Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2007-08-09   Bilder Galerie 1.0 - 'index.php' Remote File Inclusion 3 WEB Rizgar
2007-08-09   Shoutbox 1.0 - 'Shoutbox.php' Remote File Inclusion 3 WEB Rizgar
2013-12-24   PHP MBB CMS 004 - Multiple Vulnerabilities 3 WEB cr4wl3r
2013-12-24   Song Exporter 2.1.1 RS iOS - Local File Inclusion 4 WEB Vulnerability-Lab
2013-12-24   Synology DSM 4.3-3810 - Directory Traversal 3 WEB Andrea Fabrizi
2013-12-24   Zimbra Collaboration Server 7.2.2/8.0.2 - Local File Inclusion (Metasploit) 3 WEB Metasploit
2007-08-09   File Uploader 1.1 - 'datei.php?config[root_ordner]' Remote File Inclusion 3 WEB Rizgar
2007-08-09   File Uploader 1.1 - 'index.php?config[root_ordner]' Remote File Inclusion 3 WEB Rizgar
2007-08-09   Mapos-Scripts.de Gastebuch 1.5 - 'index.php' Remote File Inclusion 3 WEB Rizgar
2007-08-08   Coppermine Photo Gallery 1.3/1.4 - 'YABBSE.INC.php' Remote File Inclusion 3 WEB Ma$tEr-0F-De$a$t0r
2007-08-07   VietPHP - 'index.php?language' Remote File Inclusion 2 WEB master-of-desastor
2007-08-07   VietPHP - '/admin/index.php?language' Remote File Inclusion 3 WEB master-of-desastor
2007-08-07   VietPHP - '_functions.php?dirpath' Remote File Inclusion 3 WEB master-of-desastor
2007-08-06   snif 1.5.2 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 3 WEB r0t
2007-08-04   J! Reactions 1.8.1 - comPath Remote File Inclusion 3 WEB Yollubunlar.Org
2007-08-03   Next Gen Portfolio Manager - 'default.asp' Multiple SQL Injections 3 WEB Aria-Security Team
2007-08-03   Lanius CMS 1.2.14 GALLERY Module - 'gid' SQL Injection 3 WEB k1tk4t
2007-08-03   Lanius CMS 1.2.14 EZSHOPINGCART Module - 'cid' SQL Injection 3 WEB k1tk4t
2007-08-03   Lanius CMS 1.2.14 FAQ Module - 'mid' SQL Injection 3 WEB k1tk4t
2007-08-02   Hunkaray Okul Portali 1.1 - 'Duyuruoku.asp' SQL Injection 3 WEB Yollubunlar.Org
2007-08-02   Joomla! Component Tour de France Pool 1.0.1 Module - MosConfig_absolute_path Remote File Inclusion 2 WEB Yollubunlar.Org
2013-12-23   WordPress Theme Persuasion 2.x - Arbitrary File Download / File Deletion 3 WEB Interference Security
2007-08-01   WebDirector - 'index.php' Cross-Site Scripting 4 WEB r0t
2007-07-31   WebEvent 4.03 - 'Webevent.cgi' Cross-Site Scripting 3 WEB d3hydr8
2007-07-30   Global Centre Aplomb Poll 1.1 - 'admin.php?Madoa' Remote File Inclusion 3 WEB ilker Kandemir
2007-07-30   Global Centre Aplomb Poll 1.1 - 'vote.php?Madoa' Remote File Inclusion 3 WEB ilker Kandemir
2007-07-30   Global Centre Aplomb Poll 1.1 - 'index.php?Madoa' Remote File Inclusion 2 WEB ilker Kandemir
2007-07-30   IT!CMS 0.2 - 'titletext-ed.php?wndtitle' Cross-Site Scripting 3 WEB Aria-Security Team
2007-07-30   IT!CMS 0.2 - 'menu-ed.php?wndtitle' Cross-Site Scripting 2 WEB Aria-Security Team
2007-07-30   IT!CMS 0.2 - 'lang-en.php?wndtitle' Cross-Site Scripting 3 WEB Aria-Security Team
2007-07-28   phpCoupon - Remote Payment Bypass 2 WEB freeprotect.net
2007-07-28   Real Estate Listing Website Application Template Login Dialog - SQL Injection 3 WEB Aria-Security Team
2007-07-28   Pay Roll Time Sheet and Punch Card Application With Web UI - 'login.asp' SQL Injection 3 WEB Aria-Security Team
2007-07-28   Message Board / Threaded Discussion Forum - 'Sign_In.aspx' SQL Injection 3 WEB Aria-Security Team
2007-07-28   Online Store Application Template - 'Sign_In.aspx' SQL Injection 3 WEB Aria-Security Team
2007-07-28   Berthanas Ziyaretci Defteri 2.0 - 'Yonetici.asp' SQL Injection 3 WEB Yollubunlar
2007-07-27   Metyus Forum Portal 1.0 - 'Philboard_Forum.asp' SQL Injection 3 WEB Cr@zy_King
2013-12-21   Cisco EPC3925 - Persistent Cross-Site Scripting 3 WEB Jeroen - IT Nerdbox
2013-12-18   SonarQube Jenkins Plugin - Plain Text Password 2 WEB Christian Catalano
2013-12-18   Jenkins 1.523 - Persistent HTML Code 3 WEB Christian Catalano
2007-07-27   Bandersnatch 0.4 - Multiple Input Validation Vulnerabilities 3 WEB Tim Brown
2007-07-26   WordPress Plugin WP-FeedStats 2.1 - HTML Injection 3 WEB David Kierznowski
2007-07-26   Nukedit 4.9.x - 'login.asp' Cross-Site Scripting 3 WEB d3hydr8
2013-12-17   InstantCMS 1.10.3 - Blind SQL Injection 3 WEB High-Tech Bridge SA
2013-12-17   Ditto Forensic FieldStation 2013Oct15a - Multiple Vulnerabilities 4 WEB Martin Wundram
2007-07-26   PHPHostBot 1.05 - 'Authorize.php' Remote File Inclusion 2 WEB S4M3K
2007-07-26   BSM Store Dependent Forums 1.02 - 'Username' SQL Injection 3 WEB Aria-Security Team
2007-07-25   iFoto 1.0 - 'index.php' Directory Traversal 3 WEB Lostmon
2007-07-25   Vikingboard 0.1.2 - 'cp.php' Information Disclosure 3 WEB Lostmon
2007-07-25   Vikingboard 0.1.2 - 'forum.php' Information Disclosure 3 WEB Lostmon
2007-07-25   Vikingboard 0.1.2 - 'topic.php' Cross-Site Scripting 3 WEB Lostmon
2007-07-25   Vikingboard 0.1.2 - 'post.php' Cross-Site Scripting 3 WEB Lostmon
2007-07-25   Vikingboard 0.1.2 - 'user.php' Cross-Site Scripting 3 WEB Lostmon
2007-07-25   Vikingboard 0.1.2 - 'cp.php' Cross-Site Scripting 3 WEB Lostmon
2007-07-25   W1L3D4 philboard 0.3 - Cross-Site Scripting 3 WEB GeFORC3
2007-07-24   cPanel 10.9.1 - 'Resname' Cross-Site Scripting 3 WEB Aria-Security Team
2007-07-24   Webbler CMS 3.1.3 - Mail A Friend Open Email Relay 3 WEB Adrian Pastor
2007-07-24   Webbler CMS 3.1.3 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 3 WEB Adrian Pastor
2013-12-17   FileMaster SY-IT 3.1 iOS - Multiple Web Vulnerabilities 3 WEB Vulnerability-Lab
2007-07-23   Alstrasoft Affiliate Network Pro 8.0 - 'pgmid' SQL Injection 3 WEB Lostmon
2007-07-23   Alstrasoft Affiliate Network Pro 8.0 - 'temp.php' Cross-Site Scripting 3 WEB Lostmon
2007-07-23   Alstrasoft Affiliate Network Pro 8.0 - 'index.php' Cross-Site Scripting 3 WEB Lostmon
2007-07-23   Alstrasoft Sms Text Messaging Enterprise 2.0 - '/admin/edituser.php?userid' Cross-Site Scripting 3 WEB Lostmon
2007-07-23   Alstrasoft Sms Text Messaging Enterprise 2.0 - '/admin/membersearch.php' Multiple Cross-Site Scripti 3 WEB Lostmon
2007-07-23   Alstrasoft Video Share Enterprise 4.x - Multiple Input Validation Vulnerabilities 3 WEB Lostmon
2013-12-16   Penny Auction 5 - SQL Injection 3 WEB 3spi0n
2013-12-16   Lowest Unique Bid Auction - SQL Injection 3 WEB 3spi0n
2013-12-16   Cisco EPC3925 - Cross-Site Request Forgery 3 WEB Jeroen - IT Nerdbox
2013-12-16   Beetel TC1-450 Airtel Wireless Router - Multiple Cross-Site Request Forgery Vulnerabilities 3 WEB Samandeep Singh
2013-12-16   UPC Ireland Cisco EPC 2425 Router / Horizon Box - WPA-PSK Handshake Information 3 WEB Matt O'Connor
2013-12-16   iScripts MultiCart 2.4 - Persistent Cross-Site Scripting / Cross-Site Request Forgery / Cross-Site S 3 WEB Saadi Siddiqui
2013-12-16   Wallpaper Script 3.5.0082 - Persistent Cross-Site Scripting 3 WEB null pointer
2007-07-23   PHMe 0.0.2 - 'Function_List.php' Local File Inclusion 3 WEB You_You
2007-07-23   Image Racer - 'searchresults.asp' SQL Injection 3 WEB Aria-Security Team
2007-07-23   ASP cvmatik 1.1 - Multiple HTML Injection Vulnerabilities 3 WEB GeFORC3
2007-07-23   Alisveris Sitesi Scripti - 'index.asp' Cross-Site Scripting 3 WEB GeFORC3
2013-12-16   Gitlab 6.0 - Persistent Cross-Site Scripting 2 WEB hellok
2007-07-23   Alisveris Sitesi Scripti - 'index.asp' SQL Injection 2 WEB GeFORC3
2007-07-23   Dora Emlak 1.0 Script - Multiple Input Validation Vulnerabilities 2 WEB GeFORC3
2007-07-20   UseBB 1.0.7 - '/install/upgrade-0-3.php?PHP_SELF' Cross-Site Scripting 2 WEB s4mi
2007-07-20   UseBB 1.0.7 - '/install/upgrade-0-2-3.php?PHP_SELF' Cross-Site Scripting 2 WEB s4mi
2007-07-19   GeoBlog MOD_1.0 - 'deleteblog.php?id' Arbitrary Blog Deletion 3 WEB joseph.giron13
2007-07-19   GeoBlog MOD_1.0 - 'deletecomment.php?id' Arbitrary Comment Deletion 3 WEB joseph.giron13
2007-07-17   Insanely Simple Blog 0.4/0.5 - Cross-Site Scripting 3 WEB joseph.giron13
2007-07-17   Insanely Simple Blog 0.4/0.5 - 'index.php' SQL Injection 3 WEB joseph.giron13
2007-07-17   husrevforum 1.0.1/2.0.1 - 'Philboard_forum.asp' SQL Injection 3 WEB GeFORC3
2007-07-16   TBDev.NET DR - 'TakeProfEdit.php' HTML Injection 3 WEB PescaoDeth
2007-07-14   Citadel WebCit 7.02/7.10 - 'showuser?who' Cross-Site Scripting 3 WEB Christopher Schwardt
2013-12-15   Phone Drive Eightythree 4.1.1 iOS - Multiple Vulnerabilities 3 WEB Vulnerability-Lab
2013-12-15   Piwigo CMS 2.5.3 - Multiple Web Vulnerabilities 3 WEB sajith
2007-07-13   Dating Gold 3.0.5 - 'secure.admin.php?int_path' Remote File Inclusion 3 WEB mostafa_ragab
2007-07-13   Dating Gold 3.0.5 - 'footer.php?int_path' Remote File Inclusion 2 WEB mostafa_ragab
2007-07-13   Dating Gold 3.0.5 - 'header.php?int_path' Remote File Inclusion 3 WEB mostafa_ragab
2007-03-23   MzK Blog - 'Katgoster.asp' SQL Injection 2 WEB GeFORC3
2007-07-13   ActiveWeb Contentserver CMS 5.6.2929 - Client-Side Filtering Bypass 4 WEB RedTeam Pentesting
2007-07-13   contentserver 5.6.2929 - '/errors/transaction.asp?msg' Cross-Site Scripting 4 WEB RedTeam Pentesting
2007-07-13   contentserver 5.6.2929 - '/errors/rights.asp?msg' Cross-Site Scripting 4 WEB RedTeam Pentesting
2007-07-13   ActiveWeb Contentserver 5.6.2929 - 'Picture_Real_Edit.asp' SQL Injection 4 WEB RedTeam Pentesting
2007-07-12   Inmostore 4.0 - 'index.php' SQL Injection 4 WEB Keniobats
2007-07-12   Helma 1.5.3 - Search Script Cross-Site Scripting 3 WEB Hanno Boeck
2007-07-11   IBM Proventia Sensor Appliance - Multiple Input Validation Vulnerabilities 4 WEB Alex Hernandez
2007-07-11   EnViVo!CMS - 'default.asp?ID' SQL Injection 4 WEB durito
2007-07-10   ImgSvr 0.6 - 'Template' Local File Inclusion 3 WEB Tim Brown
2007-07-09   SquirrelMail G/PGP Encryption Plugin 2.0/2.1 - Multiple Remote Command Execution Vulnerabilities 4 WEB Stefan Esser
2007-07-07   Levent Veysi Portal 1.0 - 'Oku.asp' SQL Injection 3 WEB GeFORC3
2007-07-05   Maia Mailguard 1.0.2 - 'login.php' Multiple Local File Inclusions 4 WEB Adriel T. Desautels
2007-07-04   OpManager 6/7 - '/admin/DeviceAssociation.do' Multiple Cross-Site Scripting Vulnerabilities 4 WEB Lostmon
2007-07-04   OpManager 6/7 - 'admin/ServiceConfiguration.do?Operation' Cross-Site Scripting 4 WEB Lostmon
2007-07-04   OpManager 6/7 - reports/ReportViewAction.do Multiple Cross-Site Scripting Vulnerabilities 3 WEB Lostmon
2007-07-04   OpManager 6/7 - 'traceRoute.do?name' Cross-Site Scripting 4 WEB Lostmon
2007-07-04   OpManager 6/7 - 'ping.do?name' Cross-Site Scripting 4 WEB Lostmon
2007-07-04   NetFlow Analyzer 5 - '/jspui/customReport.jsp?rtype' Cross-Site Scripting 3 WEB Lostmon
2007-07-04   NetFlow Analyzer 5 - '/jspui/selectDevice.jsp?rtype' Cross-Site Scripting 4 WEB Lostmon
2007-07-04   NetFlow Analyzer 5 - 'netflow/jspui/index.jsp?view' Cross-Site Scripting 3 WEB Lostmon
2007-07-04   NetFlow Analyzer 5 - '/jspui/appConfig.jsp?task' Cross-Site Scripting 3 WEB Lostmon
2007-07-04   NetFlow Analyzer 5 - '/jspui/applicationList.jsp?alpha' Cross-Site Scripting 4 WEB Lostmon
2007-07-03   Oliver - Multiple Cross-Site Scripting Vulnerabilities 3 WEB A. R.
2007-07-02   Liesbeth Base CMS - Information Disclosure 5 WEB durito
2007-07-02   Moodle 1.7.1 - 'index.php' Cross-Site Scripting 4 WEB MustLive
2007-07-02   Yoggie Pico and Pico Pro Backticks - Remote Code Execution 4 WEB Cody Brocious
2007-07-02   Claroline 1.8.3 - '$_SERVER['PHP_SELF']' Multiple Cross-Site Scripting Vulnerabilities 4 WEB munozferna
2007-06-27   ETicket 1.5.5 - 'Open.php' Multiple Cross-Site Scripting Vulnerabilities 4 WEB Jesper Jurcenoks
2006-12-02   DUClassmate 1.x - 'ICity' SQL Injection 3 WEB Aria-Security Team
2007-06-27   Papoo 1.0.3 - 'Plugin.php' Authentication Bypass 4 WEB Nico Leidecker
2013-12-12   Pentagram Cerberus P 6363 DSL Router - Multiple Vulnerabilities 2 WEB condis