2014-07-06
|
|
Frog CMS 0.9.5 - Arbitrary File Upload
|
2 |
WEB
|
Javid Hussain
|
2010-05-13
|
|
NPDS REvolution 10.02 - 'download.php' SQL Injection
|
2 |
WEB
|
High-Tech Bridge SA
|
2010-05-19
|
|
C99Shell 1.0 Pre-Release build 16 (Web Shell) - 'ch99.php' Cross-Site Scripting
|
2 |
WEB
|
indoushka
|
2010-05-12
|
|
TomatoCMS 2.0.x - SQL Injection
|
1 |
WEB
|
Russ McRee
|
2010-05-11
|
|
Saurus CMS 4.7 - 'edit.php' Cross-Site Scripting
|
1 |
WEB
|
High-Tech Bridge SA
|
2010-05-11
|
|
Affiliate Store Builder - 'edit_cms.php' Multiple SQL Injections
|
1 |
WEB
|
High-Tech Bridge SA
|
2010-05-10
|
|
Advanced Poll 2.0 - 'mysql_host' Cross-Site Scripting
|
1 |
WEB
|
High-Tech Bridge SA
|
2010-05-10
|
|
EasyPublish CMS 23.04.2010 - URI Cross-Site Scripting
|
1 |
WEB
|
High-Tech Bridge SA
|
2010-05-09
|
|
eFront 3.x - 'ask_chat.php' SQL Injection
|
2 |
WEB
|
Stefan Esser
|
2010-01-20
|
|
Chipmunk NewsLetter 2.0 - Multiple Cross-Site Scripting Vulnerabilities
|
1 |
WEB
|
b0telh0
|
2010-05-07
|
|
ECShop 2.7.2 - 'category.php' SQL Injection
|
1 |
WEB
|
Liscker
|
2010-05-07
|
|
Consona - 'n6plugindestructor.asp' Cross-Site Scripting
|
1 |
WEB
|
Ruben Santamarta
|
2010-05-06
|
|
Digital Factory Publique! 2.3 - 'sid' SQL Injection
|
1 |
WEB
|
Christophe de la Fuente
|
2010-01-20
|
|
kloNews 2.0 - 'cat.php' Cross-Site Scripting
|
1 |
WEB
|
cr4wl3r
|
2014-07-02
|
|
Kerio Control 8.3.1 - Blind SQL Injection
|
1 |
WEB
|
Khashayar Fereidani
|
2014-07-02
|
|
Zurmo CRM - Persistent Cross-Site Scripting
|
1 |
WEB
|
Provensec
|
2010-01-31
|
|
HAWHAW - 'newsread.php' SQL Injection
|
0 |
WEB
|
s4r4d0
|
2010-01-31
|
|
Site Manager 3.0 - 'id' SQL Injection
|
2 |
WEB
|
Sec Attack Team
|
2010-01-31
|
|
Last Wizardz - 'id' SQL Injection
|
1 |
WEB
|
Sec Attack Team
|
2010-02-01
|
|
EmiratesHost - Insecure Cookie Authentication Bypass
|
1 |
WEB
|
jago-dz
|
2010-05-06
|
|
DeluxeBB 1.x - 'newpost.php' SQL Injection
|
1 |
WEB
|
Stefan Esser
|
2014-07-01
|
|
IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities
|
1 |
WEB
|
SEC Consult
|
2010-02-06
|
|
ShopEx Single 4.5.1 - 'errinfo' Cross-Site Scripting
|
1 |
WEB
|
cp77fk4r
|
2010-05-05
|
|
WordPress Plugin TYPO3 't3m_cumulus_tagcloud' Extension 1.0 - HTML Injection / Cross-Site Scripting
|
1 |
WEB
|
MustLive
|
2009-02-09
|
|
eZoneScripts (Multiple Scripts) - Insecure Cookie Authentication Bypass
|
1 |
WEB
|
JIKO
|
2010-02-09
|
|
ThinkPHP 2.0 - 'index.php' Cross-Site Scripting
|
1 |
WEB
|
zx
|
2010-05-18
|
|
ecoCMS 18.4.2010 - 'admin.php' Cross-Site Scripting
|
1 |
WEB
|
High-Tech Bridge SA
|
2010-03-11
|
|
SamaGraph CMS - 'inside.aspx' SQL Injection
|
1 |
WEB
|
K053
|
2010-03-15
|
|
CH-CMS.ch 2 - Multiple Arbitrary File Upload Vulnerabilities
|
1 |
WEB
|
EL-KAHINA
|
2010-05-03
|
|
IslamSound - Multiple SQL Injections
|
1 |
WEB
|
JIKO
|
2010-05-01
|
|
NolaPro Enterprise 4.0.5538 - Cross-Site Scripting / SQL Injection
|
1 |
WEB
|
ekse
|
2010-05-01
|
|
CF Image Hosting Script 1.1 - 'upload.php' Arbitrary File Upload
|
1 |
WEB
|
The.Morpheus
|
2010-05-02
|
|
Billwerx RC5.2.2 PL2 - 'primary_number' SQL Injection
|
2 |
WEB
|
indoushka
|
2010-05-03
|
|
Mango Blog 1.4.1 - '/archives.cfm/search' Cross-Site Scripting
|
1 |
WEB
|
MustLive
|
2010-04-30
|
|
Campsite 3.x - 'article_id' SQL Injection
|
1 |
WEB
|
Stefan Esser
|
2010-03-21
|
|
4x CMS - 'login.php' Multiple SQL Injections
|
1 |
WEB
|
cr4wl3r
|
2010-04-30
|
|
osCommerce 3.0a5 - Local File Inclusion / HTML Injection
|
1 |
WEB
|
Jordi Chancel
|
2010-04-28
|
|
Tele Data's Contact Management Server 0.9 - 'Username' SQL Injection
|
1 |
WEB
|
John Leitch
|
2010-04-29
|
|
Your Articles Directory - Login Option SQL Injection
|
1 |
WEB
|
Sid3^effects
|
2010-04-28
|
|
velBox 1.2 - Insecure Cookie Authentication Bypass
|
2 |
WEB
|
indoushka
|
2014-06-27
|
|
Endeca Latitude 2.2.2 - Cross-Site Request Forgery
|
1 |
WEB
|
RedTeam Pentesting
|
2014-06-27
|
|
WordPress Plugin Simple Share Buttons Adder 4.4 - Multiple Vulnerabilities
|
1 |
WEB
|
dxw
|
2014-06-27
|
|
Python CGIHTTPServer - Encoded Directory Traversal
|
1 |
WEB
|
RedTeam Pentesting
|
2010-04-27
|
|
SmartBlog 1.3 - SQL Injection / Cross-Site Scripting
|
1 |
WEB
|
indoushka
|
2010-04-27
|
|
ProArcadeScript - 'search.php' Cross-Site Scripting
|
1 |
WEB
|
Sid3^effects
|
2014-06-27
|
|
Mailspect Control Panel 4.0.5 - Multiple Vulnerabilities
|
1 |
WEB
|
Onur Alanbel (BGA)
|
2010-04-13
|
|
Zikula Application Framework 1.2.2 - 'index.php?func' Cross-Site Scripting
|
1 |
WEB
|
High-Tech Bridge SA
|
2010-04-13
|
|
Zikula Application Framework 1.2.2 - 'ZLanguage.php?lang' Cross-Site Scripting
|
1 |
WEB
|
High-Tech Bridge SA
|
2010-04-26
|
|
Kasseler CMS 2.0.5 - 'index.php' Cross-Site Scripting
|
1 |
WEB
|
indoushka
|
2009-11-26
|
|
CyberCMS - 'faq.php' SQL Injection
|
1 |
WEB
|
hc0de
|
2010-04-24
|
|
PowerEasy 2006 - 'ComeUrl' Cross-Site Scripting
|
1 |
WEB
|
Liscker
|
2010-03-30
|
|
HuronCMS - 'index.php' Multiple SQL Injections
|
1 |
WEB
|
mat
|
2010-04-26
|
|
Ektron CMS400.NET 7.5.2 - Multiple Vulnerabilities
|
1 |
WEB
|
Richard Moore
|
2010-04-22
|
|
FlashCard 2.6.5 - 'id' Cross-Site Scripting
|
1 |
WEB
|
Valentin
|
2014-06-25
|
|
Lunar CMS 3.3 - Remote Command Execution
|
1 |
WEB
|
LiquidWorm
|
2014-06-25
|
|
Thomson TWG87OUIR - POST Password Cross-Site Request Forgery
|
1 |
WEB
|
nopesled
|
2010-04-21
|
|
DBSite wb CMS - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
|
1 |
WEB
|
The_Exploited
|
2010-04-21
|
|
e107 0.7.x - '/e107_admin/banner.php' SQL Injection
|
1 |
WEB
|
High-Tech Bridge SA
|
2010-04-09
|
|
Viennabux Beta! - 'cat' SQL Injection
|
1 |
WEB
|
Easy Laster
|
2010-04-20
|
|
vBulletin Two-Step External Link Module - 'externalredirect.php' Cross-Site Scripting
|
1 |
WEB
|
Edgard Chammas
|
2010-04-19
|
|
Kleophatra CMS 0.1.1 - 'module' Cross-Site Scripting
|
1 |
WEB
|
anT!-Tr0J4n
|
2014-06-24
|
|
Multiple WordPress Plugins (TimThumb 2.8.13 / WordThumb 1.07) - 'WebShot' Remote Code Execution
|
1 |
WEB
|
@u0x
|
2014-06-23
|
|
ZeroCMS 1.0 - 'zero_transact_article.php' SQL Injection
|
2 |
WEB
|
Filippos Mastrogiannis
|
2010-04-15
|
|
Ziggurat Farsi CMS - 'bck' Directory Traversal
|
2 |
WEB
|
Pouya Daneshmand
|
2010-04-12
|
|
AneCMS 1.0 - Multiple Local File Inclusions
|
2 |
WEB
|
AmnPardaz Security Research Team
|
2010-04-13
|
|
Vana CMS - 'Filename' Arbitrary File Download
|
2 |
WEB
|
Pouya Daneshmand
|
2010-04-12
|
|
Blog System 1.x - Multiple Input Validation Vulnerabilities
|
2 |
WEB
|
cp77fk4r
|
2010-04-12
|
|
TANDBERG Video Communication Server 4.2.1/4.3.0 - Multiple Remote Vulnerabilities
|
2 |
WEB
|
Jon Hart
|
2014-06-21
|
|
Lunar CMS 3.3 - Cross-Site Request Forgery / Persistent Cross-Site Scripting
|
2 |
WEB
|
LiquidWorm
|
2010-04-07
|
|
Istgah For Centerhost - 'view_ad.php' Cross-Site Scripting
|
2 |
WEB
|
indoushka
|
2010-04-15
|
|
Ziggurat Farsi CMS - 'id' Cross-Site Scripting
|
2 |
WEB
|
Pouya Daneshmand
|
2014-06-21
|
|
D-Link DSL-2760U-E1 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Yuval tisf Nativ
|
2010-02-24
|
|
n-cms-equipe 1.1c.Debug - Multiple Local File Inclusions
|
2 |
WEB
|
ITSecTeam
|
2010-04-07
|
|
PotatoNews 1.0.2 - 'nid' Multiple Local File Inclusions
|
2 |
WEB
|
mat
|
2014-06-19
|
|
web2Project 3.1 - Multiple Vulnerabilities
|
3 |
WEB
|
High-Tech Bridge SA
|
2010-03-31
|
|
OSSIM 2.2.1 - '$_SERVER['PHP_SELF']' Cross-Site Scripting
|
2 |
WEB
|
CONIX Security
|
2010-03-31
|
|
Piwik 0.5.5 - 'form_url' Cross-Site Scripting
|
2 |
WEB
|
garwga
|
2008-12-13
|
|
WordPress Plugin Fuctweb CapCC 1.0 - 'plugins.php' SQL Injection
|
2 |
WEB
|
MustLive
|
2010-03-29
|
|
Joomla! Component com_weblinks - 'id' SQL Injection
|
2 |
WEB
|
Pouya Daneshmand
|
2014-06-18
|
|
Cacti Superlinks Plugin 1.4-2 - SQL Injection
|
2 |
WEB
|
Napsterakos
|
2014-06-18
|
|
ZTE WXV10 W300 - Multiple Vulnerabilities
|
1 |
WEB
|
Osanda Malith Jayathissa
|
2010-03-24
|
|
Joomla! Component com_jresearch - 'Controller' Local File Inclusion
|
2 |
WEB
|
Chip d3 bi0s
|
2010-03-23
|
|
Joomla! Component com_cb - 'cat' SQL Injection
|
2 |
WEB
|
DevilZ TM
|
2010-03-23
|
|
Joomla! Component com_aml_2 - 'art' SQL Injection
|
2 |
WEB
|
Metropolis
|
2010-03-23
|
|
SpringSource (Multiple Products) - Multiple HTML Injection Vulnerabilities
|
2 |
WEB
|
Aaron Kulick
|
2010-03-23
|
|
Kasseler CMS News Module - 'id' SQL Injection
|
2 |
WEB
|
Palyo34
|
2014-06-17
|
|
Motorola SBG901 Wireless Modem - Cross-Site Request Forgery
|
2 |
WEB
|
Blessen Thomas
|
2010-03-23
|
|
PHPAuthent 0.2.1 - 'useradd.php' Multiple HTML Injection Vulnerabilities
|
1 |
WEB
|
Yoyahack
|
2010-03-23
|
|
RepairShop2 - 'index.php?Prod' Cross-Site Scripting
|
1 |
WEB
|
kaMtiEz
|
2010-03-23
|
|
agXchange ESM - 'ucquerydetails.jsp' Cross-Site Scripting
|
1 |
WEB
|
Lament
|
2010-03-19
|
|
vBulletin 4.0.2 - Search Cross-Site Scripting
|
1 |
WEB
|
5ubzer0
|
2010-03-22
|
|
PHPKIT 1.6.x - 'b-day.php' Addon SQL Injection
|
0 |
WEB
|
n3w7u
|
2010-03-23
|
|
Lussumo Vanilla 1.1.10 - 'definitions.php' Multiple Remote File Inclusions
|
2 |
WEB
|
eidelweiss
|
2010-03-22
|
|
agXchange ESM - 'ucschcancelproc.jsp' Open Redirection
|
1 |
WEB
|
Lament
|
2010-03-19
|
|
PHPWind 6.0 - Multiple Cross-Site Scripting Vulnerabilities
|
1 |
WEB
|
Liscker
|
2010-03-18
|
|
Kempt SiteDone 2.0 - '/detail.php' Cross-Site Scripting / SQL Injection
|
1 |
WEB
|
d3v1l
|
2010-03-18
|
|
tenfourzero.net Shutter 0.1.4 - 'admin.html' Multiple SQL Injections
|
1 |
WEB
|
blake
|
2010-03-17
|
|
PHPBB2 Plus 1.53 - 'kb.php' SQL Injection
|
1 |
WEB
|
Gamoscu
|
2010-03-17
|
|
Joomla! Component com_alert - 'q_item' SQL Injection
|
1 |
WEB
|
N2n-Hacker
|
2010-03-17
|
|
eFront 3.5.5 - 'langname' Local File Inclusion
|
1 |
WEB
|
7Safe
|
2010-03-16
|
|
Joomla! Component com_as - 'catid' SQL Injection
|
1 |
WEB
|
N2n-Hacker
|
2010-03-15
|
|
Dojo Toolkit 1.4.1 - '/doh/runner.html' Multiple Cross-Site Scripting Vulnerabilities
|
1 |
WEB
|
Adam Bixby
|
2010-03-15
|
|
Dojo Toolkit 1.4.1 - '/dijit/tests/_testCommon.js?theme' Cross-Site Scripting
|
1 |
WEB
|
Adam Bixby
|
2010-03-15
|
|
Domain Verkaus & Auktions Portal - 'index.php' SQL Injection
|
1 |
WEB
|
Easy Laster
|
2010-03-15
|
|
Andromeda 1.9.2 - 's' Cross-Site Scripting / Session Fixation
|
1 |
WEB
|
indoushka
|
2010-03-15
|
|
Pars CMS - 'RP' Multiple SQL Injections
|
1 |
WEB
|
Isfahan
|
2010-03-15
|
|
(Multiple Products) - 'banner.swf' Cross-Site Scripting
|
1 |
WEB
|
MustLive
|
2010-03-14
|
|
DirectAdmin 1.33.6 - 'CMD_DB_VIEW' Cross-Site Scripting
|
1 |
WEB
|
r0t
|
2010-03-15
|
|
Zigurrat Farsi CMS - '/manager/textbox.asp' SQL Injection
|
1 |
WEB
|
Isfahan
|
2010-03-13
|
|
Joomla! Component com_d-greinar - 'maintree' Cross-Site Scripting
|
0 |
WEB
|
DevilZ TM
|
2010-03-13
|
|
Joomla! Component com_seek - 'id' SQL Injection
|
1 |
WEB
|
DevilZ TM
|
2010-03-12
|
|
pMyAdmin 3.3.5.1 - 'db_create.php' Cross-Site Scripting
|
1 |
WEB
|
Liscker
|
2010-03-12
|
|
Easynet4u Forum Host - 'topic.php' SQL Injection
|
1 |
WEB
|
Pr0T3cT10n
|
2010-03-11
|
|
CodeIgniter 1.0 - 'BASEPATH' Multiple Remote File Inclusions
|
1 |
WEB
|
eidelweiss
|
2010-03-11
|
|
ARTIS ABTON CMS - Multiple SQL Injections
|
1 |
WEB
|
MustLive
|
2010-03-11
|
|
AneCMS 1.0 - 'index.php' Multiple HTML Injection Vulnerabilities
|
1 |
WEB
|
pratul agrawal
|
2014-06-13
|
|
ZeroCMS 1.0 - 'zero_transact_user.php' Handling Privilege Escalation
|
1 |
WEB
|
Tiago Carvalho
|
2014-06-13
|
|
Yealink VoIP Phone SIP-T38G - Local File Inclusion
|
1 |
WEB
|
Mr.Un1k0d3r
|
2014-06-13
|
|
Plesk 10.4.4/11.0.9 - SSO XML External Entity / Cross-Site Scripting Injection
|
1 |
WEB
|
BLacK ZeRo
|
2010-03-10
|
|
DDL CMS 2.1 - 'blacklist.php' Cross-Site Scripting
|
1 |
WEB
|
ITSecTeam
|
2010-03-10
|
|
60cycleCMS - 'select.php' Multiple HTML Injection Vulnerabilities
|
1 |
WEB
|
pratul agrawal
|
2010-03-10
|
|
Friendly Technologies TR-069 ACS 2.8.9 - Login SQL Injection
|
1 |
WEB
|
Yaniv Miron
|
2010-03-10
|
|
Max Network Technology BBSMAX 4.2 - 'threadid' Cross-Site Scripting
|
1 |
WEB
|
Liscker
|
2010-03-09
|
|
IBM ENOVIA SmarTeam - 'LoginPage.aspx' Cross-Site Scripting
|
1 |
WEB
|
Lament
|
2010-02-16
|
|
wh-em.com upload 7.0 - Insecure Cookie Authentication Bypass
|
2 |
WEB
|
indoushka
|