Ihsan Sencan

985 exploits Active since Sep 2017
EIP-2026-108802 EXPLOITDB text WRITEUP
Joomla! Component My MSG 3.2.1 - SQL Injection
CVE-2018-17375 EXPLOITDB CRITICAL text WORKING POC
Music Collection 3.0.3 - SQL Injection
SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter.
CVSS 9.8
EIP-2026-108799 EXPLOITDB text WORKING POC
Joomla! Component MultiTier 3.1 - SQL Injection
EIP-2026-108797 EXPLOITDB text WORKING POC
Joomla! Component Most Wanted Real Estate 1.1.0 - SQL Injection
EIP-2026-108796 EXPLOITDB text WORKING POC
Joomla! Component Monthly Archive 3.6.4 - 'author_form' SQL Injection
CVE-2018-5971 EXPLOITDB CRITICAL text WORKING POC
MediaLibrary Free 4.0.12 - SQL Injection
SQL Injection exists in the MediaLibrary Free 4.0.12 component for Joomla! via the id parameter or the mid array parameter.
CVSS 9.8
EIP-2026-108783 EXPLOITDB text WORKING POC
Joomla! Component MediaLibrary Basic 3.5 - SQL Injection
EIP-2026-108782 EXPLOITDB text WORKING POC
Joomla! Component MaQma Helpdesk 4.2.7 - 'id' SQL Injection
EIP-2026-108777 EXPLOITDB text WORKING POC
Joomla! Component Magic Deals Web 1.2.0 - SQL Injection
EIP-2026-108767 EXPLOITDB text WRITEUP
Joomla! Component JUX EventOn 1.0.1 - 'id' SQL Injection
CVE-2018-6585 EXPLOITDB CRITICAL text WORKING POC
JTicketing 2.0.16 - SQL Injection via filter_creator or filter_events_cat Parameter
SQL Injection exists in the JTicketing 2.0.16 component for Joomla! via a view=events action with a filter_creator or filter_events_cat parameter.
CVSS 9.8
CVE-2018-6008 EXPLOITDB HIGH text WORKING POC
Jtag Members Directory 5.3.7 - Info Disclosure
Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter.
CVSS 7.5
CVE-2018-6609 EXPLOITDB CRITICAL text WORKING POC
jsp_tickets 1.1 - SQL Injection via Ticketcode or ID Parameter
SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit action, or the id parameter in a statuslist (or prioritylist) edit action.
CVSS 9.8
EIP-2026-108764 EXPLOITDB text WORKING POC
Joomla! Component JSP Store Locator 2.2 - 'id' SQL Injection
CVE-2018-6007 EXPLOITDB HIGH html WORKING POC
JS Support Ticket 1.1.0 - Cross-Site Request Forgery
CSRF exists in the JS Support Ticket 1.1.0 component for Joomla! and allows attackers to inject HTML or edit a ticket.
CVSS 8.8
CVE-2018-5994 EXPLOITDB CRITICAL text WORKING POC
JS Jobs 1.1.9 - SQL Injection via Zipcode or ta Parameter
SQL Injection exists in the JS Jobs 1.1.9 component for Joomla! via the zipcode parameter in a newest-jobs request, or the ta parameter in a view_resume request.
CVSS 9.8
CVE-2018-6006 EXPLOITDB CRITICAL text WORKING POC
JS Autoz 1.0.9 - SQL Injection via vtype, pre, or prs Parameter
SQL Injection exists in the JS Autoz 1.0.9 component for Joomla! via the vtype, pre, or prs parameter.
CVSS 9.8
CVE-2018-5983 EXPLOITDB CRITICAL text WORKING POC
jquickcontact 1.3.2.2.1 - SQL Injection via task=refresh&sid= Request
SQL Injection exists in the JquickContact 1.3.2.2.1 component for Joomla! via a task=refresh&sid= request.
CVSS 9.8
EIP-2026-108746 EXPLOITDB text WORKING POC
Joomla! Component Joomloc-Lite 1.3.2 - 'site_id' SQL Injection
EIP-2026-108745 EXPLOITDB text WORKING POC
Joomla! Component Joomloc-CAT 4.1.3 - 'ville' SQL Injection
EIP-2026-108194 EXPLOITDB text WORKING POC
Joomla! Component Advertisement Board 3.0.4 - 'id' SQL Injection
EIP-2026-108739 EXPLOITDB text WORKING POC
Joomla! Component JoomBlog 1.3.1 - SQL Injection
EIP-2026-108738 EXPLOITDB text WORKING POC
Joomla! Component Joomanager 2.0.0 - 'com_Joomanager' Arbitrary File Download (PoC)
EIP-2026-108736 EXPLOITDB text WORKING POC
Joomla! Component JooDatabase 3.1.0 - SQL Injection
EIP-2026-108735 EXPLOITDB text WORKING POC
Joomla! Component JooCart 2.x - 'product_id' SQL Injection