Pham Kien Cuong

3 exploits Active since Jan 2015
CVE-2015-2275 EXPLOITDB text WORKING POC
Wotlab Community Gallery - XSS
Cross-site scripting (XSS) vulnerability in WoltLab Community Gallery 2.0 before 2014-12-26 allows remote attackers to inject arbitrary web script or HTML via the parameters[data][7][title] parameter in a saveImageData action to index.php/AJAXProxy.
CVE-2015-1518 EXPLOITDB text WORKING POC
Redaxscript <2.3.0 - SQL Injection
SQL injection vulnerability in the search_post function in includes/search.php in Redaxscript before 2.3.0 allows remote attackers to execute arbitrary SQL commands via the search_terms parameter.
CVE-2014-9464 EXPLOITDB text WORKING POC
Microweber CMS <20141209 - SQL Injection
SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands via the category parameter when displaying a category, related to the $parent_id variable.