Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2016-10-16   PHP Telephone Directory - Multiple Vulnerabilities 11 WEB larrycompress
2016-10-14   Health Record System 0.1 - Authentication Bypass 12 WEB lahilote
2016-10-14   Fashion Shopping Cart 0.1 - SQL Injection 10 WEB lahilote
2016-10-14   Learning Management System 0.1 - Authentication Bypass 9 WEB lahilote
2016-10-14   Simple Dynamic Web 0.1 - SQL Injection 10 WEB lahilote
2016-10-14   Web Based Alumni Tracking System 0.1 - SQL Injection 10 WEB lahilote
2016-10-14   Student Information System (SIS) 0.1 - Authentication Bypass 10 WEB lahilote
2016-10-14   YouTube Automated CMS 1.0.7 - Cross-Site Request Forgery / Persistent Cross-Site Scripting 10 WEB Arbin Godar
2016-10-14   Simple Forum PHP 2.4 - Cross-Site Request Forgery (Edit Options) 11 WEB Ehsan Hosseini
2016-10-14   Simple Forum PHP 2.4 - SQL Injection 10 WEB Ehsan Hosseini
2016-10-13   JonhCMS 4.5.1 - SQL Injection 10 WEB Besim
2016-10-13   RSS News AutoPilot Script 1.0.1/3.1.0 - Admin Panel Authentication Bypass 10 WEB Arbin Godar
2016-10-13   Colorful Blog - Cross-Site Request Forgery (Change Admin Password) 11 WEB Besim
2016-10-13   Colorful Blog - Persistent Cross-Site Scripting 10 WEB Besim
2016-10-13   Thatware 0.4.6 - SQL Injection 10 WEB Besim
2016-10-13   Simple Blog PHP 2.0 - SQL Injection 11 WEB Ehsan Hosseini
2016-10-13   Simple Blog PHP 2.0 - Multiple Vulnerabilities 10 WEB Ehsan Hosseini
2016-10-12   ApPHP MicroCMS 3.9.5 - Cross-Site Request Forgery (Add Admin) 9 WEB Besim
2016-10-12   ApPHP MicroCMS 3.9.5 - Persistent Cross-Site Scripting 11 WEB Besim
2016-10-12   OpenCimetiere 3.0.0-a5 - Blind SQL Injection 11 WEB Wadeek
2016-10-12   NetBilletterie 2.8 - Multiple Vulnerabilities 9 WEB Wadeek
2016-10-12   Categorizator 0.3.1 - SQL Injection 11 WEB Wadeek
2016-10-11   ApPHP MicroBlog 1.0.2 - Cross-Site Request Forgery (Add New Author) 13 WEB Besim
2016-10-11   ApPHP MicroBlog 1.0.2 - Persistent Cross-Site Scripting 11 WEB Besim
2016-10-11   RSA Enterprise Compromise Assessment Tool 4.1.0.1 - XML External Entity Injection 10 WEB SEC Consult
2016-10-11   AVTECH IP Camera / NVR / DVR Devices - Multiple Vulnerabilities 10 WEB Gergely Eberhardt
2016-10-11   phpEnter 4.2.7 - Cross-Site Request Forgery (Add New Post) 11 WEB Besim
2016-10-11   BirdBlog 1.4.0 - Cross-Site Request Forgery (Add New Post) 10 WEB Besim
2016-10-10   Spacemarc News - Cross-Site Request Forgery (Add New Post) 11 WEB Besim
2016-10-10   Maian Weblog 4.0 - Cross-Site Request Forgery (Add New Post) 11 WEB Besim
2016-10-09   PHP Press Release - Persistent Cross-Site Scripting 11 WEB Besim
2016-10-09   PHP Press Release - Cross-Site Request Forgery (Add Admin) 10 WEB Besim
2016-09-19   ShoreTel Connect ONSITE - Blind SQL Injection 10 WEB Iraklis Mathiopoulos
2016-10-09   miniblog 1.0.1 - Cross-Site Request Forgery (Add New Post) 9 WEB Besim
2016-10-07   Entrepreneur Job Portal Script 2.06 - SQL Injection 9 WEB OoN_Boy
2016-10-07   Simple PHP Blog 0.8.4 - Cross-Site Request Forgery (Add Admin) 13 WEB Besim
2016-10-06   Just Dial Clone Script - 'fid' SQL Injection 9 WEB OoN_Boy
2016-10-06   MLM Unilevel Plan Script 1.0.2 - SQL Injection 11 WEB N4TuraL
2016-10-06   B2B Portal Script - Blind SQL Injection 9 WEB OoN_Boy
2016-10-06   PHP Classifieds Rental Script - Blind SQL Injection 10 WEB OoN_Boy
2016-10-06   Advance MLM Script - SQL Injection 9 WEB OoN_Boy
2016-10-05   Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusion 9 WEB KoreLogic
2016-10-05   Cisco Firepower Threat Management Console 6.0.1 - Remote Command Execution 9 WEB KoreLogic
2016-10-05   Witbe - Remote Code Execution 8 WEB BeLmar
2016-10-05   Picosafe Web GUI - Multiple Vulnerabilities 10 WEB Shahab Shamsi
2016-09-28   Symantec Messaging Gateway 10.6.1 - Directory Traversal 10 WEB R-73eN
2016-09-27   TP-Link Archer CR-700 - Cross-Site Scripting 11 WEB Ayushman Dutta
2016-09-26   Joomla! Component Event Booking 2.10.1 - SQL Injection 11 WEB Persian Hack Team
2016-09-22   Matrimonial Website Script 1.0.2 - SQL Injection 12 WEB N4TuraL
2016-09-22   Kerio Control Unified Threat Management 9.1.0 build 1087/9.1.1 build 1324 - Multiple Vulnerabilities 14 WEB SEC Consult
2016-09-22   Joomla! Component com_videogallerylite 1.0.9 - SQL Injection 10 WEB Larry W. Cashdollar
2016-09-22   Exponent CMS 2.3.9 - Blind SQL Injection 13 WEB Manuel García Cárdenas
2016-09-22   Microix Timesheet Module - SQL Injection 14 WEB Anthony Cole
2016-09-20   Dolphin 7.3.0 - Error-Based SQL Injection 13 WEB Kacper Szurek
2016-09-20   VegaDNS 0.13.2 - Remote Command Injection 14 WEB Wireghoul
2016-09-19   ZineBasic 1.1 - Arbitrary File Disclosure 13 WEB bd0rk
2016-09-19   MuM MapEdit 3.2.6.0 - Multiple Vulnerabilities 11 WEB Paul Baade & Sven Krewitt
2016-09-19   MyBB 1.8.6 - SQL Injection 12 WEB Curesec Research Team
2016-09-19   Kajona 4.7 - Cross-Site Scripting / Directory Traversal 12 WEB Curesec Research Team
2016-09-19   WordPress Plugin Order Export Import for WooCommerce - Order Information Disclosure 15 WEB david-peltier
2016-09-19   BuilderEngine 3.5.0 - Arbitrary File Upload 12 WEB metanubix
2016-09-16   AnoBBS 1.0.1 - Remote File Inclusion 12 WEB bd0rk
2016-09-15   Cisco EPC 3925 - Multiple Vulnerabilities 14 WEB Patryk Bogdan
2016-09-13   Open-Xchange App Suite 7.8.2 - Cross-Site Scripting 10 WEB Jakub A>>oczek
2016-09-13   Open-Xchange Guard 2.4.2 - Multiple Cross-Site Scripting Vulnerabilities 12 WEB Benjamin Daniel Mussler
2016-09-13   ASUS DSL-X11 ADSL Router - DNS Change 14 WEB Todor Donev
2016-09-13   COMTREND ADSL Router CT-5367 C01_R12 / CT-5624 C01_R03 - DNS Change 13 WEB Todor Donev
2016-09-13   Tenda ADSL2/2+ Modem 963281TAN - DNS Change 17 WEB Todor Donev
2016-09-13   PLANET VDR-300NU ADSL Router - DNS Change 16 WEB Todor Donev
2016-09-13   PIKATEL 96338WS_ 96338L-2M-8M - DNS Change 12 WEB Todor Donev
2016-09-13   Inteno EG101R1 VoIP Router - DNS Change 12 WEB Todor Donev
2016-09-13   Exper EWM-01 ADSL/MODEM - DNS Change 16 WEB Todor Donev
2016-09-13   Contrexx CMS egov Module 1.0.0 - SQL Injection 17 WEB hamidreza borghei
2016-09-13   wdCalendar 2 - SQL Injection 20 WEB Alfonso Castillo Angel
2016-09-13   Cherry Music 0.35.1 - Arbitrary File Disclosure 17 WEB feedersec
2016-09-09   Airmail 3.0.2 - Cross-Site Scripting 15 WEB redrain
2016-09-09   Vodafone Mobile Wifi - Reset Admin Password 11 WEB Daniele Linguaglossa
2016-09-08   Zabbix 2.0 < 3.0.3 - SQL Injection 14 WEB Zzzians
2016-09-08   Jobberbase 2.0 - Multiple Vulnerabilities 15 WEB Ross Marks
2016-09-07   Adobe ColdFusion < 11 Update 10 - XML External Entity Injection 13 WEB Dawid Golunski
2016-09-07   FreePBX 13.0.x < 13.0.154 - Remote Command Execution 13 WEB i-Hmx
2016-09-07   CumulusClips 2.4.1 - Multiple Vulnerabilities 13 WEB kor3k
2016-09-06   PHPIPAM 1.2.1 - Multiple Vulnerabilities 10 WEB Saeed reza Zamanian
2016-09-05   WordPress Plugin RB Agency 2.4.7 - Local File Disclosure 13 WEB Persian Hack Team
2016-09-04   Belkin F9K1122v1 1.00.30 - Buffer Overflow (via Cross-Site Request Forgery) 12 WEB b1ack0wl
2016-08-31   ZKTeco ZKAccess Security System 5.3.1 - Persistent Cross-Site Scripting 14 WEB LiquidWorm
2016-08-31   ZKTeco ZKBioSecurity 3.0 - 'visLogin.jsp' Local Authentication Bypass 12 WEB LiquidWorm
2016-08-31   ZKTeco ZKBioSecurity 3.0 - Directory Traversal 13 WEB LiquidWorm
2016-08-31   ZKTeco ZKBioSecurity 3.0 - Cross-Site Request Forgery (Add Superadmin) 15 WEB LiquidWorm
2016-08-31   ZKTeco ZKBioSecurity 3.0 - Hard-Coded Credentials SYSTEM Remote Code Execution 16 WEB LiquidWorm
2016-08-29   FreePBX 13.0.35 - SQL Injection 17 WEB i-Hmx
2016-08-29   PLC Wireless Router GPN2.4P21-C-CN - Arbitrary File Disclosure 14 WEB Rahul Raz
2016-08-29   Intellinet IP Camera INT-L100M20N - Unauthorized Admin Credential Change 14 WEB Todor Donev
2016-08-29   HelpDeskZ 1.0.2 - Arbitrary File Upload 14 WEB Lars Morgenroth
2016-08-29   FreePBX 13.0.35 - Remote Command Execution 12 WEB 0x4148
2016-08-24   WordPress Plugin CYSTEME Finder 1.3 - Arbitrary File Disclosure/Arbitrary File Upload 13 WEB T0w3ntum
2016-08-23   chatNow - Multiple Vulnerabilities 13 WEB HaHwul
2016-08-23   SimplePHPQuiz - Blind SQL Injection 12 WEB HaHwul
2016-08-23   WordPress Plugin Mail Masta 1.0 - Local File Inclusion 13 WEB Guillermo Garcia Marcos
2016-08-22   WordPress Core 4.5.3 - Directory Traversal / Denial of Service 13 WEB Yorick Koster
2016-08-22   Sakai 10.7 - Multiple Vulnerabilities 11 WEB LiquidWorm
2016-08-22   Ocomon 2.0 - SQL Injection 10 WEB Jonatas Fil
2016-08-22   VideoIQ Camera - Local File Disclosure 13 WEB Yakir Wizman
2016-08-22   Honeywell IP-Camera HICC-1100PT - Local File Disclosure 10 WEB Yakir Wizman
2016-08-22   JVC IP-Camera VN-T216VPRU - Local File Disclosure 9 WEB Yakir Wizman
2016-08-22   Vanderbilt IP-Camera CCPW3025-IR / CVMW3025-IR - Local File Disclosure 12 WEB Yakir Wizman
2016-08-19   tcPbX - 'tcpbx_lang' Local File Inclusion 12 WEB 0x4148
2016-08-19   MESSOA IP Cameras (Multiple Models) - Password Change 10 WEB Todor Donev
2016-08-19   Fortigate Firewalls - 'EGREGIOUSBLUNDER' Remote Code Execution 12 WEB Shadow Brokers
2016-08-19   TOPSEC Firewalls - 'ELIGIBLEBOMBSHELL' Remote Code Execution 11 WEB Shadow Brokers
2016-08-19   TOPSEC Firewalls - 'ELIGIBLECANDIDATE' Remote Code Execution 10 WEB Shadow Brokers
2016-08-19   TOPSEC Firewalls - 'ELIGIBLECONTESTANT' Remote Code Execution 10 WEB Shadow Brokers
2016-08-19   ZYCOO IP Phone System - Remote Command Execution 10 WEB 0x4148
2016-08-19   MESSOA IP-Camera NIC990 - Authentication Bypass / Configuration Download 10 WEB Todor Donev
2016-08-19   TOSHIBA IP-Camera IK-WP41A - Authentication Bypass / Configuration Download 8 WEB Todor Donev
2016-08-19   C2S DVR Management IRDOME-II-C2S / IRBOX-II-C2S / DVR - Credentials Disclosure / Authentication Bypa 10 WEB Yakir Wizman
2016-08-19   JVC IP-Camera VN-T216VPRU - Credentials Disclosure 12 WEB Yakir Wizman
2016-08-19   Vanderbilt IP-Camera CCPW3025-IR / CVMW3025-IR - Credentials Disclosure 11 WEB Yakir Wizman
2016-08-19   SIEMENS IP Cameras (Multiple Models) - Credential Disclosure / Configuration Download 12 WEB Todor Donev
2016-08-18   Honeywell IP-Camera HICC-1100PT - Credentials Disclosure 11 WEB Yakir Wizman
2016-08-18   SIEMENS IP Camera CCMW1025 x.2.2.1798 - Remote Admin Credentials Change 11 WEB Todor Donev
2016-08-17   SIEMENS IP-Camera CVMS2025-IR / CCMS2025 - Credentials Disclosure 13 WEB Yakir Wizman
2016-08-16   Nagios Incident Manager 2.0.0 - Multiple Vulnerabilities 12 WEB Security-Assessment.com
2016-08-16   Nagios Network Analyzer 2.2.0 - Multiple Vulnerabilities 11 WEB Security-Assessment.com
2016-08-16   Nagios Log Server 1.4.1 - Multiple Vulnerabilities 10 WEB Security-Assessment.com