AkkuS
99 exploits
Active since Nov 2018
NewsBee CMS 1.4 - 'home-text-edit.php' SQL Injection
Listing Hub CMS 1.0 - SQL Injection
i-doit 1.11.2 - Authenticated Remote Code Execution via Plugin ZIP Upload
CVSS 7.2
GPSTracker 1.0 - 'id' SQL Injection
Gigs 2.0 - 'username' SQL Injection
FTP2FTP 1.0 - Arbitrary File Download
EasyService Billing 1.0 - 'p1' SQL Injection
EasyService Billing 1.0 - SQL Injection / Cross-Site Scripting
Feng Office 3.7.0.5 - Unauthenticated Remote Code Execution via .shtml File Upload
CVSS 9.8
Feedy RSS News Ticker 2.0 - 'cat' SQL Injection
Employee Work Schedule 5.9 - 'cal_id' SQL Injection
ebrigade < 4.5 - Arbitrary File Download via showfile.php File Parameter
CVSS 4.3
Easy File Uploader 1.7 - SQL Injection / Cross-Site Scripting
easyLetters 1.0 - 'id' SQL Injection
Dolibarr ERP/CRM <= 8.0.3 - Cross-Site Scripting via Export Datatoexport Parameter
CVSS 6.1
phpscheduleit Booked Scheduler <2.7.5 - RCE
CVSS 8.8
BookingWizz Booking System 5.5 - 'id' SQL Injection
phpscheduleit Booked Scheduler <2.7.5 - RCE
CVSS 8.8
ATutor < 2.2.4 - Authenticated Arbitrary File Upload via File Manager
CVSS 8.8
Baby Names Search Engine 1.0 - 'a' SQL Injection
Ajax Full Featured Calendar 2.0 - 'search' SQL Injection
CutePHP CuteNews 2.1.2 - Code Injection
CVSS 8.8
TeemIp < 2.4.0 - Remote Code Execution via exec.php new_config Parameter
CVSS 7.2
php-fusion < 9.03.00 - Authenticated Remote Code Execution via Avatar Upload
CVSS 8.8
Rejected