Stack
155 exploits
Active since Mar 2006
Sports Clubs Web Panel 0.0.1 - Arbitrary File Upload
SmallBiz eShop - 'content_id' SQL Injection
Social Site Generator 2.0 - Unauthenticated Arbitrary File Read via File Parameter
Kalptaru Infotech Stararticles - SQL Injection
FCKeditor - Remote Code Execution via File Upload
Rianxosencabos CMS 0.9 - Unauthenticated Authentication Bypass via Cookie Manipulation
SG Real Estate Portal 2.0 - Auth Bypass
SG Real Estate Portal 2.0 - SQL Injection
Scripts For Sites EZ Top Sites - SQL Injection via topsite.php ts Parameter
Scripts For Sites EZ Career - SQL Injection via Topic Parameter
Scripts for Sites EZ Auction - SQL Injection via viewfaqs.php cat Parameter
RPG.Board <= 0.8 Beta2 - Unauthenticated Authentication Bypass via keep4u Cookie
RoomPHPlanning 1.5 - Authenticated Privilege Escalation via admin/userform.php
Powie pLink 2.07 - SQL Injection via id Parameter
ProManager 0.73 - Remote File Inclusion via Language Parameter Path Traversal
Phlatline Personal Information Manager 1.01 - Path Traversal via Notes.php ID Parameter
PHPWebGallery 1.3.4 - Blind SQL Injection (1)
phpecho_cms < 2.0-rc3 - SQL Injection via Forum Module id Parameter
PHPhotoalbum 0.5 - SQL Injection via Album or PID Parameter
PHP Booking Calendar <1.0c - SQL Injection
JnSHosts PHP Hosting Directory 2.0 - Auth Bypass
PHP infoBoard V.7 Plus - Unauthenticated Authentication Bypass via infouser Cookie
phpicalendar <= 2.24 - Unauthenticated Authentication Bypass via Cookie Manipulation
PHP Booking Calendar 10 d - 'FCKeditor' Arbitrary File Upload
Ocean12 FAQ Manager Pro - Unauthenticated Sensitive Data Exposure via Direct Database Request