEB
|
Br0ly
|
2010-12-09
|
|
CMScout 2.09 - Cross-Site Request Forgery
|
2 |
WEB
|
High-Tech Bridge SA
|
2010-12-09
|
|
Joomla! Component JE Auto 1.0 - SQL Injection
|
2 |
WEB
|
Salvatore Fresta
|
2010-12-09
|
|
Abtp Portal Project 0.1.0 - Local File Inclusion
|
1 |
WEB
|
Br0ly
|
2010-12-09
|
|
Apache Archiva 1.0 < 1.3.1 - Cross-Site Request Forgery
|
2 |
WEB
|
Anatolia Security
|
2010-12-07
|
|
SOOP Portal Raven 1.0b - Arbitrary File Upload
|
2 |
WEB
|
Sun Army
|
2010-12-06
|
|
MODx REvolution CMS 2.0.4-pl2 - POST injection Cross-Site Scripting
|
2 |
WEB
|
LiquidWorm
|
2010-12-06
|
|
phpMyAdmin - Client-Side Code Injection / Redirect Link Falsification
|
1 |
WEB
|
emgent white_sheep & scox
|
2010-12-05
|
|
Pulse CMS Basic - Local File Inclusion
|
2 |
WEB
|
Mark Stanislav
|
2010-12-05
|
|
SOOP Portal 2.0 - Arbitrary File Upload
|
2 |
WEB
|
Net.Edit0r
|
2010-12-05
|
|
HotWebScripts HotWeb Rentals - 'resorts.asp' SQL Injection
|
1 |
WEB
|
R4dc0re
|
2010-12-05
|
|
Ecommercemax Solutions Digital Goods Seller - SQL Injection
|
2 |
WEB
|
R4dc0re
|
2010-12-05
|
|
Gatesoft Docusafe 4.1.0 - SQL Injection
|
2 |
WEB
|
R4dc0re
|
2010-12-05
|
|
PHPKF Forum 1.80 - 'profil_degistir.php' Cross-Site Request Forgery
|
2 |
WEB
|
FreWaL
|
2010-12-05
|
|
WordPress Core 3.0.1 - 'do_trackbacks()' SQL Injection
|
2 |
WEB
|
M4g
|
2010-12-04
|
|
ASPSiteWare Contact Directory 1.0 - SQL Injection
|
2 |
WEB
|
R4dc0re
|
2010-12-04
|
|
ASPSiteWare ASP Gallery 1.0 - SQL Injection
|
2 |
WEB
|
R4dc0re
|
2010-12-04
|
|
ASPSiteWare JobPost 1.0 - SQL Injection
|
2 |
WEB
|
R4dc0re
|
2010-12-04
|
|
ASPSiteWare Project Reporter - SQL Injection
|
2 |
WEB
|
R4dc0re
|
2010-12-04
|
|
ASPSiteWare Recipe ORGanizer - SQL Injection
|
1 |
WEB
|
R4dc0re
|
2010-12-04
|
|
T-Dreams Job Seekers Package 3.0 - SQL Injection
|
2 |
WEB
|
R4dc0re
|
2010-12-04
|
|
T-Dreams Cars Ads Package 2.0 - SQL Injection
|
2 |
WEB
|
R4dc0re
|
2010-12-04
|
|
Linksys Routers - Cross-Site Request Forgery
|
2 |
WEB
|
Martin Barbella
|
2010-12-04
|
|
Dejcom Market CMS - 'showbrand.aspx' SQL Injection
|
2 |
WEB
|
Mormoroth
|
2010-12-03
|
|
D-Link Routers - Authentication Bypass (1)
|
2 |
WEB
|
Craig Heffner
|
2010-12-03
|
|
Easy Travel Portal 2 - 'travelbycountry.asp' SQL Injection
|
2 |
WEB
|
Ulrik Persson
|
2010-12-02
|
|
Ananda Real Estate 3.4 - 'list.asp' Multiple SQL Injections
|
2 |
WEB
|
underground-stockholm.com
|
2010-12-02
|
|
etomite 1.1 - Multiple Vulnerabilities
|
2 |
WEB
|
High-Tech Bridge SA
|
2010-12-02
|
|
Contenido CMS 4.8.12 - Cross-Site Scripting
|
2 |
WEB
|
High-Tech Bridge SA
|
2010-12-01
|
|
LittlePhpGallery 1.0.2 - Local File Inclusion
|
2 |
WEB
|
kire bozorge khavarmian
|
2010-12-01
|
|
Digitalus 1.10.0 Alpha2 - Arbitrary File Upload
|
2 |
WEB
|
eidelweiss
|
2010-12-01
|
|
BugTracker.NET 3.4.4 - Multiple Vulnerabilities
|
2 |
WEB
|
Core Security
|
2010-12-01
|
|
OsCSS 1.2 - Arbitrary File Upload
|
2 |
WEB
|
Shichemt Alen
|
2010-12-01
|
|
Alibaba Clone B2B 3.4 - SQL Injection
|
2 |
WEB
|
Dr.0rYX & Cr3W-DZ
|
2010-11-30
|
|
Elxis CMS 2009.2 - SQL Injection
|
2 |
WEB
|
High-Tech Bridge SA
|
2010-11-30
|
|
DynPG 4.2.0 - Multiple Vulnerabilities
|
2 |
WEB
|
High-Tech Bridge SA
|
2010-11-30
|
|
enano CMS 1.1.7pl1 - Multiple Vulnerabilities
|
1 |
WEB
|
High-Tech Bridge SA
|
2010-11-30
|
|
Eclime 1.1.2b - Multiple Vulnerabilities
|
2 |
WEB
|
High-Tech Bridge SA
|
2010-11-30
|
|
Pandora Fms 3.1 - Directory Traversal / Local File Inclusion
|
1 |
WEB
|
Juan Galiana Lara
|
2010-11-30
|
|
Pandora Fms 3.1 - Blind SQL Injection
|
2 |
WEB
|
Juan Galiana Lara
|
2010-11-30
|
|
Pandora Fms 3.1 - SQL Injection
|
2 |
WEB
|
Juan Galiana Lara
|
2010-11-30
|
|
Pandora Fms 3.1 - OS Command Injection
|
2 |
WEB
|
Juan Galiana Lara
|
2010-11-30
|
|
Pandora FMS 3.1 - Authentication Bypass
|
2 |
WEB
|
Juan Galiana Lara
|
2010-11-30
|
|
Duhok Forum 1.1 - Arbitrary File Upload
|
1 |
WEB
|
BrOx-Dz
|
2010-11-30
|
|
Link Protect 1.2 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Shichemt Alen
|
2010-11-30
|
|
Orbis CMS 1.0.2 - Arbitrary File Upload
|
2 |
WEB
|
Mark Stanislav
|
2010-11-29
|
|
Diferior 8.03 - Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
High-Tech Bridge SA
|
2010-11-29
|
|
MicroNetSoft RV Dealer Website - 'search.asp' / showAlllistings.asp' SQL Injection
|
2 |
WEB
|
underground-stockholm.com
|
2010-11-28
|
|
Site2Nite Big Truck Broker - 'txtSiteId' SQL Injection
|
2 |
WEB
|
underground-stockholm.com
|
2010-11-28
|
|
Skeletonz CMS - Persistent Cross-Site Scripting
|
2 |
WEB
|
Jbyte
|
2010-11-27
|
|
MemHT Portal 4.0.1 - 'User Agent' Persistent Cross-Site Scripting
|
1 |
WEB
|
ZonTa
|
2010-11-27
|
|
Jurpopage 0.2.0 - SQL Injection
|
2 |
WEB
|
Sudden_death
|
2010-11-25
|
|
Frog CMS 0.9.5 - Multiple Vulnerabilities
|
2 |
WEB
|
High-Tech Bridge SA
|
2010-11-25
|
|
Wolf CMS 0.6.0b - Multiple Vulnerabilities
|
2 |
WEB
|
High-Tech Bridge SA
|
2010-11-25
|
|
SiteEngine 7.1 - SQL Injection
|
2 |
WEB
|
Beach
|
2010-11-25
|
|
JDownloader Webinterface - Source Code Disclosure
|
2 |
WEB
|
Sil3nt_Dre4m
|
2010-11-25
|
|
Joomla! Component JE Ajax Event Calendar - SQL Injection
|
1 |
WEB
|
ALTBTA
|
2010-11-24
|
|
Free Simple Software - SQL Injection
|
2 |
WEB
|
Mark Stanislav
|
2010-11-24
|
|
WSN Links - SQL Injection
|
2 |
WEB
|
Mark Stanislav
|
2010-11-24
|
|
phpvidz 0.9.5 - Administrative Credentials Disclosure
|
1 |
WEB
|
Michael Brooks
|
2010-11-24
|
|
Getsimple CMS 2.01 < 2.02 - Administrative Credentials Disclosure
|
2 |
WEB
|
Michael Brooks
|
2010-11-23
|
|
PHPmotion 1.62 - 'FCKeditor' Arbitrary File Upload
|
2 |
WEB
|
trycyber
|
2010-11-22
|
|
Acidcat CMS 3.3 - 'FCKeditor' Arbitrary File Upload
|
2 |
WEB
|
Net.Edit0r
|
2010-11-22
|
|
JCMS 2010 - File Download
|
2 |
WEB
|
Beach
|
2010-11-22
|
|
jSchool Advanced - Blind SQL Injection
|
2 |
WEB
|
Don Tukulesto
|
2010-11-22
|
|
AuraCMS 1.62 - 'pfd.php' SQL Injection
|
1 |
WEB
|
Don Tukulesto
|
2010-11-21
|
|
cPanel 11.x - Cross-Site Request Forgery (Edit E-mail)
|
2 |
WEB
|
Mon7rF .
|
2010-11-21
|
|
sahitya graphics CMS - Multiple Vulnerabilities
|
2 |
WEB
|
Dr.0rYX & Cr3W-DZ
|
2010-11-20
|
|
vBulletin 4.0.8 PL1 - Cross-Site Scripting Filter Bypass within Profile Customization
|
2 |
WEB
|
MaXe
|
2010-11-20
|
|
S_CMS 2.5 - Multiple Vulnerabilities
|
2 |
WEB
|
LordTittiS
|
2010-11-20
|
|
Joomla! Component Jimtawl 1.0.2 - Local File Inclusion
|
2 |
WEB
|
Mask_magicianz
|
2010-11-19
|
|
DVD Rental Software - SQL Injection
|
2 |
WEB
|
JaMbA
|
2010-11-19
|
|
Plogger Gallery 1.0 - Cross-Site Request Forgery (Change Admin Password)
|
2 |
WEB
|
Or4nG.M4N
|
2010-11-19
|
|
Arabian YouTube Script - Blind SQL Injection
|
1 |
WEB
|
R3d-D3V!L
|
2010-11-19
|
|
PHPGallery 1.1.0 - Cross-Site Request Forgery
|
1 |
WEB
|
Or4nG.M4N
|
2010-11-19
|
|
ViArt Shop 4.0.5 - Multiple Vulnerabilities
|
1 |
WEB
|
Ariko-Security
|
2010-11-18
|
|
Fozzcom Shopping < 7.94 / < 8.04 - Multiple Vulnerabilities
|
1 |
WEB
|
Dr.0rYX & Cr3W-DZ
|
2010-11-18
|
|
Joomla! Component com_mtree 2.1.6 - Overwrite Cross-Site Request Forgery
|
1 |
WEB
|
jdc
|
2010-11-18
|
|
chCounter 3.1.3 - SQL Injection
|
1 |
WEB
|
Matias Fontanini
|
2010-11-18
|
|
WebRCSdiff 0.9 - 'viewver.php' Remote File Inclusion
|
1 |
WEB
|
FL0RiX
|
2010-11-17
|
|
Front Accounting 2.3RC2 - Multiple SQL Injections
|
1 |
WEB
|
Juan Manuel Garcia
|
2010-11-17
|
|
Front Accounting 2.3RC2 - Multiple Persistent Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
Juan Manuel Garcia
|
2010-11-17
|
|
Sitefinity CMS - 'ASP.NET' Arbitrary File Upload
|
1 |
WEB
|
Net.Edit0r
|
2010-11-16
|
|
CompactCMS 1.4.1 - SQL Injection
|
2 |
WEB
|
High-Tech Bridge SA
|
2010-11-16
|
|
ClanSphere 2010.0 Final - Multiple Vulnerabilities
|
2 |
WEB
|
High-Tech Bridge SA
|
2010-11-16
|
|
IceBB 1.0-rc10 - Multiple Vulnerabilities
|
2 |
WEB
|
High-Tech Bridge SA
|
2010-11-16
|
|
openEngine 2.0 100226 - Local File Inclusion / Cross-Site Scripting
|
1 |
WEB
|
SecPod Research
|
2010-11-16
|
|
Joomla! Component com_maianmedia - SQL Injection
|
2 |
WEB
|
v3n0m
|
2010-11-16
|
|
BPRealestate Real Estate - Authentication Bypass
|
2 |
WEB
|
v3n0m
|
2010-11-16
|
|
BPConferenceReporting Web Reporting - Authentication Bypass
|
2 |
WEB
|
v3n0m
|
2010-11-16
|
|
BPDirectory Business Directory - Authentication Bypass
|
2 |
WEB
|
v3n0m
|
2010-11-16
|
|
BPAffiliate Affiliate Tracking - Authentication Bypass
|
2 |
WEB
|
v3n0m
|
2010-11-16
|
|
vBulletin 4.0.8 - Persistent Cross-Site Scripting via Profile Customization
|
2 |
WEB
|
MaXe
|
2010-11-15
|
|
Joomla! Component com_alfurqan15x - SQL Injection
|
1 |
WEB
|
kaMtiEz
|
2010-11-15
|
|
Nuked-klaN Module Boutique - Blind SQL Injection
|
2 |
WEB
|
[AR51]Kevinos
|
2010-11-15
|
|
Web Wiz NewsPad Express Edition 1.03 - Database File Disclosure
|
2 |
WEB
|
keracker
|
2010-11-15
|
|
Chameleon Social Networking Software - Persistent Cross-Site Scripting
|
2 |
WEB
|
Dr-mosta
|
2010-11-14
|
|
BSI Advance Hotel Booking System 1.0 - SQL Injection
|
1 |
WEB
|
v3n0m
|
2010-11-13
|
|
Pre Online Tests Generator Pro - SQL Injection
|
1 |
WEB
|
Cru3l.b0y
|
2010-11-13
|
|
Pre ADS Portal - Authentication Bypass
|
1 |
WEB
|
Cru3l.b0y
|
2010-11-13
|
|
OneOrZero AIms 2.6.0 Members Edition - Multiple Vulnerabilities
|
1 |
WEB
|
Valentin
|
2010-11-13
|
|
Joomla! Component CCBoard 1.2-RC - Multiple Vulnerabilities
|
1 |
WEB
|
jdc
|
2010-11-13
|
|
Webmatic - 'index.php' SQL Injection
|
1 |
WEB
|
v3n0m
|
2010-11-13
|
|
EasyJobPortal - Arbitrary File Upload
|
0 |
WEB
|
MeGo
|
2010-11-13
|
|
Invision Power Board 3 - 'search_app' SQL Injection
|
0 |
WEB
|
Lord Tittis3000
|
2010-11-13
|
|
WordPress Plugin Event Registration 5.32 - SQL Injection
|
1 |
WEB
|
k3m4n9i
|
2010-11-13
|
|
DBSite - SQL Injection
|
1 |
WEB
|
God_Of_Pain
|
2010-11-13
|
|
AWCM 2.1 Final - Remote File Inclusion
|
1 |
WEB
|
LoSt.HaCkEr
|
2010-11-13
|
|
Build a Niche Store 3.0 - 'BANS' Authentication Bypass
|
1 |
WEB
|
ThunDEr HeaD
|
2010-11-13
|
|
Camtron CMNC-200 IP Camera - Undocumented Default Accounts
|
1 |
WEB
|
Trustwave's SpiderLabs
|
2010-11-13
|
|
Camtron CMNC-200 IP Camera - Authentication Bypass
|
1 |
WEB
|
Trustwave's SpiderLabs
|
2010-11-12
|
|
Joomla! Component JSupport 1.5.6 - SQL Injection
|
1 |
WEB
|
Valentin
|
2010-11-12
|
|
Joomla! Component JSupport 1.5.6 - Cross-Site Scripting
|
1 |
WEB
|
Valentin
|
2010-11-12
|
|
Woltlab Burning Board 2.3.4 - File Disclosure
|
1 |
WEB
|
sfx
|
2010-11-12
|
|
ASPilot Pilot Cart 7.3 - 'newsroom.asp' SQL Injection
|
2 |
WEB
|
Daikin
|
2010-11-12
|
|
Metinfo 3.0 - Multiple Vulnerabilities
|
1 |
WEB
|
anT!-Tr0J4n
|