Mahendra
9 exploits
Active since Oct 2013
Softaculous Webuzo < 2.1.4 - Remote Code Execution via SOFTCookies sid Cookie
Webuzo < 2.1.4 - Cross-Site Scripting via File Manager Login User Parameter
vtiger CRM < 6.0.0 - Authenticated Path Traversal via KCFinder File Parameter
Fiyo CMS 2.0.1.8 - SQL Injection via Multiple Parameters
Fiyo CMS 2.0.1.8 - Cross-Site Scripting via Multiple URI Parameters
Fiyo CMS < 2.0.1.8 - Exposure of Sensitive Information via Database Backup File
CVSS 7.5
Xibo 1.2.x < 1.2.3 and 1.4.x < 1.4.2 - Path Traversal via Index.php p Parameter
Softaculous Webuzo < 2.1.4 - Username Enumeration via Login Error Messages
fiyo_cms < 2.0.1.8 - Improper Access Control via Direct Request to fiyo/dapur
CVSS 9.8