2008-07-16
|
|
Evaria ECMS 1.1 - 'DOCUMENT_ROOT' Multiple Remote File Inclusions
|
3 |
WEB
|
ahmadbady
|
2008-07-15
|
|
WordPress Core 2.5.1 - 'press-this.php' Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
anonymous
|
2008-07-14
|
|
Pubs Black Cat [The Fun] - 'browse.groups.php' SQL Injection
|
3 |
WEB
|
RMx
|
2008-07-11
|
|
Hudson 1.223 - 'q' Cross-Site Scripting
|
2 |
WEB
|
syniack
|
2008-07-11
|
|
IBM Maximo 4.1/5.2 - '/debug.jsp' HTML Injection / Information Disclosure
|
3 |
WEB
|
Deniz Cevik
|
2008-07-10
|
|
eSyndiCat 2.2 - 'register.php' Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Fugitif
|
2014-03-03
|
|
SpagoBI 4.0 - Arbitrary Cross-Site Scripting / Arbitrary File Upload
|
3 |
WEB
|
Christian Catalano
|
2014-03-03
|
|
SpagoBI 4.0 - Persistent HTML Script Insertion
|
3 |
WEB
|
Christian Catalano
|
2014-03-03
|
|
SpagoBI 4.0 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Christian Catalano
|
2014-03-03
|
|
couponPHP CMS 1.0 - Multiple Persistent Cross-Site Scripting / SQL Injections
|
3 |
WEB
|
LiquidWorm
|
2008-07-10
|
|
V-Webmail 1.6.4 - '/includes/email.list.search.php?CONFIG[includes]' Remote File Inclusion
|
3 |
WEB
|
CraCkEr
|
2008-07-10
|
|
V-Webmail 1.6.4 - '/includes/prepend.php?CONFIG[includes]' Remote File Inclusion
|
3 |
WEB
|
CraCkEr
|
2008-07-10
|
|
V-Webmail 1.6.4 - '/includes/cachedConfig.php?CONFIG[pear_dir]' Remote File Inclusion
|
2 |
WEB
|
CraCkEr
|
2008-07-10
|
|
V-Webmail 1.6.4 - '/includes/prepend.php?CONFIG[pear_dir]' Remote File Inclusion
|
3 |
WEB
|
CraCkEr
|
2008-07-10
|
|
V-Webmail 1.6.4 - '/includes/pear/File.php?CONFIG[pear_dir]' Remote File Inclusion
|
3 |
WEB
|
CraCkEr
|
2008-07-10
|
|
V-Webmail 1.6.4 - '/includes/pear/Log.php?CONFIG[pear_dir]' Remote File Inclusion
|
3 |
WEB
|
CraCkEr
|
2008-07-10
|
|
V-Webmail 1.6.4 - '/includes/pear/System.php?CONFIG[pear_dir]' Remote File Inclusion
|
3 |
WEB
|
CraCkEr
|
2008-07-10
|
|
V-Webmail 1.6.4 - '/includes/pear/Console/Getopt.php?CONFIG[pear_dir]' Remote File Inclusion
|
3 |
WEB
|
CraCkEr
|
2008-07-10
|
|
V-Webmail 1.6.4 - '/includes/pear/Mail/mimeDecode.php?CONFIG[pear_dir]' Remote File Inclusion
|
3 |
WEB
|
CraCkEr
|
2008-07-10
|
|
V-Webmail 1.6.4 - '/includes/pear/XML/Tree.php?CONFIG[pear_dir]' Remote File Inclusion
|
3 |
WEB
|
CraCkEr
|
2008-07-10
|
|
V-Webmail 1.6.4 - '/includes/pear/XML/parser.php?CONFIG[pear_dir]' Remote File Inclusion
|
3 |
WEB
|
CraCkEr
|
2008-07-10
|
|
V-Webmail 1.6.4 - '/includes/pear/Net/Socket.php?CONFIG[pear_dir]' Remote File Inclusion
|
3 |
WEB
|
CraCkEr
|
2008-07-10
|
|
V-Webmail 1.6.4 - '/includes/pear/Mail/RFC822.php?CONFIG[pear_dir]' Remote File Inclusion
|
3 |
WEB
|
CraCkEr
|
2008-07-09
|
|
TGS Content Management 0.3.2r2 - 'login.php' Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Julian Rodriguez
|
2008-07-09
|
|
TGS Content Management 0.3.2r2 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Julian Rodriguez
|
2008-07-09
|
|
Xomol CMS 1.2 - '/index.php' HTML Injection / Cross-Site Scripting
|
3 |
WEB
|
Julian Rodriguez
|
2008-07-09
|
|
PageFusion 1.5 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Julian Rodriguez
|
2008-07-08
|
|
vBulletin 3.7.1 - 'admincp/faq.php?Injection adminlog.php' Cross-Site Scripting
|
3 |
WEB
|
Jessica Hope
|
2008-07-07
|
|
Fuzzylime (cms) 3.01 - 'blog.php' Local File Inclusion
|
2 |
WEB
|
Cod3rZ
|
2008-07-07
|
|
PHP-Nuke 4ndvddb 0.91 Module - 'id' SQL Injection
|
3 |
WEB
|
Lovebug
|
2008-07-07
|
|
Zoph 0.7.2.1 - 'search.php?_off' Cross-Site Scripting
|
2 |
WEB
|
Julian Rodriguez
|
2008-07-07
|
|
Zoph 0.7.2.1 - SQL Injection
|
2 |
WEB
|
Julian Rodriguez
|
2008-07-07
|
|
DodosMail 2.5 - 'dodosmail.php' Local File Inclusion
|
4 |
WEB
|
ahmadbady
|
2008-07-02
|
|
Joomla! / Mambo Component com_is 1.0.1 - Multiple SQL Injections
|
3 |
WEB
|
H-T Team
|
2008-06-30
|
|
FaName 1.0 - 'page.php?name' Cross-Site Scripting
|
4 |
WEB
|
Jesper Jurcenoks
|
2008-06-30
|
|
FaName 1.0 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Jesper Jurcenoks
|
2008-06-30
|
|
RSS-aggregator 1.0 - Authentication Bypass
|
4 |
WEB
|
CWH Underground
|
2008-06-30
|
|
RSS-aggregator 1.0 - 'IdTag' SQL Injection
|
4 |
WEB
|
CWH Underground
|
2008-06-30
|
|
RSS-aggregator 1.0 - 'IdFlux' SQL Injection
|
4 |
WEB
|
CWH Underground
|
2014-03-01
|
|
Oracle Demantra 12.2.1 - Database Credentials Disclosure
|
3 |
WEB
|
Portcullis
|
2014-03-01
|
|
Oracle Demantra 12.2.1 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Portcullis
|
2014-03-01
|
|
Oracle Demantra 12.2.1 - SQL Injection
|
3 |
WEB
|
Portcullis
|
2014-03-01
|
|
Oracle Demantra 12.2.1 - Arbitrary File Disclosure
|
3 |
WEB
|
Portcullis
|
2014-02-28
|
|
SpagoBI 4.0 - Privilege Escalation
|
3 |
WEB
|
Christian Catalano
|
2014-02-28
|
|
webERP 4.11.3 - 'SalesInquiry.php?SortBy' SQL Injection
|
3 |
WEB
|
HauntIT
|
2014-02-28
|
|
WordPress Plugin VideoWhisper 4.27.3 - Multiple Vulnerabilities
|
3 |
WEB
|
High-Tech Bridge SA
|
2014-02-28
|
|
MICROSENS Profi Line Switch 10.3.1 - Privilege Escalation
|
4 |
WEB
|
SEC Consult
|
2014-02-28
|
|
Plex Media Server 0.9.9.2.374-aa23a69 - Multiple Vulnerabilities
|
3 |
WEB
|
SEC Consult
|
2014-02-28
|
|
Webuzo 2.1.3 - Multiple Vulnerabilities
|
2 |
WEB
|
Mahendra
|
2008-06-26
|
|
The Rat CMS - 'viewarticle2.php?id' SQL Injection
|
2 |
WEB
|
CWH Underground
|
2008-06-26
|
|
The Rat CMS - 'viewarticle.php?id' SQL Injection
|
3 |
WEB
|
CWH Underground
|
2008-06-26
|
|
The Rat CMS - 'viewarticle2.php?id' Cross-Site Scripting
|
3 |
WEB
|
CWH Underground
|
2008-06-26
|
|
The Rat CMS - 'viewarticle.php' Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
CWH Underground
|
2014-02-28
|
|
PHP Ticket System Beta 1 - 'get_all_created_by_user.php?id' SQL Injection
|
3 |
WEB
|
HauntIT
|
2014-02-28
|
|
PHP-CMDB 0.7.3 - Multiple Vulnerabilities
|
3 |
WEB
|
HauntIT
|
2008-06-26
|
|
Commtouch Anti-Spam Enterprise Gateway - Cross-Site Scripting
|
3 |
WEB
|
Erez Metula
|
2014-02-27
|
|
Bluetooth Photo Share Pro 2.0 iOS - Multiple Vulnerabilities
|
3 |
WEB
|
Vulnerability-Lab
|
2014-02-27
|
|
GDL 4.2 - Multiple Vulnerabilities
|
3 |
WEB
|
ByEge
|
2008-06-23
|
|
A+ PHP Scripts News Management System 0.3 - Multiple Input Validation Vulnerabilities
|
3 |
WEB
|
CraCkEr
|
2008-06-23
|
|
Benja CMS 0.1 - '/admin/admin_edit_topmenu.php' Cross-Site Scripting
|
3 |
WEB
|
CWH Underground
|
2008-06-23
|
|
Benja CMS 0.1 - '/admin/admin_new_submenu.php' Cross-Site Scripting
|
3 |
WEB
|
CWH Underground
|
2008-06-23
|
|
Benja CMS 0.1 - '/admin/admin_edit_submenu.php' Cross-Site Scripting
|
3 |
WEB
|
CWH Underground
|
2008-06-23
|
|
Chipmunk Blog - 'cat.php' Cross-Site Scripting
|
2 |
WEB
|
sl4xUz
|
2008-06-23
|
|
Chipmunk Blog - 'archive.php' Cross-Site Scripting
|
2 |
WEB
|
sl4xUz
|
2008-06-23
|
|
Chipmunk Blog - 'photos.php' Cross-Site Scripting
|
2 |
WEB
|
sl4xUz
|
2008-06-23
|
|
Chipmunk Blog - 'comments.php' Cross-Site Scripting
|
2 |
WEB
|
sl4xUz
|
2008-06-23
|
|
Chipmunk Blog - 'members.php' Cross-Site Scripting
|
4 |
WEB
|
sl4xUz
|
2008-06-22
|
|
Open Digital Assets Repository System 1.0.2 - Remote File Inclusion
|
3 |
WEB
|
CraCkEr
|
2008-06-22
|
|
Joomla! Component EXP Shop 1.0 - SQL Injection
|
3 |
WEB
|
His0k4
|
2008-06-23
|
|
IDMOS 1.0 - 'site_absolute_path' Multiple Remote File Inclusions
|
3 |
WEB
|
CraCkEr
|
2008-06-23
|
|
PEGames - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
CraCkEr
|
2008-06-21
|
|
phpAuction - 'profile.php' SQL Injection (2)
|
3 |
WEB
|
Mr.SQL
|
2008-06-20
|
|
GL-SH Deaf Forum 6.5.5 - Cross-Site Scripting / Arbitrary File Upload
|
3 |
WEB
|
AmnPardaz
|
2008-06-19
|
|
vBulletin 3.7.1 - Moderation Control Panel 'redirect' Cross-Site Scripting
|
3 |
WEB
|
Jessica Hope
|
2008-06-18
|
|
KEIL Software PhotoKorn 1.542 - 'index.php' SQL Injection
|
3 |
WEB
|
t@nzo0n
|
2008-06-17
|
|
OpenDocMan 1.x - 'out.php' Cross-Site Scripting
|
3 |
WEB
|
Sergi Rosello
|
2008-06-16
|
|
SimpleNotes - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
sl4xUz
|
2014-02-26
|
|
Piwigo 2.6.1 - Cross-Site Request Forgery
|
3 |
WEB
|
killall-9
|
2008-06-13
|
|
vBulletin 3.6.10/3.7.1 - 'redirect' Cross-Site Scripting
|
3 |
WEB
|
anonymous
|
2008-06-11
|
|
Flat Calendar 1.1 - Multiple Administrative Scripts Authentication Bypass Vulnerabilities
|
2 |
WEB
|
Crackers_Child
|
2008-06-11
|
|
PHPEasyData 1.5.4 - 'annuaire.php' Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Sylvain THUAL
|
2008-06-11
|
|
PHPEasyData 1.5.4 - 'last_records.php?annuaire' Cross-Site Scripting
|
3 |
WEB
|
Sylvain THUAL
|
2008-06-11
|
|
PHPEasyData 1.5.4 - '/admin/login.php?Username' SQL Injection
|
3 |
WEB
|
Sylvain THUAL
|
2008-06-11
|
|
PHPEasyData 1.5.4 - 'annuaire.php?annuaire' SQL Injection
|
3 |
WEB
|
Sylvain THUAL
|
2008-06-10
|
|
Noticia Portal - 'detalle_noticia.php' SQL Injection
|
3 |
WEB
|
t@nzo0n
|
2014-02-25
|
|
Private Camera Pro 5.0 iOS - Multiple Vulnerabilities
|
3 |
WEB
|
Vulnerability-Lab
|
2014-02-25
|
|
Sendy 1.1.8.4 - SQL Injection
|
3 |
WEB
|
Hurley
|
2014-02-25
|
|
WiFiles HD 1.3 iOS - Local File Inclusion
|
3 |
WEB
|
Vulnerability-Lab
|
2014-02-25
|
|
Technicolor TC7200 - Credentials Disclosure
|
3 |
WEB
|
Jeroen - IT Nerdbox
|
2008-06-10
|
|
Hot Links SQL-PHP - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
sl4xUz
|
2008-06-10
|
|
Tornado Knowledge Retrieval System 4.2 - 'p' Cross-Site Scripting
|
3 |
WEB
|
Unohope
|
2008-06-09
|
|
Real Estate Website 1.0 - 'location.asp' Multiple Input Validation Vulnerabilities
|
3 |
WEB
|
JosS
|
2008-06-06
|
|
SchoolCenter 7.5 - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Doz
|
2008-06-05
|
|
SamTodo 1.1 - 'completed' Cross-Site Scripting
|
3 |
WEB
|
David Sopas Ferreira
|
2008-06-05
|
|
SamTodo 1.1 - 'tid' Cross-Site Scripting
|
3 |
WEB
|
David Sopas Ferreira
|
2008-06-04
|
|
PHP Address Book 3.1.5 - Multiple SQL Injections / Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
CWH Underground
|
2008-06-04
|
|
WyMIEN PHP 1.0 - 'index.php' Cross-Site Scripting
|
3 |
WEB
|
ZoRLu
|
2014-02-24
|
|
Ganib Project Management 2.3 - SQL Injection
|
3 |
WEB
|
drone
|
2008-06-02
|
|
Te Ecard - 'id' Multiple SQL Injections
|
3 |
WEB
|
Ugurcan Engyn
|
2008-06-02
|
|
Joomla! / Mambo Component Joo!BB 0.5.9 - 'forum' SQL Injection
|
2 |
WEB
|
His0k4
|
2008-06-02
|
|
i-pos StoreFront 1.3 - 'index.asp' SQL Injection
|
3 |
WEB
|
KnocKout
|
2008-06-02
|
|
OtomiGenX 2.2 - 'userAccount' SQL Injection
|
3 |
WEB
|
hadihadi
|
2008-05-30
|
|
CMS Easyway - 'mid' SQL Injection
|
3 |
WEB
|
Lidloses_Auge
|
2008-05-31
|
|
TorrentTrader Classic 1.x - 'scrape.php' SQL Injection
|
2 |
WEB
|
Charles Vaughn
|
2008-05-30
|
|
DotNetNuke 4.8.3 - 'Default.aspx' Cross-Site Scripting
|
3 |
WEB
|
AmnPardaz Security Research Team
|
2008-05-29
|
|
dvbbs 8.2 - 'login.asp' Multiple SQL Injections
|
3 |
WEB
|
hackerbinhphuoc
|
2008-05-29
|
|
Proje ASP Portal 2.0 - 'id' Multiple SQL Injections
|
3 |
WEB
|
Ugurcan Engin
|
2008-05-29
|
|
JustPORTAL 1.0 - 'site' Multiple SQL Injections
|
3 |
WEB
|
Ugurcan Engin
|
2008-05-28
|
|
Calcium 3.10/4.0.4 - 'Calcium40.pl' Cross-Site Scripting
|
3 |
WEB
|
Marvin Simkin
|
2008-05-28
|
|
Joomla! / Mambo Component Artists - 'idgalery' SQL Injection
|
3 |
WEB
|
Cr@zy_King
|
2008-05-27
|
|
Tr Script News 2.1 - 'news.php' Cross-Site Scripting
|
3 |
WEB
|
ZoRLu
|
2008-05-26
|
|
The Campus Request Repairs System 1.2 - 'sentout.asp' Unauthorized Access
|
2 |
WEB
|
Unohope
|
2008-05-26
|
|
Campus Bulletin Board 3.4 - '/post3/book.asp?review' SQL Injection
|
3 |
WEB
|
Unohope
|
2008-05-26
|
|
Campus Bulletin Board 3.4 - '/post3/view.asp?id' SQL Injection
|
2 |
WEB
|
Unohope
|
2008-05-26
|
|
Campus Bulletin Board 3.4 - '/post3/book.asp?review' Cross-Site Scripting
|
3 |
WEB
|
Unohope
|
2008-05-26
|
|
ClassSystem 2.0/2.3 - 'class/ApplyDB.php' Unrestricted Arbitrary File Upload / Arbitrary Code Execut
|
3 |
WEB
|
Unohope
|
2008-05-26
|
|
ClassSystem 2.0/2.3 - 'MessageReply.php?teacher_id' SQL Injection
|
3 |
WEB
|
Unohope
|
2008-05-26
|
|
ClassSystem 2.0/2.3 - 'HomepageMain.php?teacher_id' SQL Injection
|
3 |
WEB
|
Unohope
|
2008-05-26
|
|
ClassSystem 2.0/2.3 - 'HomepageTop.php?teacher_id' SQL Injection
|
3 |
WEB
|
Unohope
|
2008-05-26
|
|
PHPFix 2.0 - '/auth/00_pass.php?account' SQL Injection
|
3 |
WEB
|
Unohope
|
2008-05-26
|
|
PHPFix 2.0 - '/fix/browse.php?kind' SQL Injection
|
3 |
WEB
|
Unohope
|
2008-05-26
|
|
Excuse Online - 'pwd.asp' SQL Injection
|
2 |
WEB
|
Unohope
|
2008-05-26
|
|
AbleSpace 1.0 - 'adv_cat.php' SQL Injection
|
3 |
WEB
|
Jasbi
|
2008-05-26
|
|
miniCWB 2.1.1 - 'connector.php' Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
CWH Underground
|
2008-05-24
|
|
Horde Multiple Product - 'day.php?Timestamp' Cross-Site Scripting
|
3 |
WEB
|
Ivan Sanchez
|