2007-10-04
|
|
Cart32 6.x - GetImage Arbitrary File Download
|
1 |
WEB
|
Paul Craig
|
2007-10-04
|
|
GForge 4.6/4.5/3.1 - 'Verify.php' Cross-Site Scripting
|
1 |
WEB
|
Jose Sanchez
|
2007-10-04
|
|
WordPress Plugin Google FeedBurner FeedSmith 2.2 - Cross-Site Request Forgery
|
1 |
WEB
|
David Kierznowski
|
2007-10-03
|
|
Content Builder 0.7.5 - 'postComment.php' Remote File Inclusion
|
1 |
WEB
|
Mehrad Ansari Targhi
|
2007-10-03
|
|
Uebimiau Webmail 2.7.x - 'index.php' Cross-Site Scripting
|
1 |
WEB
|
Ivan Sanches
|
2007-10-03
|
|
DRBGuestbook 1.1.13 - 'index.php' Cross-Site Scripting
|
1 |
WEB
|
Gokhan
|
2007-10-01
|
|
ASP Product Catalog 1.0 - 'default.asp' SQL Injection
|
2 |
WEB
|
joseph.giron13
|
2007-10-01
|
|
Ohesa Emlak Portal 1.0 - 'detay.asp?Emlak' SQL Injection
|
1 |
WEB
|
GeFORC3
|
2007-10-01
|
|
Ohesa Emlak Portal 1.0 - 'satilik.asp?Kategori' SQL Injection
|
1 |
WEB
|
GeFORC3
|
2007-10-01
|
|
Netkamp Emlak Scripti - Multiple Input Validation Vulnerabilities
|
1 |
WEB
|
GeFORC3
|
2007-09-29
|
|
MD-Pro 1.0.76 - 'index.php' Firefox ID SQL Injection
|
0 |
WEB
|
unidentified1_ is
|
2007-09-27
|
|
Novus 1.0 - 'Buscar.asp' Cross-Site Scripting
|
2 |
WEB
|
Zutr4
|
2007-09-25
|
|
SimpNews 2.41.3 - 'backurl' Cross-Site Scripting
|
2 |
WEB
|
Jesper Jurcenoks
|
2007-09-25
|
|
SimpNews 2.41.3 - 'l_username' Cross-Site Scripting
|
1 |
WEB
|
Jesper Jurcenoks
|
2007-09-25
|
|
SimpGB 1.46.2 - '/admin/emoticonlist.php?l_emoticonlist' Cross-Site Scripting
|
2 |
WEB
|
netVigilance
|
2007-09-25
|
|
SimpGB 1.46.2 - '/admin/?l_username' Cross-Site Scripting
|
2 |
WEB
|
netVigilance
|
2007-09-25
|
|
PHP-Nuke Dance Music Module - 'index.php' Local File Inclusion
|
1 |
WEB
|
waraxe
|
2007-09-25
|
|
JSPWiki 2.5.139 - 'Diff.jsp' Multiple Cross-Site Scripting Vulnerabilities
|
0 |
WEB
|
Jason Kratzer
|
2007-09-25
|
|
JSPWiki 2.5.139 - 'Login.jsp' Multiple Cross-Site Scripting Vulnerabilities
|
1 |
WEB
|
Jason Kratzer
|
2007-09-25
|
|
JSPWiki 2.5.139 - 'UserPreferences.jsp' Multiple Cross-Site Scripting Vulnerabilities
|
1 |
WEB
|
Jason Kratzer
|
2007-09-25
|
|
JSPWiki 2.5.139 - 'Comment.jsp' Multiple Cross-Site Scripting Vulnerabilities
|
0 |
WEB
|
Jason Kratzer
|
2007-09-25
|
|
JSPWiki 2.5.139 - 'edit.jsp?edittime' Cross-Site Scripting
|
1 |
WEB
|
Jason Kratzer
|
2007-09-25
|
|
JSPWiki 2.5.139 - 'NewGroup.jsp' Multiple Cross-Site Scripting Vulnerabilities
|
0 |
WEB
|
Jason Kratzer
|
2007-09-24
|
|
bcoos 1.0.10 Arcade Module - 'index.php' SQL Injection
|
1 |
WEB
|
nights shadow
|
2007-09-24
|
|
Urchin 5.7.x - 'session.cgi' Cross-Site Scripting
|
1 |
WEB
|
pagvac
|
2007-09-22
|
|
XCMS 1.1/1.7 - 'Password' Arbitrary PHP Code Execution
|
3 |
WEB
|
x0kster
|
2007-09-22
|
|
WordPress Core 2.0 - 'wp-register.php' Multiple Cross-Site Scripting Vulnerabilities
|
1 |
WEB
|
Adrian Pastor
|
2007-09-20
|
|
Vigile CMS 1.8 Wiki Module - Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
x0kster
|
2007-09-20
|
|
WebBatch - 'webbatch.exe?dumpinputdata' Remote Information Disclosure
|
2 |
WEB
|
Doz
|
2007-09-20
|
|
WebBatch - 'webbatch.exe' Cross-Site Scripting
|
2 |
WEB
|
Doz
|
2007-09-19
|
|
LevelOne WBR3404TX Broadband Router - 'RC' Cross-Site Scripting
|
2 |
WEB
|
azizov
|
2007-09-17
|
|
b1gMail 6.3.1 - 'hilfe.php' Cross-Site Scripting
|
2 |
WEB
|
malibu.r
|
2007-09-17
|
|
Coppermine Photo Gallery 1.4.12 - 'log' Local File Inclusion
|
1 |
WEB
|
L4teral
|
2007-09-17
|
|
Coppermine Photo Gallery 1.4.12 - 'referer' Cross-Site Scripting
|
2 |
WEB
|
L4teral
|
2007-09-17
|
|
Alcatel-Lucent OmniPCX Enterprise 7.1 - Remote Command Execution
|
2 |
WEB
|
RedTeam Pentesting GmbH
|
2007-09-17
|
|
ewire Payment Client 1.60/1.70 - Command Execution
|
2 |
WEB
|
anonymous
|
2007-09-14
|
|
Axis Communications 207W Network Camera - Web Interface '/admin/restartMessage.shtml?server' Cross-S
|
3 |
WEB
|
Seth Fogie
|
2007-09-14
|
|
Axis Communications 207W Network Camera - Web Interface 'axis-cgi/admin/pwdgrp.cgi' Multiple Cross-S
|
2 |
WEB
|
Seth Fogie
|
2007-09-14
|
|
Axis Communications 207W Network Camera - Web Interface axis-cgi/admin/restart.cgi Cross-Site Reques
|
2 |
WEB
|
Seth Fogie
|
2007-09-14
|
|
PHP-Stats 0.1.9.2 - 'Tracking.php' Cross-Site Scripting
|
2 |
WEB
|
root@hanicker.it
|
2007-09-12
|
|
CS-Guestbook 0.1 - Login Credentials Information Disclosure
|
2 |
WEB
|
Cr@zy_King
|
2007-09-12
|
|
SWSoft Plesk 8.2 - 'login.php3' PLESKSESSID Cookie SQL Injection
|
2 |
WEB
|
Nick I Merritt
|
2007-09-12
|
|
BOINC 5.10.20 - 'text_search_action.php?search_string' Cross-Site Scripting
|
1 |
WEB
|
Doz
|
2007-09-12
|
|
BOINC 5.10.20 - 'forum_forum.php?id' Cross-Site Scripting
|
1 |
WEB
|
Doz
|
2007-09-10
|
|
SisfoKampus - 'dwoprn.php' Arbitrary File Download
|
2 |
WEB
|
PUPET
|
2007-09-10
|
|
PHPMyQuote 0.20 - '/index.php' SQL Injection / Cross-Site Scripting
|
2 |
WEB
|
Yollubunlar.Org
|
2007-09-10
|
|
Proxy Anket 3.0.1 - 'anket.asp' SQL Injection
|
2 |
WEB
|
Yollubunlar.Org
|
2007-09-08
|
|
Toms Gastebuch 1.00/1.01 - 'header.php' Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
hd1979
|
2007-09-06
|
|
Pulsewiki And Pawfaliki 0.5.1 - 'index.php' Local File Inclusion
|
2 |
WEB
|
mafialbano
|
2007-09-04
|
|
E-Smart Cart 1.0 - 'login.asp' SQL Injection
|
2 |
WEB
|
SmOk3
|
2007-09-04
|
|
Apache Tomcat 5.5.15 - cal2.jsp Cross-Site Scripting
|
1 |
WEB
|
Tushar Vartak
|
2007-09-04
|
|
212Cafe WebBoard 6.30 - 'Read.php' SQL Injection
|
2 |
WEB
|
Lopez Bran Digrap
|
2007-09-03
|
|
Claroline 1.x - '/admin/campusProblem.php?view' Cross-Site Scripting
|
2 |
WEB
|
Fernando Munoz
|
2007-09-03
|
|
Claroline 1.x - '/admin/advancedUserSearch.php?action' Cross-Site Scripting
|
2 |
WEB
|
Fernando Munoz
|
2007-09-03
|
|
Claroline 1.x - '/admin/adminusers.php?dir' Cross-Site Scripting
|
2 |
WEB
|
Fernando Munoz
|
2007-09-03
|
|
Claroline 1.x - '/inc/lib/language.lib.php?language' Traversal Local File Inclusion
|
3 |
WEB
|
Fernando Munoz
|
2007-09-03
|
|
MKPortal 1.0/1.1 - 'admin.php' Authentication Bypass
|
2 |
WEB
|
Demential
|
2007-09-07
|
|
Toms Gästebuch 1.00 - '/admin/header.php' Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
cod3in
|
2007-09-07
|
|
Toms Gästebuch 1.00 - 'form.php' Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
cod3in
|
2013-12-28
|
|
D-Link DSL-2750u ME_1.09 - Cross-Site Request Forgery
|
2 |
WEB
|
FIGHTERx war
|
2007-08-30
|
|
Absolute Poll Manager XE 4.1 - 'xlaapmview.asp' Cross-Site Scripting
|
2 |
WEB
|
Richard Brain
|
2007-08-29
|
|
Cisco CallManager 4.2 / CUCM 4.2 - Logon Page 'lang' SQL Injection
|
2 |
WEB
|
anonymous
|
2007-08-28
|
|
ACG News 1.0 - 'index.php' Multiple SQL Injections
|
2 |
WEB
|
SmOk3
|
2007-08-27
|
|
PHPGedView 4.1 - 'login.php' Cross-Site Scripting
|
2 |
WEB
|
Joshua Morin
|
2007-08-27
|
|
Dale Mooney Calendar Events - 'Viewevent.php' SQL Injection
|
2 |
WEB
|
s0cratex
|
2007-08-27
|
|
AutoIndex PHP Script 2.2.1 - 'index.php' Cross-Site Scripting
|
2 |
WEB
|
d3hydr8
|
2007-08-24
|
|
Arcadem 2.01 - 'index.php' Remote File Inclusion
|
2 |
WEB
|
sm0k3
|
2007-08-13
|
|
WordPress Core 1.0.7 - 'Pool index.php' Cross-Site Scripting
|
2 |
WEB
|
MustLive
|
2007-08-22
|
|
Ripe Website Manager 0.8.x - '/pages/delete_page.php?id' SQL Injection
|
2 |
WEB
|
Nagendra Kumar G
|
2007-08-21
|
|
m-phorum 0.3 - 'index.php' Cross-Site Scripting
|
2 |
WEB
|
CodeXpLoder'tq
|
2007-08-21
|
|
coWiki - 'index.php' Cross-Site Scripting
|
2 |
WEB
|
MustLive
|
2007-08-21
|
|
ALeadSoft Search Engine Builder - Search.HTML Cross-Site Scripting
|
2 |
WEB
|
MustLive
|
2007-08-20
|
|
Gurur Haber 2.0 - 'Uyeler2.php' SQL Injection
|
2 |
WEB
|
dumenci
|
2007-08-20
|
|
Firesoft - 'Class_TPL.php' Remote File Inclusion
|
1 |
WEB
|
DarKdewiL
|
2007-08-20
|
|
Dalai Forum 1.1 - 'forumreply.php' Local File Inclusion
|
2 |
WEB
|
DarKdewiL
|
2007-08-17
|
|
Text File Search Classic - 'TextFileSearch.asp' Cross-Site Scripting
|
2 |
WEB
|
GeFORC3
|
2007-07-16
|
|
Olate Download 3.4.1 - 'admin.php' Remote Authentication Bypass
|
2 |
WEB
|
imei
|
2007-07-09
|
|
Systeme de vote pour site Web 1.0 - Multiple Remote File Inclusions
|
1 |
WEB
|
Crackers_Child
|
2007-07-13
|
|
SkilMatch Systems JobLister3 - 'index.php' SQL Injection
|
1 |
WEB
|
joseph.giron13
|
2007-08-11
|
|
Openads (PHPAdsNew) < 2.0.8 - 'lib-remotehost.inc.php' Remote File Inclusion
|
1 |
WEB
|
Ma$tEr-0F-De$a$t0r
|
2007-08-11
|
|
Haudenschilt Family Connections 0.8 - 'index.php' Authentication Bypass
|
1 |
WEB
|
ilker Kandemir
|
2007-08-11
|
|
PHP-Stats 0.1.9.2 - 'WhoIs.php' Cross-Site Scripting
|
1 |
WEB
|
vasodipandora
|
2007-08-11
|
|
Lib2 PHP Library 0.2 - 'My_Statistics.php' Remote File Inclusion
|
1 |
WEB
|
ilker Kandemir
|
2007-08-09
|
|
Web News 1.1 - 'news.php?config[root_ordner]' Remote File Inclusion
|
2 |
WEB
|
Rizgar
|
2007-08-09
|
|
Web News 1.1 - 'feed.php?config[root_ordner]' Remote File Inclusion
|
1 |
WEB
|
Rizgar
|
2007-08-09
|
|
Web News 1.1 - 'index.php?config[root_ordner]' Remote File Inclusion
|
1 |
WEB
|
Rizgar
|
2007-08-09
|
|
Bilder Galerie 1.0 - 'index.php' Remote File Inclusion
|
1 |
WEB
|
Rizgar
|
2007-08-09
|
|
Shoutbox 1.0 - 'Shoutbox.php' Remote File Inclusion
|
1 |
WEB
|
Rizgar
|
2013-12-24
|
|
PHP MBB CMS 004 - Multiple Vulnerabilities
|
2 |
WEB
|
cr4wl3r
|
2013-12-24
|
|
Song Exporter 2.1.1 RS iOS - Local File Inclusion
|
3 |
WEB
|
Vulnerability-Lab
|
2013-12-24
|
|
Synology DSM 4.3-3810 - Directory Traversal
|
2 |
WEB
|
Andrea Fabrizi
|
2013-12-24
|
|
Zimbra Collaboration Server 7.2.2/8.0.2 - Local File Inclusion (Metasploit)
|
1 |
WEB
|
Metasploit
|
2007-08-09
|
|
File Uploader 1.1 - 'datei.php?config[root_ordner]' Remote File Inclusion
|
2 |
WEB
|
Rizgar
|
2007-08-09
|
|
File Uploader 1.1 - 'index.php?config[root_ordner]' Remote File Inclusion
|
2 |
WEB
|
Rizgar
|
2007-08-09
|
|
Mapos-Scripts.de Gastebuch 1.5 - 'index.php' Remote File Inclusion
|
2 |
WEB
|
Rizgar
|
2007-08-08
|
|
Coppermine Photo Gallery 1.3/1.4 - 'YABBSE.INC.php' Remote File Inclusion
|
2 |
WEB
|
Ma$tEr-0F-De$a$t0r
|
2007-08-07
|
|
VietPHP - 'index.php?language' Remote File Inclusion
|
1 |
WEB
|
master-of-desastor
|
2007-08-07
|
|
VietPHP - '/admin/index.php?language' Remote File Inclusion
|
2 |
WEB
|
master-of-desastor
|
2007-08-07
|
|
VietPHP - '_functions.php?dirpath' Remote File Inclusion
|
2 |
WEB
|
master-of-desastor
|
2007-08-06
|
|
snif 1.5.2 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
r0t
|
2007-08-04
|
|
J! Reactions 1.8.1 - comPath Remote File Inclusion
|
2 |
WEB
|
Yollubunlar.Org
|
2007-08-03
|
|
Next Gen Portfolio Manager - 'default.asp' Multiple SQL Injections
|
2 |
WEB
|
Aria-Security Team
|
2007-08-03
|
|
Lanius CMS 1.2.14 GALLERY Module - 'gid' SQL Injection
|
2 |
WEB
|
k1tk4t
|
2007-08-03
|
|
Lanius CMS 1.2.14 EZSHOPINGCART Module - 'cid' SQL Injection
|
2 |
WEB
|
k1tk4t
|
2007-08-03
|
|
Lanius CMS 1.2.14 FAQ Module - 'mid' SQL Injection
|
2 |
WEB
|
k1tk4t
|
2007-08-02
|
|
Hunkaray Okul Portali 1.1 - 'Duyuruoku.asp' SQL Injection
|
2 |
WEB
|
Yollubunlar.Org
|
2007-08-02
|
|
Joomla! Component Tour de France Pool 1.0.1 Module - MosConfig_absolute_path Remote File Inclusion
|
1 |
WEB
|
Yollubunlar.Org
|
2013-12-23
|
|
WordPress Theme Persuasion 2.x - Arbitrary File Download / File Deletion
|
2 |
WEB
|
Interference Security
|
2007-08-01
|
|
WebDirector - 'index.php' Cross-Site Scripting
|
3 |
WEB
|
r0t
|
2007-07-31
|
|
WebEvent 4.03 - 'Webevent.cgi' Cross-Site Scripting
|
2 |
WEB
|
d3hydr8
|
2007-07-30
|
|
Global Centre Aplomb Poll 1.1 - 'admin.php?Madoa' Remote File Inclusion
|
2 |
WEB
|
ilker Kandemir
|
2007-07-30
|
|
Global Centre Aplomb Poll 1.1 - 'vote.php?Madoa' Remote File Inclusion
|
2 |
WEB
|
ilker Kandemir
|
2007-07-30
|
|
Global Centre Aplomb Poll 1.1 - 'index.php?Madoa' Remote File Inclusion
|
1 |
WEB
|
ilker Kandemir
|
2007-07-30
|
|
IT!CMS 0.2 - 'titletext-ed.php?wndtitle' Cross-Site Scripting
|
2 |
WEB
|
Aria-Security Team
|
2007-07-30
|
|
IT!CMS 0.2 - 'menu-ed.php?wndtitle' Cross-Site Scripting
|
1 |
WEB
|
Aria-Security Team
|
2007-07-30
|
|
IT!CMS 0.2 - 'lang-en.php?wndtitle' Cross-Site Scripting
|
2 |
WEB
|
Aria-Security Team
|
2007-07-28
|
|
phpCoupon - Remote Payment Bypass
|
1 |
WEB
|
freeprotect.net
|
2007-07-28
|
|
Real Estate Listing Website Application Template Login Dialog - SQL Injection
|
2 |
WEB
|
Aria-Security Team
|
2007-07-28
|
|
Pay Roll Time Sheet and Punch Card Application With Web UI - 'login.asp' SQL Injection
|
1 |
WEB
|
Aria-Security Team
|
2007-07-28
|
|
Message Board / Threaded Discussion Forum - 'Sign_In.aspx' SQL Injection
|
2 |
WEB
|
Aria-Security Team
|
2007-07-28
|
|
Online Store Application Template - 'Sign_In.aspx' SQL Injection
|
2 |
WEB
|
Aria-Security Team
|
2007-07-28
|
|
Berthanas Ziyaretci Defteri 2.0 - 'Yonetici.asp' SQL Injection
|
2 |
WEB
|
Yollubunlar
|
2007-07-27
|
|
Metyus Forum Portal 1.0 - 'Philboard_Forum.asp' SQL Injection
|
2 |
WEB
|
Cr@zy_King
|
2013-12-21
|
|
Cisco EPC3925 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Jeroen - IT Nerdbox
|
2013-12-18
|
|
SonarQube Jenkins Plugin - Plain Text Password
|
1 |
WEB
|
Christian Catalano
|