Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2017-08-28   Car or Cab Booking Script - Authentication Bypass 3 WEB Ali BawazeEer
2017-08-29   D-Link DIR-600 - Authentication Bypass 2 WEB Jithin D Kurup
2017-08-28   NethServer 7.3.1611 - Cross-Site Request Forgery (Create User / Enable SSH Access) 3 WEB LiquidWorm
2017-08-28   NethServer 7.3.1611 - Cross-Site Request Forgery / Cross-Site Scripting 2 WEB LiquidWorm
2017-08-28   Schools Alert Management Script - Authentication Bypass 2 WEB Ali BawazeEer
2017-06-01   CMS Web-Gooroo < 1.141 - Multiple Vulnerabilities 3 WEB Kaimi
2017-08-28   Login-Reg Members Management PHP 1.0 - Arbitrary File Upload 3 WEB Ihsan Sencan
2017-08-28   Flash Poker 2.0 - 'game' SQL Injection 3 WEB Ihsan Sencan
2017-08-28   PHP Search Engine 1.0 - SQL Injection 3 WEB Ihsan Sencan
2017-08-28   Easy Web Search 4.0 - SQL Injection 4 WEB Ihsan Sencan
2017-08-28   WYSIWYG HTML Editor PRO 1.0 - Arbitrary File Download 3 WEB Ihsan Sencan
2017-08-28   FTP Made Easy PRO 1.2 - SQL Injection 3 WEB Ihsan Sencan
2017-08-28   Smart Chat 1.0.0 - SQL Injection 3 WEB Ihsan Sencan
2017-08-27   Matrimonial Script 2.7 - Authentication Bypass 3 WEB Ali BawazeEer
2017-08-25   Joomla! Component Responsive Portfolio 1.6.1 - SQL Injection 3 WEB Ihsan Sencan
2017-08-25   Joomla! Component Photo Contest 1.0.2 - SQL Injection 3 WEB Ihsan Sencan
2017-08-25   AutoCar 1.1 - 'category' SQL Injection 2 WEB Bora Bozdogan
2017-08-25   Joomla! Component OSDownloads 1.7.4 - SQL Injection 2 WEB Ihsan Sencan
2017-08-24   Joomla! Component Price Alert 3.0.2 - 'product_id' SQL Injection 3 WEB Ihsan Sencan
2017-08-24   Joomla! Component Bargain Product VM3 1.0 - 'product_id' SQL Injection 3 WEB Ihsan Sencan
2017-08-23   Wireless Repeater BE126 - Local File Inclusion 3 WEB Hay Mizrachi
2017-08-22   Matrimonial Script - SQL Injection 3 WEB Ihsan Sencan
2017-08-22   Automated Logic WebCTRL 6.5 - Unrestricted File Upload / Remote Code Execution 3 WEB LiquidWorm
2017-08-22   Automated Logic WebCTRL 6.1 - Path Traversal / Arbitrary File Write 3 WEB LiquidWorm
2017-08-21   PHPMyWind 5.3 - Cross-Site Scripting 3 WEB 小雨
2017-08-21   PHP Jokesite 2.0 - 'joke_id' SQL Injection 3 WEB Ihsan Sencan
2017-08-21   PHP-Lance 1.52 - 'subcat' SQL Injection 3 WEB Ihsan Sencan
2017-08-21   Joomla! Component Ajax Quiz 1.8 - SQL Injection 2 WEB Ihsan Sencan
2017-08-21   (Bitcoin / Dogecoin) PHP Cloud Mining Script - Authentication Bypass 2 WEB Ihsan Sencan
2017-08-21   Joomla! Component FocalPoint 1.2.3 - SQL Injection 1 WEB Ihsan Sencan
2017-08-21   iTech Social Networking Script 3.08 - SQL Injection 3 WEB Ihsan Sencan
2017-08-21   PHP Coupon Script 6.0 - 'cid' SQL Injection 3 WEB Ihsan Sencan
2017-08-21   Affiliate Niche Script 3.4.0 - SQL Injection 2 WEB Ihsan Sencan
2017-08-21   PHP Classifieds Script 5.6.2 - SQL Injection 3 WEB Ihsan Sencan
2017-08-21   Joomla! Component Sponsor Wall 8.0 - SQL Injection 3 WEB Ihsan Sencan
2017-08-21   Joomla! Component Flip Wall 8.0 - 'wallid' SQL Injection 3 WEB Ihsan Sencan
2017-08-21   Apache2Triad 1.5.4 - Multiple Vulnerabilities 3 WEB hyp3rlinx
2017-08-18   Symantec Messaging Gateway 10.6.3-2 - Root Remote Command Execution 3 WEB Philip Pettersson
2017-08-18   QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilities 3 WEB VVVSecurity
2017-08-18   iTech Movie Script 7.51 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   iTech Job Script 9.27 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   iTech Dating Script 3.40 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   iTech Multi Vendor Script 6.63 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   iTech Travel Script 9.49 - SQL Injection 2 WEB Ihsan Sencan
2017-08-18   iTech Freelancer Script 5.27 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   iTech Image Sharing Script 4.13 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   iTech Classifieds Script 7.41 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   iTech Caregiver Script 2.71 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   iTech Business Networking Script 8.26 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   iTech B2B Script 4.42 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   DeWorkshop 1.0 - Arbitrary File Upload 3 WEB Ihsan Sencan
2017-08-18   Joomla! Component SP Movie Database 1.3 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   Joomla! Component Calendar Planner 1.0.1 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   Joomla! Component Zap Calendar Lite 4.3.4 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   SOA School Management 3.0 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   eCardMAX 10.5 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   Matrimony Script 2.7 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   Joomla! Component KissGallery 1.0.0 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   Joomla! Component Twitch Tv 1.1 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   Joomla! Component Appointment 1.1 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   LiveProjects 1.0 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   LiveSales 1.0 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   LiveInvoices 1.0 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   LiveSupport 1.0 - SQL Injection 3 WEB Ihsan Sencan
2017-08-18   LiveCRM 1.0 - SQL Injection 3 WEB Ihsan Sencan
2017-08-17   Food Ordering Script 1.0 - SQL Injection 3 WEB Ihsan Sencan
2017-08-17   Doctor Patient Project 1.0 - SQL Injection 3 WEB Ihsan Sencan
2017-08-17   Photogallery Project 1.0 - SQL Injection 2 WEB Ihsan Sencan
2017-08-17   Online Quiz Project 1.0 - SQL Injection 3 WEB Ihsan Sencan
2017-08-15   AdvanDate iCupid Dating Software 12.2 - SQL Injection 2 WEB Ihsan Sencan
2017-08-15   ClipBucket 2.8.3 - Multiple Vulnerabilities 3 WEB bRpsd
2017-08-14   Quali CloudShell 7.1.0.6508 (Patch 6) - Persistent Cross-Site Scripting 3 WEB Benjamin Lee
2017-08-14   RPi Cam Control < 6.3.14 - Remote Command Execution 2 WEB Alexander Korznikov
2017-08-12   AirMaster 3000M - Multiple Vulnerabilities 3 WEB Mr.8Th BiT
2017-08-12   RealTime RWR-3G-100 Router - Cross-Site Request Forgery (Change Admin Password) 3 WEB Touhid M.Shaikh
2017-08-11   De-Tutor 1.0 - SQL Injection 2 WEB Ihsan Sencan
2017-08-11   De-Journal 1.0 - SQL Injection 2 WEB Ihsan Sencan
2017-08-11   DeWorkshop 1.0 - SQL Injection 3 WEB Ihsan Sencan
2017-08-10   Red-Gate SQL Monitor < 3.10 / 4.2 - Authentication Bypass 2 WEB Paul Taylor
2017-08-10   Piwigo Plugin User Tag 0.9.0 - Cross-Site Scripting 3 WEB Touhid M.Shaikh
2017-08-10   GIF Collection 2.0 - SQL Injection 3 WEB Ihsan Sencan
2017-08-10   ImageBay 1.0 - SQL Injection 3 WEB Ihsan Sencan
2017-08-09   WebFile Explorer 1.0 - Arbitrary File Download 3 WEB Ihsan Sencan
2017-08-09   DALIM SOFTWARE ES Core 5.0 build 7184.1 - Server-Side Request Forgery 3 WEB LiquidWorm
2017-08-09   DALIM SOFTWARE ES Core 5.0 build 7184.1 - Directory Traversal 3 WEB LiquidWorm
2017-08-09   DALIM SOFTWARE ES Core 5.0 build 7184.1 - Cross-Site Scripting / Cross-Site Request Forgery 2 WEB LiquidWorm
2017-08-09   DALIM SOFTWARE ES Core 5.0 build 7184.1 - User Enumeration 3 WEB LiquidWorm
2017-08-08   Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution 4 WEB Kacper Szurek
2017-08-07   WordPress Plugin Easy Modal 2.0.17 - SQL Injection 3 WEB defensecode
2017-08-03   Technicolor TC7337 - 'SSID' Persistent Cross-Site Scripting 4 WEB Geolado giolado
2017-08-03   Joomla! Component StreetGuessr Game 1.1.8 - SQL Injection 3 WEB Ihsan Sencan
2017-08-02   Muviko 1.0 - 'q' SQL Injection 3 WEB Kaan KAMIS
2017-08-02   EDUMOD Pro 1.3 - SQL Injection 2 WEB Kaan KAMIS
2017-08-02   Premium Servers List Tracker 1.0 - SQL Injection 3 WEB Kaan KAMIS
2017-08-02   Joomla! Component Ultimate Property Listing 1.0.2 - SQL Injection 3 WEB Ihsan Sencan
2017-08-02   Joomla! Component Event Registration Pro Calendar 4.1.3 - SQL Injection 3 WEB Ihsan Sencan
2017-08-02   Joomla! Component LMS King Professional 3.2.4.0 - SQL Injection 3 WEB Ihsan Sencan
2017-08-02   Joomla! Component PHP-Bridge 1.2.3 - SQL Injection 3 WEB Ihsan Sencan
2017-08-02   Joomla! Component SIMGenealogy 2.1.5 - SQL Injection 3 WEB Ihsan Sencan
2017-08-02   Entrepreneur B2B Script - 'pid' SQL Injection 3 WEB Meisam Monsef
2017-08-01   JoySale 2.2.1 - Arbitrary File Upload 3 WEB Mutlu Benmutlu
2017-08-01   SOL.Connect ISET-mpp meter 1.2.4.2 - SQL Injection 3 WEB Andy Tan
2017-08-01   VehicleWorkshop - Arbitrary File Upload 3 WEB Touhid M.Shaikh
2017-08-01   VehicleWorkshop - Authentication Bypass 3 WEB Touhid M.Shaikh
2017-08-01   Advantech SUSIAccess < 3.0 - 'RecoveryMgmt' File Upload 3 WEB James Fitts
2017-08-01   Advantech SUSIAccess < 3.0 - Directory Traversal / Information Disclosure (Metasploit) 3 WEB James Fitts
2017-07-28   VehicleWorkshop - SQL Injection 3 WEB Shahab Shamsi
2017-03-15   GitHub Enterprise < 2.8.7 - Remote Code Execution 3 WEB orange
2017-07-28   Fortinet FortiOS < 5.6.0 - Cross-Site Scripting 3 WEB patryk_bogdan
2017-07-27   Joomla! Component CCNewsLetter 2.1.9 - 'sbid' SQL Injection 3 WEB Shahab Shamsi
2017-07-26   Friends in War Make or Break 1.7 - Cross-Site Request Forgery (Change Admin Password) 3 WEB shinnai
2017-07-26   Friends in War Make or Break 1.7 - SQL Injection 3 WEB Ihsan Sencan
2017-07-25   WordPress Plugin Ads Pro < 3.4 - Cross-Site Scripting / SQL Injection 2 WEB 8bitsec
2017-07-25   Friends in War Make or Break 1.7 - Authentication Bypass 3 WEB Adam
2017-07-25   WebKit JSC - 'JSObject::putInlineSlow' / 'JSValue::putToPrimitive' Universal Cross-Site Scripting 3 WEB Google Security Research
2017-07-24   REDDOXX Appliance Build 2032 / 2.0.625 - Arbitrary File Disclosure 4 WEB RedTeam Pentesting
2017-07-24   REDDOXX Appliance Build 2032 / 2.0.625 - Remote Command Execution 3 WEB RedTeam Pentesting
2017-07-24   PaulShop - SQL Injection / Cross-Site Scripting 2 WEB BTIS Team
2017-07-24   ManageEngine Desktop Central 10 Build 100087 - Remote Code Execution (Metasploit) 3 WEB Kacper Szurek
2017-07-21   NEC UNIVERGE UM4730 < 11.8 - SQL Injection 4 WEB b0x41s
2017-07-20   VACRON VIG-US731VE 1.0.18-09-B727 IP Camera - Authentication Bypass 3 WEB Viktoras
2017-07-20   WordPress Plugin IBPS Online Exam 1.0 - SQL Injection / Cross-Site Scripting 3 WEB 8bitsec
2017-07-20   Tilde CMS 1.01 - Multiple Vulnerabilities 4 WEB Raffaele Forte
2017-07-20   Joomla! Component JoomRecipe 1.0.4 - 'search_author' SQL Injection 3 WEB Teng
2017-07-19   Citrix CloudBridge - 'CAKEPHP' Cookie Command Injection 2 WEB xort