2014-08-28
|
|
PhpWiki - Remote Command Execution
|
5 |
WEB
|
Benjamin Harris
|
2014-08-28
|
|
ActualAnalyzer Lite 2.81 - Command Execution
|
4 |
WEB
|
Benjamin Harris
|
2014-08-28
|
|
ManageEngine DeviceExpert 5.9 - User Credential Disclosure
|
6 |
WEB
|
Pedro Ribeiro
|
2014-08-28
|
|
Plogger 1.0-RC1 - (Authenticated) Arbitrary File Upload
|
6 |
WEB
|
b0z
|
2009-08-31
|
|
LiveStreet 0.2 - '/include/ajax/blogInfo.php?asd' Cross-Site Scripting
|
4 |
WEB
|
Inj3ct0r
|
2009-08-31
|
|
LiveStreet 0.2 - Comment Topic Header Cross-Site Scripting
|
4 |
WEB
|
Inj3ct0r
|
2009-09-16
|
|
RSSMediaScript - 'index.php' Cross-Site Scripting
|
4 |
WEB
|
Moudi
|
2009-09-16
|
|
PaoLink 1.0 - 'scrivi.php' Cross-Site Scripting
|
6 |
WEB
|
Moudi
|
2010-05-13
|
|
JForum 2.08 - BBCode Color Tag HTML Injection
|
3 |
WEB
|
Giorgio Fedon
|
2010-08-12
|
|
Computer Associates Oneview Monitor 6.0 - 'doSave.jsp' Remote Code Execution
|
5 |
WEB
|
Giorgio Fedon
|
2010-08-11
|
|
MybbCentral TagCloud 2.0 - 'Topic' HTML Injection
|
5 |
WEB
|
3ethicalhackers.com
|
2014-08-28
|
|
WordPress Plugin ShortCode 0.2.3 - Local File Inclusion
|
5 |
WEB
|
Mehdi Karout & Christian Galeone
|
2010-10-22
|
|
Simple Directory Listing 2.1 - 'SDL2.php' Cross-Site Scripting
|
5 |
WEB
|
Amol Naik
|
2009-10-29
|
|
Wowd - 'index.html' Multiple Cross-Site Scripting Vulnerabilities
|
6 |
WEB
|
Lostmon
|
2010-08-09
|
|
Preation Eden Platform 27.7.2010 - Multiple HTML Injection Vulnerabilities
|
3 |
WEB
|
High-Tech Bridge SA
|
2010-08-09
|
|
Allinta CMS 22.07.2010 - Multiple SQL Injections / Cross-Site Scripting Vulnerabilities
|
5 |
WEB
|
High-Tech Bridge SA
|
2014-08-27
|
|
WordPress Plugin WooCommerce Store Exporter 1.7.5 - Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Mike Manzotti
|
2014-08-26
|
|
VTLS Virtua InfoStation.cgi - SQL Injection
|
3 |
WEB
|
José Tozo
|
2014-08-26
|
|
ntopng 1.2.0 - Cross-Site Scripting Injection
|
4 |
WEB
|
Steffen Bauch
|
2010-08-06
|
|
Dataface 1.0 - 'admin.php' Cross-Site Scripting
|
4 |
WEB
|
MustLive
|
2010-08-06
|
|
Prado Portal 1.2 - 'page' Cross-Site Scripting
|
6 |
WEB
|
High-Tech Bridge SA
|
2010-08-05
|
|
Muraus Open Blog - Multiple HTML Injection Vulnerabilities
|
3 |
WEB
|
High-Tech Bridge SA
|
2010-08-05
|
|
Hulihan Applications Amethyst 0.1.5 - Multiple HTML Injection Vulnerabilities
|
4 |
WEB
|
High-Tech Bridge SA
|
2010-08-05
|
|
DiamondList - '/user/main/update_category?category[description]' Cross-Site Scripting
|
4 |
WEB
|
High-Tech Bridge SA
|
2010-08-05
|
|
DiamondList - '/user/main/update_settings?setting[site_title]' Cross-Site Scripting
|
4 |
WEB
|
High-Tech Bridge SA
|
2010-08-05
|
|
Hulihan Applications BXR 0.6.8 - SQL Injection / HTML Injection
|
4 |
WEB
|
High-Tech Bridge SA
|
2010-08-05
|
|
DT Centrepiece 4.5 - Cross-Site Scripting / Security Bypass
|
4 |
WEB
|
High-Tech Bridge SA
|
2010-08-05
|
|
PHPFinance 0.6 - '/group.php' SQL Injection / HTML Injection
|
5 |
WEB
|
skskilL
|
2014-08-25
|
|
ManageEngine Password Manager - MetadataServlet.dat SQL Injection (Metasploit)
|
4 |
WEB
|
Pedro Ribeiro
|
2014-08-25
|
|
Innovaphone PBX Admin-GUI - Cross-Site Request Forgery
|
4 |
WEB
|
Rainer Giedat
|
2014-08-25
|
|
PHP Stock Management System 1.02 - Multiple Persistent Cross-Site Scripting Vulnerabilities
|
5 |
WEB
|
Ragha Deepthi K R
|
2009-10-08
|
|
OpenSolution Quick.Cart - Local File Inclusion / Cross-Site Scripting
|
4 |
WEB
|
kl3ryk
|
2009-10-04
|
|
PHP168 Template Editor - 'Filename' Directory Traversal
|
4 |
WEB
|
esnra
|
2014-08-03
|
|
RaidenTunes - 'music_out.php' Cross-Site Scripting
|
4 |
WEB
|
LiquidWorm
|
2009-09-25
|
|
Activedition - '/activedition/aelogin.asp' Multiple Cross-Site Scripting Vulnerabilities
|
5 |
WEB
|
Richard Brain
|
2010-07-03
|
|
FuseTalk 3.2/4.0 - Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Juan Manuel Garcia
|
2010-08-03
|
|
Joomla! Component com_jigsaw - 'Controller' Directory Traversal
|
4 |
WEB
|
FL0RiX
|
2010-08-02
|
|
MyIT CRM - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
|
5 |
WEB
|
Juan Manuel Garcia
|
2010-07-30
|
|
Sourcefabric Campsite - Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
High-Tech Bridge SA
|
2010-07-27
|
|
Impact Software AdPeeps - Cross-Site Scripting / HTML Injection
|
4 |
WEB
|
Matt
|
2010-07-28
|
|
SPIP 2.1 - 'var_login' Cross-Site Scripting
|
5 |
WEB
|
dotsafe.fr
|
2010-07-28
|
|
Cetera eCommerce - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
|
4 |
WEB
|
MustLive
|
2010-07-28
|
|
Cetera eCommerce - Multiple SQL Injections
|
4 |
WEB
|
MustLive
|
2010-07-28
|
|
Jira 4.0.1 - Cross-Site Scripting / Information Disclosure
|
4 |
WEB
|
MaXe
|
2010-07-27
|
|
Social Media - 'index.php' Local File Inclusion
|
5 |
WEB
|
Harri Johansson
|
2014-08-21
|
|
MyBB 1.8 Beta 3 - Multiple Vulnerabilities
|
4 |
WEB
|
DemoLisH B3yaZ
|
2009-12-22
|
|
Active Business Directory 2 - 'searchadvance.asp' Cross-Site Scripting
|
3 |
WEB
|
Andrea Bocchetti
|
2010-07-26
|
|
SyndeoCMS 2.9 - Multiple HTML Injection Vulnerabilities
|
3 |
WEB
|
High-Tech Bridge SA
|
2009-12-04
|
|
Clixint Technologies DPI - Cross-Site Scripting
|
4 |
WEB
|
anonymous
|
2010-10-04
|
|
Portili Personal and Team Wiki 1.14 - Multiple Vulnerabilities (2)
|
4 |
WEB
|
Abysssec
|
2009-10-06
|
|
e-Courier CMS - 'UserGUID' Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
BugsNotHugs
|
2010-07-26
|
|
Joomla! Component FreiChat 1.0/2.x - HTML Injection
|
4 |
WEB
|
nag_sunny
|
2010-07-25
|
|
MC Content Manager 10.1 - SQL Injection / Cross-Site Scripting
|
4 |
WEB
|
MustLive
|
2010-07-23
|
|
SAP NetWeaver 6.4/7.0 - 'wsnavigator' Cross-Site Scripting
|
4 |
WEB
|
Alexandr Polyakov
|
2009-10-28
|
|
Piwigo 2.0 - 'comments.php' Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Andrew Paterson
|
2009-11-02
|
|
Stratek Web Design Twilight CMS 4.0 - 'calendar' Cross-Site Scripting
|
4 |
WEB
|
Vladimir Vorontsov
|
2010-07-22
|
|
Claus Muus Spitfire 1.0.336 - Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
High-Tech Bridge SA
|
2014-08-18
|
|
Tenda A5s Router 3.02.05_CN - Authentication Bypass
|
4 |
WEB
|
zixian
|
2009-12-15
|
|
Scriptsez Ez FAQ Maker 1.0 - Cross-Site Scripting / Cross-Site Request Forgery
|
3 |
WEB
|
Milos Zivanovic
|
2009-12-14
|
|
TenderSystem 0.9.5 - 'main.php' Multiple Local File Inclusions
|
4 |
WEB
|
Packetdeath
|
2010-07-19
|
|
SnowFlake CMS 0.9.5 Beta - 'uid' SQL Injection
|
3 |
WEB
|
Dinesh Arora
|
2009-12-16
|
|
BOLDfx Recipe Script 5.0 - Multiple Remote Vulnerabilities
|
4 |
WEB
|
Milos Zivanovic
|
2009-12-16
|
|
BOLDfx eUploader 3.1.1 - 'admin.php' Multiple Remote Vulnerabilities
|
4 |
WEB
|
Milos Zivanovic
|
2010-07-15
|
|
Sourcefabric Campsite Articles - HTML Injection
|
4 |
WEB
|
D4rk357
|
2010-07-18
|
|
YACS CMS 10.5.27 - 'context[path_to_root]' Remote File Inclusion
|
4 |
WEB
|
eidelweiss
|
2010-07-18
|
|
iOffice 0.1 - 'parametre' Remote Command Execution
|
4 |
WEB
|
Marshall Whittaker
|
2009-12-17
|
|
jCore - 'search' Cross-Site Scripting
|
5 |
WEB
|
loneferret
|
2009-12-17
|
|
Pre Jobo.NET - Multiple SQL Injections
|
4 |
WEB
|
bi0
|
2007-12-17
|
|
MOJO IWms 7 - 'default.asp' Cookie Manipulation
|
5 |
WEB
|
cp77fk4r
|
2009-12-14
|
|
Ez Poll Hoster - Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Milos Zivanovic
|
2009-09-21
|
|
WX-Guestbook 1.1.208 - SQL Injection / HTML Injection
|
4 |
WEB
|
learn3r
|
2010-07-15
|
|
Pligg CMS 1.0.4 - 'search.php' Cross-Site Scripting
|
3 |
WEB
|
High-Tech Bridge SA
|
2010-07-15
|
|
Pixie 1.0.4 - HTML Injection / Cross-Site Scripting
|
4 |
WEB
|
High-Tech Bridge SA
|
2010-07-15
|
|
Gekko Web Builder 9.0 - 'index.php' Cross-Site Scripting
|
4 |
WEB
|
High-Tech Bridge SA
|
2014-08-14
|
|
WordPress Plugin Disqus 2.7.5 - Cross-Site Request Forgery (Admin Persistent) / Cross-Site Scripting
|
4 |
WEB
|
Nik Cubrilovic
|
2010-07-15
|
|
FestOS 2.3 - 'contents' Cross-Site Scripting
|
4 |
WEB
|
High-Tech Bridge SA
|
2010-07-15
|
|
DSite CMS 4.81 - 'modmenu.php' Cross-Site Scripting
|
4 |
WEB
|
High-Tech Bridge SA
|
2010-07-15
|
|
PHPWCMS 1.4.5 - 'PHPwcms.php' Cross-Site Scripting
|
4 |
WEB
|
High-Tech Bridge SA
|
2010-07-15
|
|
Spitfire 1.0.381 - Cross-Site Scripting / Cross-Site Request Forgery
|
4 |
WEB
|
Nijel the Destroyer
|
2009-12-14
|
|
Ez Cart - 'index.php' Cross-Site Scripting
|
3 |
WEB
|
anti-gov
|
2009-12-13
|
|
Zeecareers 2.0 - Cross-Site Scripting / Authentication Bypass
|
4 |
WEB
|
bi0
|
2009-12-13
|
|
WS Interactive Automne 4.0 - '228-recherche.php' Cross-Site Scripting
|
4 |
WEB
|
loneferret
|
2009-12-14
|
|
The Next Generation of Genealogy Sitebuilding - 'searchform.php' Cross-Site Scripting
|
3 |
WEB
|
bi0
|
2014-08-09
|
|
TomatoCart 1.x - SQL Injection
|
3 |
WEB
|
Breaking.Technology
|
2014-08-09
|
|
Easy FTP Pro 4.2 iOS - Command Injection
|
3 |
WEB
|
Vulnerability-Lab
|
2014-08-09
|
|
PhotoSync Wifi & Bluetooth 1.0 - Local File Inclusion
|
3 |
WEB
|
Vulnerability-Lab
|
2010-07-13
|
|
Diem 5.1.2 - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
High-Tech Bridge SA
|
2010-07-11
|
|
CMS Made Simple Module Antz Toolkit 1.02 - Arbitrary File Upload
|
3 |
WEB
|
John Leitch
|
2010-07-11
|
|
CMS Made Simple 1.8 - 'default_cms_lang' Local File Inclusion
|
3 |
WEB
|
John Leitch
|
2010-07-11
|
|
CMS Made Simple Module Download Manager 1.4.1 - Arbitrary File Upload
|
3 |
WEB
|
John Leitch
|
2010-07-11
|
|
CSSTidy 1.3 - 'css_optimiser.php' Cross-Site Scripting
|
4 |
WEB
|
John Leitch
|
2010-07-11
|
|
RunCMS 2.1 - 'magpie_debug.php' Cross-Site Scripting
|
4 |
WEB
|
John Leitch
|
2010-07-09
|
|
WordPress Plugin Firestats 1.6.5 - Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Jelmer de Hen
|
2010-07-12
|
|
dotDefender 4.02 - 'clave' Cross-Site Scripting
|
3 |
WEB
|
David K
|
2010-07-10
|
|
eliteCMS 1.01 - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
10n1z3d
|
2010-07-10
|
|
Joomla! Component Rapid-Recipe - HTML Injection
|
4 |
WEB
|
Sid3^effects
|
2010-07-11
|
|
Mac's CMS 1.1.4 - 'SearchString' Cross-Site Scripting
|
3 |
WEB
|
10n1z3d
|
2009-12-21
|
|
Web Cocoon simpleCMS - 'show.php' SQL Injection
|
2 |
WEB
|
anonymous
|
2009-12-22
|
|
pragmaMX 0.1.11 - 'modules.php' Multiple SQL Injections
|
4 |
WEB
|
Hadi Kiamarsi
|
2010-07-09
|
|
Yappa 3.1.2 - 'yappa.php' Multiple Remote Command Execution Vulnerabilities
|
4 |
WEB
|
Sn!pEr.S!Te Hacker
|
2010-07-09
|
|
SimpNews 2.47.3 - Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
MustLive
|
2010-12-13
|
|
Articlems 2.0 - 'c[]' Cross-Site Scripting
|
3 |
WEB
|
Packetdeath
|
2010-07-08
|
|
osCSS 1.2.2 - 'page' Cross-Site Scripting
|
4 |
WEB
|
High-Tech Bridge SA
|
2009-12-13
|
|
Model Agency Manager - 'search_process.php' Cross-Site Scripting
|
4 |
WEB
|
bi0
|
2010-07-09
|
|
Real Estate Manager 1.0.1 - 'index.php' Cross-Site Scripting
|
4 |
WEB
|
bi0
|
2010-07-04
|
|
phpFaber CMS 2.0.5 - Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
prodigy
|
2014-08-06
|
|
Feng Office - Persistent Cross-Site Scripting
|
4 |
WEB
|
Juan Sacco
|
2014-08-06
|
|
Pro Chat Rooms 8.2.0 - Multiple Vulnerabilities
|
4 |
WEB
|
Mike Manzotti
|
2014-08-06
|
|
HybridAuth 2.2.2 - Remote Code Execution
|
2 |
WEB
|
@u0x
|
2010-07-07
|
|
Worxware DCP-Portal 7.0 - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Andrei Rimsa Alvares
|
2010-07-07
|
|
RunCMS 2.1 - 'check.php' Cross-Site Scripting
|
3 |
WEB
|
Andrei Rimsa Alvares
|
2010-07-07
|
|
Exponent CMS 0.97 - 'Slideshow.js.php' Cross-Site Scripting
|
4 |
WEB
|
Andrei Rimsa Alvares
|
2014-08-04
|
|
FreeDisk 1.01 iOS - Multiple Vulnerabilities
|
4 |
WEB
|
Vulnerability-Lab
|
2014-08-04
|
|
Video WiFi Transfer 1.01 - Directory Traversal
|
3 |
WEB
|
Vulnerability-Lab
|
2010-07-05
|
|
odCMS 1.07 - 'archive.php' Cross-Site Scripting
|
4 |
WEB
|
John Leitch
|
2010-07-05
|
|
Bitweaver 2.7 - 'fImg' Cross-Site Scripting
|
3 |
WEB
|
John Leitch
|
2010-07-05
|
|
NewsOffice 2.0.18 - 'news_show.php' Cross-Site Scripting
|
4 |
WEB
|
John Leitch
|
2010-07-06
|
|
NTSOFT BBS E-Market Professional - Multiple Cross-Site Scripting Vulnerabilities (2)
|
4 |
WEB
|
Ivan Sanchez
|
2010-07-05
|
|
SocialABC NetworX 1.0.3 - Arbitrary File Upload / Cross-Site Scripting
|
4 |
WEB
|
John Leitch
|
2010-07-03
|
|
cPanel 11.25 - Cross-Site Request Forgery
|
4 |
WEB
|
G0D-F4Th3r
|
2014-08-03
|
|
TP-Link TL-WR740N v4 Router (FW-Ver. 3.16.6 Build 130529 Rel.47286n) - Command Execution
|
4 |
WEB
|
Christoph Kuhl
|
2010-07-05
|
|
Orbis CMS 1.0.2 - 'editor-body.php' Cross-Site Scripting
|
4 |
WEB
|
John Leitch
|
2010-07-06
|
|
i-Net Solution Matrimonial Script 2.0.3 - 'alert.php' Cross-Site Scripting
|
3 |
WEB
|
Andrea Bocchetti
|
2010-07-05
|
|
Joomla! Component Canteen 1.0 - Local File Inclusion
|
4 |
WEB
|
Drosophila
|
2009-12-25
|
|
AL-Caricatier 2.5 - 'comment.php' Cross-Site Scripting
|
4 |
WEB
|
indoushka
|