Mirabbas Ağalarov
61 exploits
Active since Jul 2023
WBCE CMS 1.6.1 - Authenticated Stored Cross-Site Scripting via Page Content
CVSS 5.4
WBCE CMS 1.6.1 - Authenticated Stored Cross-Site Scripting via SVG File Upload
CVSS 5.4
projectSend r1605 - Authenticated Stored Cross-Site Scripting via Custom Assets Page
CVSS 4.8
ProjectSend r1605 - Authenticated CSV Injection via User Profile Name Field
CVSS 8.0
WebsiteBaker 2.13.3 - Authenticated Stored Cross-Site Scripting via SVG File Upload
CVSS 5.4
WebsiteBaker 2.13.3 - Path Traversal
CVSS 6.5
WBCE CMS 1.6.1 - Stored Cross-Site Scripting via CSS Keylogging
CVSS 5.4
PodcastGenerator 3.2.9 - Server-Side Request Forgery via Episode Upload Shortdesc Parameter
CVSS 9.8
Rukovoditel 3.4.1 - Authenticated Stored Cross-Site Scripting via Application Copyright Text
CVSS 5.4
Rukovoditel 3.4.1 - Authenticated Stored Cross-Site Scripting via Project Task Comments
CVSS 5.4
Blackcat CMS 1.4 - Authenticated Remote Code Execution via jQuery Plugin Manager
CVSS 7.2
Blackcat CMS 1.4 - Authenticated Stored Cross-Site Scripting via Page Modification
CVSS 5.4
Perch CMS 3.2 - Authenticated Stored Cross-Site Scripting via SVG File Upload
CVSS 5.4
Perch CMS 3.2 - Authenticated Remote Code Execution via Arbitrary PHP File Upload
CVSS 7.2
Zomplog 3.9 - Remote Code Execution
CVSS 8.8
Zomplog 3.9 - Authenticated Stored Cross-Site Scripting via Page Creation
CVSS 5.4
Webutler 3.2 - Authenticated Remote Code Execution via PHAR File Upload
CVSS 7.2
Webedition CMS 2.9.8.8 - Authenticated Stored Cross-Site Scripting via SVG Upload
CVSS 5.4
Webedition CMS <2.9.8.8 - Authenticated RCE
CVSS 7.2
Coppermine Gallery 1.6.25 - Authenticated RCE
CVSS 8.8
CMS Made Simple 2.2.17 - Authenticated Remote Code Execution via File Upload
CVSS 8.8
Webedition CMS v2.9.8.8 - Blind SSRF
Rukovoditel 3.3.1 - Remote Code Execution (RCE)
Pluck v4.7.18 - Remote Code Execution (RCE)
ProjeQtOr Project Management System v10.4.1 - Multiple XSS