Ihsan Sencan

985 exploits Active since Sep 2017
EIP-2026-108661 EXPLOITDB text WORKING POC
Joomla! Component Gnosis 1.1.2 - 'id' SQL Injection
CVE-2018-5981 EXPLOITDB CRITICAL text WORKING POC
Gallery WD 1.3.6 - SQL Injection via tag_id or gallery_id Parameter
SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter.
CVSS 9.8
CVE-2018-5991 EXPLOITDB CRITICAL text WORKING POC
Joomla! Form Maker 3.6.12 - SQL Injection
SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats request, a different vulnerability than CVE-2015-2798.
CVSS 9.8
CVE-2018-6004 EXPLOITDB CRITICAL text WORKING POC
Joomla! File Download Tracker 3.0 - SQL Injection
SQL Injection exists in the File Download Tracker 3.0 component for Joomla! via the dynfield[phone] or sess parameter.
CVSS 9.8
CVE-2018-6373 EXPLOITDB CRITICAL text WORKING POC
fastball 2.5 - SQL Injection via Season Parameter
SQL Injection exists in the Fastball 2.5 component for Joomla! via the season parameter in a view=player action.
CVSS 9.8
EIP-2026-108643 EXPLOITDB text WRITEUP
Joomla! Component Eventix Events Calendar 1.0 - SQL Injection
EIP-2026-108639 EXPLOITDB text WORKING POC
Joomla! Component EShop 2.5.1 - 'id' SQL Injection
CVE-2018-7315 EXPLOITDB CRITICAL text WORKING POC
Ek Rishta 2.9 - SQL Injection via Gender, Age, Religion, Mother Tongue, Caste, or Country Parameter
SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, caste, or country parameter.
CVSS 9.8
CVE-2018-6584 EXPLOITDB CRITICAL text WORKING POC
DT Register 3.2.7 - SQL Injection via Task Parameter
SQL Injection exists in the DT Register 3.2.7 component for Joomla! via a task=edit&id= request.
CVSS 9.8
EIP-2026-108623 EXPLOITDB text WRITEUP
Joomla! Component Directorix Directory Manager 1.1.1 - SQL Injection
CVE-2018-7313 EXPLOITDB CRITICAL text WORKING POC
CW Tags 2.0.6 - SQL Injection via Searchtext Array Parameter
SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter.
CVSS 9.8
CVE-2018-6398 EXPLOITDB CRITICAL text WORKING POC
CP Event Calendar 3.0.1 - SQL Injection via id Parameter
SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action.
CVSS 9.8
EIP-2026-108617 EXPLOITDB text WORKING POC
Joomla! Component Coupon 3.5 - SQL Injection
EIP-2026-108615 EXPLOITDB text WORKING POC
Joomla! Component ContentMap 1.3.8 - 'contentid' SQL Injection
EIP-2026-108614 EXPLOITDB text WORKING POC
Joomla! Component Content ConstructionKit 1.1 - SQL Injection
EIP-2026-108246 EXPLOITDB text WORKING POC
Joomla! Component Community Surveys 4.3 - SQL Injection
EIP-2026-108245 EXPLOITDB text WORKING POC
Joomla! Component Community Quiz 4.3.5 - SQL Injection
EIP-2026-108244 EXPLOITDB text WORKING POC
Joomla! Component Community Polls 4.5.0 - SQL Injection
CVE-2018-17383 EXPLOITDB CRITICAL text WORKING POC
Collection Factory 4.1.9 - SQL Injection via filter_order or filter_order_Dir Parameter
SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter.
CVSS 9.8
CVE-2018-7318 EXPLOITDB CRITICAL text WORKING POC
belitsoft checklist SQL Injection via title_search, tag_search, name_search, description_search, or filter_order
SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search, name_search, description_search, or filter_order parameter.
CVSS 9.8
EIP-2026-108236 EXPLOITDB text WORKING POC
Joomla! Component CheckList 1.1.0 - SQL Injection
CVE-2018-5989 EXPLOITDB CRITICAL text WORKING POC
ccNewsletter 2.x - Joomla! - SQL Injection
SQL Injection exists in the ccNewsletter 2.x component for Joomla! via the id parameter in a task=removeSubscriber action, a related issue to CVE-2011-5099.
CVSS 9.8
EIP-2026-108224 EXPLOITDB text WORKING POC
Joomla! Component BookLibrary 3.6.1 - SQL Injection
EIP-2026-108220 EXPLOITDB text WORKING POC
Joomla! Component Bazaar Platform 3.0 - SQL Injection
EIP-2026-108218 EXPLOITDB text WORKING POC
Joomla! Component AYS Quiz 1.0 - 'id' SQL Injection