DarkFig
81 exploits
Active since Mar 2006
Tr Forum 2.0 - Privilege Escalation
Simple Web Content Management System - SQL Injection via Page ID Parameter
SturGeoN Upload - Unauthenticated Arbitrary PHP Code Execution via File Upload
SoftBB < 0.1 - Path Disclosure via Invalid page[] Parameter
Simple PHP Blog (sPHPblog) 0.5.1 - Multiple Vulnerabilities
ShoutLIVE 1.1.0 - Remote Code Execution via settings.php Variable Injection
registroTL - Unauthenticated Sensitive Information Exposure via Direct Database Download
Pluxml 0.3.1 - Cross-Site Scripting via msg Parameter in admin/auth.php
PunBB 1.2.14 - Remote Code Execution
phpslash <= 0.8.1.1 - Remote Code Execution via Fields Parameter
phpBB 2.0.18 - Remote Brute Force/Dictionary (2)
PHP Security Framework - Multiple Input Validation Vulnerabilities
Rejected
NPDS 5.10 - Multiple Input Validation Vulnerabilities
Nuked-klaN 1.7.6 - SQL Injection via X-Forwarded-For Header
NukeSentinel <2.5.06 - SQL Injection
NukeSentinel <2.5.06 - SQL Injection
Oxygen O2PHP BB <1.1.3 - SQL Injection
Net Portal Dynamic System <5.10 - Code Injection
MyBB < 1.2.3 - SQL Injection via Client-IP HTTP Header
Jupiter CMS 1.1.5 - Unauthenticated Arbitrary File Upload via Emoticons Module
Jupiter CMS 1.1.5 - SQL Injection via HTTP Headers
Jupiter CMS <1.1.5 - Path Traversal
JBC Explorer <7.20 RC1 - Code Injection
Nayco JASmine - Remote File Inclusion via Section Parameter