tmrswrr
43 exploits
Active since Sep 2014
diafan.cms v6.0 - Reflected Cross-Site Scripting via cat_id Parameter
CVSS 6.1
Xoops CMS 2.5.10 - Stored Cross-Site Scripting via Image Manager Category Name Field
CVSS 9.0
MotoCMS 3.4.3 - SQL Injection via Search Keyword Parameter
CVSS 9.8
Total CMS 1.7.4 - Unauthenticated Arbitrary File Upload via Edit Page Function
CVSS 8.8
Barebones CMS 2.0.2 - Authenticated Stored Cross-Site Scripting
CVSS 5.4
MotoCMS 3.4.3 - Server-Side Template Injection via Keyword Parameter
CVSS 9.8
CE Phoenix 1.0.8.20 - Remote Code Execution via define_language.php
CVSS 7.2
Lepton CMS 7.0.0 - Remote Code Execution via Upgrade.php Language Parameter
CVSS 7.8
Lepton CMS 7.0.0 - Authenticated Arbitrary File Upload via Backend Languages Index
CVSS 7.2
liveSite 2019.1 - Remote Code Execution via edit_designer_region.php or add_email_campaign.php
CVSS 9.8
WBCE CMS Version 1.6.1 - Remote Command Execution (Authenticated)
PopojiCMS Version 2.0.1 - Remote Command Execution
Moodle 4.3 - Insecure Direct Object Reference
Monstra 3.0.4 - Stored Cross-Site Scripting (XSS)
HTMLy Version v2.9.6 - Stored XSS
elFinder Web file manager Version - 2.1.53 Remote Command Execution
CSZ CMS Version 1.3.0 - Authenticated Remote Command Execution
Magento ver. 2.4.6 - XSLT Server Side Injection