2009-05-14
|
|
Easy Scripts Answer and Question Script - Multiple Vulnerabilities
|
1 |
WEB
|
InjEctOr5
|
2009-05-14
|
|
2DayBiz Business Community Script - Multiple Vulnerabilities
|
2 |
WEB
|
TiGeR-Dz
|
2009-05-14
|
|
MRCGIGUY Ultimate Profit Portal 1.0.1 - Insecure Cookie Handling
|
1 |
WEB
|
TiGeR-Dz
|
2009-05-14
|
|
MRCGIGUY The Ticket System 2.0 - Insecure Cookie Handling
|
1 |
WEB
|
TiGeR-Dz
|
2009-05-14
|
|
MRCGIGUY Message Box 1.0 - Insecure Cookie Handling
|
1 |
WEB
|
TiGeR-Dz
|
2009-05-14
|
|
MRCGIGUY Amazon Directory 1.0/2.0 - Insecure Cookie Handling
|
1 |
WEB
|
TiGeR-Dz
|
2009-05-14
|
|
MRCGIGUY Hot Links SQL 3.2.0 - Insecure Cookie Handling
|
1 |
WEB
|
TiGeR-Dz
|
2009-05-14
|
|
Submitter Script - Authentication Bypass
|
1 |
WEB
|
ThE g0bL!N
|
2009-05-14
|
|
MRCGIGUY ClickBank Directory 1.0.1 - Insecure Cookie Handling
|
2 |
WEB
|
TiGeR-Dz
|
2009-05-14
|
|
StrawBerry 1.1.1 - Local File Inclusion / Remote Command Execution
|
2 |
WEB
|
[AVT]
|
2009-05-14
|
|
beLive 0.2.3 - 'arch.php?arch' Local File Inclusion
|
2 |
WEB
|
Kacper
|
2009-05-14
|
|
Shutter 0.1.1 - Multiple SQL Injections
|
2 |
WEB
|
YEnH4ckEr
|
2009-05-14
|
|
My Game Script 2.0 - Authentication Bypass
|
2 |
WEB
|
ThE g0bL!N
|
2009-05-14
|
|
Ascad Networks 5 - Products Insecure Cookie Handling
|
2 |
WEB
|
G4N0K
|
2009-05-13
|
|
Mlffat 2.1 - Cookie Authentication Bypass
|
2 |
WEB
|
Qabandi
|
2009-05-13
|
|
MaxCMS 2.0 - 'm_username' Arbitrary Create Admin
|
2 |
WEB
|
Securitylab.ir
|
2009-05-13
|
|
Family Connections CMS 1.9 - SQL Injection
|
2 |
WEB
|
YEnH4ckEr
|
2009-05-13
|
|
Password Protector SD 1.3.1 - Insecure Cookie Handling
|
1 |
WEB
|
Mr.tro0oqy
|
2009-05-13
|
|
TinyButStrong 3.4.0 - 'script' Local File Disclosure
|
2 |
WEB
|
ahmadbady
|
2009-05-12
|
|
BigACE 2.5 - SQL Injection
|
2 |
WEB
|
YEnH4ckEr
|
2009-05-12
|
|
Bitweaver 2.6 - 'saveFeed()' Remote Code Execution
|
0 |
WEB
|
Nine:Situations:Group
|
2009-05-11
|
|
PHP recommend 1.3 - Authentication Bypass / Remote File Inclusion / Code Injection
|
1 |
WEB
|
scriptjunkie
|
2009-05-11
|
|
microTopic 1 - 'Rating' Blind SQL Injection
|
2 |
WEB
|
YEnH4ckEr
|
2009-05-11
|
|
openWYSIWYG 1.4.7 - Local Directory Traversal
|
2 |
WEB
|
StAkeR
|
2009-05-11
|
|
Dacio's Image Gallery 1.6 - Directory Traversal / Authentication Bypass / Arbitrary File Upload
|
2 |
WEB
|
ahmadbady
|
2009-05-11
|
|
EggBlog 4.1.1 - Local Directory Traversal
|
2 |
WEB
|
StAkeR
|
2009-05-08
|
|
TinyWebGallery 1.7.6 - Local File Inclusion / Remote Code Execution
|
2 |
WEB
|
EgiX
|
2009-05-08
|
|
RTWebalbum 1.0.462 - 'albumID' Blind SQL Injection
|
2 |
WEB
|
YEnH4ckEr
|
2009-05-08
|
|
Battle Blog 1.25 - 'uploadform.asp' Arbitrary File Upload
|
2 |
WEB
|
Cyber-Zone
|
2009-05-08
|
|
Luxbum 0.5.5/stable - Authentication Bypass
|
2 |
WEB
|
knxone
|
2009-05-08
|
|
Realty Web-Base 1.0 - Authentication Bypass
|
2 |
WEB
|
ThE g0bL!N
|
2009-05-08
|
|
The Recipe Script 5 - Authentication Bypass / Database Backup
|
2 |
WEB
|
TiGeR-Dz
|
2009-05-07
|
|
Job Script 2.0 - Arbitrary Change Admin Password
|
2 |
WEB
|
TiGeR-Dz
|
2009-05-07
|
|
Simple Customer 1.3 - Arbitrary Change Admin Password
|
2 |
WEB
|
ahmadbady
|
2009-05-07
|
|
ST-Gallery 0.1a - Multiple SQL Injections
|
1 |
WEB
|
YEnH4ckEr
|
2009-05-07
|
|
VIDEOSCRIPT.us - Authentication Bypass
|
1 |
WEB
|
snakespc
|
2009-05-07
|
|
T-Dreams Job Career Package 3.0 - Insecure Cookie Handling
|
2 |
WEB
|
TiGeR-Dz
|
2009-05-07
|
|
TCPDB 3.8 - Arbitrary Add Admin Account
|
2 |
WEB
|
Mr.tro0oqy
|
2009-05-07
|
|
webSPELL 4.2.0e - 'page' Blind SQL Injection
|
1 |
WEB
|
DNX
|
2009-05-05
|
|
Joomla! Component Almond Classifieds 5.6.2 - Blind SQL Injection
|
2 |
WEB
|
InjEctOr5
|
2009-05-05
|
|
LinkBase 2.0 - Remote Cookie Grabber
|
2 |
WEB
|
SirGod
|
2009-05-05
|
|
TemaTres 1.0.3 - Blind SQL Injection
|
2 |
WEB
|
YEnH4ckEr
|
2009-05-05
|
|
TemaTres 1.0.3 - Authentication Bypass / SQL Injection / Cross-Site Scripting
|
2 |
WEB
|
YEnH4ckEr
|
2009-05-04
|
|
Ublog access version - Arbitrary Database Disclosure
|
2 |
WEB
|
Cyber-Zone
|
2009-05-04
|
|
Uguestbook 1.0b - 'Guestbook.mdb' Arbitrary Database Disclosure
|
2 |
WEB
|
Cyber-Zone
|
2009-05-04
|
|
projectCMS 1.1b - Multiple Vulnerabilities
|
2 |
WEB
|
YEnH4ckEr
|
2009-05-04
|
|
Million Dollar Text Links 1.0 - Arbitrary Authentication Bypass
|
2 |
WEB
|
ThE g0bL!N
|
2009-05-04
|
|
PHP Site Lock 2.0 - Insecure Cookie Handling
|
2 |
WEB
|
ThE g0bL!N
|
2009-05-04
|
|
eLitius 1.0 - Remote Command Execution
|
2 |
WEB
|
G4N0K
|
2009-05-04
|
|
Qt QuickTeam - Multiple Remote File Inclusions
|
1 |
WEB
|
ahmadbady
|
2009-05-04
|
|
BluSky CMS - 'news_id' SQL Injection
|
2 |
WEB
|
snakespc
|
2009-05-04
|
|
AGTC MyShop 3.2 - Insecure Cookie Handling
|
1 |
WEB
|
Mr.tro0oqy
|
2009-05-04
|
|
Winn ASP Guestbook 1.01b - Remote Database Disclosure
|
1 |
WEB
|
ZoRLu
|
2009-05-01
|
|
pecio CMS 1.1.5 - 'index.php?language' Local File Inclusion
|
2 |
WEB
|
SirGod
|
2009-05-01
|
|
MiniTwitter 0.2b - Remote User Options Changer
|
2 |
WEB
|
YEnH4ckEr
|
2009-05-01
|
|
MiniTwitter 0.2b - Multiple SQL Injections
|
2 |
WEB
|
YEnH4ckEr
|
2009-05-01
|
|
Golabi CMS 1.0.1 - Session Poisoning
|
2 |
WEB
|
CrazyAngel
|
2009-04-30
|
|
Leap CMS 0.1.4 - SQL Injection / Cross-Site Scripting / Arbitrary File Upload
|
2 |
WEB
|
YEnH4ckEr
|
2009-04-30
|
|
Leap CMS 0.1.4 - 'searchterm' Blind SQL Injection
|
2 |
WEB
|
YEnH4ckEr
|
2009-04-29
|
|
Tiger Dms - Authentication Bypass
|
2 |
WEB
|
ThE g0bL!N
|
2009-04-29
|
|
Zubrag Smart File Download 1.3 - Arbitrary File Download
|
2 |
WEB
|
Aodrulez
|
2009-04-29
|
|
S-CMS 1.1 Stable - 'page' Local File Inclusion
|
2 |
WEB
|
ZoRLu
|
2009-04-29
|
|
ProjectCMS 1.0b - 'index.php?sn' SQL Injection
|
2 |
WEB
|
YEnH4ckEr
|
2009-04-29
|
|
eLitius 1.0 - 'banner-details.php?id' SQL Injection
|
1 |
WEB
|
snakespc
|
2009-04-28
|
|
webSPELL 4.2.0d (Linux) - Local File Disclosure
|
2 |
WEB
|
StAkeR
|
2009-04-28
|
|
MIM: InfiniX 1.2.003 - Multiple SQL Injections
|
1 |
WEB
|
YEnH4ckEr
|
2009-04-28
|
|
VisionLms 1.0 - 'changePW.php' Remote Password Change
|
2 |
WEB
|
Mr.tro0oqy
|
2009-04-27
|
|
ABC Advertise 1.0 - Admin Password Disclosure
|
1 |
WEB
|
SirGod
|
2009-04-27
|
|
Teraway LinkTracker 1.0 - Remote Password Change
|
1 |
WEB
|
ThE g0bL!N
|
2009-04-27
|
|
Teraway LiveHelp 2.0 - Insecure Cookie Handling
|
1 |
WEB
|
ThE g0bL!N
|
2009-04-27
|
|
Teraway FileStream 1.0 - Insecure Cookie Handling
|
1 |
WEB
|
ThE g0bL!N
|
2009-04-27
|
|
Teraway LinkTracker 1.0 - Insecure Cookie Handling
|
1 |
WEB
|
ThE g0bL!N
|
2009-04-27
|
|
Flatchat 3.0 - 'pmscript.php' Local File Inclusion
|
1 |
WEB
|
SirGod
|
2009-04-27
|
|
ECShop 2.5.0 - 'order_sn' SQL Injection
|
1 |
WEB
|
Securitylab.ir
|
2009-04-27
|
|
EZ-Blog Beta2 - 'category' SQL Injection
|
1 |
WEB
|
YEnH4ckEr
|
2009-04-27
|
|
Thickbox Gallery 2 - 'index.php' Local File Inclusion
|
1 |
WEB
|
SirGod
|
2009-04-27
|
|
Dew-NewPHPLinks 2.0 - Local File Inclusion / Cross-Site Scripting
|
2 |
WEB
|
d3v1l
|
2009-04-27
|
|
LightBlog 9.9.2 - 'register.php' Remote Code Execution
|
2 |
WEB
|
EgiX
|
2009-04-27
|
|
Opencart 1.1.8 - 'route' Local File Inclusion
|
2 |
WEB
|
OoN_Boy
|
2009-04-27
|
|
Invision Power Board (IP.Board) 3.0.0b5 - Active Cross-Site Scripting / Full Path Disclosure
|
2 |
WEB
|
brain[pillow]
|
2009-04-24
|
|
Pragyan CMS 2.6.4 - Multiple SQL Injections
|
1 |
WEB
|
Salvatore Fresta
|
2009-04-24
|
|
photo-rigma.biz 30 - SQL Injection / Cross-Site Scripting
|
2 |
WEB
|
YEnH4ckEr
|
2009-04-24
|
|
Absolute Form Processor XE-V 1.5 - Remote Change Password
|
2 |
WEB
|
ThE g0bL!N
|
2009-04-24
|
|
Absolute Form Processor XE-V 1.5 - Insecure Cookie Handling
|
2 |
WEB
|
ZoRLu
|
2009-04-23
|
|
fowlcms 1.1 - Authentication Bypass / Local File Inclusion / Arbitrary File Upload
|
1 |
WEB
|
YEnH4ckEr
|
2009-04-22
|
|
Joomla! Component rsmonials - Cross-Site Scripting
|
2 |
WEB
|
jdc
|
2009-04-22
|
|
WebPortal CMS 0.8b - Multiple Local/Remote File Inclusions
|
2 |
WEB
|
ahmadbady
|
2009-04-22
|
|
5 star Rating 1.2 - Authentication Bypass
|
2 |
WEB
|
zer0day
|
2009-04-22
|
|
Elkagroup Image Gallery 1.0 - Arbitrary File Upload
|
1 |
WEB
|
Securitylab.ir
|
2009-04-22
|
|
Dokeos Lms 1.8.5 - 'Include' Remote Code Execution
|
2 |
WEB
|
StAkeR
|
2009-04-21
|
|
mixedcms 1.0b - Local File Inclusion / Arbitrary File Upload / Authentication Bypass / File Disclosu
|
2 |
WEB
|
YEnH4ckEr
|
2009-04-21
|
|
Studio Lounge Address Book 2.5 - Authentication Bypass
|
2 |
WEB
|
ThE g0bL!N
|
2009-04-21
|
|
I-Rater Pro/Plantinum 4.0 - Authentication Bypass
|
2 |
WEB
|
Hakxer
|
2009-04-21
|
|
VS PANEL 7.3.6 - 'Cat_ID' SQL Injection
|
1 |
WEB
|
Player
|
2009-04-21
|
|
Quick.CMS.Lite 0.5 - 'id' SQL Injection
|
1 |
WEB
|
Player
|
2009-04-21
|
|
NotFTP 1.3.1 - 'newlang' Local File Inclusion
|
1 |
WEB
|
Kacper
|
2009-04-21
|
|
TotalCalendar 2.4 - 'Include' Local File Inclusion
|
1 |
WEB
|
SirGod
|
2009-04-21
|
|
pastelcms 0.8.0 - Local File Inclusion / SQL Injection
|
2 |
WEB
|
SirGod
|
2009-04-21
|
|
CRE Loaded 6.2 - 'products_id' SQL Injection
|
1 |
WEB
|
Player
|
2009-04-21
|
|
Dokeos Lms 1.8.5 - 'whoisonline.php' PHP Code Injection
|
2 |
WEB
|
EgiX
|
2009-04-20
|
|
eLitius 1.0 - Arbitrary Database Backup
|
2 |
WEB
|
ThE g0bL!N
|
2009-04-20
|
|
Creasito E-Commerce 1.3.16 - Authentication Bypass
|
2 |
WEB
|
Salvatore Fresta
|
2009-04-20
|
|
TotalCalendar 2.4 - Remote Password Change
|
2 |
WEB
|
ThE g0bL!N
|
2009-04-20
|
|
e107 < 0.7.15 - 'extended_user_fields' Blind SQL Injection
|
1 |
WEB
|
StAkeR
|
2009-04-20
|
|
TotalCalendar 2.4 - 'inc_dir' Remote File Inclusion
|
1 |
WEB
|
DarKdewiL
|
2009-04-20
|
|
fungamez rc1 - Authentication Bypass / Local File Inclusion
|
1 |
WEB
|
YEnH4ckEr
|
2009-04-20
|
|
WB News 2.1.2 - Insecure Cookie Handling
|
2 |
WEB
|
ThE g0bL!N
|
2009-04-20
|
|
WysGui CMS 1.2b - Insecure Cookie Handling Blind SQL Injection
|
2 |
WEB
|
YEnH4ckEr
|
2009-04-20
|
|
Pligg CMS 9.9.0 - 'editlink.php' Blind SQL Injection
|
2 |
WEB
|
Rohit Bansal
|
2009-04-20
|
|
EZ Webitor - Authentication Bypass
|
2 |
WEB
|
snakespc
|
2009-04-20
|
|
webClassifieds 2005 - (Authentication Bypass) Insecure Cookie Handling
|
2 |
WEB
|
ThE g0bL!N
|
2009-04-20
|
|
Flatnux 2009-03-27 - Arbitrary File Upload / Information Disclosure
|
2 |
WEB
|
girex
|
2009-04-20
|
|
Seditio CMS Events Plugin - 'c' SQL Injection
|
2 |
WEB
|
OoN_Boy
|
2009-04-20
|
|
Studio Lounge Address Book 2.5 - 'profile' Arbitrary File Upload
|
2 |
WEB
|
JosS
|
2009-04-20
|
|
multi-lingual E-Commerce system 0.2 - Multiple Vulnerabilities
|
2 |
WEB
|
Salvatore Fresta
|
2009-04-17
|
|
Hot Project 7.0 - Authentication Bypass
|
2 |
WEB
|
HCOCA_MAN
|
2009-04-17
|
|
Online Email Manager - Insecure Cookie Handling
|
2 |
WEB
|
Hussin X
|
2009-04-17
|
|
Esoftpro Online Guestbook Pro - 'display' Blind SQL Injection
|
2 |
WEB
|
Hussin X
|
2009-04-17
|
|
e-cart.biz Shopping Cart - Arbitrary File Upload
|
2 |
WEB
|
ahmadbady
|
2009-04-17
|
|
ClanTiger 1.1.1 - 'slug' Blind SQL Injection
|
2 |
WEB
|
YEnH4ckEr
|
2009-04-17
|
|
ClanTiger 1.1.1 - Authentication Bypass
|
2 |
WEB
|
YEnH4ckEr
|
2009-04-17
|
|
ClanTiger < 1.1.1 - Multiple Insecure Cookie Handling Vulnerabilities
|
2 |
WEB
|
YEnH4ckEr
|
2009-04-17
|
|
Limbo CMS 1.0.4.2 - Cross-Site Request Forgery / Privilege Escalation
|
1 |
WEB
|
Alfons Luja
|
2009-04-17
|
|
Tiny Blogr 1.0.0 rc4 - Authentication Bypass
|
2 |
WEB
|
Salvatore Fresta
|
2009-04-16
|
|
chCounter 3.1.3 - Authentication Bypass
|
2 |
WEB
|
tmh
|