Ihsan Sencan

985 exploits Active since Sep 2017
CVE-2018-6605 EXPLOITDB CRITICAL text WORKING POC
Zh BaiduMap 3.0.0.1 - SQL Injection via id Parameter
SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request.
CVSS 9.8
EIP-2026-108899 EXPLOITDB text WORKING POC
Joomla! Component WMT Content Timeline 1.0 - 'id' SQL Injection
CVE-2018-6395 EXPLOITDB CRITICAL text WORKING POC
Visual Calendar 3.1.3 - SQL Injection via id Parameter
SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action.
CVSS 9.8
EIP-2026-108892 EXPLOITDB text WRITEUP
Joomla! Component Vik Rent Items 1.3 - SQL Injection
EIP-2026-108891 EXPLOITDB text WRITEUP
Joomla! Component Vik Rent Car 1.11 - SQL Injection
EIP-2026-108889 EXPLOITDB text WORKING POC
Joomla! Component Vik Appointments 1.5 - SQL Injection
EIP-2026-108888 EXPLOITDB text WORKING POC
Joomla! Component VehicleManager 3.9 - SQL Injection
EIP-2026-108884 EXPLOITDB text WORKING POC
Joomla! Component UserExtranet 1.3.1 - SQL Injection
CVE-2018-17394 EXPLOITDB CRITICAL text WRITEUP
Joomla! Timetable Schedule <3.6.8 - SQL Injection
SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter.
CVSS 9.8
CVE-2018-6583 EXPLOITDB CRITICAL text WORKING POC
Timetable Responsive Schedule 1.5 - SQL Injection via view=event&alias= Request
SQL Injection exists in the Timetable Responsive Schedule 1.5 component for Joomla! via a view=event&alias= request.
CVSS 9.8
EIP-2026-108880 EXPLOITDB text WRITEUP
Joomla! Component Team Display 1.2.1 - 'filter_category' SQL Injection
CVE-2018-17384 EXPLOITDB CRITICAL text WORKING POC
Swap Factory 2.2.1 - SQL Injection via filter_order_Dir or filter_order Parameter
SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.
CVSS 9.8
EIP-2026-108877 EXPLOITDB text WORKING POC
Joomla! Component StreetGuessr Game 1.0 - SQL Injection
EIP-2026-108876 EXPLOITDB text WRITEUP
Joomla! Component Store for K2 3.8.2 - SQL Injection
CVE-2018-5992 EXPLOITDB CRITICAL text WORKING POC
Staff Master < 1.0 - SQL Injection via Name Parameter
SQL Injection exists in the Staff Master through 1.0 RC 1 component for Joomla! via the name parameter in a view=staff request.
CVSS 9.8
CVE-2018-7179 EXPLOITDB CRITICAL text WORKING POC
SquadManagement 1.0.3 - SQL Injection via id Parameter
SQL Injection exists in the SquadManagement 1.0.3 component for Joomla! via the id parameter.
CVSS 9.8
EIP-2026-108873 EXPLOITDB text WRITEUP
Joomla! Component Spinner 360 1.3.0 - SQL Injection
EIP-2026-108871 EXPLOITDB text WORKING POC
Joomla! Component Spider FAQ Lite 1.3.1 - SQL Injection
EIP-2026-108869 EXPLOITDB text WRITEUP
Joomla! Component Spider Facebook 1.6.1 - SQL Injection
EIP-2026-108867 EXPLOITDB text WORKING POC
Joomla! Component Spider Catalog Lite 1.8.10 - SQL Injection
EIP-2026-108865 EXPLOITDB text WORKING POC
Joomla! Component Spider Calendar Lite 3.2.16 - SQL Injection
CVE-2018-5980 EXPLOITDB CRITICAL text WORKING POC
Solidres 2.5.1 - SQL Injection via Hub Search Direction Parameter
SQL Injection exists in the Solidres 2.5.1 component for Joomla! via the direction parameter in a hub.search action.
CVSS 9.8
CVE-2018-17385 EXPLOITDB CRITICAL text WORKING POC
Social Factory 3.8.3 - SQL Injection
SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter.
CVSS 9.8
EIP-2026-108860 EXPLOITDB text WRITEUP
Joomla! Component Soccer Bet 4.1.5 - 'userid' SQL Injection
CVE-2018-5974 EXPLOITDB CRITICAL text WORKING POC
SimpleCalendar 3.1.9 - SQL Injection
SQL Injection exists in the SimpleCalendar 3.1.9 component for Joomla! via the catid array parameter.
CVSS 9.8