Mirabbas Ağalarov
61 exploits
Active since Jul 2023
Pluck-CMS 4.7.18 - Arbitrary File Upload via ZIP File in Modules Install
Pluck-CMS 4.7.18 - Arbitrary File Upload via ZIP File in Modules Install
Jumbo Website Manager - Remote Code Execution
ProjectSend r1605 - Remote Code Execution via File Extension Manipulation
CVSS 9.8
WebsiteBaker 2.13.3 - Authenticated Stored Cross-Site Scripting via Page Title
CVSS 5.4
Dotclear 2.25.3 - Authenticated Remote Code Execution via PHAR File Upload
CVSS 8.8
TinyWebGallery 2.5 - Authenticated Stored Cross-Site Scripting via Folder Name Parameter
CVSS 5.4
Serendipity 2.4.0 - Authenticated Remote Code Execution via PHAR File Upload
CVSS 8.8
Serendipity 2.4.0 - Authenticated Stored Cross-Site Scripting via Blog Entry Creation
CVSS 5.4
Revive Adserver 5.4.1 - Stored Cross-Site Scripting via Banner Advanced Settings
CVSS 6.1
ProjectSend r1605 - Info Disclosure
CVSS 7.5
phpMyFAQ 3.1.12 - Authenticated CSV Injection via User Profile Export
CVSS 8.8
PHPFusion 9.10.30 - Stored Cross-Site Scripting via File Manager SVG Upload
CVSS 5.4
UliCMS 2023.1 - Stored Cross-Site Scripting via SVG File Upload
CVSS 6.1
UliCMS 2023.1-sniffing-vicuna - RCE
CVSS 8.8
UliCMS 2023.1 - Privilege Escalation
CVSS 9.8
TinyWebGallery 2.5 - Unauthenticated Remote Code Execution via Malicious PHAR File Upload
CVSS 9.8
SitemagicCMS 4.4.3 - PHP File Upload Command Execution
CVSS 9.8
PodcastGenerator 3.2.9 - Stored Cross-Site Scripting via Podcast Title Field
CVSS 5.4
PodcastGenerator 3.2.9 - Stored Cross-Site Scripting in Freebox Content Field
CVSS 5.4
PodcastGenerator 3.2.9 - Stored Cross-Site Scripting in Episode Title Field
CVSS 6.1
Zenphoto 1.6 - Stored Cross-Site Scripting in User Postal Code Field
CVSS 4.6
Zenphoto 1.6 - Authenticated Stored Cross-Site Scripting via Album Description
CVSS 4.6
UliCMS 2023.1 - Unauthenticated Authentication Bypass via Mass Assignment in UserController
CVSS 9.8
Rukovoditel 3.3.1 - Authenticated CSV Injection via Firstname Field
CVSS 8.8