Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2010-05-24   Getsimple CMS 2.01 - 'components.php' Cross-Site Scripting 3 WEB High-Tech Bridge SA
2010-05-24   RazorCMS 1.0 - '/admin/index.php' HTML Injection 3 WEB High-Tech Bridge SA
2014-07-12   Aerohive HiveOS 5.1r5 < 6.1r5 - Multiple Vulnerabilities 3 WEB DearBytes
2010-05-23   OpenForum 2.2 b005 - 'saveAsAttachment()' Method Arbitrary File Creation 2 WEB John Leitch
2010-05-22   cyberhost - 'default.asp' SQL Injection 3 WEB redst0rm
2010-05-20   NPDS REvolution 10.02 - 'admin.php' Cross-Site Request Forgery 3 WEB High-Tech Bridge SA
2010-05-18   gpEasy CMS 1.6.2 - 'editing_files.php' Cross-Site Scripting 3 WEB High-Tech Bridge SA
2014-07-10   Infoblox 6.8.2.11 - OS Command Injection 3 WEB Nate Kettlewell
2010-05-21   Specialized Data Systems Parent Connect 2010.04.11 - Multiple SQL Injections 2 WEB epixoip
2014-07-10   C99Shell (Web Shell) - 'c99.php' Authentication Bypass 3 WEB Mandat0ry
2010-01-15   Triburom - 'forum.php' Cross-Site Scripting 3 WEB ViRuSMaN
2010-05-20   Lisk CMS 4.4 - 'id' Multiple Cross-Site Scripting / SQL Injections 3 WEB High-Tech Bridge SA
2010-01-13   StivaSoft Stiva SHOPPING CART 1.0 - 'demo.php' Cross-Site Scripting 3 WEB PaL-D3v1L
2010-05-19   Joomla! Component com_horses - 'id' SQL Injection 3 WEB Kernel Security Group
2010-05-20   Snipe Gallery 3.1 - 'image.php?cfg_admin_path' Remote File Inclusion 2 WEB Sn!pEr.S!Te Hacker
2010-05-20   Snipe Gallery 3.1 - 'gallery.php?cfg_admin_path' Remote File Inclusion 3 WEB Sn!pEr.S!Te Hacker
2010-05-19   SoftDirec 1.05 - 'delete_confirm.php' Cross-Site Scripting 3 WEB indoushka
2010-05-08   Web 2.0 Social Network Freunde Community System - 'user.php' SQL Injection 3 WEB Easy Laster
2010-05-19   Caucho Resin Professional 3.1.5 - '/resin-admin/digest.php' Multiple Cross-Site Scripting Vulnerabil 3 WEB xuanmumu
2010-05-19   Shopzilla Affiliate Script PHP - 'search.php' Cross-Site Scripting 3 WEB Andrea Bocchetti
2010-05-19   Joomla! Component Percha Multicategory Article 0.6 - 'Controller' Arbitrary File Access 3 WEB AntiSecurity
2014-07-08   Dolibarr ERP/CRM 3.5.3 - Multiple Vulnerabilities 3 WEB Deepak Rathore
2010-05-19   Joomla! Component Percha Gallery 1.6 Beta - 'Controller' Traversal Arbitrary File Access 4 WEB AntiSecurity
2010-05-19   Joomla! Component Percha Downloads Attach 1.1 - 'Controller' Traversal Arbitrary File Access 3 WEB AntiSecurity
2010-05-19   Joomla! Component Percha Fields Attach 1.0 - 'Controller' Traversal Arbitrary File Access 3 WEB AntiSecurity
2010-05-19   Joomla! Component Percha Image Attach 1.1 - 'Controller' Traversal Arbitrary File Access 3 WEB AntiSecurity
2010-01-18   Serialsystem 1.0.4 Beta - 'list' Cross-Site Scripting 3 WEB indoushka
2010-01-18   Mobile Chat 2.0.2 - 'chatsmileys.php' Cross-Site Scripting 3 WEB indoushka
2010-05-18   Joomla! Component JComments 2.1 - 'ComntrNam' Cross-Site Scripting 3 WEB High-Tech Bridge SA
2010-05-18   NPDS REvolution 10.02 - 'download.php' Cross-Site Scripting 3 WEB High-Tech Bridge SA
2014-07-07   Photo Org WonderApplications 8.3 iOS - Local File Inclusion 2 WEB Vulnerability-Lab
2010-01-19   Blaze Apps 1.x - SQL Injection / HTML Injection 3 WEB AmnPardaz Security Research Team
2010-05-17   PonVFTP - Insecure Cookie Authentication Bypass 3 WEB SkuLL-HackeR
2010-05-14   Planet Script 1.x - 'idomains.php' Cross-Site Scripting 3 WEB Mr.ThieF
2010-05-17   Platnik 8.1.1 - Multiple SQL Injections 3 WEB podatnik386
2010-01-03   PHP Banner Exchange 1.2 - 'signupconfirm.php' Cross-Site Scripting 3 WEB indoushka
2010-01-03   PHP File Uploader - Arbitrary File Upload 3 WEB indoushka
2010-05-13   NPDS REvolution 10.02 - 'topic' Cross-Site Scripting 4 WEB High-Tech Bridge SA
2014-07-07   Netgear WNR1000v3 - Password Recovery Credential Disclosure (Metasploit) 3 WEB c1ph04
2014-07-06   Frog CMS 0.9.5 - Arbitrary File Upload 3 WEB Javid Hussain
2010-05-13   NPDS REvolution 10.02 - 'download.php' SQL Injection 3 WEB High-Tech Bridge SA
2010-05-19   C99Shell 1.0 Pre-Release build 16 (Web Shell) - 'ch99.php' Cross-Site Scripting 3 WEB indoushka
2010-05-12   TomatoCMS 2.0.x - SQL Injection 2 WEB Russ McRee
2010-05-11   Saurus CMS 4.7 - 'edit.php' Cross-Site Scripting 3 WEB High-Tech Bridge SA
2010-05-11   Affiliate Store Builder - 'edit_cms.php' Multiple SQL Injections 3 WEB High-Tech Bridge SA
2010-05-10   Advanced Poll 2.0 - 'mysql_host' Cross-Site Scripting 3 WEB High-Tech Bridge SA
2010-05-10   EasyPublish CMS 23.04.2010 - URI Cross-Site Scripting 3 WEB High-Tech Bridge SA
2010-05-09   eFront 3.x - 'ask_chat.php' SQL Injection 3 WEB Stefan Esser
2010-01-20   Chipmunk NewsLetter 2.0 - Multiple Cross-Site Scripting Vulnerabilities 3 WEB b0telh0
2010-05-07   ECShop 2.7.2 - 'category.php' SQL Injection 3 WEB Liscker
2010-05-07   Consona - 'n6plugindestructor.asp' Cross-Site Scripting 3 WEB Ruben Santamarta
2010-05-06   Digital Factory Publique! 2.3 - 'sid' SQL Injection 3 WEB Christophe de la Fuente
2010-01-20   kloNews 2.0 - 'cat.php' Cross-Site Scripting 3 WEB cr4wl3r
2014-07-02   Kerio Control 8.3.1 - Blind SQL Injection 3 WEB Khashayar Fereidani
2014-07-02   Zurmo CRM - Persistent Cross-Site Scripting 3 WEB Provensec
2010-01-31   HAWHAW - 'newsread.php' SQL Injection 2 WEB s4r4d0
2010-01-31   Site Manager 3.0 - 'id' SQL Injection 3 WEB Sec Attack Team
2010-01-31   Last Wizardz - 'id' SQL Injection 3 WEB Sec Attack Team
2010-02-01   EmiratesHost - Insecure Cookie Authentication Bypass 3 WEB jago-dz
2010-05-06   DeluxeBB 1.x - 'newpost.php' SQL Injection 3 WEB Stefan Esser
2014-07-01   IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities 3 WEB SEC Consult
2010-02-06   ShopEx Single 4.5.1 - 'errinfo' Cross-Site Scripting 3 WEB cp77fk4r
2010-05-05   WordPress Plugin TYPO3 't3m_cumulus_tagcloud' Extension 1.0 - HTML Injection / Cross-Site Scripting 3 WEB MustLive
2009-02-09   eZoneScripts (Multiple Scripts) - Insecure Cookie Authentication Bypass 3 WEB JIKO
2010-02-09   ThinkPHP 2.0 - 'index.php' Cross-Site Scripting 3 WEB zx
2010-05-18   ecoCMS 18.4.2010 - 'admin.php' Cross-Site Scripting 3 WEB High-Tech Bridge SA
2010-03-11   SamaGraph CMS - 'inside.aspx' SQL Injection 2 WEB K053
2010-03-15   CH-CMS.ch 2 - Multiple Arbitrary File Upload Vulnerabilities 3 WEB EL-KAHINA
2010-05-03   IslamSound - Multiple SQL Injections 3 WEB JIKO
2010-05-01   NolaPro Enterprise 4.0.5538 - Cross-Site Scripting / SQL Injection 3 WEB ekse
2010-05-01   CF Image Hosting Script 1.1 - 'upload.php' Arbitrary File Upload 3 WEB The.Morpheus
2010-05-02   Billwerx RC5.2.2 PL2 - 'primary_number' SQL Injection 4 WEB indoushka
2010-05-03   Mango Blog 1.4.1 - '/archives.cfm/search' Cross-Site Scripting 3 WEB MustLive
2010-04-30   Campsite 3.x - 'article_id' SQL Injection 3 WEB Stefan Esser
2010-03-21   4x CMS - 'login.php' Multiple SQL Injections 3 WEB cr4wl3r
2010-04-30   osCommerce 3.0a5 - Local File Inclusion / HTML Injection 3 WEB Jordi Chancel
2010-04-28   Tele Data's Contact Management Server 0.9 - 'Username' SQL Injection 3 WEB John Leitch
2010-04-29   Your Articles Directory - Login Option SQL Injection 3 WEB Sid3^effects
2010-04-28   velBox 1.2 - Insecure Cookie Authentication Bypass 3 WEB indoushka
2014-06-27   Endeca Latitude 2.2.2 - Cross-Site Request Forgery 3 WEB RedTeam Pentesting
2014-06-27   WordPress Plugin Simple Share Buttons Adder 4.4 - Multiple Vulnerabilities 2 WEB dxw
2014-06-27   Python CGIHTTPServer - Encoded Directory Traversal 2 WEB RedTeam Pentesting
2010-04-27   SmartBlog 1.3 - SQL Injection / Cross-Site Scripting 3 WEB indoushka
2010-04-27   ProArcadeScript - 'search.php' Cross-Site Scripting 3 WEB Sid3^effects
2014-06-27   Mailspect Control Panel 4.0.5 - Multiple Vulnerabilities 3 WEB Onur Alanbel (BGA)
2010-04-13   Zikula Application Framework 1.2.2 - 'index.php?func' Cross-Site Scripting 3 WEB High-Tech Bridge SA
2010-04-13   Zikula Application Framework 1.2.2 - 'ZLanguage.php?lang' Cross-Site Scripting 3 WEB High-Tech Bridge SA
2010-04-26   Kasseler CMS 2.0.5 - 'index.php' Cross-Site Scripting 3 WEB indoushka
2009-11-26   CyberCMS - 'faq.php' SQL Injection 3 WEB hc0de
2010-04-24   PowerEasy 2006 - 'ComeUrl' Cross-Site Scripting 3 WEB Liscker
2010-03-30   HuronCMS - 'index.php' Multiple SQL Injections 3 WEB mat
2010-04-26   Ektron CMS400.NET 7.5.2 - Multiple Vulnerabilities 4 WEB Richard Moore
2010-04-22   FlashCard 2.6.5 - 'id' Cross-Site Scripting 4 WEB Valentin
2014-06-25   Lunar CMS 3.3 - Remote Command Execution 4 WEB LiquidWorm
2014-06-25   Thomson TWG87OUIR - POST Password Cross-Site Request Forgery 4 WEB nopesled
2010-04-21   DBSite wb CMS - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 3 WEB The_Exploited
2010-04-21   e107 0.7.x - '/e107_admin/banner.php' SQL Injection 3 WEB High-Tech Bridge SA
2010-04-09   Viennabux Beta! - 'cat' SQL Injection 3 WEB Easy Laster
2010-04-20   vBulletin Two-Step External Link Module - 'externalredirect.php' Cross-Site Scripting 3 WEB Edgard Chammas
2010-04-19   Kleophatra CMS 0.1.1 - 'module' Cross-Site Scripting 4 WEB anT!-Tr0J4n
2014-06-24   Multiple WordPress Plugins (TimThumb 2.8.13 / WordThumb 1.07) - 'WebShot' Remote Code Execution 4 WEB @u0x
2014-06-23   ZeroCMS 1.0 - 'zero_transact_article.php' SQL Injection 4 WEB Filippos Mastrogiannis
2010-04-15   Ziggurat Farsi CMS - 'bck' Directory Traversal 4 WEB Pouya Daneshmand
2010-04-12   AneCMS 1.0 - Multiple Local File Inclusions 3 WEB AmnPardaz Security Research Team
2010-04-13   Vana CMS - 'Filename' Arbitrary File Download 3 WEB Pouya Daneshmand
2010-04-12   Blog System 1.x - Multiple Input Validation Vulnerabilities 3 WEB cp77fk4r
2010-04-12   TANDBERG Video Communication Server 4.2.1/4.3.0 - Multiple Remote Vulnerabilities 3 WEB Jon Hart
2014-06-21   Lunar CMS 3.3 - Cross-Site Request Forgery / Persistent Cross-Site Scripting 4 WEB LiquidWorm
2010-04-07   Istgah For Centerhost - 'view_ad.php' Cross-Site Scripting 3 WEB indoushka
2010-04-15   Ziggurat Farsi CMS - 'id' Cross-Site Scripting 4 WEB Pouya Daneshmand
2014-06-21   D-Link DSL-2760U-E1 - Persistent Cross-Site Scripting 3 WEB Yuval tisf Nativ
2010-02-24   n-cms-equipe 1.1c.Debug - Multiple Local File Inclusions 3 WEB ITSecTeam
2010-04-07   PotatoNews 1.0.2 - 'nid' Multiple Local File Inclusions 3 WEB mat
2014-06-19   web2Project 3.1 - Multiple Vulnerabilities 3 WEB High-Tech Bridge SA
2010-03-31   OSSIM 2.2.1 - '$_SERVER['PHP_SELF']' Cross-Site Scripting 3 WEB CONIX Security
2010-03-31   Piwik 0.5.5 - 'form_url' Cross-Site Scripting 3 WEB garwga
2008-12-13   WordPress Plugin Fuctweb CapCC 1.0 - 'plugins.php' SQL Injection 3 WEB MustLive
2010-03-29   Joomla! Component com_weblinks - 'id' SQL Injection 4 WEB Pouya Daneshmand
2014-06-18   Cacti Superlinks Plugin 1.4-2 - SQL Injection 3 WEB Napsterakos
2014-06-18   ZTE WXV10 W300 - Multiple Vulnerabilities 3 WEB Osanda Malith Jayathissa
2010-03-24   Joomla! Component com_jresearch - 'Controller' Local File Inclusion 3 WEB Chip d3 bi0s
2010-03-23   Joomla! Component com_cb - 'cat' SQL Injection 3 WEB DevilZ TM
2010-03-23   Joomla! Component com_aml_2 - 'art' SQL Injection 3 WEB Metropolis
2010-03-23   SpringSource (Multiple Products) - Multiple HTML Injection Vulnerabilities 3 WEB Aaron Kulick
2010-03-23   Kasseler CMS News Module - 'id' SQL Injection 3 WEB Palyo34