DarkFig
81 exploits
Active since Mar 2006
Net Portal Dynamic System < 5.10 - SQL Injection via _FILES[DB][tmp_name] Parameter
dmx_forum < 2.1a - Unauthenticated Sensitive Information Exposure via Web-Accessible Database Configuration
Blog Pixel Motion 2.1.1 - Code Injection
Pluxml 0.3.1 - Unauthenticated Arbitrary File Upload via admin/images.php
alex_guestbook 4.0.2 - SQL Injection via Lang Parameter
Coppermine Photo Gallery < 1.4.10 - Authenticated SQL Injection via Multiple Parameters
registroTL main.php - Remote File Inclusion Code Execution
JBC Explorer < 7.20_rc1 - Unauthenticated Authentication Bypass via auth.php Parameter Manipulation
Connectix Boards <0.7 - SQL Injection
Jupiter CMS 1.1.5 - Remote Code Execution via FTP URL in Index.php
ixprim_cms 1.2 - Information Disclosure via FCKeditor Plugin Path Exposure
SoftBB < 0.1 - SQL Injection via Groupe or Select Parameter
SoftBB < 0.1 - Authenticated Direct Static Code Injection via cache_forum Parameter
Tr Forum 2.0 - Authenticated SQL Injection via id2 Parameter
Tr Forum 2.0 - Unauthenticated Authentication Bypass and Admin Account Creation via Admin Insert Endpoint
NukeSentinel <2.5.05 - SQL Injection
NukeSentinel <2.5.12 - SQL Injection
Zen Cart <= 1.3.8a - Unauthenticated Arbitrary File Upload via record_company_image Parameter
Visual Shapers ezContents 2.0.3 - Cross-Site Scripting via subgroupname Parameter
webSPELL 4.01.02 - SQL Injection via gallery.php picID Parameter
Vincent-Leclercq News 5.2 - 'Diver.php' SQL Injection
webSPELL 4.01.02 - PHP Remote Code Execution
Visual Shapers ezContents 2.0.3 - SQL Injection via Groupname Parameter
Vincent Leclercq News 5.2 - Cross-Site Scripting via divers.php id and disabled Parameters
Tr Forum 2.0 - Privilege Escalation