← Back to moaaztaha.com

Public research

Five CVE records linked to their original public evidence. This page is intentionally a record, not a claim of current exploitability.

2021 · vulnerability record

CVE-2021-32076

SolarWinds Web Help Desk — access restriction bypass

A referrer-spoofing issue allowed access to the Web Help Desk setup wizard from outside the expected network range. SolarWinds fixed the issue in Web Help Desk 12.7.6.

The vendor advisory acknowledges Moaaz Taha by name.

2021 · vulnerability record

CVE-2021-34249

Online Book Store 1.0 — SQL injection

The id parameter in the application URL allowed retrieval of sensitive database information.

The referenced submission credits Moaaz Taha (0xStorm).

2020 · vulnerability record

CVE-2020-25905

Mobile Shop System 1.0 — SQL injection

SQL injection in the email parameter of the user and administrator login routes allowed authentication bypass.

The referenced submission credits Moaaz Taha (0xStorm).

2020 · vulnerability record

CVE-2020-25362

Online Shopping Alphaware 1.0 — SQL injection

The id parameter in the product-details route was vulnerable to error-based blind SQL injection.

The referenced submission credits Moaaz Taha (0xStorm).

2020 · vulnerability record

CVE-2020-24862

Pharmacy Medical Store and Sale Point 1.0 — SQL injection

The catID parameter in the inventory route was vulnerable to time-based blind SQL injection.

The referenced submission credits Moaaz Taha (0xStorm).

How the records connect

SolarWinds names Moaaz Taha in its advisory. The four Exploit-DB submissions name the author as “Moaaz Taha (0xStorm)”; the matching NVD records cite those submissions as public references.

Product and vulnerability descriptions are short summaries of the linked records. The external records remain authoritative.