CodeSecLab
28 exploits
Active since Mar 2017
RosarioSIS < 7.6.1 - Unauthenticated SQL Injection via PortalPollsNotes Votes Parameter
CVSS 9.8
RosarioSIS 6.7.2 - Cross-Site Scripting via PrintSchedules.php include_inactive Parameter
CVSS 6.1
RosarioSIS 6.7.2 - Cross-Site Scripting via Preferences.php Tab Parameter
CVSS 6.1
Piwigo 13.6.0 - SQL Injection via Profile Function
CVSS 9.8
Pluck 4.7.10 - Remote Code Execution via Trashcan Restore Item File Upload
CVSS 7.2
Pluck < 4.7.7-dev2 - Unauthenticated Arbitrary PHP File Upload via .htaccess MIME Type Bypass
CVSS 9.8
phpipam v1.6 - Reflected Cross-Site Scripting via closeClass Parameter
CVSS 6.1
phpipam < 1.4 - SQL Injection via Custom Fields Order Table Parameter
CVSS 9.8
phpipam < 1.5.2 - SQL Injection
CVSS 7.2
phpipam 1.6 - Cross-Site Scripting via Import Load Data
CVSS 6.1
phpipam 1.6 - Cross-Site Scripting via PowerDNS Record Edit Page
CVSS 7.1
phpMyAdmin <4.9.4-5.0.1 - SQL Injection
CVSS 8.8
phpmyfaq < 2.9.8 - Cross-Site Request Forgery for Glossary Modification
CVSS 8.8
phpmyfaq < 2.9.8 - Cross-Site Request Forgery in admin/ajax.config.php
CVSS 8.8
phpmyfaq < 2.9.8 - Cross-Site Request Forgery in admin/stat.main.php
CVSS 8.8
phpmyfaq < 3.1.9 - Reflected Cross-Site Scripting
CVSS 6.1
OpenRepeater <2.2 - Command Injection
CVSS 9.8
openSIS 8.0 - SQL Injection via ForgotPassUserName.php
CVSS 9.8
mobiledetect < 2.8.32 - Cross-Site Scripting via $_SERVER['PHP_SELF'] in session_example.php
CVSS 3.5
MiniCMS 1.1 - Cross-Site Scripting via Date Parameter
CVSS 6.1
GetSimpleCMS < 3.3.15 - Remote Code Execution via PHAR File Upload
CVSS 7.2
Gnuboard5 <=5.3.2.8 - SQL Injection
CVSS 9.8
flatcore < 1.5 - Cross-Site Request Forgery via File Upload
CVSS 8.8
flatcore 1.4.7 - Authenticated Arbitrary PHP File Upload via Addons Feature
CVSS 7.2
YOURLS < 1.8.3 - Cross-Site Request Forgery
CVSS 7.4