2017-09-26
|
|
Job Links - Arbitrary File Upload
|
2 |
WEB
|
Ihsan Sencan
|
2017-09-16
|
|
WordPress Plugin Content Timeline - SQL Injection
|
3 |
WEB
|
Jeroen - IT Nerdbox
|
2017-08-31
|
|
Sitefinity CMS 9.2 - Cross-Site Scripting
|
4 |
WEB
|
Pralhad Chaskar
|
2017-09-25
|
|
FLIR Thermal Camera F/FC/PT/D - Stream Disclosure
|
3 |
WEB
|
LiquidWorm
|
2017-09-25
|
|
FLIR Thermal Camera FC-S/PT - Command Injection
|
3 |
WEB
|
LiquidWorm
|
2017-09-25
|
|
FLIR Thermal Camera F/FC/PT/D - Information Disclosure
|
3 |
WEB
|
LiquidWorm
|
2017-09-25
|
|
FLIR Thermal Camera PT-Series (PT-334 200562) - Root Remote Code Execution
|
3 |
WEB
|
LiquidWorm
|
2017-09-22
|
|
JitBit HelpDesk < 9.0.2 - Authentication Bypass
|
3 |
WEB
|
Kc57
|
2017-09-22
|
|
PHP Auction Ecommerce Script 1.6 - SQL Injection
|
2 |
WEB
|
8bitsec
|
2017-09-22
|
|
Secure E-commerce Script 1.02 - 'sid' SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-09-22
|
|
Claydip Airbnb Clone 1.0 - Arbitrary File Upload
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-22
|
|
Cash Back Comparison Script 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-22
|
|
Multi Level Marketing - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-22
|
|
Lending And Borrowing - 'pid' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-19
|
|
DenyAll WAF < 6.3.0 - Remote Code Execution (Metasploit)
|
3 |
WEB
|
Mehmet Ince
|
2017-09-22
|
|
Stock Photo Selling 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-21
|
|
PHPMyFAQ 2.9.8 - Cross-Site Scripting (1)
|
3 |
WEB
|
Ishaq Mohammed
|
2017-05-19
|
|
Tecnovision DLX Spot - Arbitrary File Upload
|
2 |
WEB
|
Simon Brannstrom
|
2017-05-19
|
|
Tecnovision DLX Spot - Authentication Bypass
|
3 |
WEB
|
Simon Brannstrom
|
2017-09-15
|
|
iTech Gigs Script 1.20 - 'cat' SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-09-13
|
|
Foodspotting Clone 1.0 - SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-09-18
|
|
Apache < 2.2.34 / < 2.4.27 - OPTIONS Memory Leak
|
3 |
WEB
|
Hanno Bock
|
2017-09-18
|
|
iBall ADSL2+ Home Router - Authentication Bypass
|
3 |
WEB
|
Gem George
|
2017-09-15
|
|
UTStar WA3002G4 ADSL Broadband Modem - Authentication Bypass
|
3 |
WEB
|
Gem George
|
2017-09-18
|
|
DigiAffiliate 1.4 - Cross-Site Request Forgery (Update Admin)
|
2 |
WEB
|
Ihsan Sencan
|
2017-09-18
|
|
Digileave 1.2 - Cross-Site Request Forgery (Update Admin)
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-18
|
|
Digirez 3.4 - Cross-Site Request Forgery (Update Admin)
|
2 |
WEB
|
Ihsan Sencan
|
2017-09-15
|
|
Contact Manager 1.0 - 'femail' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-15
|
|
PTCEvolution 5.50 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-09-14
|
|
Humax Wi-Fi Router HG100R 2.0.6 - Authentication Bypass
|
2 |
WEB
|
Kivson
|
2017-09-12
|
|
D-Link DIR-8xx Routers - Local Firmware Upload
|
2 |
WEB
|
embedi
|
2017-09-12
|
|
D-Link DIR-8xx Routers - Root Remote Code Execution
|
2 |
WEB
|
embedi
|
2017-09-12
|
|
D-Link DIR-8xx Routers - Leak Credentials
|
3 |
WEB
|
embedi
|
2017-09-12
|
|
Consumer Review Script 1.0 - SQL Injection
|
1 |
WEB
|
8bitsec
|
2017-09-12
|
|
XYZ Auto Classifieds 1.0 - SQL Injection
|
1 |
WEB
|
8bitsec
|
2017-09-14
|
|
Justdial Clone Script - 'fid' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-14
|
|
Theater Management Script - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-14
|
|
PTC KSV1 Script 1.7 - 'type' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-09-14
|
|
Adserver Script 5.6 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-09-14
|
|
Enterprise Edition Payment Processor Script 3.7 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2011-09-13
|
|
Carel PlantVisor 2.4.4 - Directory Traversal
|
2 |
WEB
|
Luigi Auriemma
|
2017-09-13
|
|
Carel PlantVisor 2.4.4 - Directory Traversal Information Disclosure (Metasploit)
|
2 |
WEB
|
James Fitts
|
2017-09-13
|
|
Carlo Gavazzi Powersoft 2.1.1.1 - Directory Traversal File Disclosure (Metasploit)
|
0 |
WEB
|
James Fitts
|
2017-09-13
|
|
Indusoft Web Studio - Directory Traversal Information Disclosure (Metasploit)
|
1 |
WEB
|
James Fitts
|
2017-09-13
|
|
ICAffiliateTracking 1.1 - Authentication Bypass
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
ICSiteBuilder 1.1 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
ICHelpDesk 1.1 - 'pk' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
ICEstate 1.1 - 'id' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
ICDental Clinic 1.2 - 'key' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
ICProjectBidding 1.1 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
ICCallLimousine 1.1 - 'key' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
ICGrocery 1.1 - 'key' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
ICProductConfigurator 1.1 - 'key' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
IC-T-Shirt 1.2 - 'key' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
ICJewelry 1.1 - 'key' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
ICSurvey 1.1 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
ICStudents 1.2 - 'key' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
ICClassifieds 1.1 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
ICTraveling 2.2 - Authentication Bypass
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
ICAutosales 2.2 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
ICDutchAuction 1.2 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
ICRestaurant software 1.4 - 'key' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
ICDoctor Appointment 1.3 - 'key' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
ICAuction 2.2 - 'id' SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
ICHotelReservation 3.3 - 'key' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
ICMLM 2.1 - 'key' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-13
|
|
ICLowBidAuction 3.3 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-12
|
|
inClick Cloud Server 5.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-09-12
|
|
Gr8 Multiple Search Engine Script 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-12
|
|
FoodStar 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-12
|
|
osTicket 1.10 - SQL Injection (PoC)
|
3 |
WEB
|
Mehmet Ince
|
2017-09-11
|
|
AirStar Airbnb Clone Script 1.0 - SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-09-11
|
|
EduStar Udemy Clone Script 1.0 - SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-09-11
|
|
iTech StockPhoto Script 2.02 - SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-09-11
|
|
iTech Book Store Script 2.02 - SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-09-11
|
|
JobStar Monster Clone Script 1.0 - SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-09-11
|
|
PHP Dashboards NEW 4.4 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-11
|
|
PHP Dashboards NEW 4.4 - Arbitrary File Read
|
2 |
WEB
|
Ihsan Sencan
|
2017-09-11
|
|
WiseGiga NAS - Multiple Vulnerabilities
|
3 |
WEB
|
Pierre Kim
|
2017-09-05
|
|
FiberHome ADSL AN1020-25 - Improper Access Restrictions
|
3 |
WEB
|
Ibad Shah
|
2017-09-11
|
|
Nimble Professional 1.0 - Cross-Site Request Forgery (Update Admin)
|
4 |
WEB
|
Ihsan Sencan
|
2017-09-09
|
|
My Builder Marketplace 1.0 - SQL Injection
|
4 |
WEB
|
Ihsan Sencan
|
2017-09-09
|
|
Topsites Script 1.0 - Cross-Site Request Forgery / PHP Code Injection
|
4 |
WEB
|
Ihsan Sencan
|
2017-09-09
|
|
Law Firm 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-09
|
|
Restaurant Website Script 1.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-09-09
|
|
Professional Service Booking 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-09
|
|
Online Print Business 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-09
|
|
Just Dial Marketplace 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-08-16
|
|
RPi Cam Control < 6.3.14 - Multiple Vulnerabilities
|
3 |
WEB
|
Alexander Korznikov
|
2017-09-09
|
|
Job Board Software 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-09
|
|
Babysitter Website Script 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-09
|
|
Escort Marketplace 1.0 - SQL Injection
|
4 |
WEB
|
Ihsan Sencan
|
2017-09-07
|
|
Huawei HG255s - Directory Traversal
|
3 |
WEB
|
Ahmet Mersin
|
2017-09-07
|
|
Roteador Wireless Intelbras WRN150 - Cross-Site Scripting
|
3 |
WEB
|
Elber Tavares
|
2017-09-07
|
|
EzInvoice 6.02 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-07
|
|
EzBan 5.3 - 'id' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-07
|
|
Online Invoice System 3.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-09-05
|
|
Ultimate HR System < 1.2 - Directory Traversal / Cross-Site Scripting
|
3 |
WEB
|
8bitsec
|
2017-09-06
|
|
Pay Banner Text Link Ad 1.0.6.1 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-06
|
|
Pay Banner Text Link Ad 1.0.6.1 - Cross-Site Request Forgery (Update Admin)
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-06
|
|
Advertiz PHP Script 0.2 - Cross-Site Request Forgery (Update Admin)
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-06
|
|
Cory Support - 'pr' SQL Injection
|
3 |
WEB
|
v3n0m
|
2017-09-05
|
|
The Car Project 1.0 - SQL Injection
|
4 |
WEB
|
Ihsan Sencan
|
2017-09-01
|
|
WordPress Plugin Participants Database < 1.7.5.10 - Cross-Site Scripting
|
3 |
WEB
|
Benjamin Lim
|
2017-09-04
|
|
iGreeting Cards 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-04
|
|
A2billing 2.x - Backup File Download / Remote Code Execution
|
2 |
WEB
|
0x4148
|
2017-09-05
|
|
A2billing 2.x - SQL Injection
|
3 |
WEB
|
0x4148
|
2017-08-09
|
|
Symantec Messaging Gateway < 10.6.3-267 - Cross-Site Request Forgery
|
3 |
WEB
|
Dhiraj Mishra
|
2017-09-04
|
|
CodeMeter 6.50 - Cross-Site Scripting
|
3 |
WEB
|
Vulnerability-Lab
|
2017-09-04
|
|
Wireless Repeater BE126 - Remote Code Execution
|
3 |
WEB
|
Hay Mizrachi
|
2017-09-03
|
|
Joomla! Component CheckList 1.1.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-09-03
|
|
Joomla! Component Survey Force Deluxe 3.2.4 - 'invite' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-08-29
|
|
FineCMS 1.0 - Multiple Vulnerabilities
|
2 |
WEB
|
sohaip-hackerDZ
|
2017-08-31
|
|
Joomla! Component Huge-IT Portfolio Gallery Plugin 1.0.7 - SQL Injection
|
3 |
WEB
|
Larry W. Cashdollar
|
2017-08-31
|
|
Joomla! Component Huge-IT Portfolio Gallery Plugin 1.0.6 - SQL Injection
|
3 |
WEB
|
Larry W. Cashdollar
|
2017-08-31
|
|
Joomla! Component Huge-IT Video Gallery 1.0.9 - SQL Injection
|
3 |
WEB
|
Larry W. Cashdollar
|
2017-08-30
|
|
PHP-SecureArea < 2.7 - Multiple Vulnerabilities
|
4 |
WEB
|
Cryo
|
2017-08-30
|
|
Invoice Manager 3.1 - Cross-Site Request Forgery (Add Admin)
|
3 |
WEB
|
Ali BawazeEer
|
2017-03-07
|
|
iBall Baton 150M Wireless Router - Authentication Bypass
|
3 |
WEB
|
Indrajith.A.N
|
2017-08-30
|
|
Joomla! Component Joomanager 2.0.0 - 'com_Joomanager' Arbitrary File Download (PoC)
|
3 |
WEB
|
Ihsan Sencan
|
2017-08-30
|
|
Joomla! Component Quiz Deluxe 3.7.4 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-08-29
|
|
Brickcom IP Camera - Credentials Disclosure
|
3 |
WEB
|
Emiliano Ipar
|
2017-08-28
|
|
PHP Video Battle Script 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-08-29
|
|
User Login and Management - Multiple Vulnerabilities
|
3 |
WEB
|
Ali BawazeEer
|
2017-08-28
|
|
PHP Appointment Booking Script - Authentication Bypass
|
3 |
WEB
|
Ali BawazeEer
|