Qabandi
30 exploits
Active since Oct 2008
Tourism Scripts Adult Portal Escort Listing - SQL Injection via profile.php user_id Parameter
4images <= 1.7.7 - Authenticated Cross-Site Scripting via User Homepage Parameter
EgyPlus 7ammel < 1.0.1 - SQL Injection via Username or Password Parameter
YourTube 2.0 - Arbitrary Database Disclosure
ZaoCMS - 'user_id' SQL Injection
ZaoCMS (PhpCommander) - Arbitrary File Upload
Traidnt UP 2.0 - Blind SQL Injection
Traidnt Up 2.0 - SQL Injection via trupuser and truppassword Cookies
Scripteen Free Image Hosting Script 2.3 - Unauthenticated Authentication Bypass via cookgid Cookie
Pixaria Gallery 2.0.0-2.3.5 - Path Traversal via Base64-Encoded File Parameter
phpfastnews 1.0.0 - Unauthenticated Authentication Bypass via Cookie Manipulation
PC4Arb Pc4 Uploader <= 9.0 - SQL Injection via id Parameter Filter Bypass
Pc4 Uploader <10.0 - Path Traversal
Mobilelib GOLD 3.0 - Path Traversal via GLOBALS[page] Parameter
Mole Group Adult Portal Script - SQL Injection
Mlffat 2.2 - SQL Injection via Member Cookie in Edit Profile Action
Mlffat 2.1 - Cookie Authentication Bypass
Million Dollar Text Links <1.0 - SQL Injection
VivaPrograms Infinity < 2.0.5 - Unauthenticated Administrative Account Creation via Profile Action
Free PHP Petition Signing Script - Authentication Bypass
EgyPlus 7ammel <1.0.1 - Auth Bypass
CVSS 9.8
Clipbucket 1.7.1 - Multiple SQL Injections
Clip Bucket 1.7.1 - Insecure Cookie Handling
Allomani Mobile 2.5 - SQL Injection via Login Username Parameter
Arab Portal < 2.2 - Remote File Inclusion via Module Parameter Path Traversal