AmnPardaz Security Research Team
76 exploits
Active since Jul 2007
Academic Web Tools < 1.4.2.8 - Open Redirect via rss_getfile.php file Parameter
Academic Web Tools < 1.4.2.8 - Cross-Site Scripting via Query String and glb_sid Parameter
Academic Web Tools < 1.4.2.8 - SQL Injection via rating.php book_id Parameter
Academic Web Tools <= 1.4.2.8 - Path Traversal via dfile Parameter
QuickerSite 1.8.5 - Unauthenticated Administrative Functionality Access
QuickerSite 1.8.5 - Denial of Service via mailPage.asp sEmail Parameter
QuickerSite 1.8.5 - Cross-Site Scripting via Multiple Parameters
QuickerSite 1.8.5 - Information Disclosure via showThumb.aspx
QuickerSite 1.8.5 - Remote Code Execution via Unrestricted File Upload
chillyCMS 1.1.3 - SQL Injection via Name Parameter
PHPRunner < 4.2 - SQL Injection via SearchField Parameter
OneCMS < 2.4 - SQL Injection via Username or User Parameter
Cilekyazilim Chicomas - XSS
cpCommerce 1.1.0 - SQL Injection via id_product, id_manufacturer, or id_category Parameter
cpCommerce 1.1.0 - Cross-Site Scripting via Calendar Year Parameter
Carbon Communities <2.4 - SQL Injection
Bitweaver R2 - Unrestricted File Upload
elinestudio site_composer < 2.6 - Path Traversal via inpCurrFolder Parameter
eLineStudio Site Composer < 2.6 - SQL Injection via id or template_id Parameter
eLineStudio Site Composer <= 2.6 - Cross-Site Scripting via Multiple Parameters
doitlive/cms < 2.50 - Cross-Site Scripting via FILE Parameter
MegaBBS 2.2 - Cross-Site Scripting via toid Parameter
Acidcat CMS 3.4.1 - Info Disclosure
Acidcat CMS 3.4.1 - Cross-Site Scripting via admin_colors_swatch.asp field Parameter
Acidcat CMS 3.4.1 - SQL Injection via cID or Username Parameter