Ihsan Sencan

985 exploits Active since Sep 2017
EIP-2026-108734 EXPLOITDB text WORKING POC
Joomla! Component JomWALL 4.0 - 'wuid' SQL Injection
EIP-2026-108732 EXPLOITDB text WORKING POC
Joomla! Component JomSocial - SQL Injection
CVE-2018-6368 EXPLOITDB CRITICAL text WORKING POC
JomEstate PRO < 3.7 - SQL Injection via id Parameter in task=detailed Action
SQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed action.
CVSS 9.8
CVE-2018-17382 EXPLOITDB CRITICAL text WORKING POC
Jobs Factory 2.0.4 - SQL Injection via filter_letter Parameter
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
CVSS 9.8
EIP-2026-108728 EXPLOITDB text WORKING POC
Joomla! Component JO Facebook Gallery 4.5 - SQL Injection
CVE-2018-6581 EXPLOITDB CRITICAL text WORKING POC
jms_music 1.1.1 - SQL Injection via Search Parameter
SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username parameter.
CVSS 9.8
CVE-2018-6610 EXPLOITDB HIGH php WORKING POC
jlike 1.0 - Exposure of Sensitive Information via task Parameter
Information Leakage exists in the jLike 1.0 component for Joomla! via a task=getUserByCommentId request.
CVSS 7.5
CVE-2018-6580 EXPLOITDB CRITICAL text WRITEUP
Jimtawl 2.1.6 and 2.2.5 - Unrestricted File Upload via Component Request
Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true&tmpl=component request.
CVSS 9.8
CVE-2018-5970 EXPLOITDB CRITICAL text WORKING POC
JGive 2.0.9 - SQL Injection via filter_org_ind_type or campaign_countries Parameter
SQL Injection exists in the JGive 2.0.9 component for Joomla! via the filter_org_ind_type or campaign_countries parameter.
CVSS 9.8
CVE-2017-17872 EXPLOITDB CRITICAL text WORKING POC
JEXTN Video Gallery 3.0.5 - SQL Injection via id Parameter
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
CVSS 9.8
CVE-2018-6579 EXPLOITDB CRITICAL text WORKING POC
JEXTN Reverse Auction 3.1.0 - SQL Injection via view=products&uid= Parameter
SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request.
CVSS 9.8
CVE-2017-17871 EXPLOITDB CRITICAL text WORKING POC
JEXTN Question And Answer 3.1.0 - SQL Injection via an or ques-srch Parameter
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.
CVSS 9.8
CVE-2018-6577 EXPLOITDB CRITICAL html WORKING POC
JEXTN Membership 3.1.0 - SQL Injection via usr_plan Parameter
SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request.
CVSS 9.8
CVE-2017-17875 EXPLOITDB CRITICAL text WORKING POC
JEXTN FAQ Pro 4.0.0 - SQL Injection via id Parameter
The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.
CVSS 9.8
CVE-2018-6575 EXPLOITDB CRITICAL text WORKING POC
JEXTN Classified 1.0.0 - SQL Injection via view=boutique&sid Parameter
SQL Injection exists in the JEXTN Classified 1.0.0 component for Joomla! via a view=boutique&sid= request.
CVSS 9.8
EIP-2026-108721 EXPLOITDB text WORKING POC
Joomla! Component JEmbedAll 1.4 - SQL Injection
EIP-2026-108718 EXPLOITDB text WORKING POC
Joomla! Component JE Video Rate 1.0 - SQL Injection
EIP-2026-108717 EXPLOITDB text WORKING POC
Joomla! Component JE Tour 2.0 - SQL Injection
EIP-2026-108716 EXPLOITDB text WORKING POC
Joomla! Component JE Ticket System 1.2 - SQL Injection
EIP-2026-108713 EXPLOITDB text WORKING POC
Joomla! Component JE QuoteForm - 'Itemid' SQL Injection
EIP-2026-108712 EXPLOITDB text WORKING POC
Joomla! Component JE Quiz 2.3 - SQL Injection
EIP-2026-108711 EXPLOITDB text WORKING POC
Joomla! Component JE Property Finder 1.6.3 - SQL Injection
EIP-2026-108710 EXPLOITDB text WORKING POC
Joomla! Component JE Portfolio Creator 1.2 - 'd_itemid' SQL Injection
CVE-2018-6578 EXPLOITDB CRITICAL html WORKING POC
je_paypervideo 3.0.0 - SQL Injection via usr_plan Parameter
SQL Injection exists in the JE PayperVideo 3.0.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request.
CVSS 9.8
EIP-2026-108706 EXPLOITDB text WORKING POC
Joomla! Component JE Messanger - SQL Injection