Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2014-05-28   WordPress Plugin WP Rss Poster - '/wp-admin/admin.php' SQL Injection 3 WEB Anant Shrivastava
2014-05-28   WordPress Plugin BookX 1.7 - 'bookx_export.php' Local File Inclusion 3 WEB Anant Shrivastava
2014-07-13   WordPress Plugin DZS-VideoGallery - Cross-Site Scripting / Command Injection 3 WEB MustLive
2014-07-10   WeBid - Multiple Cross-Site Scripting / LDAP Injection Vulnerabilities 2 WEB Govind Singh
2016-01-15   mcart.xls Bitrix Module 6.5.2 - SQL Injection 3 WEB High-Tech Bridge SA
2016-01-15   Roundcube Webmail 1.1.3 - Directory Traversal 3 WEB High-Tech Bridge SA
2016-01-15   phpDolphin 2.0.5 - Multiple Vulnerabilities 3 WEB WhiteCollarGroup
2016-01-15   GlassFish Server - Arbitrary File Read 2 WEB bingbing
2014-07-09   WordPress Plugin BSK PDF Manager - '/wp-admin/admin.php' Multiple SQL Injections 3 WEB Claudio Viviani
2014-07-07   xClassified - 'ads.php' SQL Injection 2 WEB Lazmania61
2014-07-07   AtomCMS - SQL Injection / Arbitrary File Upload 2 WEB Jagriti Sahu
2014-05-19   WordPress Plugin NextGEN Gallery 1.9.1 - 'photocrati_ajax' Arbitrary File Upload 2 WEB SANTHO
2016-01-14   Manage Engine Application Manager 12.5 - Arbitrary Command Execution 2 WEB Bikramaditya Guha
2016-01-14   Manage Engine Applications Manager 12 - Multiple Vulnerabilities 3 WEB Bikramaditya Guha
2016-01-14   SevOne NMS 5.3.6.0 - Remote Command Execution 3 WEB @iamsecurity
2016-01-13   WhatsUp Gold 16.3 - Remote Code Execution 3 WEB Matt Buzanowski
2014-06-24   ZeusCart - 'prodid' SQL Injection 3 WEB Kenny Mathis
2014-06-10   WordPress Plugin Featured Comments - Cross-Site Request Forgery 2 WEB Tom Adams
2014-06-10   WordPress Plugin JW Player for Flash & HTML5 Video - Cross-Site Request Forgery 3 WEB Tom Adams
2014-06-08   WordPress Theme Infocus - '/infocus/lib/scripts/dl-skin.php' Local File Disclosure 3 WEB Felipe Andrian Peixoto
2014-05-15   Seo Panel - 'file' Directory Traversal 3 WEB Eric Sesterhenn
2014-05-28   webEdition CMS - 'we_fs.php' SQL Injection 3 WEB RedTeam Pentesting GmbH
2016-01-08   WordPress Plugin WP Symposium Pro Social Network Plugin 15.12 - Multiple Vulnerabilities 3 WEB Rahul Pratap Singh
2014-05-24   PHP-Nuke 'Submit_News' Component - SQL Injection 4 WEB ali ahmady
2014-05-23   Pyplate - 'addScript.py' Cross-Site Request Forgery 3 WEB Henri Salo
2014-05-25   User Cake - Cross-Site Request Forgery 4 WEB Dolev Farhi
2014-05-21   WordPress Plugin Booking System (Booking Calendar) - 'booking_form_id' SQL Injection 4 WEB maodun
2016-01-07   OpenMRS Reporting Module 0.9.7 - Remote Code Execution 3 WEB Brian D. Hysell
2016-01-07   D-Link DCS-931L - Arbitrary File Upload (Metasploit) 4 WEB Metasploit
2014-05-20   Clipperz Password Manager - '/backend/PHP/src/setup/rpc.php' Remote Code Execution 4 WEB Manish Tanwar
2014-05-18   WordPress Plugin cnhk-Slideshow - Arbitrary File Upload 4 WEB Ashiyane Digital Security Team
2014-05-19   Softmatica SMART iPBX - Multiple SQL Injections 4 WEB AtT4CKxT3rR0r1ST
2014-05-19   XOOPS Glossaire Module - '/modules/glossaire/glossaire-aff.php' SQL Injection 3 WEB AtT4CKxT3rR0r1ST
2014-05-16   CIS Manager - 'email' SQL Injection 4 WEB Edge
2016-01-06   MediaAccess TG788vn - File Disclosure 4 WEB 0x4148
2014-05-08   CMS Touch - 'news.php?News_ID' SQL Injection 3 WEB indoushka
2014-05-08   CMS Touch - 'pages.php?Page_ID' SQL Injection 4 WEB indoushka
2014-05-08   TOA - Cross-Site Request Forgery 4 WEB High-Tech Bridge
2014-05-07   Caldera - '/costview2/printers.php?tr' SQL Injection 4 WEB Thomas Fischer
2014-05-07   Caldera - '/costview2/jobs.php?tr' SQL Injection 4 WEB Thomas Fischer
2014-05-05   PrestaShop - 'getSimilarManufacturer.php?id_manufacturer' SQL Injection 3 WEB indoushka
2016-01-05   PHPIPAM 1.1.010 - Multiple Vulnerabilities 4 WEB Mickael Dorigny
2016-01-05   Atlassian Confluence 5.2/5.8.14/5.8.15 - Multiple Vulnerabilities 4 WEB Sebastian Perez
2016-01-05   Simple PHP Polling System - Multiple Vulnerabilities 3 WEB WICS
2016-01-05   Online Airline Booking System - Multiple Vulnerabilities 3 WEB Manish Tanwar
2014-04-06   Puntopy - 'novedad.php' SQL Injection 4 WEB Felipe Andrian Peixoto
2014-04-02   ZamFoo - Multiple Remote Command Execution Vulnerabilities 5 WEB Al-Shabaab
2014-04-22   iDevAffiliate - 'idevads.php' SQL Injection 3 WEB Robert Cooper
2016-01-02   Open Audit - SQL Injection 3 WEB Rahul Pratap Singh
2014-04-14   Jigowatt PHP Event Calendar - 'day_view.php' SQL Injection 3 WEB Daniel Godoy
2014-04-14   Xangati XSR / XNR - 'gui_input_test.pl' Remote Command Execution 3 WEB Jan Kadijk
2014-04-14   Xangati - '/servlet/Installer?file' Directory Traversal 3 WEB Jan Kadijk
2014-04-14   Xangati - '/servlet/MGConfigData' Multiple Directory Traversals 3 WEB Jan Kadijk
2014-04-09   eazyCMS - 'index.php' SQL Injection 3 WEB Renzi
2014-04-08   Joomla! Component Inneradmission - 'index.php' SQL Injection 3 WEB Lazmania61
2014-04-05   PHPFox - Access Control Security Bypass 4 WEB Wesley Henrique
2014-03-31   Primo Interactive CMS - 'pcm.cgi' Remote Command Execution 3 WEB Felipe Andrian Peixoto
2014-03-24   Symphony 2.2.4 - Cross-Site Request Forgery 3 WEB High-Tech Bridge
2014-03-23   WordPress Theme Felici - 'Uploadify.php' Arbitrary File Upload 2 WEB CaFc Versace
2015-12-30   WordPress Plugin Simple Ads Manager 2.9.4.116 - SQL Injection 2 WEB Kacper Szurek
2014-03-26   Beheer Systeem - 'pbs.cgi' Remote Command Execution 2 WEB Felipe Andrian Peixoto
2014-03-26   DotItYourself - 'dot-it-yourself.cgi' Remote Command Execution 3 WEB Felipe Andrian Peixoto
2014-03-25   qEngine 4.1.6/6.0.0 - 'task.php' Local File Inclusion 3 WEB Gjoko Krstic
2014-02-21   Jorjweb - 'id' SQL Injection 3 WEB Vulnerability Laboratory
2014-03-21   innoEDIT - 'innoedit.cgi' Remote Command Execution 3 WEB Felipe Andrian Peixoto
2014-03-19   BigACE 2.7.5 - 'LANGUAGE' Directory Traversal 3 WEB Hossein Hezami
2014-03-10   MeiuPic 2.1.2 - 'ctl' Local File Inclusion 2 WEB Dr.3v1l
2014-03-17   osCMax 2.5 - Cross-Site Request Forgery 4 WEB TUNISIAN CYBER
2014-03-15   OpenX 2.8.x - Multiple Cross-Site Request Forgery Vulnerabilities 4 WEB Mahmoud Ghorbanzadeh
2014-03-19   GNUBoard 4.3x - 'ajax.autosave.php' Multiple SQL Injections 2 WEB Claepo Wang
2014-03-08   Professional Designer E-Store - 'id' Multiple SQL Injections 3 WEB Nawaf Alkeraithe
2014-03-06   WordPress Plugin Premium Gallery Manager - Arbitrary File Upload 2 WEB eX-Sh1Ne
2014-03-05   Cory Jobs Search - 'cid' SQL Injection 3 WEB Slotleet
2014-03-04   WordPress Plugin Relevanssi - 'category_name' SQL Injection 3 WEB anonymous
2014-02-26   POSH 3.1.x - 'addtoapplication.php' SQL Injection 3 WEB Anthony BAUBE
2014-02-22   ATutor - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities 4 WEB HauntIT
2014-02-22   eshtery CMS - 'FileManager.aspx' Local File Disclosure 2 WEB peng.deng
2014-02-18   MODx Evogallery Module - 'Uploadify.php' Arbitrary File Upload 2 WEB TUNISIAN CYBER
2014-02-19   WordPress Plugin NextGEN Gallery - 'jqueryFileTree.php' Directory Traversal 3 WEB Tom Adams
2014-02-12   Rhino - Cross-Site Scripting / Password Reset 2 WEB Slotleet
2014-02-17   Joomla! Component com_wire_immogest - 'index.php' SQL Injection 4 WEB MR.XpR
2014-02-17   i-doit Pro - 'objID' SQL Injection 4 WEB Stephan Rickauer
2015-12-24   Rips Scanner 0.5 - 'code.php' Local File Inclusion 3 WEB Ashiyane Digital Security Team
2015-12-24   Beezfud - Remote Code Execution 3 WEB Ashiyane Digital Security Team
2014-02-05   WordPress Theme Kiddo - Arbitrary File Upload 4 WEB TUNISIAN CYBER
2013-12-13   Joomla! Component Projoom NovaSFH 3.0.2 - 'upload.php' Arbitrary File Upload 5 WEB Yuri Kramarz
2014-02-05   Singapore 0.9.9b Beta - Image Gallery Remote File Inclusion / Cross-Site Scripting 3 WEB TUNISIAN CYBER
2015-12-23   PhpSocial 2.0.0304_20222226 - Cross-Site Request Forgery 3 WEB Curesec Research Team
2015-12-23   Arastta 1.1.5 - SQL Injection 3 WEB Curesec Research Team
2015-12-23   Grawlix 1.0.3 - Cross-Site Request Forgery 2 WEB Curesec Research Team
2015-12-23   Bigware Shop 2.3.01 - Multiple Local File Inclusions 3 WEB bd0rk
2013-03-25   Atmail WebMail - 'INBOX.Trash?mailId' Reflected Cross-Site Scripting 3 WEB Vicente Aguilera Diaz
2013-03-25   Atmail WebMail - 'searchResultsTab5?filter' Reflected Cross-Site Scripting 3 WEB Vicente Aguilera Diaz
2013-03-25   Atmail WebMail - Message Attachment File Name Reflected Cross-Site Scripting 3 WEB Vicente Aguilera Diaz
2014-01-22   Web Video Streamer - Multiple Vulnerabilities 3 WEB Eric Sesterhenn
2015-12-21   Ovidentia Widgets 1.0.61 - Remote Command Execution 3 WEB bd0rk
2015-12-21   Ovidentia online Module 2.8 - 'GLOBALS[babAddonPhpPath]' Remote File Inclusion 3 WEB bd0rk
2014-01-28   Eventum 2.3.4 - 'hostname' Remote Code Execution 3 WEB High-Tech Bridge
2014-01-27   Eventum - Insecure File Permissions 3 WEB High-Tech Bridge
2014-01-24   Maian Uploader 4.0 - Multiple Vulnerabilities 3 WEB KedAns-Dz
2014-01-24   WordPress Plugin WP E-Commerce - Multiple Vulnerabilities 3 WEB KedAns-Dz
2014-01-24   ZenPhoto - SQL Injection 2 WEB KedAns-Dz
2014-01-24   XOS Shop - 'goto' SQL Injection 2 WEB JoKeR_StEx
2014-01-18   WordPress Plugin Global Flash Gallery - 'swfupload.php' Arbitrary File Upload 3 WEB Ashiyane Digital Security Team
2014-01-21   Imageview - 'upload.php' Arbitrary File Upload 2 WEB TUNISIAN CYBER
2014-01-13   Dell Kace 1000 Systems Management Appliance DS-2014-001 - Multiple SQL Injections 2 WEB Rohan Stelling
2015-12-18   pfSense 2.2.5 - Directory Traversal 3 WEB R-73eN
2015-12-18   Ovidentia maillist Module 4.0 - Remote File Inclusion 3 WEB bd0rk
2015-12-18   Joomla! 1.5 < 3.4.6 - Object Injection 'x-forwarded-for' Header Remote Code Execution 3 WEB Andrew McNicol
2014-01-17   BloofoxCMS 0.5.0 - 'fileurl' Local File Inclusion 3 WEB AtT4CKxT3rR0r1ST
2014-01-17   BloofoxCMS - '/admin/index.php' Cross-Site Request Forgery (Add Admin) 3 WEB AtT4CKxT3rR0r1ST
2014-01-17   BloofoxCMS - '/bloofox/admin/index.php?Username' SQL Injection 3 WEB AtT4CKxT3rR0r1ST
2014-01-17   BloofoxCMS - '/bloofox/index.php?Username' SQL Injection 3 WEB AtT4CKxT3rR0r1ST
2014-01-16   Joomla! Component Sexy polling 1.0.8 - 'answer_id' SQL Injection 3 WEB High-Tech Bridge
2015-12-17   Zen Cart 1.5.4 - Local File Inclusion 2 WEB High-Tech Bridge SA
2014-01-10   Joomla! Component Almond Classifieds - Arbitrary File Upload 2 WEB DevilScreaM
2014-01-14   Atmail Webmail Server - Email Body HTML Injection 2 WEB Zhao Liang
2014-01-08   EZGenerator - Local File Disclosure / Cross-Site Request Forgery 1 WEB AtT4CKxT3rR0r1ST
2014-01-08   Built2Go PHP Shopping - Cross-Site Request Forgery (Admin Password) 2 WEB AtT4CKxT3rR0r1ST
2014-01-08   UAEPD Shopping Script - 'news.php?id' SQL Injection 2 WEB AtT4CKxT3rR0r1ST
2014-01-08   UAEPD Shopping Script - 'products.php' Multiple SQL Injections 1 WEB AtT4CKxT3rR0r1ST
2015-12-16   Ovidentia NewsLetter Module 2.2 - 'admin.php' Remote File Inclusion 3 WEB bd0rk
2015-12-15   ArticleSetup Article Script 1.00 - SQL Injection 3 WEB Linux Zone Research Team
2015-12-15   Ovidentia bulletindoc Module 2.9 - Multiple Remote File Inclusions 3 WEB bd0rk
2014-01-07   Dredge School Administration System - '/DSM/Backup/processbackup.php' Database Backup Information Di 3 WEB AtT4CKxT3rR0r1ST