Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2012-04-26   Concrete5 CMS 5.5.2.1 - Information Disclosure / SQL Injection / Cross-Site Scripting 2 WEB Jakub Galczyk
2012-04-24   Joomla! Component com_videogallery - Local File Inclusion / SQL Injection 2 WEB KedAns-Dz
2012-04-23   Joomla! Component CCNewsLetter 1.0.7 - 'id' SQL Injection 2 WEB E1nzte1N
2012-04-20   Waylu CMS - '/products_xx.php' SQL Injection / HTML Injection 2 WEB TheCyberNuxbie
2012-04-20   Anchor CMS 0.6-14-ga85d0a0 - 'id' Multiple HTML Injection Vulnerabilities 2 WEB Gjoko Krstic
2012-04-20   Pendulab ChatBlazer 8.5 - 'Username' Cross-Site Scripting 2 WEB sonyy
2012-04-18   ownCloud 3.0.0 - 'index.php?redirect_url' Arbitrary Site Redirect 2 WEB Tobias Glemser
2012-04-18   XOOPS 2.5.4 - '/tiny_mce/plugins/xoopsimagemanager/xoopsimagebrowser.php' Multiple Cross-Site Script 2 WEB High-Tech Bridge SA
2012-04-18   XOOPS 2.5.4 - '/modules/pm/pmlite.php?to_userid' Cross-Site Scripting 2 WEB High-Tech Bridge SA
2012-04-17   Acuity CMS 2.6.2 - 'Username' Cross-Site Scripting 1 WEB Aung Khant
2012-04-17   Joomla! Component JA T3 Framework - Directory Traversal 1 WEB indoushka
2012-04-17   TeamPass 2.1.5 - 'login' HTML Injection 2 WEB Marcos Garcia
2012-04-16   WordPress Plugin Yahoo Answer - Multiple Cross-Site Scripting Vulnerabilities 2 WEB Ryuzaki Lawlet
2012-04-15   Seditio CMS 165 - 'plug.php' SQL Injection 2 WEB AkaStep
2012-04-13   Munin 2.0~rc4-1 - Remote Command Injection 2 WEB Helmut Grohne
2012-04-16   Joomla! Plugin Beatz 1.1 - Multiple Cross-Site Scripting Vulnerabilities 2 WEB Aung Khant
2012-04-16   Bioly 1.3 - '/index.php' Cross-Site Scripting / SQL Injection 2 WEB T0xic
2015-05-21   WordPress Plugin WP Symposium 15.1 - '&show=' SQL Injection 2 WEB Hannes Trunde
2015-05-21   Forma LMS 1.3 - Multiple SQL Injections 2 WEB Filippo Roncari
2012-04-11   WordPress Plugin All-in-One Event Calendar 1.4 - 'agenda-widget.php' Multiple Cross-Site Scripting V 2 WEB High-Tech Bridge SA
2012-04-11   WordPress Plugin All-in-One Event Calendar 1.4 - 'save_successful.php?msg' Cross-Site Scripting 2 WEB High-Tech Bridge SA
2012-04-11   WordPress Plugin All-in-One Event Calendar 1.4 - 'box_publish_button.php?button_value' Cross-Site Sc 2 WEB High-Tech Bridge SA
2012-04-11   WordPress Plugin All-in-One Event Calendar 1.4 - 'agenda-widget-form.php?title' Cross-Site Scripting 2 WEB High-Tech Bridge SA
2015-05-21   WordPress Plugin WP Membership 1.2.3 - Multiple Vulnerabilities 2 WEB Panagiotis Vagenas
2012-04-11   BGS CMS 2.2.1 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities 2 WEB LiquidWorm
2012-04-10   Matterdaddy Market 1.1 - 'cat_name' Multiple SQL Injections 2 WEB Chokri B.A
2012-04-09   CitrusDB 2.4.1 - Local File Inclusion / SQL Injection 2 WEB wacky
2012-04-06   WordPress Plugin Uploadify Integration 0.9.6 - Multiple Cross-Site Scripting Vulnerabilities 2 WEB waraxe
2015-05-20   WordPress Plugin FeedWordPress 2015.0426 - SQL Injection 1 WEB Adrián M. F.
2012-04-05   WordPress Plugin TagGator - 'tagid' SQL Injection 1 WEB Am!r
2012-04-04   vBulletin 4.1.10 - 'announcementid' SQL Injection 1 WEB Am!r
2015-05-18   ManageEngine EventLog Analyzer 10.0 Build 10001 - Cross-Site Request Forgery 1 WEB Akash S. Chavan
2015-05-18   OYO File Manager 1.1 (iOS / Android) - Multiple Vulnerabilities 1 WEB Vulnerability-Lab
2015-05-18   Wireless Photo Transfer 3.0 iOS - Local File Inclusion 1 WEB Vulnerability-Lab
2015-05-18   Forma LMS 1.3 - Multiple PHP Object Injection Vulnerabilities 0 WEB Filippo Roncari
2015-05-18   ElasticSearch < 1.4.5 / < 1.5.2 - Directory Traversal 1 WEB pandujar
2015-05-18   Chronosite 5.12 - SQL Injection 1 WEB Wadeek
2012-04-04   osCMax 2.5 - '/admin/stats_monthly_sales.php?status' SQL Injection 1 WEB High-Tech Bridge SA
2012-04-04   osCMax 2.5 - '/admin/login.php?Username' SQL Injection 1 WEB High-Tech Bridge SA
2012-04-04   osCMax 2.5 - '/admin/new_attributes_include.php' Multiple Cross-Site Scripting Vulnerabilities 1 WEB High-Tech Bridge SA
2012-04-04   osCMax 2.5 - '/admin/geo_zones.php?zID' Cross-Site Scripting 1 WEB High-Tech Bridge SA
2012-04-04   osCMax 2.5 - '/admin/information_manager.php?information_id' Cross-Site Scripting 1 WEB High-Tech Bridge SA
2012-04-04   osCMax 2.5 - '/admin/stats_customers.php?sorted' Cross-Site Scripting 1 WEB High-Tech Bridge SA
2012-04-04   osCMax 2.5 - '/admin/stats_monthly_sales.php?status' Cross-Site Scripting 0 WEB High-Tech Bridge SA
2012-04-04   osCMax 2.5 - '/admin/stats_products_purchased.php' Multiple Cross-Site Scripting Vulnerabilities 1 WEB High-Tech Bridge SA
2012-04-04   osCMax 2.5 - '/admin/xsell.php?search' Cross-Site Scripting 1 WEB High-Tech Bridge SA
2012-04-04   osCMax 2.5 - '/admin/htaccess.php' Multiple Cross-Site Scripting Vulnerabilities 1 WEB High-Tech Bridge SA
2012-04-04   osCMax 2.5 - '/admin/login.php?Username' Cross-Site Scripting 2 WEB High-Tech Bridge SA
2012-04-01   FlatnuX CMS - Cross-Site Request Forgery (Add Admin) 3 WEB Vulnerability Laboratory
2012-04-01   FlatnuX CMS - Traversal Arbitrary File Access 2 WEB Vulnerability Laboratory
2012-04-02   JBMC Software DirectAdmin 1.403 - 'domain' Cross-Site Scripting 2 WEB Dawid Golak
2012-04-01   ManageEngine Firewall Analyzer 7.2 - 'fw/syslogViewer.do?port' Cross-Site Scripting 2 WEB Vulnerability Research Laboratory
2012-04-01   ManageEngine Firewall Analyzer 7.2 - 'fw/mindex.do?url' Cross-Site Scripting 2 WEB Vulnerability Research Laboratory
2012-04-01   ManageEngine Firewall Analyzer 7.2 - 'fw/createAnomaly.do?subTab' Cross-Site Scripting 2 WEB Vulnerability Research Laboratory
2012-04-01   ManageEngine Firewall Analyzer 7.2 - '/fw/index2.do' Multiple Cross-Site Scripting Vulnerabilities 2 WEB Vulnerability Research Laboratory
2012-03-30   JamWiki 1.1.5 - 'num' Cross-Site Scripting 2 WEB Sooraj K.S
2012-03-29   Simple Machines Forum (SMF) 2.0.2 - 'scheduled' Cross-Site Scripting 2 WEB Am!r
2012-03-30   e107 1.0 - 'view' SQL Injection 2 WEB Am!r
2012-03-30   PHP Designer 2007 Personal - Multiple SQL Injections 2 WEB MR.XpR
2012-03-29   EZ Publish 4.x 'ezjscore' Module - Cross-Site Scripting 1 WEB Yann MICHARD
2012-03-29   EasyPHP - 'main.php' SQL Injection 2 WEB Skote Vahshat
2012-03-28   ocPortal 7.1.5 - 'code_editor.php' Multiple Cross-Site Scripting Vulnerabilities 2 WEB High-Tech Bridge
2012-03-28   TomatoCart 1.2.0 Alpha 2 - 'json.php' Local File Inclusion 2 WEB Canberk BOLAT
2013-03-27   MyBB 1.6.6 - 'index.php?conditions[usergroup][]' Cross-Site Scripting 2 WEB Aditya Modha
2013-03-27   MyBB 1.6.6 - 'index.php?conditions[usergroup][]' SQL Injection 2 WEB Aditya Modha
2012-03-28   Invision Power Board (IP.Board) 4.2.1 - 'searchText' Cross-Site Scripting 2 WEB sonyy
2012-03-28   WordPress Plugin Integrator 1.32 - 'redirect_to' Cross-Site Scripting 2 WEB Stefan Schurtz
2012-03-27   Matthew1471 BlogX - Multiple Cross-Site Scripting Vulnerabilities 2 WEB demonalex
2012-03-27   NextBBS 0.6 - 'index.php?do' Cross-Site Scripting 2 WEB waraxe
2012-03-27   NextBBS 0.6 - 'ajaxserver.php' Multiple SQL Injections 1 WEB waraxe
2012-03-27   Geeklog 1.8.1 - 'index.php' SQL Injection 2 WEB HELLBOY
2012-03-25   Zumset.com FbiLike 1.00 - 'id' Cross-Site Scripting 1 WEB Crim3R
2012-03-23   Apache Struts 2.0 - 'XSLTResult.java' Arbitrary File Upload 1 WEB voidloafer
2012-03-24   Event Calendar PHP - 'cal_year' Cross-Site Scripting 2 WEB 3spi0n
2012-03-21   Minify 2.1.x - 'g' Cross-Site Scripting 2 WEB Ayoub Aboukir
2015-05-13   PHPCollab 2.5 - 'deletetopics.php' SQL Injection 2 WEB Wadeek
2015-05-13   WordPress Plugin Booking Calendar Contact Form 1.0.2 - Multiple Vulnerabilities 2 WEB i0akiN SEC-LABORATORY
2012-03-21   Open Journal Systems (OJS) 2.3.6 - 'rfiles.php' Traversal Arbitrary File Manipulation 2 WEB High-Tech Bridge
2012-03-21   Open Journal Systems (OJS) 2.3.6 - Multiple Script Arbitrary File Upload 2 WEB High-Tech Bridge
2012-03-21   Open Journal Systems (OJS) 2.3.6 - '/lib/pkp/classes/core/String.inc.php?String::stripUnsafeHtml()' 2 WEB High-Tech Bridge
2012-03-21   Open Journal Systems (OJS) 2.3.6 - 'index.php?authors[][url]' Cross-Site Scripting 1 WEB High-Tech Bridge
2012-03-21   CMSimple 3.3 - 'index.php' Cross-Site Scripting 2 WEB Stefan Schurtz
2009-04-17   WebGlimpse 2.18.7 - 'DOC' Directory Traversal 2 WEB MustLive
2015-05-11   SQLBuddy 1.3.3 - Directory Traversal 1 WEB hyp3rlinx
2015-05-11   Wing FTP Server Admin 4.4.5 - Cross-Site Request Forgery (Add User) 1 WEB hyp3rlinx
2015-05-11   eFront 3.6.15 - PHP Object Injection 2 WEB Filippo Roncari
2015-05-11   eFront 3.6.15 - Directory Traversal 2 WEB Filippo Roncari
2015-05-11   eFront 3.6.15 - Multiple SQL Injections 2 WEB Filippo Roncari
2015-05-11   D-Link DSL-500B Gen 2 - URL Filter Configuration Panel Persistent Cross-Site Scripting 2 WEB XLabs Security
2015-05-11   D-Link DSL-500B Gen 2 - Parental Control Configuration Panel Persistent Cross-Site Scripting 2 WEB XLabs Security
2015-05-11   Pluck CMS 4.7 - Directory Traversal 0 WEB Wadeek
2015-05-11   WordPress Plugin N-Media Website Contact Form with File Upload 1.3.4 - Arbitrary File Upload (2) 1 WEB Claudio Viviani & F17.c0de
2015-05-11   ZTE F660 - Remote Configuration Download 1 WEB Daniel Cisa
2012-03-11   CreateVision CMS - 'id' SQL Injection 0 WEB Zwierzchowski Oskar
2012-03-18   WebGlimpse 2.x - 'wgarcmin.cgi' Full Path Disclosure 1 WEB Websecurity
2012-03-19   ClassifiedsGeek.com Vacation Packages - 'listing_search' SQL Injection 1 WEB r45c4l
2012-03-20   WebGlimpse 2.14.1/2.18.8 - 'webglimpse.cgi' Remote Command Injection 1 WEB Kevin Perry
2012-03-20   GNUBoard 4.34.20 - 'download.php' HTML Injection 1 WEB wh1ant
2012-03-18   JavaBB 0.99 - 'userId' Cross-Site Scripting 1 WEB sonyy
2012-03-16   JPM Article Script 6 - 'page2' SQL Injection 1 WEB Vulnerability Research Laboratory
2012-03-14   Max's PHP Photo Album 1.0 - 'id' Local File Inclusion 1 WEB n0tch
2012-03-14   Max's Guestbook 1.0 - Multiple Remote Vulnerabilities 1 WEB n0tch
2012-03-13   Omnistar Live - Cross-Site Scripting / SQL Injection 2 WEB sonyy
2015-05-08   Alienvault OSSIM/USM 4.14/4.15/5.0 - Multiple Vulnerabilities 2 WEB Peter Lapp
2015-05-08   WordPress Plugin Ad Inserter 1.5.2 - Cross-Site Request Forgery 2 WEB Kaustubh G. Padwad
2015-05-08   Manage Engine Asset Explorer 6.1.0 Build: 6110 - Cross-Site Request Forgery 2 WEB Kaustubh G. Padwad
2015-05-08   WordPress Plugin ClickBank Ads 1.7 - Cross-Site Request Forgery 2 WEB Kaustubh G. Padwad
2015-05-08   WordPress Plugin Ultimate Profile Builder 2.3.3 - Cross-Site Request Forgery 2 WEB Kaustubh G. Padwad
2015-05-08   WordPress Plugin Yet Another Related Posts 4.2.4 - Cross-Site Request Forgery 2 WEB Evex
2015-05-08   SynTail 1.5 Build 566 - Multiple Vulnerabilities 2 WEB Marlow Tannhauser
2015-05-08   WordPress Plugin N-Media Website Contact Form with File Upload 1.5 - Local File Inclusion 2 WEB T3N38R15
2015-05-08   SynaMan 3.4 Build 1436 - Multiple Vulnerabilities 1 WEB Marlow Tannhauser
2015-05-08   Syncrify Server 3.6 Build 833 - Multiple Vulnerabilities 1 WEB Marlow Tannhauser
2015-05-08   Xeams 4.5 Build 5755 - Multiple Vulnerabilities 1 WEB Marlow Tannhauser
2012-03-12   Wikidforum 2.10 - Advanced Search Multiple Cross-Site Scripting Vulnerabilities 1 WEB Stefan Schurtz
2012-03-12   Wikidforum 2.10 - Search Field Cross-Site Scripting 2 WEB Stefan Schurtz
2012-03-12   Wikidforum 2.10 - Advanced Search Multiple Field SQL Injections 2 WEB Stefan Schurtz
2012-03-12   Synology Photo Station 5 DSM 3.2 - 'photo_one.php' Script Cross-Site Scripting 2 WEB Simon Ganiere
2015-05-07   Album Streamer 2.0 iOS - Directory Traversal 2 WEB Vulnerability-Lab
2015-05-07   WordPress Plugin Freshmail 1.5.8 - 'shortcode.php' SQL Injection 3 WEB Felipe Molina
2015-05-07   IBM Websphere Portal - Persistent Cross-Site Scripting 2 WEB Filippo Roncari
2015-05-07   Dell SonicWALL Secure Remote Access (SRA) Appliance - Cross-Site Request Forgery 2 WEB Veit Hailperin
2012-03-11   EJBCA 4.0.7 - 'issuer' Cross-Site Scripting 1 WEB MustLive
2012-03-11   Singapore 0.10.1 - 'gallery' Cross-Site Scripting 2 WEB T0xic
2012-03-09   PHPMyVisites 2.4 - 'PHPmv2/index.php' Multiple Cross-Site Scripting Vulnerabilities 2 WEB AkaStep