Bug Researchers Group

8 exploits Active since Sep 2008
EIP-2026-112447 EXPLOITDB text WORKING POC
Streamo Online Radio And TV Streaming CMS - SQL Injection
EIP-2026-109341 EXPLOITDB text WORKING POC
Matrimonial Website Script 1.0.2 - SQL Injection
EIP-2026-109514 EXPLOITDB text WORKING POC
MLM Unilevel Plan Script 1.0.2 - SQL Injection
EIP-2026-108956 EXPLOITDB text WORKING POC
Kagao 3.0 - Multiple Vulnerabilities
CVE-2008-4438 EXPLOITDB text WORKING POC
Datafeed Studio - XSS
Cross-site scripting (XSS) vulnerability in search.php in Datafeed Studio 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-4439 EXPLOITDB text WRITEUP
Martinwood Datafeed Studio < 1.6.2 - Code Injection
PHP remote file inclusion vulnerability in admin/bin/patch.php in MartinWood Datafeed Studio before 1.6.3 allows remote attackers to execute arbitrary PHP code via a URL in the INSTALL_FOLDER parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
EIP-2026-104889 EXPLOITDB text WORKING POC
AbleSpace 1.0 - 'adv_cat.php' Cross-Site Scripting
CVE-2008-4051 EXPLOITDB text WRITEUP
Smart Survey 1.0 - XSS
Cross-site scripting (XSS) vulnerability in surveyresults.asp in Smart Survey 1.0 allows remote attackers to inject arbitrary web script or HTML via the sid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.