#PHP,webapps,
-
Courier Management System 1.0 - 'ref_no' SQL Injection
-
Task Management System 1.0 - 'page' Local File Inclusion
-
Online Marriage Registration System (OMRS) 1.0 - Remote Code Execution (2)
-
Grav CMS 1.6.30 Admin Plugin 1.9.18 - 'Page Title' Persistent Cross-Site Scripting
-
Seotoaster 3.2.0 - Stored XSS on Edit page properties
-
PrestaShop ProductComments 4.2.0 - 'id_products' Time Based Blind SQL Injection
-
Dolibarr ERP-CRM 12.0.3 - Remote Code Execution (Authenticated)
-
Content Management System 1.0 - 'First Name' Stored XSS
-
Content Management System 1.0 - 'email' SQL Injection
-
Content Management System 1.0 - 'id' SQL Injection
-
Medical Center Portal Management System 1.0 - 'id' SQL Injection
-
Customer Support System 1.0 - "First Name" & "Last Name" Stored XSS
-
Interview Management System 1.0 - Stored XSS in Add New Question
-
Online Tours & Travels Management System 1.0 - "id" SQL Injection
-
Interview Management System 1.0 - 'id' SQL Injection
-
Victor CMS 1.0 - Multiple SQL Injection (Authenticated)
-
Customer Support System 1.0 - 'id' SQL Injection
-
Point of Sale System 1.0 - Authentication Bypass
-
Employee Record System 1.0 - Multiple Stored XSS
-
Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read (Metasploit)