ahrixia
14 exploits
Active since Mar 2022
Dirty Pipe Local Privilege Escalation via CVE-2022-0847
OpenKM 7.1.40 - Authenticated Stored Cross-Site Scripting via File Note Upload
QloApps 1.5.2 - Cross-Site Scripting via AuthController Parameters
mooSocial 3.1.8 - Server-Side Request Forgery via Post Function Parameters
PHPJabbers Cinema Booking System 2.0 - SQL Injection via pjActionGetUser Column Parameter
CVSS 9.8
PHPJabbers Cinema Booking System 2.0 - Reflected Cross-Site Scripting
CVSS 6.1
PHPJabbers Cinema Booking System v2.0 - Stored Cross-Site Scripting via File Upload and Seat Configuration Fields
CVSS 9.3
PHPJabbers Cinema Booking System 2.0 - Cross-Site Request Forgery in pjActionUpdate
CVSS 5.4
mooSocial 3.1.8 - Cross-Site Scripting via Search q Parameter
CVSS 6.1
mooSocial 3.1.8 - Reflected Cross-Site Scripting via Crafted URL
CVSS 6.1
mooSocial 3.1.8 - Reflected Cross-Site Scripting via data[redirect_url] Parameter
CVSS 6.1
MooSocial 3.1.8 - Cross-Site Request Forgery via Admin Password Change Function
CVSS 8.8
mooSocial 3.1.8 - Stored Cross-Site Scripting via admin_redirect_url Parameter
CVSS 6.1
mooSocial 3.1.8 - Stored Cross-Site Scripting via Invite Friend Login Mode Parameter
CVSS 6.1