Curesec Research Team
29 exploits
Active since Sep 2017
AlegroCart 1.2.8 - Authenticated Remote Code Execution via File Path Parameter
CVSS 7.2
AlegroCart 1.2.8 - Authenticated SQL Injection via Download Parameter
CVSS 7.2
ZenPhoto 1.4.11 - Remote File Inclusion
Mezzanine 4.2.0 - Cross-Site Scripting
ZeusCart 4.0 - SQL Injection
ZeusCart 4.0 - Cross-Site Request Forgery
PivotX 2.3.11 - Directory Traversal
Pligg CMS 2.0.2 - Multiple SQL Injections
Pligg CMS 2.0.2 - Directory Traversal
Pligg CMS 2.0.2 - Cross-Site Request Forgery / Code Execution
PhpSocial 2.0.0304_20222226 - Cross-Site Request Forgery
phplist 3.2.6 - SQL Injection
OpenDocMan 1.3.4 - Cross-Site Request Forgery
MyBB 1.8.6 - Cross-Site Scripting
MyBB 1.8.6 - SQL Injection
LiveZilla 5.0.1.4 - Remote Code Execution via Path Traversal
CVSS 9.8
LEPTON 2.2.2 - SQL Injection
LEPTON 2.2.2 - Remote Code Execution
Kajona 4.7 - Cross-Site Scripting / Directory Traversal
FUDforum 3.0.6 - Local File Inclusion
Grawlix 1.0.3 - Cross-Site Request Forgery
FUDforum 3.0.6 - Cross-Site Scripting / Cross-Site Request Forgery
ClipperCMS 1.3.0 - Multiple SQL Injections
CodoForum 3.3.1 - Multiple SQL Injections
BigTree CMS 4.2.3 - (Authenticated) SQL Injection