CWH Underground
145 exploits
Active since Jun 2006
Softpedia SiteXS CMS 0.1.1 Pre-Alpha - Cross-Site Scripting via User Parameter
SyndeoCMS 2.6.0 - Authenticated Path Traversal via Template Parameter
Starsgames Control Panel < 4.6.2 - Cross-Site Scripting via st Parameter
SMEWeb 1.4b and 1.4f - SQL Injection via idp and category Parameters
OneClick CMS 2008-01-24 - SQL Injection via id Parameter
rss_aggregator 1.0 - SQL Injection via IdFlux or IdTag Parameter
WallCity-Server Shoutcast Admin Panel 2.0 - Cross-Site Scripting via Username Parameter
ShareCMS 0.1 Beta - SQL Injection via eventID or userID Parameter
RSS-aggregator 1.0 - Unauthenticated Admin Function Access via admin/fonctions/ Directory
rss_aggregator 1.0 - SQL Injection via IdFlux or IdTag Parameter
Rianxosencabos CMS 0.9 - Authenticated Privilege Escalation and User Deletion via Admin Control Panel
phpSQLiteCMS 1 RC2 - Cross-Site Scripting via Multiple Language Parameters
Panuwat PromoteWeb MySQL - SQL Injection via go.php id Parameter
polypager < 1.0 - SQL Injection via nr Parameter
PodHawk 1.85 - Arbitrary File Upload
PHPSTREET Webboard 1.0 - SQL Injection via show.php id Parameter
phpSQLiteCMS 1 RC2 - Cross-Site Scripting via Multiple Language Parameters
PhpTax 0.8 - File Manipulation 'newvalue' / Remote Code Execution
PHP4dvd - 'config.php' PHP Code Injection
phpinv 0.8.0 - Remote File Inclusion via Action Parameter Path Traversal
Betster 1.0.4 - SQL Injection via id or username Parameter
Page Manager 2006-02-04 - Unauthenticated Arbitrary File Upload via upload.php
PageSquid CMS 0.3 Beta - SQL Injection via Page Parameter
PHP Address Book 3.1.5 - Multiple SQL Injections / Cross-Site Scripting Vulnerabilities
PHP infoBoard V.7 Plus - Cross-Site Scripting via isname Parameter