2007-08-09
|
|
Bilder Galerie 1.0 - 'index.php' Remote File Inclusion
|
3 |
WEB
|
Rizgar
|
2007-08-09
|
|
Shoutbox 1.0 - 'Shoutbox.php' Remote File Inclusion
|
3 |
WEB
|
Rizgar
|
2013-12-24
|
|
PHP MBB CMS 004 - Multiple Vulnerabilities
|
3 |
WEB
|
cr4wl3r
|
2013-12-24
|
|
Song Exporter 2.1.1 RS iOS - Local File Inclusion
|
4 |
WEB
|
Vulnerability-Lab
|
2013-12-24
|
|
Synology DSM 4.3-3810 - Directory Traversal
|
3 |
WEB
|
Andrea Fabrizi
|
2013-12-24
|
|
Zimbra Collaboration Server 7.2.2/8.0.2 - Local File Inclusion (Metasploit)
|
3 |
WEB
|
Metasploit
|
2007-08-09
|
|
File Uploader 1.1 - 'datei.php?config[root_ordner]' Remote File Inclusion
|
3 |
WEB
|
Rizgar
|
2007-08-09
|
|
File Uploader 1.1 - 'index.php?config[root_ordner]' Remote File Inclusion
|
3 |
WEB
|
Rizgar
|
2007-08-09
|
|
Mapos-Scripts.de Gastebuch 1.5 - 'index.php' Remote File Inclusion
|
3 |
WEB
|
Rizgar
|
2007-08-08
|
|
Coppermine Photo Gallery 1.3/1.4 - 'YABBSE.INC.php' Remote File Inclusion
|
3 |
WEB
|
Ma$tEr-0F-De$a$t0r
|
2007-08-07
|
|
VietPHP - 'index.php?language' Remote File Inclusion
|
2 |
WEB
|
master-of-desastor
|
2007-08-07
|
|
VietPHP - '/admin/index.php?language' Remote File Inclusion
|
3 |
WEB
|
master-of-desastor
|
2007-08-07
|
|
VietPHP - '_functions.php?dirpath' Remote File Inclusion
|
3 |
WEB
|
master-of-desastor
|
2007-08-06
|
|
snif 1.5.2 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
r0t
|
2007-08-04
|
|
J! Reactions 1.8.1 - comPath Remote File Inclusion
|
3 |
WEB
|
Yollubunlar.Org
|
2007-08-03
|
|
Next Gen Portfolio Manager - 'default.asp' Multiple SQL Injections
|
3 |
WEB
|
Aria-Security Team
|
2007-08-03
|
|
Lanius CMS 1.2.14 GALLERY Module - 'gid' SQL Injection
|
3 |
WEB
|
k1tk4t
|
2007-08-03
|
|
Lanius CMS 1.2.14 EZSHOPINGCART Module - 'cid' SQL Injection
|
3 |
WEB
|
k1tk4t
|
2007-08-03
|
|
Lanius CMS 1.2.14 FAQ Module - 'mid' SQL Injection
|
3 |
WEB
|
k1tk4t
|
2007-08-02
|
|
Hunkaray Okul Portali 1.1 - 'Duyuruoku.asp' SQL Injection
|
3 |
WEB
|
Yollubunlar.Org
|
2007-08-02
|
|
Joomla! Component Tour de France Pool 1.0.1 Module - MosConfig_absolute_path Remote File Inclusion
|
2 |
WEB
|
Yollubunlar.Org
|
2013-12-23
|
|
WordPress Theme Persuasion 2.x - Arbitrary File Download / File Deletion
|
3 |
WEB
|
Interference Security
|
2007-08-01
|
|
WebDirector - 'index.php' Cross-Site Scripting
|
4 |
WEB
|
r0t
|
2007-07-31
|
|
WebEvent 4.03 - 'Webevent.cgi' Cross-Site Scripting
|
3 |
WEB
|
d3hydr8
|
2007-07-30
|
|
Global Centre Aplomb Poll 1.1 - 'admin.php?Madoa' Remote File Inclusion
|
3 |
WEB
|
ilker Kandemir
|
2007-07-30
|
|
Global Centre Aplomb Poll 1.1 - 'vote.php?Madoa' Remote File Inclusion
|
3 |
WEB
|
ilker Kandemir
|
2007-07-30
|
|
Global Centre Aplomb Poll 1.1 - 'index.php?Madoa' Remote File Inclusion
|
2 |
WEB
|
ilker Kandemir
|
2007-07-30
|
|
IT!CMS 0.2 - 'titletext-ed.php?wndtitle' Cross-Site Scripting
|
3 |
WEB
|
Aria-Security Team
|
2007-07-30
|
|
IT!CMS 0.2 - 'menu-ed.php?wndtitle' Cross-Site Scripting
|
2 |
WEB
|
Aria-Security Team
|
2007-07-30
|
|
IT!CMS 0.2 - 'lang-en.php?wndtitle' Cross-Site Scripting
|
3 |
WEB
|
Aria-Security Team
|
2007-07-28
|
|
phpCoupon - Remote Payment Bypass
|
2 |
WEB
|
freeprotect.net
|
2007-07-28
|
|
Real Estate Listing Website Application Template Login Dialog - SQL Injection
|
3 |
WEB
|
Aria-Security Team
|
2007-07-28
|
|
Pay Roll Time Sheet and Punch Card Application With Web UI - 'login.asp' SQL Injection
|
3 |
WEB
|
Aria-Security Team
|
2007-07-28
|
|
Message Board / Threaded Discussion Forum - 'Sign_In.aspx' SQL Injection
|
3 |
WEB
|
Aria-Security Team
|
2007-07-28
|
|
Online Store Application Template - 'Sign_In.aspx' SQL Injection
|
3 |
WEB
|
Aria-Security Team
|
2007-07-28
|
|
Berthanas Ziyaretci Defteri 2.0 - 'Yonetici.asp' SQL Injection
|
3 |
WEB
|
Yollubunlar
|
2007-07-27
|
|
Metyus Forum Portal 1.0 - 'Philboard_Forum.asp' SQL Injection
|
3 |
WEB
|
Cr@zy_King
|
2013-12-21
|
|
Cisco EPC3925 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Jeroen - IT Nerdbox
|
2013-12-18
|
|
SonarQube Jenkins Plugin - Plain Text Password
|
2 |
WEB
|
Christian Catalano
|
2013-12-18
|
|
Jenkins 1.523 - Persistent HTML Code
|
3 |
WEB
|
Christian Catalano
|
2007-07-27
|
|
Bandersnatch 0.4 - Multiple Input Validation Vulnerabilities
|
3 |
WEB
|
Tim Brown
|
2007-07-26
|
|
WordPress Plugin WP-FeedStats 2.1 - HTML Injection
|
3 |
WEB
|
David Kierznowski
|
2007-07-26
|
|
Nukedit 4.9.x - 'login.asp' Cross-Site Scripting
|
3 |
WEB
|
d3hydr8
|
2013-12-17
|
|
InstantCMS 1.10.3 - Blind SQL Injection
|
3 |
WEB
|
High-Tech Bridge SA
|
2013-12-17
|
|
Ditto Forensic FieldStation 2013Oct15a - Multiple Vulnerabilities
|
4 |
WEB
|
Martin Wundram
|
2007-07-26
|
|
PHPHostBot 1.05 - 'Authorize.php' Remote File Inclusion
|
2 |
WEB
|
S4M3K
|
2007-07-26
|
|
BSM Store Dependent Forums 1.02 - 'Username' SQL Injection
|
3 |
WEB
|
Aria-Security Team
|
2007-07-25
|
|
iFoto 1.0 - 'index.php' Directory Traversal
|
3 |
WEB
|
Lostmon
|
2007-07-25
|
|
Vikingboard 0.1.2 - 'cp.php' Information Disclosure
|
3 |
WEB
|
Lostmon
|
2007-07-25
|
|
Vikingboard 0.1.2 - 'forum.php' Information Disclosure
|
3 |
WEB
|
Lostmon
|
2007-07-25
|
|
Vikingboard 0.1.2 - 'topic.php' Cross-Site Scripting
|
3 |
WEB
|
Lostmon
|
2007-07-25
|
|
Vikingboard 0.1.2 - 'post.php' Cross-Site Scripting
|
3 |
WEB
|
Lostmon
|
2007-07-25
|
|
Vikingboard 0.1.2 - 'user.php' Cross-Site Scripting
|
3 |
WEB
|
Lostmon
|
2007-07-25
|
|
Vikingboard 0.1.2 - 'cp.php' Cross-Site Scripting
|
3 |
WEB
|
Lostmon
|
2007-07-25
|
|
W1L3D4 philboard 0.3 - Cross-Site Scripting
|
3 |
WEB
|
GeFORC3
|
2007-07-24
|
|
cPanel 10.9.1 - 'Resname' Cross-Site Scripting
|
3 |
WEB
|
Aria-Security Team
|
2007-07-24
|
|
Webbler CMS 3.1.3 - Mail A Friend Open Email Relay
|
3 |
WEB
|
Adrian Pastor
|
2007-07-24
|
|
Webbler CMS 3.1.3 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Adrian Pastor
|
2013-12-17
|
|
FileMaster SY-IT 3.1 iOS - Multiple Web Vulnerabilities
|
3 |
WEB
|
Vulnerability-Lab
|
2007-07-23
|
|
Alstrasoft Affiliate Network Pro 8.0 - 'pgmid' SQL Injection
|
3 |
WEB
|
Lostmon
|
2007-07-23
|
|
Alstrasoft Affiliate Network Pro 8.0 - 'temp.php' Cross-Site Scripting
|
3 |
WEB
|
Lostmon
|
2007-07-23
|
|
Alstrasoft Affiliate Network Pro 8.0 - 'index.php' Cross-Site Scripting
|
3 |
WEB
|
Lostmon
|
2007-07-23
|
|
Alstrasoft Sms Text Messaging Enterprise 2.0 - '/admin/edituser.php?userid' Cross-Site Scripting
|
3 |
WEB
|
Lostmon
|
2007-07-23
|
|
Alstrasoft Sms Text Messaging Enterprise 2.0 - '/admin/membersearch.php' Multiple Cross-Site Scripti
|
3 |
WEB
|
Lostmon
|
2007-07-23
|
|
Alstrasoft Video Share Enterprise 4.x - Multiple Input Validation Vulnerabilities
|
3 |
WEB
|
Lostmon
|
2013-12-16
|
|
Penny Auction 5 - SQL Injection
|
3 |
WEB
|
3spi0n
|
2013-12-16
|
|
Lowest Unique Bid Auction - SQL Injection
|
3 |
WEB
|
3spi0n
|
2013-12-16
|
|
Cisco EPC3925 - Cross-Site Request Forgery
|
3 |
WEB
|
Jeroen - IT Nerdbox
|
2013-12-16
|
|
Beetel TC1-450 Airtel Wireless Router - Multiple Cross-Site Request Forgery Vulnerabilities
|
3 |
WEB
|
Samandeep Singh
|
2013-12-16
|
|
UPC Ireland Cisco EPC 2425 Router / Horizon Box - WPA-PSK Handshake Information
|
3 |
WEB
|
Matt O'Connor
|
2013-12-16
|
|
iScripts MultiCart 2.4 - Persistent Cross-Site Scripting / Cross-Site Request Forgery / Cross-Site S
|
3 |
WEB
|
Saadi Siddiqui
|
2013-12-16
|
|
Wallpaper Script 3.5.0082 - Persistent Cross-Site Scripting
|
3 |
WEB
|
null pointer
|
2007-07-23
|
|
PHMe 0.0.2 - 'Function_List.php' Local File Inclusion
|
3 |
WEB
|
You_You
|
2007-07-23
|
|
Image Racer - 'searchresults.asp' SQL Injection
|
3 |
WEB
|
Aria-Security Team
|
2007-07-23
|
|
ASP cvmatik 1.1 - Multiple HTML Injection Vulnerabilities
|
3 |
WEB
|
GeFORC3
|
2007-07-23
|
|
Alisveris Sitesi Scripti - 'index.asp' Cross-Site Scripting
|
3 |
WEB
|
GeFORC3
|
2013-12-16
|
|
Gitlab 6.0 - Persistent Cross-Site Scripting
|
2 |
WEB
|
hellok
|
2007-07-23
|
|
Alisveris Sitesi Scripti - 'index.asp' SQL Injection
|
2 |
WEB
|
GeFORC3
|
2007-07-23
|
|
Dora Emlak 1.0 Script - Multiple Input Validation Vulnerabilities
|
2 |
WEB
|
GeFORC3
|
2007-07-20
|
|
UseBB 1.0.7 - '/install/upgrade-0-3.php?PHP_SELF' Cross-Site Scripting
|
2 |
WEB
|
s4mi
|
2007-07-20
|
|
UseBB 1.0.7 - '/install/upgrade-0-2-3.php?PHP_SELF' Cross-Site Scripting
|
2 |
WEB
|
s4mi
|
2007-07-19
|
|
GeoBlog MOD_1.0 - 'deleteblog.php?id' Arbitrary Blog Deletion
|
3 |
WEB
|
joseph.giron13
|
2007-07-19
|
|
GeoBlog MOD_1.0 - 'deletecomment.php?id' Arbitrary Comment Deletion
|
3 |
WEB
|
joseph.giron13
|
2007-07-17
|
|
Insanely Simple Blog 0.4/0.5 - Cross-Site Scripting
|
3 |
WEB
|
joseph.giron13
|
2007-07-17
|
|
Insanely Simple Blog 0.4/0.5 - 'index.php' SQL Injection
|
3 |
WEB
|
joseph.giron13
|
2007-07-17
|
|
husrevforum 1.0.1/2.0.1 - 'Philboard_forum.asp' SQL Injection
|
3 |
WEB
|
GeFORC3
|
2007-07-16
|
|
TBDev.NET DR - 'TakeProfEdit.php' HTML Injection
|
3 |
WEB
|
PescaoDeth
|
2007-07-14
|
|
Citadel WebCit 7.02/7.10 - 'showuser?who' Cross-Site Scripting
|
3 |
WEB
|
Christopher Schwardt
|
2013-12-15
|
|
Phone Drive Eightythree 4.1.1 iOS - Multiple Vulnerabilities
|
3 |
WEB
|
Vulnerability-Lab
|
2013-12-15
|
|
Piwigo CMS 2.5.3 - Multiple Web Vulnerabilities
|
3 |
WEB
|
sajith
|
2007-07-13
|
|
Dating Gold 3.0.5 - 'secure.admin.php?int_path' Remote File Inclusion
|
3 |
WEB
|
mostafa_ragab
|
2007-07-13
|
|
Dating Gold 3.0.5 - 'footer.php?int_path' Remote File Inclusion
|
2 |
WEB
|
mostafa_ragab
|
2007-07-13
|
|
Dating Gold 3.0.5 - 'header.php?int_path' Remote File Inclusion
|
3 |
WEB
|
mostafa_ragab
|
2007-03-23
|
|
MzK Blog - 'Katgoster.asp' SQL Injection
|
2 |
WEB
|
GeFORC3
|
2007-07-13
|
|
ActiveWeb Contentserver CMS 5.6.2929 - Client-Side Filtering Bypass
|
4 |
WEB
|
RedTeam Pentesting
|
2007-07-13
|
|
contentserver 5.6.2929 - '/errors/transaction.asp?msg' Cross-Site Scripting
|
4 |
WEB
|
RedTeam Pentesting
|
2007-07-13
|
|
contentserver 5.6.2929 - '/errors/rights.asp?msg' Cross-Site Scripting
|
4 |
WEB
|
RedTeam Pentesting
|
2007-07-13
|
|
ActiveWeb Contentserver 5.6.2929 - 'Picture_Real_Edit.asp' SQL Injection
|
4 |
WEB
|
RedTeam Pentesting
|
2007-07-12
|
|
Inmostore 4.0 - 'index.php' SQL Injection
|
4 |
WEB
|
Keniobats
|
2007-07-12
|
|
Helma 1.5.3 - Search Script Cross-Site Scripting
|
3 |
WEB
|
Hanno Boeck
|
2007-07-11
|
|
IBM Proventia Sensor Appliance - Multiple Input Validation Vulnerabilities
|
4 |
WEB
|
Alex Hernandez
|
2007-07-11
|
|
EnViVo!CMS - 'default.asp?ID' SQL Injection
|
4 |
WEB
|
durito
|
2007-07-10
|
|
ImgSvr 0.6 - 'Template' Local File Inclusion
|
3 |
WEB
|
Tim Brown
|
2007-07-09
|
|
SquirrelMail G/PGP Encryption Plugin 2.0/2.1 - Multiple Remote Command Execution Vulnerabilities
|
4 |
WEB
|
Stefan Esser
|
2007-07-07
|
|
Levent Veysi Portal 1.0 - 'Oku.asp' SQL Injection
|
3 |
WEB
|
GeFORC3
|
2007-07-05
|
|
Maia Mailguard 1.0.2 - 'login.php' Multiple Local File Inclusions
|
4 |
WEB
|
Adriel T. Desautels
|
2007-07-04
|
|
OpManager 6/7 - '/admin/DeviceAssociation.do' Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Lostmon
|
2007-07-04
|
|
OpManager 6/7 - 'admin/ServiceConfiguration.do?Operation' Cross-Site Scripting
|
4 |
WEB
|
Lostmon
|
2007-07-04
|
|
OpManager 6/7 - reports/ReportViewAction.do Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Lostmon
|
2007-07-04
|
|
OpManager 6/7 - 'traceRoute.do?name' Cross-Site Scripting
|
4 |
WEB
|
Lostmon
|
2007-07-04
|
|
OpManager 6/7 - 'ping.do?name' Cross-Site Scripting
|
4 |
WEB
|
Lostmon
|
2007-07-04
|
|
NetFlow Analyzer 5 - '/jspui/customReport.jsp?rtype' Cross-Site Scripting
|
3 |
WEB
|
Lostmon
|
2007-07-04
|
|
NetFlow Analyzer 5 - '/jspui/selectDevice.jsp?rtype' Cross-Site Scripting
|
4 |
WEB
|
Lostmon
|
2007-07-04
|
|
NetFlow Analyzer 5 - 'netflow/jspui/index.jsp?view' Cross-Site Scripting
|
3 |
WEB
|
Lostmon
|
2007-07-04
|
|
NetFlow Analyzer 5 - '/jspui/appConfig.jsp?task' Cross-Site Scripting
|
3 |
WEB
|
Lostmon
|
2007-07-04
|
|
NetFlow Analyzer 5 - '/jspui/applicationList.jsp?alpha' Cross-Site Scripting
|
4 |
WEB
|
Lostmon
|
2007-07-03
|
|
Oliver - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
A. R.
|
2007-07-02
|
|
Liesbeth Base CMS - Information Disclosure
|
5 |
WEB
|
durito
|
2007-07-02
|
|
Moodle 1.7.1 - 'index.php' Cross-Site Scripting
|
4 |
WEB
|
MustLive
|
2007-07-02
|
|
Yoggie Pico and Pico Pro Backticks - Remote Code Execution
|
4 |
WEB
|
Cody Brocious
|
2007-07-02
|
|
Claroline 1.8.3 - '$_SERVER['PHP_SELF']' Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
munozferna
|
2007-06-27
|
|
ETicket 1.5.5 - 'Open.php' Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Jesper Jurcenoks
|
2006-12-02
|
|
DUClassmate 1.x - 'ICity' SQL Injection
|
3 |
WEB
|
Aria-Security Team
|
2007-06-27
|
|
Papoo 1.0.3 - 'Plugin.php' Authentication Bypass
|
4 |
WEB
|
Nico Leidecker
|
2013-12-12
|
|
Pentagram Cerberus P 6363 DSL Router - Multiple Vulnerabilities
|
2 |
WEB
|
condis
|