Nine:Situations:Group::bookoo
17 exploits
Active since Jul 2008
glFusion < 1.1.3 - Cross-Site Scripting
bitweaver <= 2.6 - Authenticated PHP Code Injection via Display Name
Smarty 2.6.22 - Remote Code Execution via Math Function Equation Attribute
glFusion <= 1.1.2 - SQL Injection via glf_session Cookie Parameter
RunCMS 2M1 - Authenticated SQL Injection via Forum Post Parameters
RunCMS 2ma - 'post.php' SQL Injection
RunCMS 2M1 - Authenticated SQL Injection via Forum Post Parameters
Pivot 1.40.5 - Path Traversal via Search Parameter
Pluck CMS 4.5.3 - 'update.php' Remote File Corruption
PHPizabi 0.848b C1 HFP1 - Privilege Escalation
PHPizabi 0.8 - 'notepad_body' SQL Injection
glFusion < 1.1.3 - Unauthenticated Privilege Escalation via Password Hash Cookie
Geeklog 1.5.2 - 'usersettings.php' SQL Injection
Geeklog 1.5.2 - 'SEC_authenticate()' SQL Injection
Geeklog 1.5.2 - 'savepreferences()/*blocks[]' SQL Injection
glFusion <= 1.1.2 - SQL Injection via Order and Direction Parameters
bitweaver < 2.6 - Path Traversal and Arbitrary File Write via Version Parameter