EgiX
136 exploits
Active since Feb 2005
PHP iCalendar <2.3.4-2.24 - Info Disclosure
php-stats 0.1.9.2 - SQL Injection via ip or t Parameter
Invision Power Board 3.1.x-3.3.x core.php - Impact Unknown
openSIS 4.5-5.2 - Remote Code Execution via ajax.php modname Parameter
Horde Application Framework < 5.1.1 - Remote Code Execution via Serialized Object in _formvars
SugarCRM CE <= 6.3.1 - Code Injection
CVSS 9.8
Tuleap < 9.6 - Remote Code Execution via User::getRecentElements() Unserialize
CVSS 8.8
Tuleap < 7.7 - Authenticated PHP Object Injection via Project Registration Data Parameter
openSIS <= 7.4 - SQL Injection
CVSS 9.8
TikiWiki CMS/Groupware < 6.7 LTS & < 8.4 - RCE
CVSS 9.8
Ajax File and Image Manager < 1.1 - Remote Code Execution via PHP Code Injection in data.php
appRain CMF <= 0.1.5 - Unauthenticated Arbitrary File Upload and Remote Code Execution
Traq Project Issue Tracking System 2.0-2.3 - Unauthenticated Remote Code Execution via Admin Plugin Injection
WikkaWiki 1.3.1 and 1.3.2 - Arbitrary PHP Code Write via User-Agent HTTP Header
SugarCRM - Unauthenticated Remote Code Execution via PHP Object Injection
PmWiki 2.x < 2.2.35 - Remote Code Execution via PageListSort Order Parameter
phpScheduleIt <1.2.10 - Code Injection
DataLife Engine 9.7 - Remote Code Execution via catlist[] Parameter
vBSEO < 3.6.0 - Remote Code Execution via char_repl Parameter
phpLDAPadmin < 1.2.2 - Remote Code Execution via Orderby Parameter
Mantis < 1.1.4 - Authenticated Remote Code Execution via Sort Parameter
HP OpenView Data Protector 5.50/6.0 - Remote Code Execution via MSG_PROTOCOL Packet
HP OpenView Storage Data Protector 5.50 and 6.0 - Remote Code Execution via MSG_PROTOCOL Command
WebCalendar < 1.2.5 - Remote Code Execution via form_single_user_login Parameter
CVSS 9.8
WeBid < 1.0.2 - Unauthenticated Remote Code Execution via Converter.php to Parameter