Ihsan Sencan

985 exploits Active since Sep 2017
EIP-2026-108855 EXPLOITDB text WORKING POC
Joomla! Component Simple Membership 3.3.3 - 'userId' SQL Injection
CVE-2018-7178 EXPLOITDB CRITICAL text WORKING POC
Saxum Picker 3.2.10 - SQL Injection via Publicid Parameter
SQL Injection exists in the Saxum Picker 3.2.10 component for Joomla! via the publicid parameter.
CVSS 9.8
CVE-2018-7177 EXPLOITDB CRITICAL text WORKING POC
Saxum Numerology 3.0.4 - SQL Injection via publicid Parameter
SQL Injection exists in the Saxum Numerology 3.0.4 component for Joomla! via the publicid parameter.
CVSS 9.8
CVE-2018-7180 EXPLOITDB CRITICAL text WORKING POC
Saxum Astro 4.0.14 - SQL Injection via publicid Parameter
SQL Injection exists in the Saxum Astro 4.0.14 component for Joomla! via the publicid parameter.
CVSS 9.8
EIP-2026-108849 EXPLOITDB text WORKING POC
Joomla! Component Room Management 1.0 - SQL Injection
CVE-2018-17376 EXPLOITDB CRITICAL text WORKING POC
Joomla! Reverse Auction Factory 4.3.8 - SQL Injection
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter.
CVSS 9.8
EIP-2026-108844 EXPLOITDB text WORKING POC
Joomla! Component Recipe Manager 2.2 - 'id' SQL Injection
CVE-2018-6005 EXPLOITDB CRITICAL text WORKING POC
realpin < 1.5.04 - SQL Injection via Pinboard Parameter
SQL Injection exists in the Realpin through 1.5.04 component for Joomla! via the pinboard parameter.
CVSS 9.8
EIP-2026-108841 EXPLOITDB text WORKING POC
Joomla! Component RealEstateManager 3.9 - SQL Injection
CVE-2018-17379 EXPLOITDB CRITICAL text WORKING POC
Raffle Factory 3.5.2 - SQL Injection
SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
CVSS 9.8
CVE-2018-17377 EXPLOITDB CRITICAL text WORKING POC
Questions 1.4.3 - SQL Injection via Term Userid Users or Groups Parameter
SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter.
CVSS 9.8
CVE-2018-6024 EXPLOITDB CRITICAL text WORKING POC
Joomla! Project Log 1.5.3 - SQL Injection
SQL Injection exists in the Project Log 1.5.3 component for Joomla! via the search parameter.
CVSS 9.8
CVE-2018-7317 EXPLOITDB HIGH text WRITEUP
Proclaim 9.1.1 - Unauthenticated Sensitive Information Exposure via Backup File Download
Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/.
CVSS 7.5
CVE-2018-7316 EXPLOITDB CRITICAL text WRITEUP
Proclaim 9.1.1 - Arbitrary File Upload via Mediafileform Action
Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action.
CVSS 9.8
CVE-2018-7314 EXPLOITDB CRITICAL text WORKING POC
PrayerCenter 3.0.2 - SQL Injection via Session ID Parameter
SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429.
CVSS 9.8
CVE-2018-6397 EXPLOITDB HIGH text WRITEUP
Picture Calendar 3.1.4 - Path Traversal via List.php Folder Parameter
Directory Traversal exists in the Picture Calendar 3.1.4 component for Joomla! via the list.php folder parameter.
CVSS 7.5
EIP-2026-108830 EXPLOITDB text WORKING POC
Joomla! Component Photo Contest 1.0.2 - SQL Injection
CVE-2018-17378 EXPLOITDB CRITICAL text WORKING POC
Penny Auction Factory 2.0.4 - SQL Injection
SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter.
CVSS 9.8
EIP-2026-108825 EXPLOITDB text WORKING POC
Joomla! Component PayPal IPN for DOCman 3.1 - 'id' SQL Injection
EIP-2026-108819 EXPLOITDB text WORKING POC
Joomla! Component OS Services Booking 2.5.1 - SQL Injection
CVE-2018-7319 EXPLOITDB CRITICAL text WRITEUP
OS Property Real Estate 3.12.7 - SQL Injection via Cooling System, Heating System, or Laundry Parameter
SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system1, or laundry parameter.
CVSS 9.8
EIP-2026-108818 EXPLOITDB text WORKING POC
Joomla! Component OS Property 3.0.8 - SQL Injection
EIP-2026-108814 EXPLOITDB text WORKING POC
Joomla! Component OneVote! 1.0 - SQL Injection
CVE-2017-15965 EXPLOITDB CRITICAL text WORKING POC
NS Download Shop 2.2.6 - SQL Injection via Invoice Create ID Parameter
The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action.
CVSS 9.8
CVE-2018-6370 EXPLOITDB CRITICAL text WORKING POC
NeoRecruit 4.1 - SQL Injection via PATH_INFO or .html File Name
SQL Injection exists in the NeoRecruit 4.1 component for Joomla! via the (1) PATH_INFO or (2) name of a .html file under the all-offers/ URI.
CVSS 9.8