Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2008-12-12   ColdFusion Scripts Red_Reservations - Database Disclosure 1 WEB Cyber-Zone
2008-12-12   Umer Inc Songs Portal Script - 'id' SQL Injection 1 WEB InjEctOr5
2008-12-12   VP-ASP Shopping Cart 6.50 - Database Disclosure 0 WEB Dxil
2008-12-12   Moodle 1.9.3 - Remote Code Execution 0 WEB USH
2008-12-12   the net guys aspired2blog - SQL Injection / File Disclosure 0 WEB Pouya_Server
2008-12-12   Social Groupie - 'create_album.php' Arbitrary File Upload 1 WEB InjEctOr5
2008-12-12   Wysi Wiki Wyg 1.0 - Remote Password Retrieve 1 WEB StAkeR
2008-12-12   Social Groupie - 'id' SQL Injection 1 WEB InjEctOr5
2008-12-12   Xpoze 4.10 - 'menu' Blind SQL Injection 1 WEB XaDoS
2008-12-12   SUMON 0.7.0 - Command Execution 1 WEB dun
2008-12-12   ASP-CMS 1.0 - 'cha' SQL Injection 1 WEB Khashayar Fereidani
2008-12-12   The Net Guys ASPired2Protect - Database Disclosure 1 WEB AlpHaNiX
2008-12-11   The Net Guys ASPired2Poll - Remote Database Disclosure 1 WEB AlpHaNiX
2008-12-11   PHP Support Tickets 2.2 - Arbitrary File Upload 0 WEB ahmadbady
2008-12-11   Banner Exchange Java - Authentication Bypass 0 WEB R3d-D3V!L
2008-12-11   Ad Management Java - Authentication Bypass 0 WEB R3d-D3V!L
2008-12-11   Affiliate Software Java 4.0 - Authentication Bypass 0 WEB R3d-D3V!L
2008-12-11   Feed CMS 1.07.03.19b - 'lang' Local File Inclusion 0 WEB x0r
2008-12-11   EZ Publish 3.9.0/3.9.5/3.10.1 - Command Execution (Admin Required) 0 WEB s4avrd0w
2008-12-11   MyCal Personal Events Calendar - Database Disclosure 0 WEB CoBRa_21
2008-12-11   evCal Events Calendar - Database Disclosure 0 WEB Cyber-Zone
2008-12-11   PhpAddEdit 1.3 - 'cookie' Authentication Bypass 0 WEB x0r
2008-12-10   phpAddEdit 1.3 - 'editform' Local File Inclusion 0 WEB nuclear
2008-12-10   CF_Forum - Blind SQL Injection 0 WEB AlpHaNiX
2008-12-10   CFMBLOG - 'categorynbr' Blind SQL Injection 0 WEB AlpHaNiX
2008-12-10   CF_Auction - Blind SQL Injection 0 WEB AlpHaNiX
2008-12-10   CF_Calendar - 'calendarevent.cfm' SQL Injection 1 WEB AlpHaNiX
2008-12-10   cf shopkart 5.2.2 - SQL Injection / File Disclosure 1 WEB AlpHaNiX
2008-12-10   Butterfly ORGanizer 2.0.1 - 'id' SQL Injection 1 WEB Osirys
2008-12-10   Pro Chat Rooms 3.0.2 - Cross-Site Scripting / Cross-Site Request Forgery 1 WEB ZynbER
2008-12-10   living Local 1.1 - Cross-Site Scripting / Arbitrary File Upload 1 WEB Bgh7
2008-12-10   WebMaster Marketplace - SQL Injection 1 WEB Hussin X
2008-12-10   EZ Publish < 3.9.5/3.10.1/4.0.1 - Privilege Escalation 1 WEB s4avrd0w
2008-12-10   HTMPL 1.11 - Command Execution 2 WEB ZeN
2008-12-09   PHP Multiple Newsletters 2.7 - Local File Inclusion / Cross-Site Scripting 1 WEB ahmadbady
2008-12-09   PHPmyGallery 1.5beta - '/common-tpl-vars.php' Local/Remote File Inclusion 2 WEB CoBRa_21
2008-12-09   postecards - SQL Injection / File Disclosure 1 WEB AlpHaNiX
2008-12-09   ProQuiz 1.0 - Authentication Bypass 2 WEB Osirys
2008-12-09   Netref 4.0 - Multiple SQL Injections 1 WEB SuB-ZeRo
2008-12-09   Peel Shopping 3.1 - 'rubid' SQL Injection 1 WEB SuB-ZeRo
2008-12-09   PHPmyGallery 1.0beta2 - Local/Remote File Inclusion 2 WEB ZoRLu
2008-12-09   Poll Pro 2.0 - Authentication Bypass 2 WEB AlpHaNiX
2008-12-09   Professional Download Assistant 0.1 - Authentication Bypass 2 WEB ZoRLu
2008-12-08   webcaf 1.4 - Local File Inclusion / Remote Code Execution 2 WEB dun
2008-12-08   phpBB 3 - Mod Tag Board 4 Blind SQL Injection 2 WEB StAkeR
2008-12-08   vBulletin Secure Downloads 2.0.0r - SQL Injection 2 WEB Cnaph
2008-12-08   Simple Directory Listing 2 - Cross-Site Arbitrary File Upload 2 WEB Michael Brooks
2008-12-08   phpMyAdmin 3.1.0 - Cross-Site Request Forgery / SQL Injection 2 WEB Michael Brooks
2008-12-08   siu guarani - Multiple Vulnerabilities 1 WEB Ubik & proudhon
2008-12-08   XOOPS 2.3.1 - Multiple Local File Inclusions 1 WEB DSecRG
2008-12-08   MG2 0.5.1 - 'filename' Remote Code Execution 1 WEB Alfons Luja
2008-12-07   asp talk - SQL Injection / Cross-Site Scripting 1 WEB Bl@ckbe@rD
2008-12-07   PHPmyGallery Gold 1.51 - 'index.php' Directory Traversal 1 WEB zAx
2008-12-07   QMail Mailing List Manager 1.2 - Database Disclosure 1 WEB Ghost Hacker
2008-12-07   Mini-CMS 1.0.1 - 'index.php' Local File Inclusion 1 WEB cOndemned
2008-12-07   Mini Blog 1.0.1 - 'index.php' Multiple Local File Inclusions 1 WEB cOndemned
2008-12-07   aspmanage banners - Arbitrary File Upload / File Disclosure 1 WEB ZoRLu
2008-12-07   Ikon ADManager 2.1 - Remote Database Disclosure 1 WEB Ghost Hacker
2008-12-07   Professional Download Assistant 0.1 - Database Disclosure 1 WEB Ghost Hacker
2008-12-07   Natterchat 1.12 - Database Disclosure 1 WEB AlpHaNiX
2008-12-07   w3blabor CMS 3.0.5 - Arbitrary File Upload / Local File Inclusion 1 WEB DNX
2008-12-07   Product Sale Framework 0.1b - SQL Injection 1 WEB b3hz4d
2008-12-07   PayPal eStore - Admin Password Change 2 WEB G4N0K
2008-12-07   Bonza Cart 1.10 - Admin Password Changing 0 WEB G4N0K
2008-12-07   DL PayCart 1.34 - Admin Password Changing 2 WEB G4N0K
2008-12-07   IPNPro3 < 1.44 - Admin Password Changing 1 WEB G4N0K
2008-12-06   phpPgAdmin 4.2.1 - '_language' Local File Inclusion 1 WEB dun
2008-12-06   ASP PORTAL - Remote Database Disclosure 1 WEB ZoRLu
2008-12-06   ASP AutoDealer - Remote Database Disclosure 1 WEB ZoRLu
2008-12-05   ASPTicker 1.0 - Remote Database Disclosure 1 WEB ZoRLu
2008-12-05   ASP Portal - Multiple SQL Injections 1 WEB AlpHaNiX
2008-12-05   ASP AutoDealer - SQL Injection / File Disclosure 1 WEB AlpHaNiX
2008-12-05   Tizag Countdown Creator 3 - Insecure Upload 1 WEB ahmadbady
2008-12-05   Cold BBS - Remote Database Disclosure 1 WEB ahmadbady
2008-12-05   Merlix Teamworx Server - File Disclosure/Bypass 1 WEB ZoRLu
2008-12-05   nightfall personal diary 1.0 - Cross-Site Scripting / File Disclosure 0 WEB AlpHaNiX
2008-12-05   Rankem - Authentication Bypass 0 WEB AlpHaNiX
2008-12-05   RankEm - 'siteID' SQL Injection 0 WEB AlpHaNiX
2008-12-05   merlix educate servert - Authentication Bypass / File Disclosure 0 WEB ZoRLu
2008-12-05   Multiple Membership Script 2.5 - 'id' SQL Injection 0 WEB ViRuS_HaCkErS
2008-12-04   BNCwi 1.04 - Local File Inclusion 1 WEB dun
2008-12-04   Gravity GTD 0.4.5 - Local File Inclusion / Remote Code Execution 1 WEB dun
2008-12-04   Joomla! Component mydyngallery 1.4.2 - SQL Injection 1 WEB Khashayar Fereidani
2008-12-04   My Simple Forum 3.0 - Local File Inclusion 1 WEB cOndemned
2008-12-04   lcxbbportal 0.1 alpha 2 - Remote File Inclusion 1 WEB NoGe
2008-12-04   Easy News Content Management - Database Disclosure 1 WEB BeyazKurt
2008-12-04   template creature - SQL Injection / File Disclosure 1 WEB ZoRLu
2008-12-04   User Engine Lite ASP - 'users.mdb' Database Disclosure 1 WEB AlpHaNiX
2008-12-04   wbstreet 1.0 - SQL Injection / File Disclosure 1 WEB CWH Underground
2008-12-04   ccTiddly 1.7.4 - 'cct_base' Remote File Inclusion 1 WEB cOndemned
2008-12-03   Multi SEO phpBB 1.1.0 - Remote File Inclusion 1 WEB NoGe
2008-12-03   Rae Media Contact MS - Authentication Bypass 2 WEB b3hz4d
2008-12-03   ASP User Engine .NET - Remote Database Disclosure 2 WEB AlpHaNiX
2008-12-03   Joomla! Component JMovies 1.1 - 'id' SQL Injection 1 WEB StAkeR
2008-12-03   Check New 4.52 - SQL Injection 2 WEB CWH Underground
2008-12-03   Calendar MX Professional 2.0.0 - Blind SQL Injection 2 WEB R3d-D3V!L
2008-12-03   Gallery MX 2.0.0 - Blind SQL Injection 0 WEB R3d-D3V!L
2008-12-02   Codefixer MailingListPro - Database Disclosure 0 WEB AlpHaNiX
2008-12-02   Rapid Classified 3.1 - Database Disclosure 1 WEB CoBRa_21
2008-12-02   SunByte e-Flower - 'id' SQL Injection 1 WEB w4rl0ck
2008-12-02   CMS MAXSITE Component Guestbook - Remote Command Execution 1 WEB CWH Underground
2008-12-02   Ocean12 Mailing List Manager Gold - File Disclosure / SQL Injection / Cross-Site Scripting 1 WEB Pouya_Server
2008-12-01   PacPoll 4.0 - Database Disclosure 1 WEB AlpHaNiX
2008-12-01   bcoos 1.0.13 - 'viewcat.php' SQL Injection 2 WEB CWH Underground
2008-12-01   ASPPortal 3.2.5 - Database Disclosure 2 WEB CWH Underground
2008-12-01   E.Z. Poll 2 - Authentication Bypass 2 WEB t0fx
2008-12-01   Andy's PHP KnowledgeBase 0.92.9 - Arbitrary File Upload 2 WEB CWH Underground
2008-12-01   z1exchange 1.0 - 'site' SQL Injection 2 WEB JIKO
2008-11-30   Broadcast Machine 0.1 - Multiple Remote File Inclusions 1 WEB NoGe
2008-11-30   CPCommerce 1.2.6 - URL Rewrite Input Variable Overwrite / Authentication Bypass 1 WEB girex
2008-11-30   minimal ablog 0.4 - SQL Injection / Arbitrary File Upload / Authentication Bypass 1 WEB NoGe
2008-11-30   KTP Computer Customer Database CMS 1.0 - Blind SQL Injection 1 WEB CWH Underground
2008-11-30   KTP Computer Customer Database CMS 1.0 - Local File Inclusion 1 WEB CWH Underground
2008-11-30   Quick Tree View .NET 3.1 - Database Disclosure 2 WEB Cyber-Zone
2008-11-30   Active Business Directory 2 - Blind SQL Injection 2 WEB AlpHaNiX
2008-11-30   Active Time Billing 3.2 - Authentication Bypass 2 WEB AlpHaNiX
2008-11-30   Active Photo Gallery 6.2 - Authentication Bypass 2 WEB R3d-D3V!L
2008-11-30   Active Web Helpdesk 2 - 'categoryId' Blind SQL Injection 2 WEB Cyber-Zone
2008-11-29   Active Test 2.1 - 'QuizID' Blind SQL Injection 2 WEB R3d-D3V!L
2008-11-29   Lito Lite CMS - 'cid' SQL Injection 1 WEB CWH Underground
2008-11-29   Active Web Helpdesk 2 - Authentication Bypass 1 WEB Cyber-Zone
2008-11-29   ASPThai.Net Forum 8.5 - Remote Database Disclosure 1 WEB CWH Underground
2008-11-29   OpenForum 0.66 Beta - Remote Reset Admin Password 1 WEB CWH Underground
2008-11-29   Active Bids 3.5 - 'itemID' Blind SQL Injection 1 WEB Stack
2008-11-30   Active Price Comparison 4 - 'ProductID' Blind SQL Injection 1 WEB R3d-D3V!L