CWH Underground
145 exploits
Active since Jun 2006
Fobuc Guestbook 0.9 - SQL Injection
Gravity Board X 2.0 BETA - SQL Injection via member_id Parameter
Galmeta Post CMS 0.2 - Remote Code Execution / Arbitrary File Upload
Galmeta Post CMS 0.2 - Multiple Local File Inclusions
FOG Forum 0.8.1 - Path Traversal and Arbitrary File Execution via fog_lang and fog_skin Parameters
Fly-High CMS 2012-07-08 - Unrestricted Arbitrary File Upload
elemata_cms RC 3.0 - SQL Injection via id Parameter
Haudenschilt Family Connections CMS 1.4 - Authenticated SQL Injection via addressbook.php address Parameter
Facil CMS 0.1RC - Path Traversal via change_lang or modload Parameter
Experts 1.0.0 - SQL Injection via Question ID Parameter
Def-Blog 1.0.3 - SQL Injection via Article Parameter
Devalcms 1.4a - Remote File Inclusion and Path Traversal via func.php currentpath Parameter
Demo4 CMS 01 Beta - SQL Injection via id Parameter
Def-Blog 1.0.3 - SQL Injection via Article Parameter
CMS MAXSITE - Remote Code Execution via Guestbook Message Parameter
little_cms 0.0.1 - SQL Injection via Index.php Term Parameter
CMS little 0.0.1 - Path Traversal via Template Parameter
ClipBucket 2.7 RC3 (2.7.0.4.v2929-rc3) - SQL Injection via Item Parameter
CMS Gratis Indonesia - 'config.php' PHP Code Injection
Cuppa CMS - '/alertConfigField.php' Local/Remote File Inclusion
ContentNow CMS 1.4.1 - Authenticated Arbitrary File Upload via upload.php
CMS Mini 0.2.2 - Path Traversal via Path or P Parameter
bcoos 1.0.13 - Authenticated SQL Injection via cid Parameter
Check Up New Generation <4.52 - SQL Injection
butterfly_organizer 2.0.0 - Cross-Site Scripting via mytable, tablehere, or letter Parameter