IHTeam
25 exploits
Active since Sep 2007
pfBlockerNG < 2.1.4_26 - Remote Code Execution via HTTP Host Header
TerraMaster Operating System <= 4.2.06 - Unauthenticated Remote Code Execution via Event Parameter in makecvs.php
CVSS 9.8
Anantasoft Gazelle CMS 1.0 - Path Traversal and Arbitrary File Write via Customize Template Parameter
Anantasoft Gazelle CMS 1.0 - Unauthenticated Password Reset via User Parameter
Anantasoft Gazelle CMS < 1.0 - Cross-Site Scripting via User or Lookup Parameter
DokuWiki < 2009-12-25b - Unauthenticated Privilege Escalation via ACL Manager Plugin
Anantasoft Gazelle CMS 1.0 - Path Traversal via Template Parameter
pfBlockerNG < 2.1.4_26 - Remote Code Execution via HTTP Host Header
CVSS 9.8
TerraMaster TOS <= 4.2.06 - Unauthenticated Remote Code Execution via Event Parameter
CVSS 9.8
WordPress Plugin E-Commerce 3.8.4 - SQL Injection
WordPress Plugin bSuite 4.0.7 - Multiple HTML Injection Vulnerabilities
w-agora < 4.2.1 - SQL Injection via Index.php Cat Parameter
WebJaxe - SQL Injection
TS Special Edition 7.0 - Multiple Vulnerabilities
smbind 0.4.7 - SQL Injection
phpFullAnnu 6.0 - SQL Injection via mod Parameter
pfBlockerNG < 2.1.4_26 - Remote Code Execution via HTTP Host Header
CVSS 9.8
Anantasoft Gazelle CMS 1.0 - Unauthenticated Arbitrary File Upload via File Manager
EFront 3.6.9 Community Edition - Multiple Vulnerabilities
DokuWiki < 2009-12-25b - Directory Traversal via ACL Manager ns Parameter
Clansphere 2007.4 - SQL Injection via cat_id Parameter
CMS Made Simple 1.6.2 - Local File Disclosure
ChillyCMS - Blind SQL Injection
TerraMaster TOS 4.2.06 - RCE (Unauthenticated)
TerraMaster Operating System <= 4.2.06 - Unauthenticated Remote Code Execution via Event Parameter in makecvs.php
CVSS 9.8