Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2009-01-23   PHP-Nuke Downloads Module - 'url' SQL Injection 1 WEB Sina Yazdanmehr
2009-01-20   MoinMoin 1.8 - 'AttachFile.py' Cross-Site Scripting 1 WEB SecureState
2009-01-20   Apache JackRabbit 1.4/1.5 Content Repository (JCR) - 'swr.jsp?q' Cross-Site Scripting 1 WEB Red Hat
2009-01-20   Apache JackRabbit 1.4/1.5 Content Repository (JCR) - 'search.jsp?q' Cross-Site Scripting 2 WEB Red Hat
2009-01-16   Blog Manager - 'categoryId' Cross-Site Scripting 2 WEB Pouya_Server
2009-01-16   Blog Manager - 'ItemID' SQL Injection 2 WEB Pouya_Server
2009-01-16   LemonLDAP:NG 0.9.3.1 - User Enumeration / Cross-Site Scripting 2 WEB clément Oudot
2009-01-15   w3bcms - '/admin/index.php' SQL Injection 2 WEB Pouya_Server
2009-01-15   Masir Camp 3.0 - 'SearchKeywords' SQL Injection 2 WEB Pouya_Server
2009-01-15   Active Bids - 'search' SQL Injection 1 WEB Pouya_Server
2009-01-15   Active Bids - 'search' Cross-Site Scripting 2 WEB Pouya_Server
2009-01-15   LinksPro - 'OrderDirection' SQL Injection 2 WEB Pouya_Server
2009-01-15   MKPortal 1.2.1 - '/modules/rss/handler_image.php?i' Cross-Site Scripting 2 WEB waraxe
2009-01-15   MKPortal 1.2.1 - '/modules/blog/index.php' Home Template Textarea SQL Injection 2 WEB waraxe
2009-01-14   Dark Age CMS 2.0 - 'login.php' SQL Injection 2 WEB darkjoker
2014-04-07   XAMPP 3.2.1 & phpMyAdmin 4.1.6 - Multiple Vulnerabilities 2 WEB hackerDesk
2009-01-12   Ovidentia 6.7.5 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 2 WEB Ivan Sanchez
2009-01-12   Comersus Cart 6 - User Email and User Password Unauthorized Access 2 WEB ajann
2009-01-12   Visuplay CMS - Multiple SQL Injections 2 WEB Joseph Giron
2009-01-07   tadbook2 Module for XOOPS - 'open_book.php' SQL Injection 1 WEB stylextra
2009-01-07   Plunet BusinessManager 4.1 - 'pagesUTF8/auftrag_job.jsp?Pfad' Direct Request Information Disclosure 2 WEB Matteo Ignaccolo
2009-01-07   Plunet BusinessManager 4.1 - 'pagesUTF8/Sys_DirAnzeige.jsp?Pfad' Direct Request Information Disclosu 1 WEB Matteo Ignaccolo
2009-01-07   Plunet BusinessManager 4.1 - '/pagesUTF8/auftrag_allgemeinauftrag.jsp' Multiple Cross-Site Scripting 2 WEB Matteo Ignaccolo
2014-04-05   Private Photo+Video 1.1 Pro iOS - Persistent 2 WEB Vulnerability-Lab
2014-04-04   WordPress Plugin XCloner 3.1.0 - Cross-Site Request Forgery 1 WEB High-Tech Bridge SA
2009-01-05   SolucionXpressPro - 'main.php' SQL Injection 2 WEB Ehsan_Hp200
2008-12-04   NPDS < 08.06 - Multiple Input Validation Vulnerabilities 2 WEB Jean-François Leclerc
2008-12-29   Madrese-Portal - 'haber.asp' SQL Injection 2 WEB Sina Yazdanmehr
2008-12-29   ViArt Shop 3.5 - 'manuals_search.php?manuals_search' Cross-Site Scripting 2 WEB Xia Shing Zee
2008-12-29   Mavi Emlak - 'newDetail.asp' SQL Injection 2 WEB Sina Yazdanmehr
2009-01-08   Openfire 3.6.2 - 'log.jsp' Directory Traversal 2 WEB Federico Muttis
2009-01-08   Openfire 3.6.2 - 'log.jsp' Cross-Site Scripting 2 WEB Federico Muttis
2009-01-08   Openfire 3.6.2 - 'user-properties.jsp' Cross-Site Scripting 2 WEB Federico Muttis
2009-01-08   Openfire 3.6.2 - 'group-summary.jsp' Cross-Site Scripting 2 WEB Federico Muttis
2008-12-19   PECL Alternative PHP Cache Local 3 - HTML Injection 2 WEB Moritz Naumann
2008-12-18   Easysitenetwork Jokes Complete Website - 'joke.php' SQL Injection 2 WEB Ehsan_Hp200
2008-12-18   DO-CMS 3.0 - 'p' Multiple SQL Injections 2 WEB crash over
2014-04-03   Oracle Identity Manager 11g R2 SP1 (11.1.2.1.0) - Unvalidated Redirects 2 WEB Giuseppe D'Amore
2008-12-17   PHPcksec 0.2 - 'PHPcksec.php' Cross-Site Scripting 2 WEB ahmadbady
2014-04-03   CMS Made Simple 1.11.10 - Multiple Cross-Site Scripting Vulnerabilities 2 WEB Blessen Thomas
2014-04-02   Kloxo-MR 6.5.0 - Cross-Site Request Forgery 1 WEB Necmettin COSKUN
2014-04-02   Kloxo 6.1.18 Stable - Cross-Site Request Forgery 2 WEB Necmettin COSKUN
2014-04-02   iShare Your Moving Library 1.0 iOS - Multiple Vulnerabilities 2 WEB Vulnerability-Lab
2008-12-15   Injader 2.1.1 - SQL Injection / HTML Injection 2 WEB anonymous
2008-12-14   WebPhotoPro - Multiple SQL Injections 2 WEB baltazar
2014-04-02   CIS Manager CMS - SQL Injection 2 WEB felipe andrian
2008-12-13   ASP-DEV XM Events Diary - 'cat' SQL Injection 2 WEB Pouya_Server
2008-12-01   Octeth Oempro 3.5.5 - Multiple SQL Injections 1 WEB security curmudgeon
2008-12-11   Multiple Ad Server Solutions Products - 'logon_processing.jsp' SQL Injection 2 WEB 3d D3v!L
2008-12-09   Professional Download Assistant 0.1 - SQL Injection 2 WEB ZoRLu
2008-12-08   PHPepperShop 1.4 - 'shop/Admin/SHOP_KONFIGURATION.php' Cross-Site Scripting 2 WEB th3.r00k.ieatpork
2008-12-08   PHPepperShop 1.4 - 'shop/Admin/shop_kunden_mgmt.php' Cross-Site Scripting 2 WEB th3.r00k.ieatpork
2008-12-08   PHPepperShop 1.4 - 'shop/kontakt.php' Cross-Site Scripting 2 WEB th3.r00k.ieatpork
2008-12-08   PHPepperShop 1.4 - 'index.php' Cross-Site Scripting 2 WEB th3.r00k.ieatpork
2008-12-08   PrestaShop 1.1 - 'order.php?PATH_INFO' Cross-Site Scripting 1 WEB th3.r00k.ieatpork
2008-12-08   PrestaShop 1.1 - '/admin/login.php?PATH_INFO' Cross-Site Scripting 1 WEB th3.r00k.ieatpork
2008-12-06   TWiki 4.x - 'URLPARAM' Cross-Site Scripting 1 WEB Marc Schoenefeld
2008-12-06   TWiki 4.x - 'SEARCH' Remote Command Execution 1 WEB Troy Bollinge
2014-04-01   Alienvault 4.5.0 - (Authenticated) SQL Injection (Metasploit) 1 WEB Brandon Perry
2008-12-04   PHPSTREET WebBoard 1.0 - 'show.php' SQL Injection 1 WEB CWH Underground
2008-12-04   RevSense 1.0 - SQL Injection / Cross-Site Scripting 1 WEB Pouya_Server
2008-12-03   Yappa-ng - Query String Cross-Site Scripting 0 WEB Pouya_Server
2008-12-03   Yappa-ng - 'index.php?album' Cross-Site Scripting 0 WEB Pouya_Server
2014-04-01   Horde Webmail 5.1 - Open Redirect 0 WEB felipe andrian
2008-12-02   Orkut Clone - 'profile_social.php?id' Cross-Site Scripting 0 WEB d3b4g
2008-12-02   Orkut Clone - 'profile_social.php?id' SQL Injection 0 WEB d3b4g
2008-12-02   Jbook - SQL Injection 0 WEB Pouya_Server
2008-12-02   Z1Exchange 1.0 - 'id' Cross-Site Scripting 0 WEB Pouya_Server
2008-12-02   Z1Exchange 1.0 - 'id' SQL Injection 0 WEB Pouya_Server
2008-12-02   Fantastico - 'index.php' Local File Inclusion 0 WEB Super-Crystal
2008-12-01   IBM Rational ClearCase 7/8 - Cross-Site Scripting 0 WEB IBM
2008-12-01   Pre ASP Job Board - 'emp_login.asp' Cross-Site Scripting 0 WEB Pouya_Server
2008-12-01   ASP Forum Script - 'default.asp' Query String Cross-Site Scripting 0 WEB Pouya_Server
2008-12-01   ASP Forum Script - 'messages.asp?forum_id' Cross-Site Scripting 0 WEB Pouya_Server
2008-12-01   ASP Forum Script - 'new_message.asp?forum_id' Cross-Site Scripting 0 WEB Pouya_Server
2008-12-01   ASP Forum Script - 'messages.asp?message_id' SQL Injection 0 WEB Pouya_Server
2008-12-01   PHP JOBWEBSITE PRO - 'forgot.php' Cross-Site Scripting 0 WEB Pouya_Server
2008-12-01   PHP JOBWEBSITE PRO - 'adname' SQL Injection 0 WEB Pouya_Server
2014-03-31   EMC Cloud Tiering Appliance 10.0 - XML External Entity Arbitrary File Read (Metasploit) 0 WEB Brandon Perry
2014-03-31   WordPress Plugin Ajax Pagination 1.1 - Local File Inclusion 0 WEB Glyn Wintle
2014-03-31   Vanctech File Commander 1.1 iOS - Multiple Vulnerabilities 0 WEB Vulnerability-Lab
2014-03-31   PhotoWIFI Lite 1.0 iOS - Multiple Vulnerabilities 0 WEB Vulnerability-Lab
2008-12-01   Softbiz Classifieds Script - '/admin/index.php?msg' Cross-Site Scripting 0 WEB Pouya_Server
2008-12-01   Softbiz Classifieds Script - '/admin/adminhome.php?msg' Cross-Site Scripting 0 WEB Pouya_Server
2008-12-01   Softbiz Classifieds Script - 'lostpassword.php?msg' Cross-Site Scripting 0 WEB Pouya_Server
2008-12-01   Softbiz Classifieds Script - 'gallery.php?radio' Cross-Site Scripting 0 WEB Pouya_Server
2008-12-01   Softbiz Classifieds Script - '/advertisers/signinform.php?msg' Cross-Site Scripting 1 WEB Pouya_Server
2008-12-01   Softbiz Classifieds Script - 'showcategory.php?radio' Cross-Site Scripting 0 WEB Pouya_Server
2008-12-01   CodeToad ASP Shopping Cart Script - Cross-Site Scripting 1 WEB Pouya_Server
2008-12-01   Pre Classified Listings 1.0 - 'signup.asp' Cross-Site Scripting 1 WEB Pouya_Server
2008-12-01   Pre Classified Listings 1.0 - 'detailad.asp' SQL Injection 1 WEB Pouya_Server
2008-11-28   RakhiSoftware Shopping Cart - PHPSESSID Cookie Manipulation Full Path Disclosure 1 WEB Charalambous Glafkos
2008-11-28   RakhiSoftware Shopping Cart - 'product.php' Multiple Cross-Site Scripting Vulnerabilities 1 WEB Charalambous Glafkos
2008-11-29   Basic-CMS - 'q' Cross-Site Scripting 1 WEB Pouya_Server
2008-11-29   Venalsur Booking Centre 2.01 - Multiple Cross-Site Scripting Vulnerabilities 2 WEB Pouya_Server
2008-11-29   ParsBlogger - 'blog.asp' Cross-Site Scripting 2 WEB Pouya_Server
2008-11-29   Ocean12 Mailing LisManager Gold 2.04 - 'Email' SQL Injection 2 WEB Charalambous Glafkos
2008-11-29   Ocean12 (Multiple Products) - 'Admin_ID' SQL Injection 2 WEB Charalambous Glafkos
2008-11-29   Ocean12 FAQ Manager Pro - 'Keyword' Cross-Site Scripting 2 WEB Charalambous Glafkos
2008-11-27   AssoCIateD 1.4.4 - 'menu' Cross-Site Scripting 1 WEB CWH Underground
2008-11-24   COms - 'dynamic.php' Cross-Site Scripting 2 WEB Pouya_Server
2008-11-23   Pilot Group PG Roommate Finder Solution - SQL Injection 2 WEB ZoRLu
2008-11-20   Softbiz Classifieds Script - Cross-Site Scripting 2 WEB Vahid Ezraeil
2008-11-19   Easyedit CMS - 'news.php?intPageID' SQL Injection 2 WEB d3v1l
2008-11-19   Easyedit CMS - 'page.php?intPageID' SQL Injection 2 WEB d3v1l
2008-11-19   Easyedit CMS - 'subcategory.php?intSubCategoryID' SQL Injection 3 WEB d3v1l
2008-11-18   Kimson CMS - 'id' Cross-Site Scripting 2 WEB md.r00t
2008-11-17   BoutikOne CMS - 'search_query' Cross-Site Scripting 2 WEB d3v1l
2014-03-29   ASP-Nuke 2.0.7 - 'gotourl.asp' Open Redirect 2 WEB felipe andrian
2008-11-11   Sun Java System Identity Manager 6.0/7.x - Multiple Vulnerabilities 2 WEB Richard Brain
2008-11-10   Dizi Portali - 'film.asp' SQL Injection 3 WEB Kaan KAMIS
2008-11-10   IBM Tivoli Netcool Service Quality Manager - Cross-Site Scripting / HTML Injection 2 WEB Francesco Bianchino
2008-11-08   Zeeways Shaadi Clone 2.0 - Authentication Bypass (2) 2 WEB G4N0K
2008-11-09   MoinMoin 1.5.8/1.9 - Cross-Site Scripting / Information Disclosure 2 WEB Xia Shing Zee
2008-11-07   TurnkeyForms Software Directory 1.0 - SQL Injection / Cross-Site Scripting 2 WEB G4N0K
2008-11-06   CuteNews aj-fork - 'path' Remote File Inclusion 2 WEB DeltahackingTEAM
2014-03-28   iStArtApp FileXChange 6.2 iOS - Multiple Vulnerabilities 1 WEB Vulnerability-Lab
2008-11-04   DHCart 3.84 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities 2 WEB Lostmon
2008-11-04   firmCHANNEL Indoor & Outdoor Digital Signage 3.24 - Cross-Site Scripting 2 WEB Brad Antoniewicz
2008-11-02   YourFreeWorld Downline Builder Pro - 'tr.php' SQL Injection 2 WEB Hussin X
2014-03-27   Joomla! Component Kunena 3.0.4 - Persistent Cross-Site Scripting 2 WEB Qoppa
2014-03-27   LinEx - Password Reset 2 WEB N B Sri Harsha
2014-03-27   ePhone Disk 1.0.2 iOS - Multiple Vulnerabilities 2 WEB Vulnerability-Lab
2014-03-27   Easy FileManager 1.1 iOS - Multiple Vulnerabilities 2 WEB Vulnerability-Lab
2014-03-27   Lazybone Studios WiFi Music 1.0 iOS - Multiple Vulnerabilities 2 WEB Vulnerability-Lab