Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2009-02-05   txtBB 1.0 RC3 - HTML/JS Injection / Arbitrary Add Admin Privileges 1 WEB cOndemned
2009-02-05   ClearBudget 0.6.1 - Insecure Database Disclosure 1 WEB Room-Hacker
2009-02-05   Kipper 2.01 - Cross-Site Scripting / Local File Inclusion / File Disclosure 1 WEB RoMaNcYxHaCkEr
2009-02-05   ClearBudget 0.6.1 - Insecure Cookie Handling / Local File Inclusion 1 WEB SirGod
2009-02-04   GR Note 0.94 Beta - (Authentication Bypass) Remote Database Backup 1 WEB JosS
2009-02-04   gr blog 1.1.4 - Arbitrary File Upload / Authentication Bypass 0 WEB JosS
2009-02-04   YapBB 1.2 - 'forumID' Blind SQL Injection 0 WEB darkjoker
2009-02-04   team 1.x - File Disclosure / Cross-Site Scripting 0 WEB Pouya_Server
2009-02-04   Power System Of Article Management 3.0 - File Disclosure / Cross-Site Scripting 0 WEB Pouya_Server
2009-02-04   PHPbbBook 1.3 - 'bbcode.php?l' Local File Inclusion 0 WEB Osirys
2009-02-04   GRBoard 1.8 - Multiple Remote File Inclusions 0 WEB make0day
2009-02-04   rgboard 4 5p1 (07.07.27) - Multiple Vulnerabilities 0 WEB make0day
2009-02-04   Syntax Desktop 2.7 - 'synTarget' Local File Inclusion 0 WEB ahmadbady
2009-02-04   Jaws 0.8.8 - Multiple Local File Inclusions 0 WEB fuzion
2009-02-03   OpenFiler 2.3 - (Authentication Bypass) Remote Password Change 2 WEB nonroot
2009-02-03   Flatnux 2009-01-27 - Remote File Inclusion 2 WEB Alfons Luja
2009-02-03   DreamPics Photo/Video Gallery - Blind SQL Injection 1 WEB Mehmet Ince
2009-02-03   TxtBlog 1.0 Alpha - Remote Command Execution 2 WEB Osirys
2009-02-03   Technote 7.2 - Remote File Inclusion 2 WEB make0day
2009-02-03   4Site CMS 2.6 - Multiple SQL Injections 2 WEB D.Mortalov
2009-02-03   MyDesing Sayac 2.0 - Authentication Bypass 2 WEB Kacak
2009-02-03   WEBalbum 2.4b - 'id' Blind SQL Injection 1 WEB Mehmet Ince
2009-02-03   AJA Modules Rapidshare 1.0.0 - Arbitrary File Upload 2 WEB Hussin X
2009-02-03   Simple Machines Forum (SMF) - 'BBCode' Cookie Stealing 2 WEB Xianur0
2009-02-03   Online Grades 3.2.4 - Authentication Bypass 0 WEB x0r
2009-02-03   groone's Guestbook 2.0 - Remote File Inclusion 0 WEB k3vin mitnick
2009-02-03   groone glinks 2.1 - Remote File Inclusion 0 WEB k3vin mitnick
2009-02-03   ClickCart 6.0 - Authentication Bypass 0 WEB R3d-D3V!L
2009-02-03   WholeHogSoftware Password Protect - Insecure Cookie Handling 0 WEB Stack
2009-02-03   WholeHogSoftware Ware Support - Insecure Cookie Handling 0 WEB Stack
2009-02-02   OpenHelpDesk 1.0.100 - 'eval()' Code Execution (Metasploit) 0 WEB LSO
2009-02-02   PHPSlash 0.8.1.1 - Remote Code Execution 0 WEB DarkFig
2009-02-02   eVision CMS 2.0 - Remote Code Execution 0 WEB Osirys
2009-02-02   sourdough 0.3.5 - Remote File Inclusion 0 WEB ahmadbady
2009-02-02   CMS Mini 0.2.2 - Remote Command Execution 0 WEB darkjoker
2009-02-02   phpBLASTER 1.0 RC1 - Blind SQL Injection 0 WEB darkjoker
2009-02-02   WholeHogSoftware Password Protect - Authentication Bypass 1 WEB ByALBAYX
2009-02-02   WholeHogSoftware Ware Support - Authentication Bypass 0 WEB ByALBAYX
2009-02-02   AJA Portal 1.2 (Windows) - Local File Inclusion 0 WEB ahmadbady
2009-02-02   Flatnux 2009-01-27 - Cross-Site Scripting / Iframe Injection 0 WEB Alfons Luja
2009-02-02   sma-db 0.3.12 - Remote File Inclusion / Cross-Site Scripting 0 WEB ahmadbady
2009-01-30   eVision CMS 2.0 - SQL Injection 1 WEB darkjoker
2009-01-30   SkaLinks 1.5 - Authentication Bypass 0 WEB Dimi4
2009-01-30   Orca 2.0.2 - 'topic ' Cross-Site Scripting 2 WEB J-Hacker
2009-01-30   bpautosales 1.0.1 - Cross-Site Scripting / SQL Injection 0 WEB Mehmet Ince
2009-01-30   GNUBoard 4.31.04 (09.01.30) - Multiple Local/Remote Vulnerabilities 2 WEB make0day
2009-01-30   Revou Twitter Clone - Cross-Site Scripting / SQL Injection 1 WEB nuclear
2009-01-30   SalesCart - Authentication Bypass 2 WEB ByALBAYX
2009-01-29   Pligg CMS 9.9.5 - Cross-Site Request Forgery / Protection Bypass / Captcha Bypass 2 WEB Michael Brooks
2009-01-29   PLE CMS 1.0 Beta 4.2 - Blind SQL Injection 2 WEB darkjoker
2009-01-29   Netartmedia Car Portal 1.0 - Authentication Bypass 2 WEB Mehmet Ince
2009-01-29   GLPI 0.71.3 - Multiple SQL Injections Vulnerabilities 1 WEB Zigma
2009-01-29   Coppermine Photo Gallery 1.4.19 - Remote File Upload 1 WEB Michael Brooks
2009-01-29   Star Articles 6.0 - Remote Contents Change 1 WEB ByALBAYX
2009-01-29   Personal Site Manager 0.3 - Remote Command Execution 1 WEB darkjoker
2009-01-28   SmartSiteCMS 1.0 - Blind SQL Injection 1 WEB certaindeath
2009-01-28   Social Engine 3.06 - 'category_id' SQL Injection 1 WEB snakespc
2009-01-28   Max.Blog 1.0.6 - 'offline_auth.php' Offline Authentication Bypass 1 WEB Salvatore Fresta
2009-01-28   Max.Blog 1.0.6 - 'submit_post.php' SQL Injection 1 WEB Salvatore Fresta
2009-01-28   phpList 2.10.x - Remote Code Execution / Local File Inclusion 1 WEB mozi
2009-01-28   Lore 1.5.6 - 'article.php' Blind SQL Injection 2 WEB OzX
2009-01-28   Gazelle CMS 1.0 - 'template' Local File Inclusion 2 WEB fuzion
2009-01-28   Chipmunk Blog - (Authentication Bypass) Add Admin 2 WEB x0r
2009-01-28   gamescript 4.6 - Cross-Site Scripting / SQL Injection / Local File Inclusion 2 WEB Encrypt3d.M!nd
2009-01-28   Community CMS 0.4 - 'id' Blind SQL Injection 2 WEB darkjoker
2009-01-27   Pixie CMS 1.0 - Multiple Local File Inclusions 1 WEB DSecRG
2009-01-27   Max.Blog 1.0.6 - 'show_post.php' SQL Injection 2 WEB Salvatore Fresta
2009-01-27   Flax Article Manager 1.1 - Remote PHP Script Upload 2 WEB S.W.A.T.
2009-01-26   OpenX 2.6.3 - 'MAX_type' Local File Inclusion 2 WEB Charlie Briggs
2009-01-26   Joomla! Component ElearningForce Flash Magazine Deluxe - SQL Injection 2 WEB TurkGuvenligi
2009-01-26   ClickAuction - Authentication Bypass 1 WEB R3d-D3V!L
2009-01-26   SiteXS CMS 0.1.1 - Local File Inclusion 2 WEB darkjoker
2009-01-26   Groone's GLink ORGanizer - 'index.php?cat' SQL Injection 2 WEB nuclear
2009-01-26   Wazzum Dating Software - 'userid' SQL Injection 2 WEB nuclear
2009-01-26   PHP-CMS 1 - 'Username' Blind SQL Injection 2 WEB darkjoker
2009-01-26   SHOP-INET 4 - 'grid' SQL Injection 2 WEB FeDeReR
2009-01-26   Script Toko Online 5.01 - SQL Injection 2 WEB k1n9k0ng
2009-01-26   E-ShopSystem - Authentication Bypass / SQL Injection 2 WEB InjEctOr5
2009-01-26   ITLPoll 2.7 Stable2 - Blind SQL Injection 2 WEB fuzion
2009-01-26   Simple Machines Forum (SMF) 1.1.7 - Cross-Site Request Forgery / Cross-Site Scripting / Package Uplo 2 WEB Xianur0
2009-01-25   EPOLL SYSTEM 3.1 - 'Password.dat' Disclosure 1 WEB Pouya_Server
2009-01-25   OpenGoo 1.1 - Local File Inclusion 1 WEB fuzion
2009-01-25   Flax Article Manager 1.1 - 'cat_id' SQL Injection 1 WEB JIKO
2009-01-25   Web-Calendar Lite 1.0 - Authentication Bypass 2 WEB ByALBAYX
2009-01-25   Mambo Component com_sim 0.8 - Blind SQL Injection 2 WEB Mehmet Ince
2009-01-25   MemHT Portal 4.0.1 - Remote Code Execution 1 WEB StAkeR
2009-01-22   Pardal CMS 0.2.0 - Blind SQL Injection 2 WEB darkjoker
2009-01-22   asp-project 1.0 - Insecure Cookie Method 2 WEB Khashayar Fereidani
2009-01-22   OwnRS Blog 1.2 - 'autor.php' SQL Injection 2 WEB nuclear
2009-01-21   Joomla! Component beamospetition 1.0.12 - SQL Injection / Cross-Site Scripting 2 WEB vds_s
2009-01-21   Joomla! Component com_pcchess - Blind SQL Injection 2 WEB InjEctOr5
2009-01-21   Sad Raven's Click Counter 1.0 - 'passwd.dat' File Disclosure 1 WEB Pouya_Server
2009-01-21   Mambo Component SOBI2 RC 2.8.2 - SQL Injection 1 WEB Br1ght D@rk
2009-01-21   Joomla! Component Com BazaarBuilder Shopping Cart 5.0 - SQL Injection 1 WEB XaDoS
2009-01-20   Dodo's Quiz Script 1.1 - Local File Inclusion 1 WEB Stack
2009-01-20   LinPHA Photo Gallery 2.0 - Remote Command Execution 0 WEB Osirys
2009-01-20   AJ Auction Pro OOPD 2.3 - 'id' SQL Injection 1 WEB snakespc
2009-01-20   Max.Blog 1.0.6 - Arbitrary Delete Post 1 WEB SirGod
2009-01-19   Ninja Blog 4.8 - Cross-Site Request Forgery/HTML Injection 1 WEB Danny Moules
2009-01-19   Joomla! Component com_waticketsystem - Blind SQL Injection 1 WEB InjEctOr5
2009-01-19   phpads 2.0 - Multiple Vulnerabilities 2 WEB Danny Moules
2009-01-19   Ninja Blog 4.8 - Remote Information Disclosure 2 WEB Danny Moules
2009-01-19   RCBlog 1.03 - Authentication Bypass 2 WEB Danny Moules
2009-01-19   Gallery Kys 1.0 - Admin Password Disclosure / Persistent Cross-Site Scripting 2 WEB Osirys
2009-01-19   Joomla! Component com_news - SQL Injection 2 WEB snakespc
2009-01-19   Joomla! Component com_pccookbook - 'recipe_id' Blind SQL Injection 2 WEB InjEctOr5
2009-01-19   Fhimage 1.2.1 - Remote Command Execution (mq = off) 2 WEB Osirys
2009-01-19   Fhimage 1.2.1 - Remote Index Change 2 WEB Osirys
2009-01-18   ESPG (Enhanced Simple PHP Gallery) 1.72 - File Disclosure 2 WEB bd0rk
2009-01-18   SCMS 1 - Local File Inclusion 1 WEB ahmadbady
2009-01-18   Click&Email - Authentication Bypass 1 WEB SuB-ZeRo
2009-01-18   DS-IPN.NET Digital Sales IPN - Database Disclosure 0 WEB Moudi
2009-01-18   Joomla! Component Gigcal 1.x - 'id' SQL Injection 1 WEB Lanti-Net
2009-01-16   BibCiter 1.4 - Multiple SQL Injections 1 WEB nuclear
2009-01-16   Simple PHP NewsLetter 1.5 - Local File Inclusion 1 WEB ahmadbady
2009-01-16   Aj Classifieds For Sale 3.0 - Arbitrary File Upload 1 WEB ZoRLu
2009-01-16   Aj Classifieds Personals 3.0 - Arbitrary File Upload 0 WEB ZoRLu
2009-01-16   Aj Classifieds Real Estate 3.0 - Arbitrary File Upload 1 WEB ZoRLu
2009-01-16   ASP ActionCalendar 1.3 - Authentication Bypass 1 WEB SuB-ZeRo
2009-01-16   blogit! - SQL Injection / File Disclosure / Cross-Site Scripting 1 WEB Pouya_Server
2009-01-16   Rankem - File Disclosure / Cross-Site Scripting / Cookie 1 WEB Pouya_Server
2009-01-16   Ping IP - Authentication Bypass 1 WEB ByALBAYX
2009-01-16   The Walking Club - Authentication Bypass 1 WEB ByALBAYX
2009-01-16   eReservations - Authentication Bypass 1 WEB ByALBAYX
2009-01-16   eFAQ - Authentication Bypass 1 WEB ByALBAYX