Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2013-09-19   WordPress Plugin RokIntroScroller - 'thumb.php' Multiple Vulnerabilities 4 WEB MustLive
2015-11-19   Horde Groupware 5.2.10 - Cross-Site Request Forgery 4 WEB High-Tech Bridge SA
2015-11-19   Netwin SurgeFTP Sever 23d6 - Persistent Cross-Site Scripting 3 WEB Un_N0n
2013-09-17   WordPress Plugin RokStories - 'thumb.php' Multiple Vulnerabilities 3 WEB MustLive
2013-09-18   WordPress Plugin RokNewsPager - 'thumb.php' Multiple Vulnerabilities 3 WEB MustLive
2013-09-13   WordPress Plugin mukioplayer4wp - 'cid' SQL Injection 3 WEB Ashiyane Digital Security Team
2013-09-10   eTransfer Lite - 'file name' HTML Injection 3 WEB Benjamin Kunz Mejri
2013-09-07   WordPress Plugin Event Easy Calendar - Multiple Cross-Site Request Forgery Vulnerabilities 3 WEB anonymous
2015-11-18   WordPress Plugin Users Ultra 1.5.50 - Unrestricted Arbitrary File Upload 2 WEB Panagiotis Vagenas
2013-09-03   Flo CMS - 'archivem' SQL Injection 2 WEB ACC3SS
2013-09-03   dBlog CMS - 'm' SQL Injection 3 WEB ACC3SS
2013-08-21   Xibo - Cross-Site Request Forgery 3 WEB Jacob Holcomb
2013-08-21   Xibo - 'layout' HTML Injection 2 WEB Jacob Holcomb
2013-08-29   appRain CMF - Multiple Cross-Site Request Forgery Vulnerabilities 4 WEB Yashar shahinzadeh
2013-08-26   cm3 Acora CMS - 'top.aspx' Information Disclosure 3 WEB Pedro Andujar
2013-08-23   SearchBlox - Multiple Information Disclosure Vulnerabilities 3 WEB Ricky Roane Jr
2013-07-31   Plone - 'in_portal.py' < 4.1.3 Session Hijacking 3 WEB Cyrill Bannwart
2013-08-21   Twilight CMS - DeWeS Web Server Directory Traversal 3 WEB High-Tech Bridge
2015-11-16   ClipperCMS 1.3.0 - Multiple SQL Injections 3 WEB Curesec Research Team
2015-11-16   AlegroCart 1.2.8 - Local/Remote File Inclusion 3 WEB Curesec Research Team
2015-11-16   AlegroCart 1.2.8 - Multiple SQL Injections 3 WEB Curesec Research Team
2013-08-20   Bo-Blog 2.1.1 - Cross-Site Scripting / SQL Injection 3 WEB Ashiyane Digital Security Team
2013-07-16   MCImageManager - Multiple Vulnerabilities 3 WEB MustLive
2015-11-16   D-Link DIR-816L Wireless Router - Cross-Site Request Forgery 3 WEB Bhadresh Patel
2015-11-16   VideoLAN VLC Media Player Web Interface 2.2.1 - Metadata Title Cross-Site Scripting 3 WEB Andrea Sindoni
2015-11-16   CF Image Host 1.65 - PHP Command Injection 2 WEB hyp3rlinx
2015-11-16   CF Image Host 1.65 - Cross-Site Request Forgery 0 WEB hyp3rlinx
2013-08-15   ACal 2.2.6 - 'view' Local File Inclusion 2 WEB ICheer_No0M
2013-08-13   DotNetNuke 6.1.x - Cross-Site Scripting 2 WEB Sajjad Pourali
2013-08-13   CakePHP 2.2.8/2.3.7 - AssetDispatcher Class Local File Inclusion 3 WEB Takeshi Terada
2013-08-08   Advanced Guestbook - 'addentry.php' Arbitrary File Upload 4 WEB Ashiyane Digital Security Team
2013-08-07   Kwok Information Server - Multiple SQL Injections 4 WEB Yogesh Phadtare
2013-08-01   SilverStripe CMS - 'MemberLoginForm.php' Information Disclosure 3 WEB Fara Rustein
2015-11-13   b374k 3.2.3/2.8 (Web Shell) - Cross-Site Request Forgery / Command Injection 4 WEB hyp3rlinx
2015-11-12   R-Scripts Vacation Rental Script 7R - Multiple Vulnerabilities 3 WEB LiquidWorm
2013-07-31   Jahia xCM - '/administration/' Multiple Cross-Site Scripting Vulnerabilities 2 WEB High-Tech Bridge
2013-07-31   Jahia xCM - '/engines/manager.jsp?site' Cross-Site Scripting 3 WEB High-Tech Bridge
2013-07-25   Alienvault Open Source SIEM (OSSIM) - Multiple Cross-Site Scripting Vulnerabilities 4 WEB xistence
2015-11-11   WordPress Plugin WP Fastest Cache 0.8.4.8 - Blind SQL Injection 3 WEB Kacper Szurek
2013-07-24   vBulletin 4.0.2 - 'update_order' SQL Injection 3 WEB n3tw0rk
2013-07-24   WordPress Plugin Duplicator - Cross-Site Scripting 4 WEB High-Tech Bridge
2013-07-24   Magnolia CMS - Multiple Cross-Site Scripting Vulnerabilities 3 WEB High-Tech Bridge
2013-07-22   WordPress Plugin FlagEm - 'cID' Cross-Site Scripting 3 WEB IeDb ir
2013-07-22   Collabtive - Multiple Vulnerabilities 3 WEB Enrico Cinquini
2015-11-10   YesWiki 0.2 - 'template' Directory Traversal 5 WEB HaHwul
2015-11-10   Jenkins 1.633 - Credential Recovery 3 WEB The Repo
2015-11-09   TestLink 1.9.14 - Cross-Site Request Forgery 4 WEB Aravind C Ajayan_ Balagopal N
2015-11-09   Arris TG1682G Modem - Persistent Cross-Site Scripting 3 WEB Nu11By73
2013-07-11   PrestaShop - Multiple Cross-Site Request Forgery Vulnerabilities 4 WEB EntPro Cyber Security Research Group
2013-07-12   Corda .NET Redirector - 'redirector.corda' Cross-Site Scripting 3 WEB Adam Willard
2013-07-12   OpenEMR 4.1 - 'note' HTML Injection 3 WEB Nate Drier
2013-07-12   Corda Highwire - 'Highwire.ashx' Full Path Disclosure 3 WEB Adam Willard
2015-11-07   Google AdWords 6.2.0 API client libraries - XML eXternal Entity Injection 3 WEB Dawid Golunski
2015-11-07   eBay Magento CE 1.9.2.1 - Unrestricted Cron Script (Code Execution / Denial of Service) 2 WEB Dawid Golunski
2015-11-07   Google AdWords API PHP client library 6.2.0 - Arbitrary PHP Code Execution 2 WEB Dawid Golunski
2015-11-06   WordPress Plugin My Calendar 2.4.10 - Multiple Vulnerabilities 3 WEB Mysticism
2015-11-06   NXFilter 3.0.3 - Multiple Cross-Site Scripting Vulnerabilities 3 WEB hyp3rlinx
2015-11-06   NXFilter 3.0.3 - Cross-Site Request Forgery 4 WEB hyp3rlinx
2013-07-12   WordPress Plugin Pie Register - 'wp-login.php' Multiple Cross-Site Scripting Vulnerabilities 5 WEB gravitylover
2013-07-12   S9Y Serendipity 1.6.2 - 'serendipity_admin_image_selector.php' Cross-Site Scripting 4 WEB Omar Kurt
2015-11-05   JSSE - SKIP-TLS 3 WEB Ramon de C Valle
2015-11-05   OpenSSL - Alternative Chains Certificate Forgery 3 WEB Ramon de C Valle
2013-07-11   WordPress Plugin miniBB - SQL Injection / Multiple Cross-Site Scripting Vulnerabilities 4 WEB Netsparker
2013-07-10   Mintboard - Multiple Cross-Site Scripting Vulnerabilities 4 WEB Canberk BOLAT
2013-07-10   iVote - 'details.php' SQL Injection 4 WEB Ashiyane Digital Security Team
2013-07-06   phpVibe 3.1 - Information Disclosure / Remote File Inclusion 2 WEB indoushka
2015-11-05   vBulletin 5.1.x - Remote Code Execution 3 WEB hhjj
2013-05-29   HostBill - 'cpupdate.php' Authentication Bypass 3 WEB localhost.re
2013-07-02   WordPress Plugin Category Grid View Gallery - 'ID' Cross-Site Scripting 3 WEB Iranian Exploit DataBase
2013-07-02   WordPress Plugin WP Feed - 'nid' SQL Injection 3 WEB Iranian Exploit DataBase
2013-06-30   WordPress Plugin Xorbin Digital Flash Clock - 'widgetUrl' Cross-Site Scripting 3 WEB Prakhar Prasad
2013-06-30   WordPress Plugin Xorbin Analog Flash Clock - 'widgetUrl' Cross-Site Scripting 2 WEB Prakhar Prasad
2013-06-30   Atomy Maxsite - 'index.php' Arbitrary File Upload 2 WEB Iranian_Dark_Coders_Team
2013-06-29   WordPress Plugin WP Private Messages - 'msgid' SQL Injection 2 WEB IeDb ir
2013-06-29   Nameko - 'nameko.php' Cross-Site Scripting 2 WEB Andrea Menin
2012-06-28   Mobile USB Drive HD - Multiple Local File Inclusion / Arbitrary File Upload Vulnerabilities 2 WEB Benjamin Kunz Mejri
2015-11-02   actiTIME 2015.2 - Multiple Vulnerabilities 3 WEB LiquidWorm
2013-06-15   ZamFoo - 'date' Remote Command Injection 3 WEB localhost.re
2013-06-26   Xaraya - Multiple Cross-Site Scripting Vulnerabilities 3 WEB High-Tech Bridge
2013-06-25   Barnraiser Prairie - 'get_file.php' Directory Traversal 2 WEB prairie
2013-06-24   FtpLocate - HTML Injection 2 WEB Chako
2013-06-19   Joomla! Component com_rokdownloads - Arbitrary File Upload 4 WEB Am!r
2013-06-18   et-chat - Privilege Escalation / Arbitrary File Upload 3 WEB MR.XpR
2013-06-17   BloofoxCMS - 'index.php' Arbitrary File Upload 5 WEB CWH Underground
2013-06-12   WordPress Plugin NextGEN Gallery - 'upload.php' Arbitrary File Upload 3 WEB Marcos Garcia
2015-10-30   Oxwall 1.7.4 - Cross-Site Request Forgery 2 WEB High-Tech Bridge SA
2015-10-30   Pligg CMS 2.0.2 - Cross-Site Request Forgery / Code Execution 3 WEB Curesec Research Team
2015-10-30   Pligg CMS 2.0.2 - Directory Traversal 3 WEB Curesec Research Team
2015-10-30   Pligg CMS 2.0.2 - Multiple SQL Injections 3 WEB Curesec Research Team
2015-10-30   Hitron Router CGN3ACSMR 4.5.8.16 - Arbitrary Code Execution 1 WEB Dolev Farhi
2015-10-30   PHP Server Monitor 3.1.1 - Cross-Site Request Forgery / Privilege Escalation 2 WEB hyp3rlinx
2015-10-30   eBay Magento 1.9.2.1 - PHP FPM XML eXternal Entity Injection 1 WEB Dawid Golunski
2015-10-30   PHP Server Monitor 3.1.1 - Multiple Cross-Site Request Forgery Vulnerabilities 2 WEB hyp3rlinx
2013-06-11   mkCMS - 'index.php' Arbitrary PHP Code Execution 1 WEB CWH Underground
2013-06-10   ScriptCase - 'scelta_categoria.php' SQL Injection 2 WEB Hossein Hezami
2013-06-10   Lokboard - 'index_4.php' PHP Code Injection 2 WEB CWH Underground
2013-06-09   WordPress Theme Ambience - 'src' Cross-Site Scripting 3 WEB Darksnipper
2013-06-09   Max Forum - Multiple Vulnerabilities 3 WEB CWH Underground
2015-10-29   Joomla! Component com_jnews 8.5.1 - SQL Injection 4 WEB Omer Ramić
2013-06-10   HP Insight Diagnostics 9.4.0.4710 - Local File Inclusion 3 WEB Markus Wulftange
2013-06-10   HP Insight Diagnostics - Remote Code Injection 3 WEB Markus Wulftange
2013-06-07   Caucho Resin - 'index.php?logout' Cross-Site Scripting 3 WEB Gjoko Krstic
2013-06-07   Caucho Resin - '/resin-admin/' URI Cross-Site Scripting 1 WEB Gjoko Krstic
2015-10-28   Sagem FAST3304-V2 - Authentication Bypass (2) 3 WEB Soufiane Alami Hassani
2015-10-28   JIRA and HipChat for JIRA Plugin - Velocity Template Injection 4 WEB Chris Wood
2013-06-05   QNAP VioStor NVR / QNAP NAS - Remote Code Execution 4 WEB Tim Herres
2013-06-03   Telaen - Information Disclosure 3 WEB Manuel García Cárdenas
2013-06-04   CMS Gratis Indonesia - 'config.php' PHP Code Injection 2 WEB CWH Underground
2013-06-04   Telaen 2.7.x - Open Redirection 2 WEB Manuel García Cárdenas
2013-06-04   Telaen 2.7.x - Cross-Site Scripting 3 WEB Manuel García Cárdenas
2013-05-28   Elastix - Multiple Cross-Site Scripting Vulnerabilities 3 WEB cheki
2012-05-31   PHP4dvd - 'config.php' PHP Code Injection 3 WEB CWH Underground
2013-05-27   WordPress Plugin ADIF Log Search Widget - 'logbook_search.php' Cross-Site Scripting 3 WEB k3170makan
2015-10-26   Joomla! 3.2.x < 3.4.4 - SQL Injection 2 WEB Manish Tanwar
2015-10-23   Joomla! Component Realtyna RPL 8.9.2 - Persistent Cross-Site Scripting / Cross-Site Request Forgery 1 WEB Bikramaditya Guha
2015-10-23   Joomla! Component Realtyna RPL 8.9.2 - Multiple SQL Injections 3 WEB Bikramaditya Guha
2015-10-23   Subrion 3.x - Multiple Vulnerabilities 4 WEB bRpsd
2013-05-24   Matterdaddy Market - Multiple Vulnerabilities 3 WEB KedAns-Dz
2013-05-23   Weyal CMS - Multiple SQL Injections 4 WEB XroGuE
2013-05-16   WordPress Plugin WP Cleanfix - Cross-Site Request Forgery 4 WEB Enigma Ideas
2013-05-15   Jojo CMS - 'x-forwarded-for' HTTP header SQL Injection 4 WEB High-Tech Bridge SA
2013-05-15   Jojo CMS - 'search' Cross-Site Scripting 4 WEB High-Tech Bridge SA
2013-05-16   WordPress Plugin Mail On Update - Cross-Site Request Forgery 3 WEB Henri Salo
2013-05-14   Open Flash Chart - 'get-data' Cross-Site Scripting 3 WEB Deepankar Arora
2013-05-15   WordPress Plugin wp-FileManager - 'path' Arbitrary File Download 4 WEB ByEge