Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2017-08-30   PHP-SecureArea < 2.7 - Multiple Vulnerabilities 6 WEB Cryo
2017-08-30   Invoice Manager 3.1 - Cross-Site Request Forgery (Add Admin) 6 WEB Ali BawazeEer
2017-03-07   iBall Baton 150M Wireless Router - Authentication Bypass 5 WEB Indrajith.A.N
2017-08-30   Joomla! Component Joomanager 2.0.0 - 'com_Joomanager' Arbitrary File Download (PoC) 5 WEB Ihsan Sencan
2017-08-30   Joomla! Component Quiz Deluxe 3.7.4 - SQL Injection 6 WEB Ihsan Sencan
2017-08-29   Brickcom IP Camera - Credentials Disclosure 5 WEB Emiliano Ipar
2017-08-28   PHP Video Battle Script 1.0 - SQL Injection 5 WEB Ihsan Sencan
2017-08-29   User Login and Management - Multiple Vulnerabilities 5 WEB Ali BawazeEer
2017-08-28   PHP Appointment Booking Script - Authentication Bypass 5 WEB Ali BawazeEer
2017-08-28   Car or Cab Booking Script - Authentication Bypass 5 WEB Ali BawazeEer
2017-08-29   D-Link DIR-600 - Authentication Bypass 3 WEB Jithin D Kurup
2017-08-28   NethServer 7.3.1611 - Cross-Site Request Forgery (Create User / Enable SSH Access) 4 WEB LiquidWorm
2017-08-28   NethServer 7.3.1611 - Cross-Site Request Forgery / Cross-Site Scripting 3 WEB LiquidWorm
2017-08-28   Schools Alert Management Script - Authentication Bypass 3 WEB Ali BawazeEer
2017-06-01   CMS Web-Gooroo < 1.141 - Multiple Vulnerabilities 4 WEB Kaimi
2017-08-28   Login-Reg Members Management PHP 1.0 - Arbitrary File Upload 4 WEB Ihsan Sencan
2017-08-28   Flash Poker 2.0 - 'game' SQL Injection 4 WEB Ihsan Sencan
2017-08-28   PHP Search Engine 1.0 - SQL Injection 4 WEB Ihsan Sencan
2017-08-28   Easy Web Search 4.0 - SQL Injection 5 WEB Ihsan Sencan
2017-08-28   WYSIWYG HTML Editor PRO 1.0 - Arbitrary File Download 5 WEB Ihsan Sencan
2017-08-28   FTP Made Easy PRO 1.2 - SQL Injection 5 WEB Ihsan Sencan
2017-08-28   Smart Chat 1.0.0 - SQL Injection 5 WEB Ihsan Sencan
2017-08-27   Matrimonial Script 2.7 - Authentication Bypass 5 WEB Ali BawazeEer
2017-08-25   Joomla! Component Responsive Portfolio 1.6.1 - SQL Injection 5 WEB Ihsan Sencan
2017-08-25   Joomla! Component Photo Contest 1.0.2 - SQL Injection 5 WEB Ihsan Sencan
2017-08-25   AutoCar 1.1 - 'category' SQL Injection 4 WEB Bora Bozdogan
2017-08-25   Joomla! Component OSDownloads 1.7.4 - SQL Injection 4 WEB Ihsan Sencan
2017-08-24   Joomla! Component Price Alert 3.0.2 - 'product_id' SQL Injection 5 WEB Ihsan Sencan
2017-08-24   Joomla! Component Bargain Product VM3 1.0 - 'product_id' SQL Injection 5 WEB Ihsan Sencan
2017-08-23   Wireless Repeater BE126 - Local File Inclusion 5 WEB Hay Mizrachi
2017-08-22   Matrimonial Script - SQL Injection 5 WEB Ihsan Sencan
2017-08-22   Automated Logic WebCTRL 6.5 - Unrestricted File Upload / Remote Code Execution 6 WEB LiquidWorm
2017-08-22   Automated Logic WebCTRL 6.1 - Path Traversal / Arbitrary File Write 6 WEB LiquidWorm
2017-08-21   PHPMyWind 5.3 - Cross-Site Scripting 5 WEB 小雨
2017-08-21   PHP Jokesite 2.0 - 'joke_id' SQL Injection 5 WEB Ihsan Sencan
2017-08-21   PHP-Lance 1.52 - 'subcat' SQL Injection 5 WEB Ihsan Sencan
2017-08-21   Joomla! Component Ajax Quiz 1.8 - SQL Injection 4 WEB Ihsan Sencan
2017-08-21   (Bitcoin / Dogecoin) PHP Cloud Mining Script - Authentication Bypass 5 WEB Ihsan Sencan
2017-08-21   Joomla! Component FocalPoint 1.2.3 - SQL Injection 3 WEB Ihsan Sencan
2017-08-21   iTech Social Networking Script 3.08 - SQL Injection 4 WEB Ihsan Sencan
2017-08-21   PHP Coupon Script 6.0 - 'cid' SQL Injection 5 WEB Ihsan Sencan
2017-08-21   Affiliate Niche Script 3.4.0 - SQL Injection 4 WEB Ihsan Sencan
2017-08-21   PHP Classifieds Script 5.6.2 - SQL Injection 5 WEB Ihsan Sencan
2017-08-21   Joomla! Component Sponsor Wall 8.0 - SQL Injection 5 WEB Ihsan Sencan
2017-08-21   Joomla! Component Flip Wall 8.0 - 'wallid' SQL Injection 5 WEB Ihsan Sencan
2017-08-21   Apache2Triad 1.5.4 - Multiple Vulnerabilities 5 WEB hyp3rlinx
2017-08-18   Symantec Messaging Gateway 10.6.3-2 - Root Remote Command Execution 5 WEB Philip Pettersson
2017-08-18   QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilities 5 WEB VVVSecurity
2017-08-18   iTech Movie Script 7.51 - SQL Injection 5 WEB Ihsan Sencan
2017-08-18   iTech Job Script 9.27 - SQL Injection 5 WEB Ihsan Sencan
2017-08-18   iTech Dating Script 3.40 - SQL Injection 5 WEB Ihsan Sencan
2017-08-18   iTech Multi Vendor Script 6.63 - SQL Injection 5 WEB Ihsan Sencan
2017-08-18   iTech Travel Script 9.49 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   iTech Freelancer Script 5.27 - SQL Injection 5 WEB Ihsan Sencan
2017-08-18   iTech Image Sharing Script 4.13 - SQL Injection 4 WEB Ihsan Sencan
2017-08-18   iTech Classifieds Script 7.41 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   iTech Caregiver Script 2.71 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   iTech Business Networking Script 8.26 - SQL Injection 4 WEB Ihsan Sencan
2017-08-18   iTech B2B Script 4.42 - SQL Injection 4 WEB Ihsan Sencan
2017-08-18   DeWorkshop 1.0 - Arbitrary File Upload 4 WEB Ihsan Sencan
2017-08-18   Joomla! Component SP Movie Database 1.3 - SQL Injection 5 WEB Ihsan Sencan
2017-08-18   Joomla! Component Calendar Planner 1.0.1 - SQL Injection 6 WEB Ihsan Sencan
2017-08-18   Joomla! Component Zap Calendar Lite 4.3.4 - SQL Injection 6 WEB Ihsan Sencan
2017-08-18   SOA School Management 3.0 - SQL Injection 5 WEB Ihsan Sencan
2017-08-18   eCardMAX 10.5 - SQL Injection 5 WEB Ihsan Sencan
2017-08-18   Matrimony Script 2.7 - SQL Injection 5 WEB Ihsan Sencan
2017-08-18   Joomla! Component KissGallery 1.0.0 - SQL Injection 5 WEB Ihsan Sencan
2017-08-18   Joomla! Component Twitch Tv 1.1 - SQL Injection 5 WEB Ihsan Sencan
2017-08-18   Joomla! Component Appointment 1.1 - SQL Injection 5 WEB Ihsan Sencan
2017-08-18   LiveProjects 1.0 - SQL Injection 5 WEB Ihsan Sencan
2017-08-18   LiveSales 1.0 - SQL Injection 5 WEB Ihsan Sencan
2017-08-18   LiveInvoices 1.0 - SQL Injection 5 WEB Ihsan Sencan
2017-08-18   LiveSupport 1.0 - SQL Injection 5 WEB Ihsan Sencan
2017-08-18   LiveCRM 1.0 - SQL Injection 5 WEB Ihsan Sencan
2017-08-17   Food Ordering Script 1.0 - SQL Injection 5 WEB Ihsan Sencan
2017-08-17   Doctor Patient Project 1.0 - SQL Injection 5 WEB Ihsan Sencan
2017-08-17   Photogallery Project 1.0 - SQL Injection 4 WEB Ihsan Sencan
2017-08-17   Online Quiz Project 1.0 - SQL Injection 5 WEB Ihsan Sencan
2017-08-15   AdvanDate iCupid Dating Software 12.2 - SQL Injection 4 WEB Ihsan Sencan
2017-08-15   ClipBucket 2.8.3 - Multiple Vulnerabilities 5 WEB bRpsd
2017-08-14   Quali CloudShell 7.1.0.6508 (Patch 6) - Persistent Cross-Site Scripting 5 WEB Benjamin Lee
2017-08-14   RPi Cam Control < 6.3.14 - Remote Command Execution 4 WEB Alexander Korznikov
2017-08-12   AirMaster 3000M - Multiple Vulnerabilities 5 WEB Mr.8Th BiT
2017-08-12   RealTime RWR-3G-100 Router - Cross-Site Request Forgery (Change Admin Password) 5 WEB Touhid M.Shaikh
2017-08-11   De-Tutor 1.0 - SQL Injection 4 WEB Ihsan Sencan
2017-08-11   De-Journal 1.0 - SQL Injection 4 WEB Ihsan Sencan
2017-08-11   DeWorkshop 1.0 - SQL Injection 5 WEB Ihsan Sencan
2017-08-10   Red-Gate SQL Monitor < 3.10 / 4.2 - Authentication Bypass 4 WEB Paul Taylor
2017-08-10   Piwigo Plugin User Tag 0.9.0 - Cross-Site Scripting 5 WEB Touhid M.Shaikh
2017-08-10   GIF Collection 2.0 - SQL Injection 5 WEB Ihsan Sencan
2017-08-10   ImageBay 1.0 - SQL Injection 5 WEB Ihsan Sencan
2017-08-09   WebFile Explorer 1.0 - Arbitrary File Download 6 WEB Ihsan Sencan
2017-08-09   DALIM SOFTWARE ES Core 5.0 build 7184.1 - Server-Side Request Forgery 5 WEB LiquidWorm
2017-08-09   DALIM SOFTWARE ES Core 5.0 build 7184.1 - Directory Traversal 7 WEB LiquidWorm
2017-08-09   DALIM SOFTWARE ES Core 5.0 build 7184.1 - Cross-Site Scripting / Cross-Site Request Forgery 4 WEB LiquidWorm
2017-08-09   DALIM SOFTWARE ES Core 5.0 build 7184.1 - User Enumeration 5 WEB LiquidWorm
2017-08-08   Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution 6 WEB Kacper Szurek
2017-08-07   WordPress Plugin Easy Modal 2.0.17 - SQL Injection 5 WEB defensecode
2017-08-03   Technicolor TC7337 - 'SSID' Persistent Cross-Site Scripting 6 WEB Geolado giolado
2017-08-03   Joomla! Component StreetGuessr Game 1.1.8 - SQL Injection 5 WEB Ihsan Sencan
2017-08-02   Muviko 1.0 - 'q' SQL Injection 5 WEB Kaan KAMIS
2017-08-02   EDUMOD Pro 1.3 - SQL Injection 5 WEB Kaan KAMIS
2017-08-02   Premium Servers List Tracker 1.0 - SQL Injection 5 WEB Kaan KAMIS
2017-08-02   Joomla! Component Ultimate Property Listing 1.0.2 - SQL Injection 5 WEB Ihsan Sencan
2017-08-02   Joomla! Component Event Registration Pro Calendar 4.1.3 - SQL Injection 5 WEB Ihsan Sencan
2017-08-02   Joomla! Component LMS King Professional 3.2.4.0 - SQL Injection 5 WEB Ihsan Sencan
2017-08-02   Joomla! Component PHP-Bridge 1.2.3 - SQL Injection 5 WEB Ihsan Sencan
2017-08-02   Joomla! Component SIMGenealogy 2.1.5 - SQL Injection 5 WEB Ihsan Sencan
2017-08-02   Entrepreneur B2B Script - 'pid' SQL Injection 5 WEB Meisam Monsef
2017-08-01   JoySale 2.2.1 - Arbitrary File Upload 5 WEB Mutlu Benmutlu
2017-08-01   SOL.Connect ISET-mpp meter 1.2.4.2 - SQL Injection 5 WEB Andy Tan
2017-08-01   VehicleWorkshop - Arbitrary File Upload 5 WEB Touhid M.Shaikh
2017-08-01   VehicleWorkshop - Authentication Bypass 5 WEB Touhid M.Shaikh
2017-08-01   Advantech SUSIAccess < 3.0 - 'RecoveryMgmt' File Upload 5 WEB James Fitts
2017-08-01   Advantech SUSIAccess < 3.0 - Directory Traversal / Information Disclosure (Metasploit) 5 WEB James Fitts
2017-07-28   VehicleWorkshop - SQL Injection 5 WEB Shahab Shamsi
2017-03-15   GitHub Enterprise < 2.8.7 - Remote Code Execution 5 WEB orange
2017-07-28   Fortinet FortiOS < 5.6.0 - Cross-Site Scripting 5 WEB patryk_bogdan
2017-07-27   Joomla! Component CCNewsLetter 2.1.9 - 'sbid' SQL Injection 4 WEB Shahab Shamsi
2017-07-26   Friends in War Make or Break 1.7 - Cross-Site Request Forgery (Change Admin Password) 5 WEB shinnai
2017-07-26   Friends in War Make or Break 1.7 - SQL Injection 5 WEB Ihsan Sencan
2017-07-25   WordPress Plugin Ads Pro < 3.4 - Cross-Site Scripting / SQL Injection 4 WEB 8bitsec
2017-07-25   Friends in War Make or Break 1.7 - Authentication Bypass 5 WEB Adam
2017-07-25   WebKit JSC - 'JSObject::putInlineSlow' / 'JSValue::putToPrimitive' Universal Cross-Site Scripting 5 WEB Google Security Research
2017-07-24   REDDOXX Appliance Build 2032 / 2.0.625 - Arbitrary File Disclosure 6 WEB RedTeam Pentesting