|
2006-06-20
|
|
Ultimate PHP Board 1.96 GOLD - Multiple Vulnerabilities
|
7 |
WEB
|
Michael Brooks
|
|
2006-06-19
|
|
ASP Stats Generator 2.1.1 - SQL Injection
|
7 |
WEB
|
Hamid Ebadi
|
|
2006-06-19
|
|
WeBBoA Host Script 1.1 - SQL Injection
|
6 |
WEB
|
EntriKa
|
|
2006-06-19
|
|
Micro CMS 0.3.5 - 'microcms_path' Remote File Inclusion
|
8 |
WEB
|
CeNGiZ-HaN
|
|
2006-06-19
|
|
IdeaBox 1.1 - 'gorumDir' Remote File Inclusion
|
7 |
WEB
|
Kacper
|
|
2006-06-18
|
|
PHP Live Helper 1.x - 'abs_path' Remote File Inclusion
|
7 |
WEB
|
SnIpEr_SA
|
|
2006-06-18
|
|
Indexu 5.0.1 - 'admin_template_path' Remote File Inclusion
|
9 |
WEB
|
CrAsh_oVeR_rIdE
|
|
2006-06-17
|
|
Ad Manager Pro 2.6 - 'ipath' Remote File Inclusion
|
8 |
WEB
|
Basti
|
|
2006-06-17
|
|
Joomla! 1.0.9 - 'Weblinks' Blind SQL Injection
|
10 |
WEB
|
rgod
|
|
2006-06-17
|
|
FlashBB 1.1.8 - 'phpbb_root_path' Remote File Inclusion
|
8 |
WEB
|
h4ntu
|
|
2006-06-17
|
|
Mambo 4.6rc1 - Weblinks Blind SQL Injection (1)
|
8 |
WEB
|
rgod
|
|
2006-06-16
|
|
CMS Faethon 1.3.2 - 'mainpath' Remote File Inclusion
|
8 |
WEB
|
K-159
|
|
2006-06-15
|
|
Bitweaver 1.3 - 'tmpImagePath' Attachment mod_mime
|
9 |
WEB
|
rgod
|
|
2006-06-15
|
|
DeluxeBB 1.06 - 'templatefolder' Remote File Inclusion
|
9 |
WEB
|
Andreas Sandblad
|
|
2006-06-14
|
|
Content-Builder (CMS) 0.7.2 - Multiple Include Vulnerabilities
|
8 |
WEB
|
Kacper
|
|
2006-06-14
|
|
PHP Blue Dragon CMS 2.9.1 - 'template.php' File Inclusion
|
8 |
WEB
|
Federico Fazzi
|
|
2006-06-14
|
|
The Bible Portal Project 2.12 - 'destination' File Inclusion
|
9 |
WEB
|
Kacper
|
|
2006-06-13
|
|
MyBulletinBoard (MyBB) < 1.1.3 - Remote Code Execution
|
8 |
WEB
|
Javier Olascoaga
|
|
2006-06-13
|
|
Minerva 2.0.8a Build 237 - 'phpbb_root_path' File Inclusion
|
9 |
WEB
|
Kacper
|
|
2006-06-13
|
|
aWebNews 1.5 - 'visview.php' Remote File Inclusion
|
8 |
WEB
|
SpC-x
|
|
2006-06-12
|
|
DCP-Portal 6.1.x - 'root' Remote File Inclusion
|
8 |
WEB
|
Federico Fazzi
|
|
2006-06-12
|
|
blur6ex 0.3.462 - 'ID' Admin Disclosure / Blind SQL Injection
|
8 |
WEB
|
rgod
|
|
2006-06-11
|
|
Content-Builder (CMS) 0.7.5 - Multiple Include Vulnerabilities
|
10 |
WEB
|
Federico Fazzi
|
|
2006-06-11
|
|
AWF CMS 1.11 - 'spaw_root' Remote File Inclusion
|
7 |
WEB
|
Federico Fazzi
|
|
2006-06-11
|
|
RCblog 1.03 - 'POST' Remote Command Execution
|
7 |
WEB
|
Hessam-x
|
|
2006-06-11
|
|
MaxiSepet 1.0 - 'link' SQL Injection
|
7 |
WEB
|
nukedx
|
|
2006-06-11
|
|
free QBoard 1.1 - 'qb_path' Remote File Inclusion
|
7 |
WEB
|
Kacper
|
|
2006-06-11
|
|
WebprojectDB 0.1.3 - 'INCDIR' Remote File Inclusion
|
7 |
WEB
|
Kacper
|
|
2006-06-10
|
|
phpOnDirectory 1.0 - Remote File Inclusion
|
7 |
WEB
|
Kacper
|
|
2006-06-10
|
|
aePartner 0.8.3 - 'dir[data]' Remote File Inclusion
|
8 |
WEB
|
Kacper
|
|
2006-06-10
|
|
empris r20020923 - 'phormationdir' Remote File Inclusion
|
7 |
WEB
|
Kacper
|
|
2006-06-09
|
|
MailEnable Enterprise 2.0 - 'ASP' Multiple Vulnerabilities
|
7 |
WEB
|
Soroush Dalili
|
|
2006-06-08
|
|
Guestex Guestbook 1.00 - 'email' Remote Code Execution
|
8 |
WEB
|
K-sPecial
|
|
2006-06-08
|
|
Enterprise Payroll Systems 1.1 - 'footer' Remote File Inclusion
|
8 |
WEB
|
Kacper
|
|
2006-06-08
|
|
CMS-Bandits 2.5 - 'spaw_root' Remote File Inclusion
|
7 |
WEB
|
Federico Fazzi
|
|
2006-06-08
|
|
Back-End CMS 0.7.2.1 - 'jpcache.php' Remote File Inclusion
|
7 |
WEB
|
Federico Fazzi
|
|
2006-06-07
|
|
Xtreme/Ditto News 1.0 - 'post.php' Remote File Inclusion
|
7 |
WEB
|
Kacper
|
|
2006-06-07
|
|
OpenEMR 2.8.1 - 'fileroot' Remote File Inclusion
|
7 |
WEB
|
Kacper
|
|
2006-06-06
|
|
myNewsletter 1.1.2 - 'adminLogin.asp' Authentication Bypass
|
8 |
WEB
|
FarhadKey
|
|
2006-06-06
|
|
Wikiwig 4.1 - 'wk_lang.php' Remote File Inclusion
|
8 |
WEB
|
Kacper
|
|
2006-06-05
|
|
Dmx Forum 2.1a - 'edit.php' Remote Password Disclosure
|
8 |
WEB
|
DarkFig
|
|
2006-06-05
|
|
DreamAccount 3.1 - 'da_path' Remote File Inclusion
|
7 |
WEB
|
Aesthetico
|
|
2006-06-05
|
|
dotWidget CMS 1.0.6 - 'file_path' Remote File Inclusion
|
7 |
WEB
|
Aesthetico
|
|
2006-06-05
|
|
Particle Wiki 1.0.2 - SQL Injection
|
7 |
WEB
|
FarhadKey
|
|
2006-06-05
|
|
Claroline 1.7.6 - 'includePath' Remote Code Execution
|
7 |
WEB
|
rgod
|
|
2006-06-04
|
|
SCart 2.0 - 'page' Remote Code Execution
|
7 |
WEB
|
K-159
|
|
2006-06-04
|
|
FunkBoard CF0.71 - 'profile.php' Remote User Pass Change
|
7 |
WEB
|
ajann
|
|
2006-06-03
|
|
LifeType 1.0.4 - SQL Injection
|
7 |
WEB
|
rgod
|
|
2006-06-03
|
|
ProPublish 2.0 - 'catid' SQL Injection
|
7 |
WEB
|
FarhadKey
|
|
2006-06-03
|
|
CS-Cart 1.3.3 - 'classes_dir' Remote File Inclusion
|
6 |
WEB
|
Kacper
|
|
2006-06-03
|
|
WebspotBlogging 3.0.1 - 'path' Remote File Inclusion
|
7 |
WEB
|
Kacper
|
|
2006-06-03
|
|
BlueShoes Framework 4.6 - Remote File Inclusion
|
7 |
WEB
|
Kacper
|
|
2006-06-03
|
|
DotClear 1.2.4 - 'prepend.php' Remote File Inclusion
|
8 |
WEB
|
rgod
|
|
2006-06-03
|
|
PixelPost 1-5rc1-2 - Privilege Escalation
|
7 |
WEB
|
rgod
|
|
2006-06-02
|
|
PHP-Nuke 7.9 Final - 'phpbb_root_path' Remote File Inclusions
|
7 |
WEB
|
ddoshomo
|
|
2006-06-02
|
|
Informium 0.12.0 - 'common-menu.php' Remote File Inclusion
|
8 |
WEB
|
Kacper
|
|
2006-06-02
|
|
ashNews 0.83 - 'pathtoashnews' Remote File Inclusion
|
8 |
WEB
|
Kacper
|
|
2006-06-02
|
|
Igloo 0.1.9 - 'Wiki.php' Remote File Inclusion
|
7 |
WEB
|
Kacper
|
|
2006-06-02
|
|
Redaxo 3.2 - 'INCLUDE_PATH' Remote File Inclusion
|
7 |
WEB
|
beford
|
|
2006-06-01
|
|
Bytehoard 2.1 - 'server.php' Remote File Inclusion
|
8 |
WEB
|
beford
|
|
2006-06-01
|
|
aspWebLinks 2.0 - SQL Injection / Admin Pass Change
|
8 |
WEB
|
ajann
|
|
2006-06-01
|
|
AssoCIateD CMS 1.1.3 - 'ROOT_PATH' Remote File Inclusion
|
7 |
WEB
|
Kacper
|
|
2006-06-01
|
|
TinyPHP Forum 3.6 - 'profile.php' Remote Code Execution
|
7 |
WEB
|
Hessam-x
|
|
2006-05-31
|
|
metajour 2.1 - 'system_path' Remote File Inclusion
|
7 |
WEB
|
Kacper
|
|
2006-05-31
|
|
Ottoman CMS 1.1.3 - '?default_path=' Remote File Inclusion (1)
|
7 |
WEB
|
Kacper
|
|
2006-05-31
|
|
pppBlog 0.3.8 - System Disclosure
|
7 |
WEB
|
rgod
|
|
2006-05-30
|
|
gnopaste 0.5.3 - 'common.php' Remote File Inclusion
|
7 |
WEB
|
SmokeZ
|
|
2006-05-29
|
|
Nukedit 4.9.6 - Unauthorized Admin Add
|
7 |
WEB
|
FarhadKey
|
|
2006-05-29
|
|
Speedy ASP Forum - 'profileupdate.asp' User Pass Change
|
6 |
WEB
|
ajann
|
|
2006-05-29
|
|
Fastpublish CMS 1.6.9 - config[fsBase] Remote File Inclusion
|
7 |
WEB
|
Kacper
|
|
2006-05-28
|
|
CosmicShoppingCart - 'search.php' SQL Injection
|
7 |
WEB
|
Vympel
|
|
2006-05-28
|
|
Blend Portal 1.2.0 - 'phpBB Mod' Remote File Inclusion
|
8 |
WEB
|
nukedx
|
|
2006-05-28
|
|
ASPSitem 2.0 - SQL Injection / Database Disclosure
|
6 |
WEB
|
nukedx
|
|
2006-05-28
|
|
Activity MOD Plus 1.1.0 - 'phpBB Mod' File Inclusion
|
6 |
WEB
|
nukedx
|
|
2006-05-28
|
|
UBBCentral UBB.Threads 5.x/6.x - Multiple Remote File Inclusions
|
7 |
WEB
|
nukedx
|
|
2006-05-28
|
|
EggBlog < 3.07 - Remote SQL Injection / Privilege Escalation
|
7 |
WEB
|
nukedx
|
|
2006-05-28
|
|
F@cile Interactive Web 0.8x - Remote File Inclusion / Cross-Site Scripting
|
7 |
WEB
|
nukedx
|
|
2006-05-28
|
|
Enigma Haber 4.3 - Multiple SQL Injections
|
7 |
WEB
|
nukedx
|
|
2006-05-28
|
|
tinyBB 0.3 - Remote File Inclusion / SQL Injection
|
8 |
WEB
|
nukedx
|
|
2006-05-27
|
|
MiniNuke 2.x - SQL Injection (Add Admin)
|
8 |
WEB
|
nukedx
|
|
2006-05-27
|
|
PrideForum 1.0 - 'forum.asp' SQL Injection
|
8 |
WEB
|
ajann
|
|
2006-05-27
|
|
Hot Open Tickets 11012004 - 'CLASS_PATH' Remote File Inclusion
|
8 |
WEB
|
Kacper
|
|
2006-05-26
|
|
Easy-Content Forums 1.0 - Multiple SQL Injection / Cross-Site Scripting Vulnerabilities
|
9 |
WEB
|
ajann
|
|
2006-05-26
|
|
qjForum - 'member.asp' SQL Injection
|
8 |
WEB
|
ajann
|
|
2006-05-26
|
|
Plume CMS 1.0.3 - 'manager_path' Remote File Inclusion
|
9 |
WEB
|
beford
|
|
2006-05-25
|
|
APC ActionApps CMS 2.8.1 - Remote File Inclusion
|
8 |
WEB
|
Kacper
|
|
2006-05-25
|
|
DoceboLms 2.0.5 - 'help.php' Remote File Inclusion
|
8 |
WEB
|
beford
|
|
2006-05-25
|
|
V-Webmail 1.6.4 - 'pear_dir' Remote File Inclusion
|
7 |
WEB
|
beford
|
|
2006-05-25
|
|
Socketmail 2.2.6 - 'site_path' Remote File Inclusion
|
8 |
WEB
|
Aesthetico
|
|
2006-05-25
|
|
Back-End CMS 0.7.2.2 - 'BE_config.php' Remote File Inclusion
|
9 |
WEB
|
Kacper
|
|
2006-05-25
|
|
open-medium.CMS 0.25 - '404.php' Remote File Inclusion
|
8 |
WEB
|
Kacper
|
|
2006-05-25
|
|
BASE 1.2.4 - melissa Snort Frontend Remote File Inclusion
|
7 |
WEB
|
str0ke
|
|
2006-05-24
|
|
Drupal 4.7 - 'Attachment mod_mime' Remote Command Execution
|
8 |
WEB
|
rgod
|
|
2006-05-23
|
|
phpCommunityCalendar 4.0.3 - Cross-Site Scripting / SQL Injection
|
7 |
WEB
|
X0r_1
|
|
2006-05-23
|
|
Docebo 3.0.3 - Multiple Remote File Inclusions
|
8 |
WEB
|
Kacper
|
|
2006-05-23
|
|
Nucleus CMS 3.22 - 'DIR_LIBS' Remote File Inclusion
|
8 |
WEB
|
rgod
|
|
2006-05-22
|
|
UBBCentral UBB.Threads 6.4.x < 6.5.2 - 'thispath' Remote File Inclusion
|
8 |
WEB
|
V4mu
|
|
2006-05-21
|
|
Fusion News 1.0 (fil_config) - Remote File Inclusion
|
8 |
WEB
|
X0r_1
|
|
2006-05-21
|
|
XOOPS 2.0.13.2 - 'xoopsOption[nocommon]' Remote Command Execution
|
8 |
WEB
|
rgod
|
|
2006-05-20
|
|
Woltlab Burning Board 2.3.5 - 'links.php' SQL Injection
|
8 |
WEB
|
666
|
|
2006-05-20
|
|
CaLogic Calendars 1.2.2 - 'CLPath' Remote File Inclusion
|
8 |
WEB
|
Kacper
|
|
2006-05-19
|
|
phpMyDirectory 10.4.4 - 'ROOT_PATH' Remote File Inclusion
|
8 |
WEB
|
OLiBekaS
|
|
2006-05-19
|
|
Zix Forum 1.12 - 'layid' SQL Injection
|
8 |
WEB
|
FarhadKey
|
|
2006-05-19
|
|
phpListPro 2.0.1 - 'Language' Remote Code Execution
|
7 |
WEB
|
[Oo]
|
|
2006-05-19
|
|
phpBazar 2.1.0 - Remote File Inclusion / Authentication Bypass
|
9 |
WEB
|
[Oo]
|
|
2006-05-17
|
|
ScozNews 1.2.1 - 'mainpath' Remote File Inclusion
|
8 |
WEB
|
Kacper
|
|
2006-05-17
|
|
Quezza BB 1.0 - 'quezza_root_path' File Inclusion
|
9 |
WEB
|
nukedx
|
|
2006-05-16
|
|
DeluxeBB 1.06 - 'Attachment mod_mime' Remote Command Execution
|
8 |
WEB
|
rgod
|
|
2006-05-16
|
|
PHP-Fusion 6.00.306 - 'srch_where' SQL Injection
|
6 |
WEB
|
rgod
|
|
2006-05-15
|
|
ezusermanager 1.6 - Remote File Inclusion
|
8 |
WEB
|
OLiBekaS
|
|
2006-05-15
|
|
DeluxeBB 1.06 - 'name' SQL Injection (mq=off)
|
8 |
WEB
|
KingOfSka
|
|
2006-05-15
|
|
Squirrelcart 2.2.0 - 'cart_content.php' Remote File Inclusion
|
10 |
WEB
|
OLiBekaS
|
|
2006-05-15
|
|
TR Newsportal 0.36tr1 - 'poll.php' Remote File Inclusion
|
9 |
WEB
|
Kacper
|
|
2006-05-14
|
|
Sugar Suite Open Source 4.2 - 'OptimisticLock' Command Execution
|
8 |
WEB
|
rgod
|
|
2006-05-13
|
|
phpBB 2.0.20 - Admin/Restore DB/default_lang Remote Command Execution
|
7 |
WEB
|
rgod
|
|
2006-05-12
|
|
PHP Blue Dragon CMS 2.9 - Remote File Inclusion
|
8 |
WEB
|
Kacper
|
|
2006-05-12
|
|
Foing 0.7.0 - 'phpBB' Remote File Inclusion
|
8 |
WEB
|
Kurdish Security
|
|
2006-05-11
|
|
Unclassified NewsBoard 1.6.1 patch 1 - Local File Inclusion
|
8 |
WEB
|
rgod
|
|
2006-05-09
|
|
pafileDB 2.0.1 - 'mxBB'/'phpBB' Remote File Inclusion
|
7 |
WEB
|
Darkfire
|
|
2006-05-09
|
|
phpRaid 3.0.b3 - 'phpBB'/'SMF' Remote File Inclusion
|
8 |
WEB
|
Kurdish Security
|
|
2006-05-08
|
|
phpListPro 2.01 - Multiple Remote File Inclusions
|
7 |
WEB
|
Aesthetico
|
|
2006-05-08
|
|
ActualAnalyzer Pro 6.88 - 'rf' Remote File Inclusion
|
8 |
WEB
|
ReZEN
|
|
2006-05-08
|
|
ActualAnalyzer Server 8.23 - 'rf' Remote File Inclusion
|
9 |
WEB
|
Aesthetico
|
|
2006-05-08
|
|
Claroline E-Learning 1.75 - 'ldap.inc.php' Remote File Inclusion
|
7 |
WEB
|
beford
|
|
2006-05-08
|
|
Dokeos Lms 1.6.4 - 'authldap.php' Remote File Inclusion
|
7 |
WEB
|
beford
|