dleffler
36 exploits
Active since Nov 2016
Exponent CMS < 2.3.9 - SQL Injection via id, title, or content_id Parameter
CVSS 9.8
Exponent CMS 2.3.9 - SQL Injection in expPaginator.php Order Parameter
CVSS 7.5
Exponent CMS < 2.3.9 - Unauthenticated Arbitrary File Upload via Pixidou Image Editor
CVSS 7.5
Exponent CMS < 2.3.9 - SQL Injection via Pixidou Image Editor
CVSS 9.8
Exponent CMS 2.3.9 - Remote Code Execution via sc Array Parameter
CVSS 9.8
Exponent CMS < 2.3.9 - SQL Injection via Version Parameter
CVSS 9.8
Exponent CMS < 2.3.9 - SQL Injection via Blog Author Parameter
CVSS 9.8
Exponent CMS < 2.3.9 - SQL Injection via Section Parameter
CVSS 9.8
Exponent CMS < 2.3.9 - SQL Injection via Username Parameter
CVSS 9.8
Exponent CMS <2.3.9 - SQL Injection
CVSS 9.8
Exponent CMS <2.3.9 - SQL Injection
CVSS 9.8
Exponent CMS <2.3.9 - Code Injection
CVSS 9.8
Exponent CMS <2.3.9 - Code Injection
CVSS 9.8
Exponent CMS <2.3.9 - SQL Injection
CVSS 9.8
Exponent CMS <2.6.0 - Info Disclosure
CVSS 9.8
Exponent CMS <2.6.0 - Info Disclosure
CVSS 9.8
Exponent CMS <2.6.0 - Info Disclosure
CVSS 9.8
Exponent CMS <2.6.0 - Info Disclosure
CVSS 9.8
Exponent CMS <2.6.0 - Info Disclosure
CVSS 9.8
Exponent CMS <2.3.9 - SQL Injection
CVSS 9.8
Exponent CMS 2.3.9 - SQL Injection in expPaginator.php Order Parameter
CVSS 7.5
Exponent CMS 2.3.9 - SQL Injection in Help Controller Version Parameter
CVSS 7.5
Exponent CMS 2.4 - Improper Access Control via Case Insensitive Method Name Bypass
CVSS 7.5
Exponent CMS 2.4.0 - Info Disclosure
CVSS 7.5
Exponent CMS 2.4.0 - SQL Injection and Information Disclosure via Table Name Manipulation
CVSS 7.5