AkkuS
99 exploits
Active since Nov 2018
Zoho ManageEngine Applications Manager <14.0 - Privilege Escalation
CVSS 9.8
WordPress Plugin Booking Calendar 3.0.0 - SQL Injection / Cross-Site Scripting
WordPress Plugin Events Calendar - SQL Injection
Wecodex Store Paypal 1.0 - SQL Injection
vtiger CRM < 7.1.0 - Unauthenticated Remote Code Execution via PHP3 Logo Upload Bypass
CVSS 7.2
TI Online Examination System v2 - Arbitrary File Download
Smart SMS & Email Manager 3.3 - 'contact_type_id' SQL Injection
Rukovoditel 2.3.1 - Authenticated Remote Code Execution via Malicious Background Image Upload
CVSS 8.8
ProjeQtOr < 7.2.5 - Remote Code Execution via Image Upload Feature
CVSS 8.8
PageResponse FB Inboxer Add-on 1.2 - 'search_field' SQL Injection
PHP-Fusion 9.03.50 - 'Edit Profile' Arbitrary File Upload
php-proxy 3.0.3 - Unauthenticated Local File Inclusion via index.php q Parameter
CVSS 7.5
PHP File Browser Script 1 - Directory Traversal
PHP Dashboards 4.5 - SQL Injection
PHP Dashboards 4.5 - 'email' SQL Injection
PaulNews 1.0 - 'keyword' SQL Injection / Cross-Site Scripting
osTicket < 1.12 - Cross-Site Scripting via User Importer CSV File Upload
CVSS 6.1
MySQL Blob Uploader 1.7 - 'download.php' SQL Injection / Cross-Site Scripting
My Directory 2.0 - SQL Injection / Cross-Site Scripting
MySQL Blob Uploader 1.7 - 'home-file-edit.php' SQL Injection / Cross-Site Scripting
MySQL Blob Uploader 1.7 - 'home-filet-edit.php' SQL Injection
MySQL Blob Uploader 1.7 - 'home-filet-edit.php' SQL Injection / Cross-Site Scripting
MySQL Smart Reports 1.0 - 'id' SQL Injection / Cross-Site Scripting
mySurvey 1.0 - 'id' SQL Injection
NewsBee CMS 1.4 - 'download.php' SQL Injection