Alisveristr E-Commerce is susceptible to SQL injection attacks during the login phase of usage.
9ba76e5ba7fdd0e4f2889d7965f9b150Zen-Cart versions 1.2.6d and below are susceptible to blind SQL injection and remote command execution attacks. Exploit included.
a507099ecbfb1ccd22d23ed6ed3eca57It appears that the Free Help Desk software by Help Desk Reloaded leaves the install.php file in place post installation, allowing remote attackers to create accounts without any authentication or access.
59d3001cc14911fe89d6c74dc9fab115WinEggDropShell Eternity version 1.7 is susceptible to preauth stack overflows. Proof of concept denial of service exploit included.
e2a03f701231a1f11975df0e44fadadbphpMyChat version 0.14.6 is susceptible to cross site scripting flaws in start_page.css.php, style.css.php, and users_popupL.php.
aca7825d44871757fae3eb67dd784b18Edgewall Trac version 0.9 is susceptible to a SQL injection attack due to a lack of sanity checking on the group variable.
7df147c2ac1998ed9869129658f50506GameFly, the popular online video game rental service, suffers from a cross site scripting flaw.
fd363324b7ba22cd1ed151f9e8b1cda4WebCalendar version 0.1.0 is susceptible to SQL injection attacks via activity_log.php and edit_report_handler.php. layers_toggle.php is susceptible to CRLF injection. Exploitation details provided.
46ca1f68ff71adaff29ee3145854d376Microsoft Windows CreateRemoteThread denial of service exploit.
5802c87f4a75cb494ecd81206bc890ba