MhZ91
29 exploits
Active since Sep 2007
Agares Media phpAutoVideo <2.21 - RCE
Falcon Series One CMS 1.4.3 - Cross-Site Scripting via Guestbook Parameters
Falcon Series One CMS 1.4.3 - Remote File Inclusion via dir[classes] or error Parameter
GF-3XPLORER 2.4 - Remote File Inclusion via Lang_sel Parameter
GF-3XPLORER 2.4 - Cross-Site Scripting via newdir Parameter
xml2owl 0.1.1 - Remote Code Execution via showCode.php Path Parameter
Markus Iser ED Engine 0.8999 alpha - Remote Code Execution via Codebase Parameter
Social Engine 2.0 - Path Traversal via Global Lang Parameter
SiteBuilder Elite 1.2 - Remote Code Execution via CarpPath Parameter
PHP Webquest 2.6 - Unauthenticated Database Credential Exposure via Direct Request to admin/backup_phpwebquest.php
Online Fantasy Football League 0.2.6 - Remote Code Execution via DOC_ROOT Parameter
LookStrike Lan Manager 0.9 - Remote Code Execution via sys_conf[path][real] Parameter
MailMachine Pro <2.2.6 - SQL Injection
Mcms Easy Web Make <1.3 - Path Traversal
MeGaCheatZ 1.1 - SQL Injection via ItemID Parameter
IPTBB 0.5.4 - SQL Injection via id Parameter in viewdir Action
Ip Reg 0.3 - SQL Injection via vlan_id Parameter
idmos_cms 1.0 - Unauthenticated Path Traversal via administrator/download.php fileName Parameter
freePHPgallery 0.6 - Path Traversal via Lang Cookie
GF-3XPLORER 2.4 - Exposure of Sensitive Information via phpinfo.php
Easy Hosting Control Panel <0.22.8 - RCE
Falcon Series One 1.4.3 stable - Multiple Input Validation Vulnerabilities
Falcon Series One CMS 1.4.3 - Cross-Site Request Forgery via Password Change Action
DomPHP 0.81 - SQL Injection via Agenda Cat Parameter
Bloo < 1.0 - SQL Injection via post_id Parameter