KeopssGroup0day_Inc

6 exploits Active since Jan 2026
CVE-2020-37035 EXPLOITDB HIGH text WORKING POC
e-Learning PHP Script 0.1.0 - SQL Injection
e-Learning PHP Script 0.1.0 contains a SQL injection vulnerability in the search functionality that allows attackers to manipulate database queries through unvalidated user input. Attackers can inject malicious SQL code in the 'search' parameter to potentially extract, modify, or access sensitive database information.
CVSS 8.2
CVE-2020-36951 EXPLOITDB HIGH text WRITEUP
Phpscript-sgh 0.1.0 - SQL Injection
Phpscript-sgh 0.1.0 contains a time-based blind SQL injection vulnerability in the admin interface that allows attackers to manipulate database queries through the 'id' parameter. Attackers can exploit this vulnerability by crafting malicious payloads that trigger time delays, enabling them to extract sensitive database information through conditional sleep techniques.
CVSS 8.2
EIP-2026-113205 EXPLOITDB text WORKING POC
Web Based Online Hotel Booking System 0.1.0 - Authentication Bypass
EIP-2026-111815 EXPLOITDB text WORKING POC
Rukovoditel 2.6.1 - Cross-Site Request Forgery (Change password)
EIP-2026-110101 EXPLOITDB text WORKING POC
Online Farm Management System 0.1.0 - Persistent Cross-Site Scripting
EIP-2026-107083 EXPLOITDB text WORKING POC
File Management System 1.1 - Persistent Cross-Site Scripting