CWH Underground
145 exploits
Active since Jun 2006
PHP Address Book 8.2.5 - SQL Injection via edit.php or import.php Parameters
OpenForum 0.66 Beta - Unauthenticated Password Reset via Direct Request
OTManager CMS 24a - Cross-Site Scripting via Conteudo Parameter
OwnRS Beta 3 - SQL Injection via clanek.php id Parameter
MyBlog - Cleartext Password Storage
MyPHP CMS 0.3.1 - SQL Injection via pid Parameter
NanoBB 0.7 - Multiple Vulnerabilities
MycroCMS 0.5 - SQL Injection via Entry ID Parameter
Max Forum - Multiple Vulnerabilities
Lito Lite CMS - SQL Injection via cid Parameter
Lokboard - 'index_4.php' PHP Code Injection
mkCMS - 'index.php' Arbitrary PHP Code Execution
GraFX miniCWB < 2.1.1 - Cross-Site Scripting via Multiple Parameters
MindDezign Photo Gallery 2.2 - SQL Injection via Username Parameter
MindDezign Photo Gallery 2.2 - Unauthenticated Privilege Escalation via Username Parameter
mForum 0.1a - SQL Injection via User Profile Fields
meBiblio 0.4.7 - Unauthenticated Arbitrary File Upload and Remote Code Execution via PHP File Upload
KTP Computer Customer Database - SQL Injection via lname Parameter
Kwalbum < 2.0.2 - Authenticated Arbitrary File Upload and Remote Code Execution via Executable File Extension
KTP Computer Customer Database - Remote File Inclusion via Path Traversal in p Parameter
Keller Web Admin CMS 0.94 Pro - Path Traversal via Action Parameter
imacs CMS 0.3.0 - Unrestricted Arbitrary File Upload
JaxUltraBB < 2.0 - Path Traversal via User Parameter
IPTBB 0.5.6 - Arbitrary Add Admin
How2ASP.net Webboard 4.1 - SQL Injection via qNo Parameter