Ihsan Sencan

985 exploits Active since Sep 2017
CVE-2018-17399 EXPLOITDB CRITICAL text WORKING POC
jimtawl 2.2.7 - SQL Injection via id Parameter
SQL Injection exists in the Jimtawl 2.2.7 component for Joomla! via the id parameter.
CVSS 9.8
CVE-2018-17398 EXPLOITDB CRITICAL perl WORKING POC
arenam AMGallery 1.2.3 - SQL Injection via filter_category_id Parameter
SQL Injection exists in the AMGallery 1.2.3 component for Joomla! via the filter_category_id parameter.
CVSS 9.8
CVE-2018-17393 EXPLOITDB CRITICAL text WORKING POC
HealthNode Hospital Management System 1.0 - SQL Injection
SQL Injection exists in HealthNode Hospital Management System 1.0 via the id parameter to dashboard/Patient/info.php or dashboard/Patient/patientdetails.php.
CVSS 9.8
CVE-2018-17389 EXPLOITDB HIGH text WORKING POC
Live Call Support Application 1.5 - Cross-Site Request Forgery in server.php
CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account.
CVSS 8.8
CVE-2018-17388 EXPLOITDB CRITICAL text WORKING POC
Twilio WEB To Fax Machine System 1.0 - SQL Injection
SQL Injection exists in Twilio WEB To Fax Machine System 1.0 via the email or password parameter to login_check.php, or the id parameter to add_email.php or edit_content.php.
CVSS 9.8
CVE-2018-17387 EXPLOITDB HIGH html WORKING POC
Nimble Messaging Bulk SMS Marketing App 1.0 - CSRF
CSRF exists in Nimble Messaging Bulk SMS Marketing Application 1.0 for adding an admin account.
CVSS 8.8
CVE-2018-17381 EXPLOITDB CRITICAL text WORKING POC
Dutch Auction Factory 2.0.2 - SQL Injection
SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
CVSS 9.8
CVE-2018-17374 EXPLOITDB CRITICAL text WORKING POC
Auction Factory 4.5.5 - SQL Injection
SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter.
CVSS 9.8
CVE-2018-17386 EXPLOITDB CRITICAL text WORKING POC
Micro Deal Factory 2.4.0 - SQL Injection
SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.
CVSS 9.8
CVE-2018-18944 EXPLOITDB HIGH python WORKING POC
Artha 1.0.3.0 - Buffer Overflow
Artha ~ The Open Thesaurus 1.0.3.0 has a Buffer Overflow.
CVSS 7.5
CVE-2018-18802 EXPLOITDB HIGH text WORKING POC
Welcome to our Resort 1.0 - Cross-Site Request Forgery via User Edit Action
The Tubigan "Welcome to our Resort" 1.0 software allows CSRF via admin/mod_users/controller.php?action=edit.
CVSS 8.8
CVE-2018-18758 EXPLOITDB CRITICAL text WORKING POC
Open Faculty Evaluation System 7 - SQL Injection via submit_feedback.php
Open Faculty Evaluation System 7 for PHP 7 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18757.
CVSS 9.8
CVE-2018-18757 EXPLOITDB CRITICAL text WORKING POC
Open Faculty Evaluation System 5.6 - SQL Injection via submit_feedback.php
Open Faculty Evaluation System 5.6 for PHP 5.6 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18758.
CVSS 9.8
CVE-2018-17843 EXPLOITDB CRITICAL text WORKING POC
ADD Clicking MLM Software <1.0 - SQL Injection
SQL injection exists in ADD Clicking MLM Software 1.0, Binary MLM Software 1.0, Level MLM Software 1.0, Singleleg MLM Software 1.0, Autopool MLM Software 1.0, Investment MLM Software 1.0, Bidding MLM Software 1.0, Moneyorder MLM Software 1.0, Repurchase MLM Software 1.0, and Gift MLM Software 1.0 via the member/readmsg.php msg_id parameter, the member/tree.php pid parameter, or the member/downline.php m_id parameter.
CVSS 9.8
CVE-2018-17842 EXPLOITDB CRITICAL text WORKING POC
Scriptzee Hotel Booking Engine 1.0 - SQL Injection
SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.
CVSS 9.8
CVE-2018-17841 EXPLOITDB CRITICAL text SUSPICIOUS
Scriptzee Flippa Marketplace Clone 1.0 - SQL Injection
SQL injection exists in Scriptzee Flippa Marketplace Clone 1.0 via the site-search sortBy or sortDir parameter.
CVSS 9.8
CVE-2018-17840 EXPLOITDB CRITICAL text WORKING POC
Scriptzee Education Website 1.0 - SQL Injection
SQL injection exists in Scriptzee Education Website 1.0 via the college_list.html subject, city, or country parameter.
CVSS 9.8
CVE-2017-20081 EXPLOITDB MEDIUM text WORKING POC
Hindu Matrimonial Script - Privilege Escalation
A vulnerability, which was classified as critical, was found in Hindu Matrimonial Script. This affects an unknown part of the file /admin/reports.php. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS 6.3
CVE-2017-20080 EXPLOITDB MEDIUM text WORKING POC
Hindu Matrimonial Script - Privilege Escalation
A vulnerability, which was classified as critical, has been found in Hindu Matrimonial Script. Affected by this issue is some unknown functionality of the file /admin/googleads.php. The manipulation leads to improper privilege management. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS 6.3
CVE-2017-20079 EXPLOITDB MEDIUM text WORKING POC
Hindu Matrimonial Script - Privilege Escalation
A vulnerability classified as critical was found in Hindu Matrimonial Script. Affected by this vulnerability is an unknown functionality of the file /admin/photo.php. The manipulation leads to improper privilege management. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS 6.3
CVE-2017-20078 EXPLOITDB MEDIUM text WORKING POC
Hindu Matrimonial Script - Privilege Escalation
A vulnerability classified as critical has been found in Hindu Matrimonial Script. Affected is an unknown function of the file /admin/featured.php. The manipulation leads to improper privilege management. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS 6.3
CVE-2017-20077 EXPLOITDB MEDIUM text WORKING POC
Hindu Matrimonial Script - Privilege Escalation
A vulnerability was found in Hindu Matrimonial Script. It has been rated as critical. This issue affects some unknown processing of the file /admin/success_story.php. The manipulation leads to improper privilege management. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS 6.3
CVE-2017-20076 EXPLOITDB MEDIUM text WORKING POC
Hindu Matrimonial Script - Privilege Escalation
A vulnerability was found in Hindu Matrimonial Script. It has been declared as critical. This vulnerability affects unknown code of the file /admin/searchview.php. The manipulation leads to improper privilege management. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS 6.3
CVE-2017-20075 EXPLOITDB MEDIUM text WORKING POC
Hindu Matrimonial Script - Privilege Escalation
A vulnerability was found in Hindu Matrimonial Script. It has been classified as critical. This affects an unknown part of the file /admin/payment.php. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS 6.3
CVE-2017-20074 EXPLOITDB MEDIUM text WORKING POC
Hindu Matrimonial Script - Privilege Escalation
A vulnerability was found in Hindu Matrimonial Script and classified as critical. Affected by this issue is some unknown functionality of the file /admin/newsletter1.php. The manipulation leads to improper privilege management. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS 6.3