Welcome once again :D
Today i was just browsing 1337day.com and come across a exploit title as Mybb Ajaxfs Plugin Sql Injection which they selling it for 150$.
http://1337day.com/exploit/description/21541
So i just start to pentest the plugin and in just two minutes i found the bug.
So here are the details
Exploit Title : Mybb Ajaxfs Plugin Sql Injection...
Hi all , was alot busy with my work , so now here comes some new stuff PHP object injection in all whmcs versions.
http://packetstormsecurity.com/files/123890/whmcs-phpobject.txt
http://blog.whmcs.com/?t=81138
http://www.securelist.com/en/advisories/55717
# Exploit Title : WHMCS <=5.2.12 PHP Object Injection
...