EgiX
136 exploits
Active since Feb 2005
Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle
CVSS 9.1
vBulletin Template Conditionals - PHP Code Execution
CVSS 9.0
openSIS <= 7.4 - Path Traversal
CVSS 7.5
openSIS <= 7.4 - Unauthenticated PHP Code Execution
CVSS 9.1
phpLDAPadmin 1.2.x - Cross-Site Scripting via _debug Command
FCKeditor 2.0 RC2 - Unauthenticated Arbitrary File Upload
SugarCRM - Unauthenticated Remote Code Execution via PHP Object Injection
DataLife Engine 9.7 - Remote Code Execution via catlist[] Parameter
DataLife Engine 9.7 - Remote Code Execution via catlist[] Parameter
vtiger CRM < 5.4.0 - Local File Inclusion and Remote Code Execution via customerportal.php
CVSS 8.1
TikiWiki CMS/Groupware < 8.2 - Exposure of Sensitive Information via Direct Request
Kish Guest Posting Plugin < 1.2 - Unauthenticated Arbitrary File Upload via uploadify.php
WebCalendar < 1.2.5 - Remote Code Execution via form_single_user_login Parameter
CVSS 9.8
Traq Project Issue Tracking System 2.0-2.3 - Unauthenticated Remote Code Execution via Admin Plugin Injection
Traq Project Issue Tracking System 2.0-2.3 - Unauthenticated Remote Code Execution via Admin Plugin Injection
WeBid < 1.0.2 - Unauthenticated Remote Code Execution via Converter.php to Parameter
WeBid < 1.0.2 - Unauthenticated Remote Code Execution via Converter.php to Parameter
phpScheduleIt <1.2.10 - Code Injection
TikiWiki CMS/Groupware < 6.7 LTS & < 8.4 - RCE
CVSS 9.8
Support Incident Tracker 3.45-3.65 - Remote Code Execution via Lang Parameter in translate.php
Docebo < 3.5.0.3 - SQL Injection via Accept-Language HTTP Header
deluxebb < 1.1 - SQL Injection via forums.php sort Parameter
ZeusCMS < 0.3 - SQL Injection via Referer HTTP Header
Coppermine Photo Gallery <1.4.18 - Info Disclosure
phpmotion < 2.0 - Authenticated Arbitrary File Upload via update_profile.php