BlackHawk
33 exploits
Active since Feb 2005
FCKeditor 2.0 RC2 - Unauthenticated Arbitrary File Upload
Project Pier <0.8.8 - Unauthenticated RCE
Podcast Generator <= 1.1 - Unauthenticated Arbitrary File Deletion via Admin Delete Endpoint
evilsentinel < 1.0.9 - Unauthenticated Privilege Escalation via admin/index.php Redirect Handling
MyCMS < 0.9.8 - Remote File Inclusion via games.php id Parameter
InoutMailingListManager <3.1 - Open Redirect
InoutMailingListManager < 3.1 - Unauthenticated Arbitrary PHP File Upload and Remote Code Execution via Admin Cookie
Kubix < 0.7 - SQL Injection via member_id Parameter
Open Newsletter < 2.5 - Unauthenticated Administrative Action Execution
phpMyNewsletter < 0.8_beta_5 - Unauthenticated Configuration Modification and Code Injection via saveGlobalconfig Action
FCKeditor 2.0-2.2 - Unauthenticated Arbitrary File Upload via Extension Blacklist Bypass
Project Pier <0.8.8 - Unauthenticated RCE
Solar Empire < 2.9.1.1 - SQL Injection via User-Agent HTTP Header
Revokebb < 1.0_rc4 - SQL Injection via revokebb_user Cookie
podcast_generator <= 1.1 - Authenticated PHP Code Injection via Recent Parameter
Pligg CMS < 2.0.1 - SQL Injection via Recover.php ID or N Parameter
phpMyNewsletter <0.8 beta5 - Open Redirect
Open Newsletter <2.5 - Command Injection
MyCMS < 0.9.8 - Remote Code Execution via Score Parameter or Login Cookie
MyCMS <0.9.8 - Privilege Escalation
myblog < 0.9.8 - Unauthenticated Authentication Bypass via Admin Cookie Parameter
Light Blog Remote - Multiple Vulnerabilities
LightBlog 8.4.1.1 - Authenticated Privilege Escalation via cp_memberedit.php
Kubix < 0.7 - Path Traversal via Theme Cookie or File Parameter
InoutMailingListManager < 3.1 - SQL Injection via id Parameter