SunCSR
19 exploits
Active since Feb 2020
LiteSpeed Web Server Enterprise 5.4.11 - Command Injection
CVSS 8.8
Orchard Core RC1 - Stored Cross-Site Scripting via Blog Post MarkdownBodyPart.Source Parameter
CVSS 6.4
BigTree CMS <4.4.10 - Command Injection
CVSS 8.8
BigTree CMS < 4.4.10 - Authenticated Stored Cross-Site Scripting via Page Content
CVSS 5.4
BigTree CMS <4.4.10 - SQL Injection
CVSS 8.8
Symphony CMS 3.0.0 - Stored Cross-Site Scripting via Event Publish Article Body Field
CVSS 5.4
php-fusion 9.03.50 - SQL Injection via Comments Administration Endpoint ctype Parameter
CVSS 7.2
idangero chop_slider - Blind SQL Injection via id GET Parameter
CVSS 9.8
Wordpress Theme Accesspress Social Icons 1.7.9 - SQL injection (Authenticated)
WordPress Plugin Form Maker 5.4.1 - 's' SQL Injection (Authenticated)
idangero chop_slider - Blind SQL Injection via id GET Parameter
CVSS 9.8
UliCMS < 2020.2 - Stored Cross-Site Scripting in PageController
CVSS 6.1
php-fusion 9.03.50 - Cross-Site Scripting via FAQ or Shoutbox Admin Panel go Parameter
CVSS 5.4
LeptonCMS 4.5.0 - Stored Cross-Site Scripting via Event Handler Injection
CVSS 6.1
E-Commerce System 1.0 - Unauthenticated Remote Code Execution
CSZ CMS 1.2.9 - Multiple Cross-Site Scripting
Openlitespeed Web Server 1.7.8 - Command Injection (Authenticated) (1)
Apache Tomcat 7.0.0-7.0.99, 8.5.0-8.5.50, 9.0.0.M1-9.0.0.30 - Remote Code Execution via AJP File Read and JSP Processing
CVSS 9.8
Apache OpenMeetings 4.0.0-5.0.0 - Denial of Service via NetTest Web Service
CVSS 7.5