2017-12-11
|
|
Vanguard 1.4 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Vanguard 1.4 - Arbitrary File Upload
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Basic Job Site Script 2.0.5 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Resume Clone Script 2.0.5 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Advanced World Database 2.0.5 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Muslim Matrimonial Script 3.02 - 'succid' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Groupon Clone Script 3.01 - 'state_id' / 'search' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Car Rental Script 2.0.4 - 'val' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
MLM Forced Matrix 2.0.9 - 'newid' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
MLM Forex Market Plan Script 2.0.4 - 'newid' / 'eventid' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Entrepreneur Bus Booking Script 3.0.4 - 'sourcebus' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Advanced Real Estate Script 4.0.7 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Single Theater Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Multiplex Movie Theater Booking Script 3.1.5 - 'moid' / 'eid' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Responsive Events & Movie Ticket Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Multireligion Responsive Matrimonial 4.7.2 - 'succid' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Responsive Realestate Script 3.2 - 'property-list?tbud' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Readymade Video Sharing Script 3.2 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Readymade PHP Classified Script 3.3 - 'subctid' / 'mctid' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Professional Service Script 1.0 - 'service-list?city' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
PHP Multivendor Ecommerce 1.0 - 'sid' / 'searchcat' / 'chid1' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Opensource Classified Ads Script 3.2 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Online Exam Test Application Script 1.6 - 'exams.php?sort' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Multivendor Penny Auction Clone Script 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Lawyer Search Script 1.1 - 'lawyer-list?city' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Laundry Booking Script 1.0 - 'list?city' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Secure E-commerce Script 2.0.1 - 'searchcat' / 'searchmain' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Kickstarter Clone Acript 2.0 - 'projid' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Foodspotting Clone Script 1.0 - 'quicksearch.php?q' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Hot Scripts Clone 3.1 - 'subctid' / 'mctid' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Freelance Website Script 2.0.6 - 'pr_id' / 'catid' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Yoga Class Script 1.0 - 'list?city' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Food Order Script 1.0 - 'list?city' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-11
|
|
Facebook Clone Script 1.0 - 'id' / 'send' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
Event Calendar Category Script 1.0 - 'city' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
Entrepreneur Dating Script 2.0.1 - 'marital' / 'gender' / 'country' / 'profileid' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
E-commerce MLM Software 1.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
Doctor Search Script 1.0 - 'city' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
Entrepreneur Job Portal Script 2.0.6 - 'jobsearch_all.php?rid1' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
Consumer Complaints Clone Script 1.0 - 'id' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
Co-work Space Search Script 1.0 - 'city' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
CMS Auditor Website 1.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
Child Care Script 1.0 - 'city' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
Chartered Accountant Booking Script 1.0 - 'city' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
Cab Booking Script 1.0 - 'city' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
Nearbuy Clone Script 3.2 - 'search' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-09
|
|
Beauty Parlour Booking Script 1.0 - 'gender' / 'city' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-09
|
|
Basic B2B Script 2.0.8 - 'product_details.php?id' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-09
|
|
Affiliate MLM Script 1.0 - 'product-category.php?key' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-09
|
|
Advance Online Learning Management Script 3.1 - 'subcatid' / 'popcourseid' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-09
|
|
Advance B2B Script 2.1.3 - 'show_id' / 'pid' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-09
|
|
FS Foodpanda Clone 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-09
|
|
FS Expedia Clone 1.0 - 'fl_orig' / 'fl_dest' / 'id' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-09
|
|
FS Trademe Clone 1.0 - 'search' / 'id' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-09
|
|
FS Amazon Clone 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-09
|
|
FS Care Clone 1.0 - 'jobFrequency' / 'jobType' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-09
|
|
FS Crowdfunding Script 1.0 - 'latest_news_details.php?id' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-09
|
|
FS Ebay Clone 1.0 - 'id' / 'sub_category_id' / 'category_id' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-09
|
|
FS Freelancer Clone 1.0 - 'profile.php?u' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-09
|
|
FS Gigs Script 1.0 - 'cat' / 'sc' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-09
|
|
FS Groupon Clone 1.0 - 'id' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-09
|
|
FS Grubhub Clone 1.0 - 'keywords' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-09
|
|
FS IMDB Clone 1.0 - 'f' / 's' / 'id' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-09
|
|
FS Indiamart Clone 1.0 - 'token' / 'id' / 'c' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-09
|
|
FS Linkedin Clone 1.0 - 'grid' / 'fid' / 'id' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
FS Makemytrip Clone 1.0 - 'fl_orig' / 'fl_dest' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
FS Monster Clone 1.0 - 'Employer_Details.php?id' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
FS Olx Clone 1.0 - 'scat' / 'pid' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
FS Quibids Clone 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
FS Shutterstock Clone 1.0 - 'keywords' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
FS Stackoverflow Clone 1.0 - 'keywords' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
FS Thumbtack Clone 1.0 - 'cat' / 'sc' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
Realestate Crowdfunding Script 2.7.2 - 'pid' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
Website Auction Marketplace 2.0.5 - 'cat_id' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
Simple Chatting System 1.0.0 - Arbitrary File Upload
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-08
|
|
DomainSale PHP Script 1.0 - 'id' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-07
|
|
OpenEMR 5.0.0 - OS Command Injection / Cross-Site Scripting
|
3 |
WEB
|
SEC Consult
|
2017-12-07
|
|
OpenEMR 5.0.0 - OS Command Injection / Cross-Site Scripting
|
3 |
WEB
|
SEC Consult
|
2017-12-07
|
|
FS Facebook Clone - 'token' SQL Injection
|
2 |
WEB
|
Dan°
|
2017-12-07
|
|
FS IMDB Clone - 'id' SQL Injection
|
3 |
WEB
|
Dan°
|
2017-12-06
|
|
FS Shaadi Clone - 'token' SQL Injection
|
3 |
WEB
|
Dan°
|
2017-12-06
|
|
WinduCMS 3.1 - Local File Disclosure
|
3 |
WEB
|
Maciek Krupa
|
2017-12-06
|
|
FS Makemytrip Clone - 'id' SQL Injection
|
3 |
WEB
|
Dan°
|
2017-12-05
|
|
Readymade Classifieds Script 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-05
|
|
Techno Portfolio Management Panel - 'id' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-12-05
|
|
Perspective ICM Investigation & Case 5.1.1.16 - Privilege Escalation
|
4 |
WEB
|
Konstantinos Alexiou
|
2017-12-01
|
|
Artica Web Proxy 3.06 - Remote Code Execution
|
3 |
WEB
|
hyp3rlinx
|
2017-12-01
|
|
MistServer 2.12 - Cross-Site Scripting
|
3 |
WEB
|
hyp3rlinx
|
2017-11-30
|
|
Jobs2Careers / Coroflot Clone - SQL Injection
|
4 |
WEB
|
8bitsec
|
2017-11-28
|
|
WordPress Plugin WooCommerce 2.0/3.0 - Directory Traversal
|
3 |
WEB
|
Fu2x2000
|
2017-11-11
|
|
osCommerce 2.3.4.1 - Arbitrary File Upload
|
3 |
WEB
|
Simon Scannell
|
2017-11-28
|
|
Synology StorageManager 5.2 - Root Remote Command Execution
|
3 |
WEB
|
SecuriTeam
|
2017-11-27
|
|
ZTE ZXDSL 831CII - Improper Access Restrictions
|
4 |
WEB
|
Ibad Shah
|
2017-11-15
|
|
CommuniGatePro 6.1.16 - Cross-Site Scripting
|
3 |
WEB
|
Boumediene KADDOUR
|
2017-11-17
|
|
Icon Time Systems RTC-1000 Firmware 2.5.7458 - Cross-Site Scripting
|
3 |
WEB
|
Keith Thome
|
2017-11-16
|
|
Zeta Components Mail 1.8.1 - Remote Code Execution
|
2 |
WEB
|
MalwareBenchmark
|
2017-11-16
|
|
Vonage VDV23 - Cross-Site Scripting
|
3 |
WEB
|
Nu11By73
|
2017-11-16
|
|
LanSweeper 6.0.100.75 - Cross-Site Scripting
|
3 |
WEB
|
Miguel Mendez Z
|
2017-11-16
|
|
TP-Link TL-WR740N - Cross-Site Scripting
|
4 |
WEB
|
bl00dy
|
2017-03-26
|
|
D-Link DCS-936L Network Camera - Cross-Site Request Forgery
|
3 |
WEB
|
SlidingWindow
|
2017-11-13
|
|
Kirby CMS < 2.5.7 - Cross-Site Scripting
|
2 |
WEB
|
Ishaq Mohammed
|
2017-11-13
|
|
Web Viewer 1.0.0.193 (Samsung SRN-1670D) - Unrestricted File Upload
|
3 |
WEB
|
0xFFFFFF
|
2017-11-11
|
|
MyBB 1.8.13 - Cross-Site Scripting
|
2 |
WEB
|
Pabstersac
|
2017-11-11
|
|
MyBB 1.8.13 - Remote Code Execution
|
3 |
WEB
|
Pabstersac
|
2017-11-07
|
|
ManageEngine Applications Manager 13 - SQL Injection
|
3 |
WEB
|
Cody Sixteen
|
2017-11-07
|
|
pfSense 2.3.1_1 - Command Execution
|
2 |
WEB
|
s4squatch
|
2017-11-03
|
|
Logitech Media Server 7.9.0 - 'Radio URL' Cross-Site Scripting
|
3 |
WEB
|
Dewank Pant
|
2017-11-03
|
|
Logitech Media Server 7.9.0 - 'favorites' Cross-Site Scripting
|
2 |
WEB
|
Dewank Pant
|
2017-11-04
|
|
WordPress Plugin Userpro < 4.9.17.1 - Authentication Bypass
|
3 |
WEB
|
Colette Chamberland
|
2017-05-17
|
|
Oracle PeopleSoft Enterprise PeopleTools < 8.55 - Remote Code Execution Via Blind XML External Entit
|
3 |
WEB
|
Charles Fol
|
2017-11-03
|
|
Ladon Framework for Python 0.9.40 - XML External Entity Expansion
|
3 |
WEB
|
RedTeam Pentesting
|
2017-11-03
|
|
WordPress Plugin JTRT Responsive Tables 4.1 - SQL Injection
|
3 |
WEB
|
Lenon Leite
|
2017-11-01
|
|
Ingenious School Management System 2.3.0 - 'friend_index' SQL injection
|
3 |
WEB
|
Giulio Comi
|
2017-11-01
|
|
OctoberCMS 1.0.426 (Build 426) - Cross-Site Request Forgery
|
3 |
WEB
|
Zain Sabahat
|
2017-10-30
|
|
Oracle Java SE - Web Start jnlp XML External Entity Processing Information Disclosure
|
3 |
WEB
|
mr_me
|
2017-10-30
|
|
Ingenious 2.3.0 - Arbitrary File Upload
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
D-Park Pro 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
Adult Script Pro 2.2.4 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
Article Directory Script 3.0 - 'id' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
iProject Management System 1.0 - 'ID' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
iStock Management System 1.0 - Arbitrary File Upload
|
3 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
iTech Gigs Script 1.21 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
Job Board Script - 'nice_theme' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
Joomla! Component NS Download Shop 2.2.6 - 'id' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
Joomla! Component Zh YandexMap 6.1.1.0 - 'placemarklistid' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|