2009-04-17
|
|
WebGlimpse 2.18.7 - 'DOC' Directory Traversal
|
3 |
WEB
|
MustLive
|
2015-05-11
|
|
SQLBuddy 1.3.3 - Directory Traversal
|
4 |
WEB
|
hyp3rlinx
|
2015-05-11
|
|
Wing FTP Server Admin 4.4.5 - Cross-Site Request Forgery (Add User)
|
2 |
WEB
|
hyp3rlinx
|
2015-05-11
|
|
eFront 3.6.15 - PHP Object Injection
|
2 |
WEB
|
Filippo Roncari
|
2015-05-11
|
|
eFront 3.6.15 - Directory Traversal
|
3 |
WEB
|
Filippo Roncari
|
2015-05-11
|
|
eFront 3.6.15 - Multiple SQL Injections
|
3 |
WEB
|
Filippo Roncari
|
2015-05-11
|
|
D-Link DSL-500B Gen 2 - URL Filter Configuration Panel Persistent Cross-Site Scripting
|
3 |
WEB
|
XLabs Security
|
2015-05-11
|
|
D-Link DSL-500B Gen 2 - Parental Control Configuration Panel Persistent Cross-Site Scripting
|
2 |
WEB
|
XLabs Security
|
2015-05-11
|
|
Pluck CMS 4.7 - Directory Traversal
|
0 |
WEB
|
Wadeek
|
2015-05-11
|
|
WordPress Plugin N-Media Website Contact Form with File Upload 1.3.4 - Arbitrary File Upload (2)
|
2 |
WEB
|
Claudio Viviani & F17.c0de
|
2015-05-11
|
|
ZTE F660 - Remote Configuration Download
|
3 |
WEB
|
Daniel Cisa
|
2012-03-11
|
|
CreateVision CMS - 'id' SQL Injection
|
1 |
WEB
|
Zwierzchowski Oskar
|
2012-03-18
|
|
WebGlimpse 2.x - 'wgarcmin.cgi' Full Path Disclosure
|
3 |
WEB
|
Websecurity
|
2012-03-19
|
|
ClassifiedsGeek.com Vacation Packages - 'listing_search' SQL Injection
|
3 |
WEB
|
r45c4l
|
2012-03-20
|
|
WebGlimpse 2.14.1/2.18.8 - 'webglimpse.cgi' Remote Command Injection
|
3 |
WEB
|
Kevin Perry
|
2012-03-20
|
|
GNUBoard 4.34.20 - 'download.php' HTML Injection
|
2 |
WEB
|
wh1ant
|
2012-03-18
|
|
JavaBB 0.99 - 'userId' Cross-Site Scripting
|
2 |
WEB
|
sonyy
|
2012-03-16
|
|
JPM Article Script 6 - 'page2' SQL Injection
|
2 |
WEB
|
Vulnerability Research Laboratory
|
2012-03-14
|
|
Max's PHP Photo Album 1.0 - 'id' Local File Inclusion
|
4 |
WEB
|
n0tch
|
2012-03-14
|
|
Max's Guestbook 1.0 - Multiple Remote Vulnerabilities
|
2 |
WEB
|
n0tch
|
2012-03-13
|
|
Omnistar Live - Cross-Site Scripting / SQL Injection
|
3 |
WEB
|
sonyy
|
2015-05-08
|
|
Alienvault OSSIM/USM 4.14/4.15/5.0 - Multiple Vulnerabilities
|
2 |
WEB
|
Peter Lapp
|
2015-05-08
|
|
WordPress Plugin Ad Inserter 1.5.2 - Cross-Site Request Forgery
|
3 |
WEB
|
Kaustubh G. Padwad
|
2015-05-08
|
|
Manage Engine Asset Explorer 6.1.0 Build: 6110 - Cross-Site Request Forgery
|
2 |
WEB
|
Kaustubh G. Padwad
|
2015-05-08
|
|
WordPress Plugin ClickBank Ads 1.7 - Cross-Site Request Forgery
|
2 |
WEB
|
Kaustubh G. Padwad
|
2015-05-08
|
|
WordPress Plugin Ultimate Profile Builder 2.3.3 - Cross-Site Request Forgery
|
2 |
WEB
|
Kaustubh G. Padwad
|
2015-05-08
|
|
WordPress Plugin Yet Another Related Posts 4.2.4 - Cross-Site Request Forgery
|
3 |
WEB
|
Evex
|
2015-05-08
|
|
SynTail 1.5 Build 566 - Multiple Vulnerabilities
|
2 |
WEB
|
Marlow Tannhauser
|
2015-05-08
|
|
WordPress Plugin N-Media Website Contact Form with File Upload 1.5 - Local File Inclusion
|
2 |
WEB
|
T3N38R15
|
2015-05-08
|
|
SynaMan 3.4 Build 1436 - Multiple Vulnerabilities
|
3 |
WEB
|
Marlow Tannhauser
|
2015-05-08
|
|
Syncrify Server 3.6 Build 833 - Multiple Vulnerabilities
|
3 |
WEB
|
Marlow Tannhauser
|
2015-05-08
|
|
Xeams 4.5 Build 5755 - Multiple Vulnerabilities
|
2 |
WEB
|
Marlow Tannhauser
|
2012-03-12
|
|
Wikidforum 2.10 - Advanced Search Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Stefan Schurtz
|
2012-03-12
|
|
Wikidforum 2.10 - Search Field Cross-Site Scripting
|
2 |
WEB
|
Stefan Schurtz
|
2012-03-12
|
|
Wikidforum 2.10 - Advanced Search Multiple Field SQL Injections
|
2 |
WEB
|
Stefan Schurtz
|
2012-03-12
|
|
Synology Photo Station 5 DSM 3.2 - 'photo_one.php' Script Cross-Site Scripting
|
3 |
WEB
|
Simon Ganiere
|
2015-05-07
|
|
Album Streamer 2.0 iOS - Directory Traversal
|
2 |
WEB
|
Vulnerability-Lab
|
2015-05-07
|
|
WordPress Plugin Freshmail 1.5.8 - 'shortcode.php' SQL Injection
|
4 |
WEB
|
Felipe Molina
|
2015-05-07
|
|
IBM Websphere Portal - Persistent Cross-Site Scripting
|
2 |
WEB
|
Filippo Roncari
|
2015-05-07
|
|
Dell SonicWALL Secure Remote Access (SRA) Appliance - Cross-Site Request Forgery
|
3 |
WEB
|
Veit Hailperin
|
2012-03-11
|
|
EJBCA 4.0.7 - 'issuer' Cross-Site Scripting
|
3 |
WEB
|
MustLive
|
2012-03-11
|
|
Singapore 0.10.1 - 'gallery' Cross-Site Scripting
|
3 |
WEB
|
T0xic
|
2012-03-09
|
|
PHPMyVisites 2.4 - 'PHPmv2/index.php' Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
AkaStep
|
2012-03-08
|
|
SAP Business Objects InfoView System - '/webi/webi_modify.aspx?id' Cross-Site Scripting
|
3 |
WEB
|
vulns@dionach.com
|
2012-03-08
|
|
SAP Business Objects InfoView System - '/help/helpredir.aspx?guide' Cross-Site Scripting
|
2 |
WEB
|
vulns@dionach.com
|
2012-03-08
|
|
SAP Business Objects InfoVew System - 'listing.aspx?searchText' Cross-Site Scripting
|
2 |
WEB
|
vulns@dionach.com
|
2015-05-07
|
|
WordPress Plugin Freshmail 1.5.8 - SQL Injection
|
3 |
WEB
|
Felipe Molina
|
2012-03-08
|
|
Ilient SysAid 8.5.5 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
|
4 |
WEB
|
Julien Ahrens
|
2012-03-08
|
|
ToendaCMS 1.6.2 - '/setup/index.php?site' Traversal Local File Inclusion
|
4 |
WEB
|
AkaStep
|
2012-03-08
|
|
LeKommerce - 'id' SQL Injection
|
3 |
WEB
|
Mazt0r
|
2015-05-06
|
|
elFinder 2 - Remote Command Execution (via File Creation)
|
3 |
WEB
|
TUNISIAN CYBER
|
2015-05-06
|
|
PDF Converter & Editor 2.1 iOS - Local File Inclusion
|
3 |
WEB
|
Vulnerability-Lab
|
2015-05-06
|
|
vPhoto-Album 4.2 iOS - Local File Inclusion
|
4 |
WEB
|
Vulnerability-Lab
|
2012-03-07
|
|
OSClass 2.3.x - Directory Traversal / Arbitrary File Upload
|
4 |
WEB
|
Filippo Cavallarin
|
2012-03-07
|
|
Exponent CMS 2.0 - 'src' SQL Injection
|
4 |
WEB
|
Rob Miller
|
2012-03-06
|
|
Fork CMS 3.2.x - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
|
3 |
WEB
|
Gjoko Krstic
|
2012-03-05
|
|
Joomla! 2.5.1 - 'redirect.php' Blind SQL Injection
|
3 |
WEB
|
Colin Wong
|
2012-03-05
|
|
11in1 CMS 1.2.1 - 'admin/tps?id' SQL Injection
|
3 |
WEB
|
Chokri B.A
|
2012-03-05
|
|
11in1 CMS 1.2.1 - 'admin/comments?topicID' SQL Injection
|
3 |
WEB
|
Chokri B.A
|
2012-03-05
|
|
Open Realty 2.5.x - 'select_users_template' Local File Inclusion
|
3 |
WEB
|
Aung Khant
|
2015-05-04
|
|
WordPress Plugin Ultimate Product Catalogue 3.1.2 - Multiple Persistent Cross-Site Scripting / Cross
|
3 |
WEB
|
Felipe Molina
|
2015-05-04
|
|
PhotoWebsite 3.1 iOS - Local File Inclusion
|
4 |
WEB
|
Vulnerability-Lab
|
2012-03-05
|
|
Etano 1.20/1.22 - 'photo_view.php?return' Cross-Site Scripting
|
3 |
WEB
|
Aung Khant
|
2012-03-05
|
|
Etano 1.20/1.22 - 'photo_search.php' Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Aung Khant
|
2012-03-05
|
|
Etano 1.20/1.22 - 'search.php' Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Aung Khant
|
2012-03-04
|
|
LastGuru ASP Guestbook - 'View.asp' SQL Injection
|
3 |
WEB
|
demonalex
|
2012-03-02
|
|
starCMS - 'q' URI Cross-Site Scripting
|
4 |
WEB
|
Am!r
|
2012-02-28
|
|
Fork CMS 3.x - '/backend/modules/error/actions/index.php?parse()' Multiple Error Display Cross-Site
|
4 |
WEB
|
anonymous
|
2012-02-28
|
|
Fork CMS 3.x - '/private/en/locale/index?name' Cross-Site Scripting
|
3 |
WEB
|
anonymous
|
2012-02-29
|
|
Traidnt Topics Viewer 2.0 - 'main.php' Cross-Site Request Forgery
|
4 |
WEB
|
Green Hornet
|
2012-02-29
|
|
Dotclear 2.4.1.2 - '/admin/plugin.php?page' Cross-Site Scripting
|
4 |
WEB
|
High-Tech Bridge SA
|
2012-02-29
|
|
Dotclear 2.4.1.2 - '/admin/comments.php' Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
High-Tech Bridge SA
|
2012-02-29
|
|
Dotclear 2.4.1.2 - '/admin/blogs.php?nb' Cross-Site Scripting
|
5 |
WEB
|
High-Tech Bridge SA
|
2012-02-29
|
|
Dotclear 2.4.1.2 - '/admin/auth.php?login_data' Cross-Site Scripting
|
4 |
WEB
|
High-Tech Bridge SA
|
2012-02-27
|
|
OSQA's CMS - Multiple HTML Injection Vulnerabilities
|
4 |
WEB
|
Ucha Gobejishvili
|
2012-02-27
|
|
Bontq - 'user/' URI Cross-Site Scripting
|
3 |
WEB
|
sonyy
|
2012-02-26
|
|
Webglimpse 2.x - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
MustLive
|
2012-02-26
|
|
MyJobList 0.1.3 - 'eid' SQL Injection
|
2 |
WEB
|
Red Security TEAM
|
2012-02-23
|
|
Mobile Mp3 Search Script 2.0 - 'dl.php' HTTP Response Splitting
|
4 |
WEB
|
Corrado Liotta
|
2012-02-22
|
|
Oxwall 1.1.1 - 'plugin' Cross-Site Scripting
|
3 |
WEB
|
Ariko-Security
|
2012-02-22
|
|
Chyrp 2.1.2 - '/includes/error.php?body' Cross-Site Scripting
|
3 |
WEB
|
High-Tech Bridge SA
|
2012-02-22
|
|
Chyrp 2.1.1 - 'ajax.php' HTML Injection
|
3 |
WEB
|
High-Tech Bridge SA
|
2012-02-22
|
|
Dolibarr ERP/CRM 3.2 Alpha - Multiple Directory Traversal Vulnerabilities
|
3 |
WEB
|
Benjamin Kunz Mejri
|
2012-02-22
|
|
ContentLion Alpha 1.3 - 'login.php' Cross-Site Scripting
|
4 |
WEB
|
Stefan Schurtz
|
2012-02-21
|
|
CPG Dragonfly CMS 9.3.3.0 - Multiple Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Ariko-Security
|
2012-02-21
|
|
Xavi 7968 ADSL Router - '/webconfig/lan/lan_config.html/local_lan_config?host_name_txtbox' Cross-Sit
|
4 |
WEB
|
Busindre
|
2012-02-20
|
|
Joomla! Component Machine - Multiple SQL Injections
|
3 |
WEB
|
the_cyber_nuxbie
|
2015-04-29
|
|
OS Solution OSProperty 2.8.0 - SQL Injection
|
4 |
WEB
|
Brandon Perry
|
2015-04-29
|
|
Wing FTP Server Admin 4.4.5 - Multiple Vulnerabilities
|
3 |
WEB
|
hyp3rlinx
|
2015-04-29
|
|
WordPress Plugin TheCartPress 1.3.9 - Multiple Vulnerabilities
|
3 |
WEB
|
High-Tech Bridge SA
|
2012-02-18
|
|
Joomla! Component com_xvs - 'Controller' Local File Inclusion
|
3 |
WEB
|
KedAns-Dz
|
2012-02-21
|
|
Dolphin 7.0.x - 'explanation.php?explain' Cross-Site Scripting
|
3 |
WEB
|
Aung Khant
|
2012-02-21
|
|
Dolphin 7.0.x - 'viewFriends.php' Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Aung Khant
|
2012-02-20
|
|
TestLink - Multiple SQL Injections
|
3 |
WEB
|
Juan M. Natal
|
2012-02-20
|
|
F*EX 20100208/20111129-2 - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
muuratsalo
|
2012-02-20
|
|
VOXTRONIC Voxlog Professional 3.7.x - 'userlogdetail.php?idclient' SQL Injection
|
3 |
WEB
|
J. Greil
|
2012-02-20
|
|
VOXTRONIC Voxlog Professional 3.7.x - 'get.php?v' Arbitrary File Access
|
3 |
WEB
|
J. Greil
|
2012-02-18
|
|
Tiki Wiki CMS Groupware - 'url' Open Redirection
|
3 |
WEB
|
sonyy
|
2015-04-27
|
|
WordPress Core 4.2 - Persistent Cross-Site Scripting
|
3 |
WEB
|
klikki
|
2015-04-27
|
|
OTRS < 3.1.x / < 3.2.x / < 3.3.x - Persistent Cross-Site Scripting
|
3 |
WEB
|
Adam Ziaja
|
2012-02-18
|
|
Joomla! Component com_xcomp - Local File Inclusion
|
2 |
WEB
|
KedAns-Dz
|
2012-02-18
|
|
Joomla! Component com_x-shop - 'idd' SQL Injection
|
2 |
WEB
|
KedAns-Dz
|
2012-02-16
|
|
Impulsio CMS - 'id' SQL Injection
|
2 |
WEB
|
sonyy
|
2012-02-17
|
|
JaWiki - 'versionNo' Cross-Site Scripting
|
2 |
WEB
|
sonyy
|
2015-04-23
|
|
WordPress Plugin Ultimate Product Catalogue - SQL Injection (2)
|
3 |
WEB
|
Felipe Molina
|
2015-04-23
|
|
WordPress Plugin Ultimate Product Catalogue - SQL Injection (1)
|
3 |
WEB
|
Felipe Molina
|
2015-04-23
|
|
WebUI 1.5b6 - Remote Code Execution
|
2 |
WEB
|
TUNISIAN CYBER
|
2015-04-22
|
|
Wolf CMS 0.8.2 - Arbitrary File Upload
|
3 |
WEB
|
CWH Underground
|
2015-04-22
|
|
Open-Letters - Remote PHP Code Injection
|
3 |
WEB
|
TUNISIAN CYBER
|
2015-04-21
|
|
BlueDragon CFChart Servlet 7.1.1.17759 - Arbitrary File Retrieval/Deletion
|
3 |
WEB
|
Portcullis
|
2015-04-21
|
|
GoAutoDial CE 3.3-1406088000 - Authentication Bypass / Arbitrary File Upload / Command Injection
|
4 |
WEB
|
Chris McCurley
|
2015-04-21
|
|
WordPress Plugin Community Events 1.3.5 - SQL Injection
|
3 |
WEB
|
Hannes Trunde
|
2015-04-21
|
|
MediaSuite CMS - Artibary File Disclosure
|
3 |
WEB
|
KnocKout inj3ct0r
|
2015-04-21
|
|
WordPress Plugin Tune Library 1.5.4 - SQL Injection
|
3 |
WEB
|
Hannes Trunde
|
2015-04-21
|
|
WordPress Plugin MiwoFTP 1.0.5 - Arbitrary File Download (2)
|
3 |
WEB
|
dadou dz
|
2015-04-21
|
|
WordPress Plugin NEX-Forms < 3.0 - SQL Injection
|
3 |
WEB
|
Claudio Viviani
|
2015-04-21
|
|
Photo Manager Pro 4.4.0 iOS - Code Execution
|
3 |
WEB
|
Vulnerability-Lab
|
2015-04-21
|
|
Mobile Drive HD 1.8 - Local File Inclusion
|
3 |
WEB
|
Vulnerability-Lab
|
2015-04-21
|
|
Photo Manager Pro 4.4.0 iOS - Local File Inclusion
|
3 |
WEB
|
Vulnerability-Lab
|
2015-04-21
|
|
Wifi Drive Pro 1.2 iOS - Local File Inclusion
|
2 |
WEB
|
Vulnerability-Lab
|
2015-04-21
|
|
SevenIT SevDesk 3.10 - Multiple Web Vulnerabilities
|
3 |
WEB
|
Vulnerability-Lab
|
2012-02-17
|
|
ButorWiki 3.0 - 'service' Cross-Site Scripting
|
3 |
WEB
|
sonyy
|
2012-02-17
|
|
Pandora FMS 4.0.1 - 'sec2' Local File Inclusion
|
3 |
WEB
|
Ucha Gobejishvili
|
2012-02-16
|
|
CMS Faethon 1.3.4 - 'articles.php' Multiple SQL Injections
|
3 |
WEB
|
tempe_mendoan
|
2012-02-16
|
|
Tube Ace - 'q' Cross-Site Scripting
|
3 |
WEB
|
Daniel Godoy
|