2011-01-16
|
|
Advanced Webhost Billing System (AWBS) 2.9.2 - 'oid' SQL Injection
|
3 |
WEB
|
ShivX
|
2011-01-15
|
|
CompactCMS 1.4.1 - Multiple Cross-Site Scripting Vulnerabilities (2)
|
3 |
WEB
|
Patrick de Brouwer
|
2011-01-14
|
|
Alguest 1.1c-patched - 'elimina' SQL Injection
|
3 |
WEB
|
Aliaksandr Hartsuyeu
|
2014-11-13
|
|
MyBB 1.8.x - Multiple Vulnerabilities
|
3 |
WEB
|
smash
|
2014-11-13
|
|
Digi Online Examination System 2.0 - Unrestricted Arbitrary File Upload
|
3 |
WEB
|
Halil Dalabasmaz
|
2014-11-13
|
|
F5 BIG-IP 10.1.0 - Directory Traversal
|
3 |
WEB
|
Anastasios Monachos
|
2014-11-13
|
|
Piwigo 2.6.0 - 'picture.php?rate' SQL Injection
|
3 |
WEB
|
Manuel García Cárdenas
|
2014-11-13
|
|
Joomla! Component com_hdflvplayer < 2.1.0.1 - SQL Injection
|
3 |
WEB
|
Claudio Viviani
|
2014-11-13
|
|
Proticaret E-Commerce Script 3.0 - SQL Injection (1)
|
3 |
WEB
|
Onur Alanbel (BGA)
|
2014-11-12
|
|
WordPress Plugin SupportEzzy Ticket System 1.2.5 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Halil Dalabasmaz
|
2014-11-11
|
|
Subex Fms 7.4 - SQL Injection
|
2 |
WEB
|
Anastasios Monachos
|
2014-11-10
|
|
WordPress Plugin / Joomla! Component XCloner - Multiple Vulnerabilities
|
3 |
WEB
|
Larry W. Cashdollar
|
2014-11-10
|
|
Password Manager Pro / Pro MSP - Blind SQL Injection
|
3 |
WEB
|
Pedro Ribeiro
|
2014-11-10
|
|
ManageEngine OpManager / Social IT Plus / IT360 - Multiple Vulnerabilities
|
3 |
WEB
|
Pedro Ribeiro
|
2014-11-10
|
|
Barracuda - Multiple Unauthentication Logfile Downloads
|
3 |
WEB
|
4CKnowLedge
|
2014-11-10
|
|
PHP-Fusion 7.02.07 - SQL Injection
|
3 |
WEB
|
XLabs Security
|
2014-11-10
|
|
WordPress Plugin Another WordPress Classifieds Plugin - SQL Injection
|
3 |
WEB
|
dill
|
2014-11-10
|
|
ZTE ZXDSL 831CII - Insecure Direct Object Reference
|
3 |
WEB
|
Paulos Yibelo
|
2014-11-10
|
|
phpSound Music Sharing Platform 1.0.5 - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Halil Dalabasmaz
|
2014-11-10
|
|
Serenity Client Management Portal 1.0.1 - Multiple Vulnerabilities
|
2 |
WEB
|
Halil Dalabasmaz
|
2014-11-10
|
|
vldPersonals 2.7 - Multiple Vulnerabilities
|
3 |
WEB
|
Mr T
|
2011-01-11
|
|
CMS Tovar - 'tovar.php' SQL Injection
|
2 |
WEB
|
jos_ali_joe
|
2011-01-08
|
|
Joostina 1.3 - 'index.php' Cross-Site Scripting
|
3 |
WEB
|
MustLive
|
2011-01-10
|
|
WikLink 0.1.3 - Multiple SQL Injections
|
3 |
WEB
|
Aliaksandr Hartsuyeu
|
2011-01-04
|
|
WonderCMS 0.3.3 - 'editText.php' Cross-Site Scripting
|
3 |
WEB
|
High-Tech Bridge SA
|
2014-11-06
|
|
Symantec Endpoint Protection 12.1.4023.4080 - Multiple Vulnerabilities
|
3 |
WEB
|
SEC Consult
|
2011-01-06
|
|
PHP MicroCMS 1.0.1 - 'page_text' Cross-Site Scripting
|
3 |
WEB
|
High-Tech Bridge SA
|
2011-01-05
|
|
Openfire 3.6.4 - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Walikar Riyaz Ahemed Dawalmalik
|
2011-01-05
|
|
BlogEngine.NET 1.6 - Directory Traversal / Information Disclosure
|
3 |
WEB
|
Deniz Cevik
|
2011-01-06
|
|
Joomla! 1.0.x - 'ordering' Cross-Site Scripting
|
3 |
WEB
|
Aung Khant
|
2011-01-05
|
|
WikLink 0.1.3 - 'getURL.php' SQL Injection
|
3 |
WEB
|
Aliaksandr Hartsuyeu
|
2014-11-05
|
|
Mouse Media Script 1.6 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Halil Dalabasmaz
|
2014-11-05
|
|
MODx CMS 2.2.14 - Cross-Site Request Forgery Bypass / Reflected Cross-Site Scripting / Persistent Cr
|
3 |
WEB
|
Narendra Bhati
|
2010-12-28
|
|
Coppermine Photo Gallery 1.5.10 - 'searchnew.php' Cross-Site Scripting
|
3 |
WEB
|
waraxe
|
2010-12-28
|
|
Coppermine Photo Gallery 1.5.10 - 'help.php' Cross-Site Scripting
|
3 |
WEB
|
waraxe
|
2010-12-26
|
|
CruxCMS 3.0 - Multiple Input Validation Vulnerabilities
|
3 |
WEB
|
ToXiC
|
2014-11-03
|
|
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Remote Code Execution)
|
3 |
WEB
|
Stefan Horst
|
2010-12-27
|
|
LiveZilla 3.2.0.2 - 'Track' Module 'server.php' Cross-Site Scripting
|
3 |
WEB
|
Ulisses Castro
|
2014-11-03
|
|
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
|
2 |
WEB
|
Ryan King (Starfall)
|
2010-12-27
|
|
Pligg CMS 1.1.3 - 'range' SQL Injection
|
3 |
WEB
|
Dr.NeT
|
2010-12-28
|
|
HotWeb Scripts HotWeb Rentals - 'PageId' SQL Injection
|
3 |
WEB
|
non customers
|
2010-12-23
|
|
Social Share - 'search' Cross-Site Scripting
|
3 |
WEB
|
Aliaksandr Hartsuyeu
|
2010-12-23
|
|
MyBB 1.6 - 'private.php?keywords' SQL Injection
|
3 |
WEB
|
Aung Khant
|
2010-12-23
|
|
MyBB 1.6 - 'search.php?keywords' SQL Injection
|
3 |
WEB
|
Aung Khant
|
2014-11-02
|
|
Esotalk CMS 1.0.0g4 - Cross-Site Scripting
|
3 |
WEB
|
evi1m0
|
2010-12-10
|
|
Social Share - 'vote.php' HTTP Response Splitting
|
3 |
WEB
|
Aliaksandr Hartsuyeu
|
2010-12-22
|
|
WordPress Plugin Accept Signups 0.1 - 'email' Cross-Site Scripting
|
3 |
WEB
|
clshack
|
2010-12-22
|
|
Joomla! Component Classified - SQL Injection
|
3 |
WEB
|
R4dc0re
|
2010-12-21
|
|
ImpressCMS 1.2.x - 'quicksearch_ContentContent' HTML Injection
|
3 |
WEB
|
High-Tech Bridge SA
|
2010-12-21
|
|
WordPress Plugin Mediatricks Viva Thumbs - Multiple Information Disclosure Vulnerabilities
|
3 |
WEB
|
Richard Brain
|
2010-12-21
|
|
Social Share - 'Username' SQL Injection
|
3 |
WEB
|
Aliaksandr Hartsuyeu
|
2014-10-31
|
|
Who's Who Script - Cross-Site Request Forgery (Add Admin)
|
3 |
WEB
|
ZoRLu Bugrahan
|
2014-10-31
|
|
ZTE Modem ZXDSL 531BIIV7.3.0f_D09_IN - Persistent Cross-Site Scripting
|
3 |
WEB
|
Ravi Rajput
|
2014-10-31
|
|
Progress OpenEdge 11.2 - Directory Traversal
|
3 |
WEB
|
XLabs Security
|
2010-12-21
|
|
Habari 0.6.5 - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
High-Tech Bridge SA
|
2010-12-21
|
|
OpenFiler - 'device' Cross-Site Scripting
|
3 |
WEB
|
db.pub.mail
|
2010-12-21
|
|
FreeNAS 0.7.2.5543 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
db.pub.mail
|
2010-12-20
|
|
Mafya Oyun Scrpti - 'profil.php' SQL Injection
|
3 |
WEB
|
DeadLy DeMon
|
2010-12-20
|
|
Social Share - 'postid' SQL Injection
|
3 |
WEB
|
Aliaksandr Hartsuyeu
|
2010-12-17
|
|
Social Share - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Aliaksandr Hartsuyeu
|
2010-12-17
|
|
Radius Manager 3.6 - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Rodrigo Rubira Branco
|
2010-12-16
|
|
PHPRS - 'model-kits.php' SQL Injection
|
3 |
WEB
|
KnocKout
|
2010-12-15
|
|
Blog:CMS 4.2.1 e - Multiple HTML Injections / Cross-Site Scripting
|
3 |
WEB
|
High-Tech Bridge SA
|
2010-12-15
|
|
HP Insight Diagnostics Online Edition 8.4 - 'search.php' Cross-Site Scripting
|
3 |
WEB
|
Richard Brain
|
2014-10-29
|
|
MAARCH 1.4 - SQL Injection
|
3 |
WEB
|
Adrien Thierry
|
2014-10-29
|
|
MAARCH 1.4 - Arbitrary File Upload
|
2 |
WEB
|
Adrien Thierry
|
2010-12-15
|
|
slickMsg - Cross-Site Scripting / HTML Injection
|
1 |
WEB
|
Aliaksandr Hartsuyeu
|
2010-12-14
|
|
BlogCFC 5.9.6.001 - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Richard Brain
|
2010-12-13
|
|
PHP TopSites 2.1 - '/rate.php' Cross-Site Scripting / SQL Injection
|
3 |
WEB
|
c0de Hunters
|
2010-12-12
|
|
MyBB 1.4.10 - 'tags.php' Cross-Site Scripting
|
3 |
WEB
|
TEAMELITE
|
2010-12-13
|
|
Mura CMS - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Richard Brain
|
2010-12-11
|
|
Cetera eCommerce - 'banner.php' Cross-Site Scripting
|
3 |
WEB
|
MustLive
|
2014-10-28
|
|
Tapatalk for vBulletin 4.x - Blind SQL Injection
|
2 |
WEB
|
tintinweb
|
2014-10-28
|
|
Enalean Tuleap 7.4.99.5 - Remote Command Execution
|
3 |
WEB
|
Portcullis
|
2014-10-28
|
|
Enalean Tuleap 7.2 - XML External Entity File Disclosure
|
3 |
WEB
|
Portcullis
|
2014-10-28
|
|
Enalean Tuleap 7.4.99.5 - Blind SQL Injection
|
3 |
WEB
|
Portcullis
|
2010-12-13
|
|
Joomla! Component com_redirect 1.5.19 - Local File Inclusion
|
3 |
WEB
|
jos_ali_joe
|
2010-12-10
|
|
Joomla! Component com_mailto - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
MustLive
|
2010-12-10
|
|
slickMsg 0.7-alpha - 'top.php' Cross-Site Scripting
|
3 |
WEB
|
Aliaksandr Hartsuyeu
|
2010-12-10
|
|
BizDir 05.10 - 'f_srch' Cross-Site Scripting
|
3 |
WEB
|
Aliaksandr Hartsuyeu
|
2010-12-10
|
|
ManageEngine EventLog Analyzer 6.1 - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Rob Kraus
|
2010-12-10
|
|
Joomla! Component JExtensions Property Finder - 'sf_id' SQL Injection
|
3 |
WEB
|
FL0RiX
|
2010-12-09
|
|
Joomla! Component Jeformcr - 'id' SQL Injection
|
3 |
WEB
|
FL0RiX
|
2010-12-09
|
|
PHP State - 'id' SQL Injection
|
3 |
WEB
|
jos_ali_joe
|
2010-12-09
|
|
net2ftp 0.98 (stable) - '/admin1.template.php' Local/Remote File Inclusion
|
3 |
WEB
|
Marcin Ressel
|
2010-12-09
|
|
WWWThread 5.0.8 Pro - 'showflat.pl' Cross-Site Scripting
|
3 |
WEB
|
Aliaksandr Hartsuyeu
|
2010-12-07
|
|
WordPress Plugin Twitter Feed - 'url' Cross-Site Scripting
|
3 |
WEB
|
John Leitch
|
2014-10-27
|
|
Folder Plus 2.5.1 iOS - Persistent Cross-Site Scripting
|
3 |
WEB
|
Vulnerability-Lab
|
2014-10-27
|
|
WebDisk+ 2.1 iOS - Code Execution
|
3 |
WEB
|
Vulnerability-Lab
|
2014-10-27
|
|
Incredible PBX 2.0.6.5.0 - Remote Command Execution
|
3 |
WEB
|
Simo Ben Youssef
|
2014-10-27
|
|
Mulesoft ESB Runtime 3.5.1 - Privilege Escalation
|
3 |
WEB
|
Brandon Perry
|
2014-10-27
|
|
HP Operations Agent - Cross-Site Scripting iFrame Injection
|
2 |
WEB
|
Matt Schmidt
|
2014-10-27
|
|
CBN CH6640E/CG6640E Wireless Gateway Series - Multiple Vulnerabilities
|
3 |
WEB
|
LiquidWorm
|
2014-10-27
|
|
WordPress Plugin CP Multi View Event Calendar 1.01 - SQL Injection
|
3 |
WEB
|
Claudio Viviani
|
2010-12-08
|
|
Drupal Module Embedded Media Field/Media 6.x : Video Flotsam/Media: Audio Flotsam - Multiple Vulnera
|
3 |
WEB
|
Justin Klein Keane
|
2010-12-08
|
|
WordPress Plugin Safe Search - 'v1' Cross-Site Scripting
|
3 |
WEB
|
John Leitch
|
2010-12-08
|
|
WordPress Plugin Processing Embed 0.5 - 'pluginurl' Cross-Site Scripting
|
3 |
WEB
|
John Leitch
|
2010-12-07
|
|
SolarWinds Orion Network Performance Monitor (NPM) 10.1 - Multiple Cross-Site Scripting Vulnerabilit
|
3 |
WEB
|
x0skel
|
2010-12-07
|
|
Zimplit CMS - 'English_manual_version_2.php?client' Cross-Site Scripting
|
3 |
WEB
|
High-Tech Bridge SA
|
2010-12-07
|
|
Zimplit CMS - 'zimplit.php?File' Cross-Site Scripting
|
3 |
WEB
|
High-Tech Bridge SA
|
2010-12-07
|
|
Aigaion 1.3.4 - 'ID' SQL Injection
|
3 |
WEB
|
KnocKout
|
2014-10-25
|
|
WordPress Plugin 0.9.7 / Joomla! Component 2.0.0 Creative Contact Form - Arbitrary File Upload
|
3 |
WEB
|
Claudio Viviani
|
2014-10-25
|
|
Dell EqualLogic Storage - Directory Traversal
|
3 |
WEB
|
XLabs Security
|
2014-10-25
|
|
Magento Server MAGMI Plugin 0.7.17a - Remote File Inclusion
|
3 |
WEB
|
Parvinder Bhasin
|
2010-12-06
|
|
Alguest 1.1 - 'start' SQL Injection
|
4 |
WEB
|
Aliaksandr Hartsuyeu
|
2010-12-04
|
|
Techno Dreams FAQ Manager Package 1.0 - 'faqlist.asp' SQL Injection
|
3 |
WEB
|
R4dc0re
|
2010-12-04
|
|
Techno Dreams Articles & Papers Package 2.0 - 'ArticlesTablelist.asp' SQL Injection
|
3 |
WEB
|
R4dc0re
|
2014-10-23
|
|
Dell SonicWALL Gms 7.2.x - Code Injection
|
3 |
WEB
|
Vulnerability-Lab
|
2014-10-23
|
|
Axway Secure Transport 5.1 SP2 - Arbitrary File Upload (via Cross-Site Request Forgery)
|
3 |
WEB
|
Emmanuel Law
|
2010-12-03
|
|
DotNetNuke 5.5.1 - 'InstallWizard.aspx' Cross-Site Scripting
|
3 |
WEB
|
Richard Brain
|
2010-12-03
|
|
Alguest 1.1 - Multiple Cookie Authentication Bypass Vulnerabilities
|
3 |
WEB
|
Aliaksandr Hartsuyeu
|
2010-12-02
|
|
Contenido CMS 4.8.12 - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
High-Tech Bridge SA
|
2014-10-23
|
|
Feng Office 1.7.4 - Cross-Site Scripting
|
3 |
WEB
|
AutoSec Tools
|
2014-10-23
|
|
Feng Office 1.7.4 - Arbitrary File Upload
|
2 |
WEB
|
AutoSec Tools
|
2014-10-22
|
|
DotNetNuke DNNspot Store 3.0.0 - Arbitrary File Upload (Metasploit)
|
3 |
WEB
|
Glafkos Charalambous
|
2014-10-22
|
|
File Manager 4.2.10 iOS - Code Execution
|
2 |
WEB
|
Vulnerability-Lab
|
2014-10-22
|
|
iFunBox Free 1.1 iOS - Local File Inclusion
|
3 |
WEB
|
Vulnerability-Lab
|
2010-12-02
|
|
Joomla! Component Annuaire - 'index.php?id' SQL Injection
|
3 |
WEB
|
Ashiyane Digital Security Team
|
2010-11-30
|
|
AWStats 6.x - Apache Tomcat Configuration File Arbitrary Command Execution
|
3 |
WEB
|
StenoPlasma
|
2010-11-30
|
|
BugTracker.NET 3.4.4 - SQL Injection / Cross-Site Scripting
|
3 |
WEB
|
BugTracker.NET
|
2010-11-26
|
|
SmartBox - 'page_id' SQL Injection
|
3 |
WEB
|
KnocKout
|
2010-11-26
|
|
E-lokaler CMS 2 - Admin Login Multiple SQL Injections
|
4 |
WEB
|
ali_err0r
|
2010-11-30
|
|
Joomla! Component com_storedirectory - 'id' SQL Injection
|
3 |
WEB
|
XroGuE
|
2010-11-29
|
|
Car Portal 2.0 - 'car_make' Cross-Site Scripting
|
3 |
WEB
|
Underground Stockholm
|
2010-11-30
|
|
Joomla! Component Catalogue - SQL Injection / Local File Inclusion
|
2 |
WEB
|
XroGuE
|