CWH Underground
145 exploits
Active since Jun 2006
phpinv 0.8.0 - Cross-Site Scripting via Search Keyword Parameter
Telephone Directory 2008 - Cross-Site Scripting via edit1.php action parameter
mebiblio 0.4.7 - SQL Injection via JID Parameter
meBiblio 0.4.7 - Cross-Site Scripting via SQL Parameter
SMEWeb 1.4b and 1.4f - Cross-Site Scripting via Multiple Parameters
WINMOD 1.4 - '.lst' Local Stack Overflow
Wolf CMS 0.8.2 - Arbitrary File Upload
WebChamado 1.1 - SQL Injection via eml Parameter
Webdevindo-CMS 1.0.0 - SQL Injection via hal Parameter
WeBid 1.1.1 - Unrestricted Arbitrary File Upload
WebXell Editor 0.1.3 - Remote Code Execution via Unrestricted File Upload
PHPSTREET Webboard 1.0 - Unauthenticated Sensitive Information Exposure via Direct Request
WCMS 1.0b - 'news_detail.asp' SQL Injection
VanGogh Web CMS 0.9 - SQL Injection via article_ID Parameter
WCMS 1.0b - Arbitrary Add Admin
The Rat CMS Pre-Alpha 2 - SQL Injection
ThaiQuickCart 3 - Path Traversal via sLanguage Cookie
The Rat CMS Pre-Alpha 2 - Cross-Site Scripting via id Parameter or PATH_INFO
TNT Forum 0.9.4 - Remote File Inclusion via Modulo Parameter
The Rat CMS Pre-Alpha 2 - SQL Injection
TxtBlog 1.0 Alpha - Path Traversal via m Parameter
Ultimate Webboard 3.00 - SQL Injection via Category Parameter
Traindepot 0.1 - Cross-Site Scripting via Search Query Parameter
Telephone Directory 2008 - SQL Injection via code or id Parameter
The Rat CMS Pre-Alpha 2 - Cross-Site Scripting via id Parameter or PATH_INFO