It appears that the Free Help Desk software by Help Desk Reloaded leaves the install.php file in place post installation, allowing remote attackers to create accounts without any authentication or access.
804b6bf95c701fc3e436588dcb9bb2b6c18779f0bb612923c56a2ad5eb75b375
SmartPPC Pro is susceptible to multiple cross site scripting flaws. Details provided.
2a1dfc606427de60d8c28ce32641f67fe30c15ce158badee9e505ba57887f164
e-Quick Cart is susceptible to multiple cross site scripting and SQL injection flaws. Exploitation details provided.
c0917d9be89c6bc5d4582e3cd2501515dc90fef1c4bbd7dc0cd3d650bec70897
EasyPageCMS is susceptible to cross site scripting attacks. Details provided.
bb5df34d5c7cc6efd88bea73311464dd7b653e7a8b51dd4b8d42eae260645bb0
aMember is susceptible to cross site scripting attacks via an unsanitized login variable.
09aeaa3107c25b1d5b405d6859a0ea1c2e31810c27dd8609186079c15aad9c49
PHP HANDICAPPER is susceptible to cross site scripting, SQL injection, and other flaws. Details provided.
2b6f990448729227c0ef62fc5049f14e49cdcabb515a207f26749fe31b402dc7
News2Net, a newspaper, magazine and newsletter publication manager, is susceptible to SQL injection attacks.
30ebe8bbd9726e841bf34724ba07a952af46fcee79d00465ed4f75837ee8d164
@lex Guestbook version 3.3 is susceptible to cross site scripting and injection attacks.
eabb3773c1c434b14ac8952462b781b24c7e0413a25f8f43a3d610378e0c73c7
PhpShop is susceptible to SQL injection attacks. Details provided.
288a5ea99da83c0773c6144310da7061e893ff7feeed0f69d24e6195255b41af
vlbook guestbook version 1.0 is susceptible to a remote file inclusion vulnerability.
4dc0e691d445ccd48ee7105f49de1ab2b22f1db170ebdc3af3ddc7cb3cfec1fe
EGuest PRO guestbook version 4.0 is susceptible to SQL injection and cross site scripting attacks.
da9102bf55a4eb5d94e8f4d3e770d4c807d5783ede3e6dba032c0523ca0842bd
xueBook guestbook version 1.0 is susceptible to SQL injection attacks.
4891c977ef261794e46acefca0cf324c3bd7969475a8b494b51f8dfa4584a2fa
BaalASP Free Bulletin Board is susceptible to SQL injection attacks.
4af8f91e97264d90528b3e43c4441a1bac958896529d9480f2b9d023e5f26e80
PHP Counter is susceptible to cross site scripting and SQL injection vulnerabilities. Exploitation details provided.
fe6f83fddf807501ff863ae0df830e71a2e3dffac6cbb41176b5e850d230df7e