tmrswrr
43 exploits
Active since Sep 2014
Apache mod_cgi Bash Environment Variable Code Injection (Shellshock)
CVSS 9.8
Total CMS 1.7.4 - Unauthenticated Arbitrary File Upload via Edit Page Function
CVSS 8.8
Lepton CMS 7.0.0 - Authenticated Arbitrary File Upload via Backend Languages Index
CVSS 7.2
Lepton CMS 7.0.0 - Authenticated Arbitrary File Upload via Backend Languages Index
CVSS 7.2
Lepton CMS 7.0.0 - Remote Code Execution via Upgrade.php Language Parameter
CVSS 7.8
CE Phoenix 1.0.8.20 - Remote Code Execution via define_language.php
CVSS 7.2
CE Phoenix <1.0.8.20 - Code Injection
CVSS 4.8
WBCE CMS 1.6.1 - Arbitrary File Upload via Languages Install Endpoint
CVSS 7.2
PluXml Blog 5.8.9 - Remote Code Execution via Static Pages Content Field
CVSS 8.8
FireBear Improved Import And Export <3.8.6 - SSRF
CVSS 7.2
CSZ CMS 1.3.0 - Unauthenticated Arbitrary File Upload via Zip Archive in Admin Upgrade
CVSS 9.8
CMS Made Simple <2.2.19/2.2.21 - RCE
CVSS 7.2
CMS Made Simple 2.2.19 - Server-Side Template Injection in Design Manager Breadcrumbs
CVSS 5.9
TS Poll < 2.4.0 - Authenticated SQL Injection via Orderby Parameter
CVSS 7.2
Loaded Commerce 6.6 - Unauthenticated Remote Code Execution via Search Parameter
ElkArte Forum 1.1.9 - Authenticated Remote Code Execution via Theme Upload
Akaunting 3.1.8 - Authenticated Server-Side Template Injection via Form Input Fields
Flatboard 3.2 - Authenticated Stored Cross-Site Scripting via Forum Information Field
Microweber 2.0.15 - Authenticated Stored Cross-Site Scripting via User Profile Fields
CVSS 5.4
Alkacon OpenCMS 15.0 - Arbitrary File Upload and Remote Code Execution via PNG File
CVSS 6.1
PyroCMS v3.0.1 - Stored Cross-Site Scripting via Admin Redirects Configuration
CVSS 5.4
CE Phoenix - Stored Cross-Site Scripting in Currencies Administration Panel
Winter CMS 1.2.3 - Authenticated Server-Side Template Injection via CMS Pages Field
CVSS 7.2
Textpattern CMS 4.8.8 - Authenticated Stored Cross-Site Scripting in Article Excerpt Field
CVSS 5.4
Netlify CMS 2.10.192 - Stored Cross-Site Scripting via New Post Body Parameter
CVSS 5.4