OpenCart version 1.5.6 suffers from cross site scripting, path disclosure, and remote file upload vulnerabilities.
371e1add9d841cd724ecebaaf12aa30d8f618c80bf66d43adecbdfa1460b8157
LokiCMS versions 0.3.4 and below suffer from arbitrary file overwrite, code injection, file inclusion, and administrative hash retrieval vulnerabilities.
1f1ae5f7ff6a42b03c2ad92a0f0f650763fb628ba8d21cd22fc17631d394f5ce
RunCMS versions 1.6 and below remote file overwrite exploit that makes use of disclaimer.php.
650bb3ef7f0e466f4df51870a23127942a02667cb48754583fe3decb65346247
RunCMS versions 1.6 and below suffer from a local file inclusion vulnerability.
e9f4f4c230016cc5662e003256d23aff40d9a22b97bf4724acff1bb507d9afe6
bcoos version 1.0.10 suffers from local file inclusion and SQL injection vulnerabilities.
fca385a2ee787e17835e94128c52ec1e428541d162914c834e7823152b844dbf
FlexBB version 1.0.0 10005 Beta Release 1 suffers from a SQL injection vulnerability when parsing the user supplied cookie value.
43fdf56c7c5fd42533478278547df832f104fe6c96ebce307fe4959802e89779
KAPDA Advisory - CuteNews version 1.4.5 suffers from multiple cross site scripting, local file inclusion, and other vulnerabilities.
4c60f4a2e8964c418a42187809d6a4b9bd58f8e9ddce32d159c9cd5222384229
KAPDA Advisory #61: Multiple vulnerabilities in PacPoll versions 4.0 and prior.
2fe05620e83e90181d68ccf81e1524097d606db200aeeebf09ada457a165ce14
KAPDA Advisory #60 - Mambo V4.6.x vulnerabilities including cross site scripting and html/sql injection.
68adf8157b330a4c6eb23279bad3662561c6abed1f3afd904536d8dbcf771fbc
Joomla! CMS versions 1.0.10 suffers from a logic weakness that allows voting without restrictions.
5aa46cebb5bbd663c76c82daf03e73c16a689e04b95ab6e952fcd41b2e133e8c
AjaxPortal version 3.0 is susceptible to a SQL injection flaw.
68241d394a552ba41f23ec3ea7e58f91c6e6a5456c5dd76262766a6dfc3bd014
KAPDA Advisory #43 - PHPWCMS suffers from path disclosure, cross site scripting, and local file inclusion vulnerabilities.
debaf511d1aedbd12e6d60efc331625068c0a7efe8b892d4cd20f8668d5ee76f
There is a high risk vulnerability in Guppy versions 4.5.11 and below that will allow remote attackers to destroy database files. Details provided.
a56334d59160722210ec923946ac49e919e81d4c1acbc090031cf3742db3b438
Noah's Classifieds versions 1.3 and below are susceptible to path disclosure, SQL injection, cross site scripting, local file inclusion, and remote code execution flaws.
222c5ab8614a5070ec578a3880f833eec8e4283ef7b6e8203c91dc0d803fb051
KAPDA Advisory #19 - vBulletin version 3.5.2 is susceptible to HTML injection attacks that can allow for cross site scripting.
bc66ce268e7da45f3992c87d2f61cfe5e1c09fdac7f6c022aa1aaef7df6341a2
KAPDA Advisory #17 - Beehive Forum Version 0.6.2 suffers from multiple HTML injection bugs if register_globals is On.
a61be49c7c4ceb6126bf3a70e18656badda1c53adca4c9072786934e338c80da
Simple Machines Forum version 1.1 rc1 is susceptible to SQL injection attacks.
fd048e492eda40c3d6301b7ec2d684adefb8d1c98ef0a539b0d176e3ac246fc0
ThWboard version 3 beta 2.8 is susceptible to HTML injection, cross site scripting, and SQL injection attacks. Details provided.
b6748f11eab63ffe76a6f2b734fd18a8b4a579dc4eeca78ae82b52b960a64150
PHPP version 1.0 is susceptible to cross site scripting vulnerabilities. Exploitation details provided.
9f0b93533446c6334581e450749eed571af105c4644900f436f6f35f2981af5c
KAPDA Advisory - XMB version 1.9.3 Nexus (Final) and 1.9.2 Nexus are susceptible to cross site scripting and html injection flaws.
297f8291e00f8750c205028ac1f0e9e23651d985c7c5fbfc6d74a6faf8f0d6f4
KAPDA Advisory - ekinboard version 1.0.3 is susceptible to cross site scripting and html injection flaws.
f2e17a9c85b4d4db9dda650d51963910482d98e209bc126458dbbef1ebcbe96f
Mambo versions 4.5.2.3, 4.5.2.2, 4.5.2.1, 4.5.2 suffer from a path disclosure vulnerability via a specially crafted url.
57f70dae3c661dfcc4fda834e1ece2567e5eb94330ef99f18e07214cdb9a1955
VUBB Alpha RC1 is susceptible to cross site scripting and path disclosure flaws. Details provided.
04077c920bd3d7027c8c2bbac8d73904b1e94fbad3a94c8ad700e51e0c2d7da2
Chipmunk Forum, Topsites, Directory, and Guestbook suffer from multiple XSS and path disclosure vulnerabilities.
23cac3529e4cae30ba7ad7123e1343b17e4ac7da4d4902d5bd9b5eb3dfbe7921
ZeroBlog versions 1.2a and 1.1f are susceptible to cross site scripting attacks.
bea71f694efcc79089a11410c0f538c2188a915129447a7392dd2f94f253781a