CWH Underground
145 exploits
Active since Jun 2006
MindDezign Photo Gallery 2.2 - SQL Injection via id Parameter
Butterfly Organizer 2.0.1 - SQL Injection via mytable Parameter
Havalite CMS 1.1.7 - Unauthenticated RCE
LibrettoCMS 1.1.7 - Unauthenticated RCE
MindDezign Photo Gallery 2.2 - SQL Injection via Username Parameter
MindDezign Photo Gallery 2.2 - SQL Injection via id Parameter
OTManager CMS 24a - Remote File Inclusion via Conteudo Parameter
ContentNow CMS 1.4.1 - Cross-Site Scripting via pageid Parameter or PATH_INFO
SyndeoCMS 2.6.0 - Cross-Site Scripting via Section Parameter
PHP infoBoard V.7 Plus - SQL Injection via idcat Parameter
polypager < 1.0 - Cross-Site Scripting via nr Parameter
OwnRS Beta 3 - Cross-Site Scripting via Clanek.php ID Parameter
traindepot 0.1 - Path Traversal via Module Parameter
WallCity-Server Shoutcast Admin Panel 2.0 - Remote File Inclusion via Page Parameter
php-address_book < 3.1.5 - Cross-Site Scripting via Group Parameter
php-address_book < 4.0 - SQL Injection via id Parameter
427BB 2.3.1 - SQL Injection via showpost.php post Parameter
Butterfly Organizer 2.0.0 and 2.0.1 - SQL Injection via id Parameter
PHPSTREET Webboard 1.0 - SQL Injection via show.php id Parameter
KTP Computer Customer Database - Authenticated SQL Injection via tid Parameter
Gravity Board X 2.0 Beta - Cross-Site Scripting via Subject Parameter
Gravity Board X 2.0 Beta - SQL Injection via searchquery or board_id Parameter
JaxUltraBB < 2.0 - Cross-Site Scripting via Forum Parameter
MyBlog - SQL Injection via View Parameter or ID Parameter
MyBlog - Cross-Site Scripting via s, sort, or id Parameters