Veeam Backup and Replications versions 6 through 8 suffer from log disclosure and broken password security vulnerabilities.
297149a77606ab6deac1de2bb98b0f033747ba6db8266944dfe68b46fdffd256
Nginx, Varnish, Cherokee, thttpd, mini-httpd, WEBrick, Orion, AOLserver, Yaws and Boa are subject to log escape sequence injection vulnerabilities.
ca929167a6a430b66650857a093ae76e47f6db643eb8bafffa59b6ebc10896d0
Jetty versions 6.x and 7.x suffer from cross site scripting, injection, and information disclosure vulnerabilities.
5f6bdd64a6596d46cbd0a5ae2448106b4656a8543eb8f07317ef5d4b92ae82d9
Vtiger CRM version 5.0.4 suffers from code execution, local file inclusion, cross site scripting, and cross site request forgery vulnerabilities.
a0599a490c531c182849299f81372c277f5eeeadc04bccdc6e9da1eb256e8a74
Whitepaper discussing a large amount of PHP filesystem attack vectors. Take Two.
50ea2f5921192ef048630929273e79e8dc80d288a30593b6b7ef6639a9180257
SugarCRM versions 5.2.0e and below suffer from a remote code execution vulnerability.
b46bbb1752deb1c9295ffea5807d2e474bb3c4c6de135549995c2c9d75270085
FormMail version 1.92 suffers from cross site scripting, header injection, and HTTP response splitting vulnerabilities.
dda541988029f268bc02136426254f2b6bbc63e0e3c487848827415005cc289e
Zabbix version 1.6.2 suffers from remote code execution, cross site request forgery, and local file inclusion vulnerabilities.
6fc6a1f1b3df47f2608e299ed5ea4014c5c4b5292607adb72d978c18e293dc26
Whitepaper discussing a large amount of PHP filesystem attack vectors.
cf9fb603acb1135b3f8a595653d1d18a8937d01270074b11448182d48a251260
Moodle version 1.9.3 suffers from a remote code execution vulnerability. Full details provided.
604fed1136c665e395b41c51641f80c673942dba92e616551632c7f5f1aac44e
Collabtive version 0.4.8 suffers from cross site scripting, authentication bypass, and shell upload vulnerabilities.
79b3e4b4ba18d65ce36a36f1ab3e00c7d5d25169f28c965cb0522f75f65a1536
Mantis Bug Tracker version 1.1.1 suffers from remote code execution, cross site scripting, and cross site request forgery vulnerabilities.
f69ef268367fecefac3205565ba9c1d3f5e36237f4b833741139a9350750a069
WiKID wClient-PHP versions 3.0-2 and below suffer from multiple cross site scripting vulnerabilities.
67d10cd0b31c2647b3ef2d33f5dd1920c1101c3453e62e3516e332f15ae75f08
Multiple security vulnerabilities such as cross site scripting and SQL injection have been discovered in Cacti versions 0.8.7a and below. Full exploitation details provided.
40eeb2e3bd758718bab24d1dda1ef1a8de3acea488b2f6daa45622393b146ba0
Original Photo Gallery versions 0.11.2 and below suffer from a remote command execution vulnerability.
6b9f382d9d8b5fa95f99764ba3fda63a36150fe8da621a53e0b5a82ae7f6bb06
PHP Nuke version 8.0, and possibly lower versions, are susceptible to a POST cross site scripting vulnerability.
240246141b63832150858dd16b81a45662e47408b15b013ca75d852b41f72486
PHP versions greater than or equal to 4.0.7 and less than or equal to 5.2.1 suffer from an arbitrary variable overwrite in import_request_variables().
5fa15988075ab903a6fb5db15ca53a4cf5cbc587310a227e5c83e5aa6494637b
Milkeyway Captive Portal versions 0.1 and 0.1.1 are vulnerable to many SQL injection and XSS vulnerabilities. Detailed POC included.
ac204592ba8d46b51a0cd05581ac6ff707420ab9e164e86a54872fef2b8f131e
WebCalendar 1.0.1 is susceptible to SQL injection attacks.
23e27c95c7836fb9ed4b91fc3f6d56dabd8ce00e2c70c418b4563aabab3e4fb9
PHP Web Statistik version 1.4 suffers from injection vulnerabilities.
1254628e2da8b1b1b6f411da297d1ea9e16f19f55e843ac8d21250c14532a6ef
FreeWebStat version 1.0 rev37 is vulnerable to multiple cross site scripting flaws.
0020303ba5ebcc0da8d674752ec0c2c826555fce3288cdd245981ad3915983ad
PHP iCalendar versions 2.0a2, 2.0b, 2.0c, and 2.0.1 are susceptible to a cross site scripting vulnerability. Exploitation details provided.
9f0ca61b9a7c8067bc32bf77050ea673995d4a2229d755fff83257c3138fc38e