2009-02-05
|
|
txtBB 1.0 RC3 - HTML/JS Injection / Arbitrary Add Admin Privileges
|
1 |
WEB
|
cOndemned
|
2009-02-05
|
|
ClearBudget 0.6.1 - Insecure Database Disclosure
|
1 |
WEB
|
Room-Hacker
|
2009-02-05
|
|
Kipper 2.01 - Cross-Site Scripting / Local File Inclusion / File Disclosure
|
1 |
WEB
|
RoMaNcYxHaCkEr
|
2009-02-05
|
|
ClearBudget 0.6.1 - Insecure Cookie Handling / Local File Inclusion
|
1 |
WEB
|
SirGod
|
2009-02-04
|
|
GR Note 0.94 Beta - (Authentication Bypass) Remote Database Backup
|
1 |
WEB
|
JosS
|
2009-02-04
|
|
gr blog 1.1.4 - Arbitrary File Upload / Authentication Bypass
|
0 |
WEB
|
JosS
|
2009-02-04
|
|
YapBB 1.2 - 'forumID' Blind SQL Injection
|
0 |
WEB
|
darkjoker
|
2009-02-04
|
|
team 1.x - File Disclosure / Cross-Site Scripting
|
0 |
WEB
|
Pouya_Server
|
2009-02-04
|
|
Power System Of Article Management 3.0 - File Disclosure / Cross-Site Scripting
|
0 |
WEB
|
Pouya_Server
|
2009-02-04
|
|
PHPbbBook 1.3 - 'bbcode.php?l' Local File Inclusion
|
0 |
WEB
|
Osirys
|
2009-02-04
|
|
GRBoard 1.8 - Multiple Remote File Inclusions
|
0 |
WEB
|
make0day
|
2009-02-04
|
|
rgboard 4 5p1 (07.07.27) - Multiple Vulnerabilities
|
0 |
WEB
|
make0day
|
2009-02-04
|
|
Syntax Desktop 2.7 - 'synTarget' Local File Inclusion
|
0 |
WEB
|
ahmadbady
|
2009-02-04
|
|
Jaws 0.8.8 - Multiple Local File Inclusions
|
0 |
WEB
|
fuzion
|
2009-02-03
|
|
OpenFiler 2.3 - (Authentication Bypass) Remote Password Change
|
2 |
WEB
|
nonroot
|
2009-02-03
|
|
Flatnux 2009-01-27 - Remote File Inclusion
|
2 |
WEB
|
Alfons Luja
|
2009-02-03
|
|
DreamPics Photo/Video Gallery - Blind SQL Injection
|
1 |
WEB
|
Mehmet Ince
|
2009-02-03
|
|
TxtBlog 1.0 Alpha - Remote Command Execution
|
2 |
WEB
|
Osirys
|
2009-02-03
|
|
Technote 7.2 - Remote File Inclusion
|
2 |
WEB
|
make0day
|
2009-02-03
|
|
4Site CMS 2.6 - Multiple SQL Injections
|
2 |
WEB
|
D.Mortalov
|
2009-02-03
|
|
MyDesing Sayac 2.0 - Authentication Bypass
|
2 |
WEB
|
Kacak
|
2009-02-03
|
|
WEBalbum 2.4b - 'id' Blind SQL Injection
|
1 |
WEB
|
Mehmet Ince
|
2009-02-03
|
|
AJA Modules Rapidshare 1.0.0 - Arbitrary File Upload
|
2 |
WEB
|
Hussin X
|
2009-02-03
|
|
Simple Machines Forum (SMF) - 'BBCode' Cookie Stealing
|
2 |
WEB
|
Xianur0
|
2009-02-03
|
|
Online Grades 3.2.4 - Authentication Bypass
|
0 |
WEB
|
x0r
|
2009-02-03
|
|
groone's Guestbook 2.0 - Remote File Inclusion
|
0 |
WEB
|
k3vin mitnick
|
2009-02-03
|
|
groone glinks 2.1 - Remote File Inclusion
|
0 |
WEB
|
k3vin mitnick
|
2009-02-03
|
|
ClickCart 6.0 - Authentication Bypass
|
0 |
WEB
|
R3d-D3V!L
|
2009-02-03
|
|
WholeHogSoftware Password Protect - Insecure Cookie Handling
|
0 |
WEB
|
Stack
|
2009-02-03
|
|
WholeHogSoftware Ware Support - Insecure Cookie Handling
|
0 |
WEB
|
Stack
|
2009-02-02
|
|
OpenHelpDesk 1.0.100 - 'eval()' Code Execution (Metasploit)
|
0 |
WEB
|
LSO
|
2009-02-02
|
|
PHPSlash 0.8.1.1 - Remote Code Execution
|
0 |
WEB
|
DarkFig
|
2009-02-02
|
|
eVision CMS 2.0 - Remote Code Execution
|
0 |
WEB
|
Osirys
|
2009-02-02
|
|
sourdough 0.3.5 - Remote File Inclusion
|
0 |
WEB
|
ahmadbady
|
2009-02-02
|
|
CMS Mini 0.2.2 - Remote Command Execution
|
0 |
WEB
|
darkjoker
|
2009-02-02
|
|
phpBLASTER 1.0 RC1 - Blind SQL Injection
|
0 |
WEB
|
darkjoker
|
2009-02-02
|
|
WholeHogSoftware Password Protect - Authentication Bypass
|
1 |
WEB
|
ByALBAYX
|
2009-02-02
|
|
WholeHogSoftware Ware Support - Authentication Bypass
|
0 |
WEB
|
ByALBAYX
|
2009-02-02
|
|
AJA Portal 1.2 (Windows) - Local File Inclusion
|
0 |
WEB
|
ahmadbady
|
2009-02-02
|
|
Flatnux 2009-01-27 - Cross-Site Scripting / Iframe Injection
|
0 |
WEB
|
Alfons Luja
|
2009-02-02
|
|
sma-db 0.3.12 - Remote File Inclusion / Cross-Site Scripting
|
0 |
WEB
|
ahmadbady
|
2009-01-30
|
|
eVision CMS 2.0 - SQL Injection
|
1 |
WEB
|
darkjoker
|
2009-01-30
|
|
SkaLinks 1.5 - Authentication Bypass
|
0 |
WEB
|
Dimi4
|
2009-01-30
|
|
Orca 2.0.2 - 'topic ' Cross-Site Scripting
|
2 |
WEB
|
J-Hacker
|
2009-01-30
|
|
bpautosales 1.0.1 - Cross-Site Scripting / SQL Injection
|
0 |
WEB
|
Mehmet Ince
|
2009-01-30
|
|
GNUBoard 4.31.04 (09.01.30) - Multiple Local/Remote Vulnerabilities
|
2 |
WEB
|
make0day
|
2009-01-30
|
|
Revou Twitter Clone - Cross-Site Scripting / SQL Injection
|
1 |
WEB
|
nuclear
|
2009-01-30
|
|
SalesCart - Authentication Bypass
|
2 |
WEB
|
ByALBAYX
|
2009-01-29
|
|
Pligg CMS 9.9.5 - Cross-Site Request Forgery / Protection Bypass / Captcha Bypass
|
2 |
WEB
|
Michael Brooks
|
2009-01-29
|
|
PLE CMS 1.0 Beta 4.2 - Blind SQL Injection
|
2 |
WEB
|
darkjoker
|
2009-01-29
|
|
Netartmedia Car Portal 1.0 - Authentication Bypass
|
2 |
WEB
|
Mehmet Ince
|
2009-01-29
|
|
GLPI 0.71.3 - Multiple SQL Injections Vulnerabilities
|
1 |
WEB
|
Zigma
|
2009-01-29
|
|
Coppermine Photo Gallery 1.4.19 - Remote File Upload
|
1 |
WEB
|
Michael Brooks
|
2009-01-29
|
|
Star Articles 6.0 - Remote Contents Change
|
1 |
WEB
|
ByALBAYX
|
2009-01-29
|
|
Personal Site Manager 0.3 - Remote Command Execution
|
1 |
WEB
|
darkjoker
|
2009-01-28
|
|
SmartSiteCMS 1.0 - Blind SQL Injection
|
1 |
WEB
|
certaindeath
|
2009-01-28
|
|
Social Engine 3.06 - 'category_id' SQL Injection
|
1 |
WEB
|
snakespc
|
2009-01-28
|
|
Max.Blog 1.0.6 - 'offline_auth.php' Offline Authentication Bypass
|
1 |
WEB
|
Salvatore Fresta
|
2009-01-28
|
|
Max.Blog 1.0.6 - 'submit_post.php' SQL Injection
|
1 |
WEB
|
Salvatore Fresta
|
2009-01-28
|
|
phpList 2.10.x - Remote Code Execution / Local File Inclusion
|
1 |
WEB
|
mozi
|
2009-01-28
|
|
Lore 1.5.6 - 'article.php' Blind SQL Injection
|
2 |
WEB
|
OzX
|
2009-01-28
|
|
Gazelle CMS 1.0 - 'template' Local File Inclusion
|
2 |
WEB
|
fuzion
|
2009-01-28
|
|
Chipmunk Blog - (Authentication Bypass) Add Admin
|
2 |
WEB
|
x0r
|
2009-01-28
|
|
gamescript 4.6 - Cross-Site Scripting / SQL Injection / Local File Inclusion
|
2 |
WEB
|
Encrypt3d.M!nd
|
2009-01-28
|
|
Community CMS 0.4 - 'id' Blind SQL Injection
|
2 |
WEB
|
darkjoker
|
2009-01-27
|
|
Pixie CMS 1.0 - Multiple Local File Inclusions
|
1 |
WEB
|
DSecRG
|
2009-01-27
|
|
Max.Blog 1.0.6 - 'show_post.php' SQL Injection
|
2 |
WEB
|
Salvatore Fresta
|
2009-01-27
|
|
Flax Article Manager 1.1 - Remote PHP Script Upload
|
2 |
WEB
|
S.W.A.T.
|
2009-01-26
|
|
OpenX 2.6.3 - 'MAX_type' Local File Inclusion
|
2 |
WEB
|
Charlie Briggs
|
2009-01-26
|
|
Joomla! Component ElearningForce Flash Magazine Deluxe - SQL Injection
|
2 |
WEB
|
TurkGuvenligi
|
2009-01-26
|
|
ClickAuction - Authentication Bypass
|
1 |
WEB
|
R3d-D3V!L
|
2009-01-26
|
|
SiteXS CMS 0.1.1 - Local File Inclusion
|
2 |
WEB
|
darkjoker
|
2009-01-26
|
|
Groone's GLink ORGanizer - 'index.php?cat' SQL Injection
|
2 |
WEB
|
nuclear
|
2009-01-26
|
|
Wazzum Dating Software - 'userid' SQL Injection
|
2 |
WEB
|
nuclear
|
2009-01-26
|
|
PHP-CMS 1 - 'Username' Blind SQL Injection
|
2 |
WEB
|
darkjoker
|
2009-01-26
|
|
SHOP-INET 4 - 'grid' SQL Injection
|
2 |
WEB
|
FeDeReR
|
2009-01-26
|
|
Script Toko Online 5.01 - SQL Injection
|
2 |
WEB
|
k1n9k0ng
|
2009-01-26
|
|
E-ShopSystem - Authentication Bypass / SQL Injection
|
2 |
WEB
|
InjEctOr5
|
2009-01-26
|
|
ITLPoll 2.7 Stable2 - Blind SQL Injection
|
2 |
WEB
|
fuzion
|
2009-01-26
|
|
Simple Machines Forum (SMF) 1.1.7 - Cross-Site Request Forgery / Cross-Site Scripting / Package Uplo
|
2 |
WEB
|
Xianur0
|
2009-01-25
|
|
EPOLL SYSTEM 3.1 - 'Password.dat' Disclosure
|
1 |
WEB
|
Pouya_Server
|
2009-01-25
|
|
OpenGoo 1.1 - Local File Inclusion
|
1 |
WEB
|
fuzion
|
2009-01-25
|
|
Flax Article Manager 1.1 - 'cat_id' SQL Injection
|
1 |
WEB
|
JIKO
|
2009-01-25
|
|
Web-Calendar Lite 1.0 - Authentication Bypass
|
2 |
WEB
|
ByALBAYX
|
2009-01-25
|
|
Mambo Component com_sim 0.8 - Blind SQL Injection
|
2 |
WEB
|
Mehmet Ince
|
2009-01-25
|
|
MemHT Portal 4.0.1 - Remote Code Execution
|
1 |
WEB
|
StAkeR
|
2009-01-22
|
|
Pardal CMS 0.2.0 - Blind SQL Injection
|
2 |
WEB
|
darkjoker
|
2009-01-22
|
|
asp-project 1.0 - Insecure Cookie Method
|
2 |
WEB
|
Khashayar Fereidani
|
2009-01-22
|
|
OwnRS Blog 1.2 - 'autor.php' SQL Injection
|
2 |
WEB
|
nuclear
|
2009-01-21
|
|
Joomla! Component beamospetition 1.0.12 - SQL Injection / Cross-Site Scripting
|
2 |
WEB
|
vds_s
|
2009-01-21
|
|
Joomla! Component com_pcchess - Blind SQL Injection
|
2 |
WEB
|
InjEctOr5
|
2009-01-21
|
|
Sad Raven's Click Counter 1.0 - 'passwd.dat' File Disclosure
|
1 |
WEB
|
Pouya_Server
|
2009-01-21
|
|
Mambo Component SOBI2 RC 2.8.2 - SQL Injection
|
1 |
WEB
|
Br1ght D@rk
|
2009-01-21
|
|
Joomla! Component Com BazaarBuilder Shopping Cart 5.0 - SQL Injection
|
1 |
WEB
|
XaDoS
|
2009-01-20
|
|
Dodo's Quiz Script 1.1 - Local File Inclusion
|
1 |
WEB
|
Stack
|
2009-01-20
|
|
LinPHA Photo Gallery 2.0 - Remote Command Execution
|
0 |
WEB
|
Osirys
|
2009-01-20
|
|
AJ Auction Pro OOPD 2.3 - 'id' SQL Injection
|
1 |
WEB
|
snakespc
|
2009-01-20
|
|
Max.Blog 1.0.6 - Arbitrary Delete Post
|
1 |
WEB
|
SirGod
|
2009-01-19
|
|
Ninja Blog 4.8 - Cross-Site Request Forgery/HTML Injection
|
1 |
WEB
|
Danny Moules
|
2009-01-19
|
|
Joomla! Component com_waticketsystem - Blind SQL Injection
|
1 |
WEB
|
InjEctOr5
|
2009-01-19
|
|
phpads 2.0 - Multiple Vulnerabilities
|
2 |
WEB
|
Danny Moules
|
2009-01-19
|
|
Ninja Blog 4.8 - Remote Information Disclosure
|
2 |
WEB
|
Danny Moules
|
2009-01-19
|
|
RCBlog 1.03 - Authentication Bypass
|
2 |
WEB
|
Danny Moules
|
2009-01-19
|
|
Gallery Kys 1.0 - Admin Password Disclosure / Persistent Cross-Site Scripting
|
2 |
WEB
|
Osirys
|
2009-01-19
|
|
Joomla! Component com_news - SQL Injection
|
2 |
WEB
|
snakespc
|
2009-01-19
|
|
Joomla! Component com_pccookbook - 'recipe_id' Blind SQL Injection
|
2 |
WEB
|
InjEctOr5
|
2009-01-19
|
|
Fhimage 1.2.1 - Remote Command Execution (mq = off)
|
2 |
WEB
|
Osirys
|
2009-01-19
|
|
Fhimage 1.2.1 - Remote Index Change
|
2 |
WEB
|
Osirys
|
2009-01-18
|
|
ESPG (Enhanced Simple PHP Gallery) 1.72 - File Disclosure
|
2 |
WEB
|
bd0rk
|
2009-01-18
|
|
SCMS 1 - Local File Inclusion
|
1 |
WEB
|
ahmadbady
|
2009-01-18
|
|
Click&Email - Authentication Bypass
|
1 |
WEB
|
SuB-ZeRo
|
2009-01-18
|
|
DS-IPN.NET Digital Sales IPN - Database Disclosure
|
0 |
WEB
|
Moudi
|
2009-01-18
|
|
Joomla! Component Gigcal 1.x - 'id' SQL Injection
|
1 |
WEB
|
Lanti-Net
|
2009-01-16
|
|
BibCiter 1.4 - Multiple SQL Injections
|
1 |
WEB
|
nuclear
|
2009-01-16
|
|
Simple PHP NewsLetter 1.5 - Local File Inclusion
|
1 |
WEB
|
ahmadbady
|
2009-01-16
|
|
Aj Classifieds For Sale 3.0 - Arbitrary File Upload
|
1 |
WEB
|
ZoRLu
|
2009-01-16
|
|
Aj Classifieds Personals 3.0 - Arbitrary File Upload
|
0 |
WEB
|
ZoRLu
|
2009-01-16
|
|
Aj Classifieds Real Estate 3.0 - Arbitrary File Upload
|
1 |
WEB
|
ZoRLu
|
2009-01-16
|
|
ASP ActionCalendar 1.3 - Authentication Bypass
|
1 |
WEB
|
SuB-ZeRo
|
2009-01-16
|
|
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
|
1 |
WEB
|
Pouya_Server
|
2009-01-16
|
|
Rankem - File Disclosure / Cross-Site Scripting / Cookie
|
1 |
WEB
|
Pouya_Server
|
2009-01-16
|
|
Ping IP - Authentication Bypass
|
1 |
WEB
|
ByALBAYX
|
2009-01-16
|
|
The Walking Club - Authentication Bypass
|
1 |
WEB
|
ByALBAYX
|
2009-01-16
|
|
eReservations - Authentication Bypass
|
1 |
WEB
|
ByALBAYX
|
2009-01-16
|
|
eFAQ - Authentication Bypass
|
1 |
WEB
|
ByALBAYX
|