AmnPardaz Security Research Team
76 exploits
Active since Jul 2007
Realm CMS < 2.3 - Exposure of Sensitive Information via Direct Request to _db/compact.asp
Realm CMS < 2.3 - Cross-Site Scripting via CmpctedDB or Boyut Parameters
Realm CMS < 2.3 - SQL Injection via KeyWordsList kwrd Parameter
Web Wiz Rich Text Editor 4.0 - Unauthenticated Arbitrary File Upload via RTE_popup_save_file.asp
Web Wiz Rich Text Editor 4.0, Forums 9.07, Newspad 1.02 - Unauthenticated Directory Listing & File Read
Web Wiz Rich Text Editor 4.0, Forums 9.07, Newspad 1.02 - Unauthenticated Directory Listing & File Read
bloofoxCMS 0.3 - Path Traversal via File Parameter
XlentProjects SphereCMS 1.1 - SQL Injection
Academic Web Tools < 1.4.2.8 - Session Fixation via PHPSESSID Parameter
VisualShapers EZContents 2.0.3 - Authentication Bypass / Multiple SQL Injections
TransLucid 1.75 - 'FCKeditor' Arbitrary File Upload
Tinypug 0.9.5 - Cross-Site Request Forgery (Password Change)
saspcms 0.9 - Multiple Vulnerabilities
QuickerSite 1.8.5 - SQL Injection via sNickName Parameter
Realm CMS 2.3 - Unauthenticated Authentication Bypass via Cookie Manipulation
pluck 4.5.1 - Path Traversal via langpref file blogpost or cat Parameter
Pooya Site Builder 6.0 - SQL Injection via xslIdn or part Parameter
PHPRunner < 4.2 - Cleartext Storage of Sensitive Information in Database
CVSS 7.5
phpList 2.10.x - Remote Code Execution / Local File Inclusion
phplist < 2.10.8 - Remote Code Execution via _SERVER[ConfigFile] Parameter
Persia BME E-Catalogue - SQL Injection
OneCMS < 2.4 - Unauthenticated Arbitrary File Upload and Remote Code Execution via a_upload.php
Modxcms - Path Traversal
MyBlog 0.9.8 - Multiple Remote Information Disclosure Vulnerabilities
MODx CMS 0.9.6.1 - Multiple Vulnerabilities