h4ck3r - Faisal Albuloushi

2 exploits Active since Dec 2025
CVE-2023-53935 EXPLOITDB MEDIUM text WORKING POC
WBiz Desk 1.2 - SQL Injection via Ticket PHP tk Parameter
WBiz Desk 1.2 contains a SQL injection vulnerability that allows non-admin users to manipulate database queries through the 'tk' parameter in ticket.php. Attackers can inject crafted SQL statements using UNION-based techniques to extract sensitive database information by sending malformed requests to the ticket endpoint.
CVSS 5.4
CVE-2023-53917 EXPLOITDB MEDIUM text WORKING POC
Affiliate Me <5.0.1 - SQL Injection
Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint that allows authenticated administrators to manipulate database queries. Attackers can exploit the 'id' parameter with crafted union-based queries to extract sensitive user information including usernames and password hashes.
CVSS 6.5