HACKERS PAL
76 exploits
Active since Nov 2005
Patrick Michaelis Wili-CMS - Remote File Inclusion via globals[content_dir] Parameter
Patrick Michaelis Wili-CMS - Cross-Site Scripting via Query String and globals[pageid] Parameter
ELSEIF CMS Beta 0.6 - Stored Cross-Site Scripting via Multiple Parameters
ELSEIF CMS Beta 0.6 - Remote Code Execution via PHP File Inclusion
ELSEIF CMS Beta 0.6 - Path Traversal
TorrentTrader Classic Edition 1.07 - Remote File Inclusion via ss_uri Parameter
IDMOS 1.0-beta - Cross-Site Scripting via err_msg or content Parameter
XMB 1.9.3 - Cross-Site Scripting via u2u.php Username Parameter
Laurentiu Matei XHP CMS 0.5.1 - XSS
Wizz Forum 1.20 - SQL Injection via AuthID TopicID Parameters
Patrick Michaelis Wili-CMS - Information Disclosure via Direct Request
Wizz Forum 1.20 - SQL Injection via AuthID TopicID Parameters
Wizz Forum 1.20 - SQL Injection via AuthID TopicID Parameters
Jelsoft vBulletin 2.x - SQL Injection
TorrentTrader Classic 1.07 - Cross-Site Scripting via Color Parameter or Category Parameter
Groupee UBB.threads 6.5.1.1 - Code Injection
David Bennett PHP-Post <= 1.0 - Cross-Site Scripting via Multiple Parameters
David Bennett PHP-Post <1.0 - Variable Overwrite
phpmytourney 2 - Remote Code Execution via tourney/index.php page Parameter
MyBulletinBoard (MyBB) 1.03 - Multiple SQL Injections
Magic News Plus 1.0.2 - Cross-Site Scripting via link_parameters Parameter
Magic News Plus 1.0.2 - Cross-Site Scripting via link_parameters Parameter
Magic News Plus 1.0.2 - Remote Code Execution via php_script_path Parameter
Jupiter CMS - Stored Cross-Site Scripting via Multiple Language Parameters
Jupiter CMS - Stored Cross-Site Scripting via Multiple Language Parameters