← Back to moaaztaha.comPublic research
Five CVE records linked to their original public evidence. This page is intentionally a record, not a claim of current exploitability.
2021 · vulnerability record
CVE-2021-32076
SolarWinds Web Help Desk — access restriction bypass
A referrer-spoofing issue allowed access to the Web Help Desk setup wizard from outside the expected network range. SolarWinds fixed the issue in Web Help Desk 12.7.6.
The vendor advisory acknowledges Moaaz Taha by name.
NVD record · SolarWinds advisory
2021 · vulnerability record
CVE-2021-34249
Online Book Store 1.0 — SQL injection
The id parameter in the application URL allowed retrieval of sensitive database information.
The referenced submission credits Moaaz Taha (0xStorm).
NVD record · Exploit-DB 48775
2020 · vulnerability record
CVE-2020-25905
Mobile Shop System 1.0 — SQL injection
SQL injection in the email parameter of the user and administrator login routes allowed authentication bypass.
The referenced submission credits Moaaz Taha (0xStorm).
NVD record · Exploit-DB 48916
2020 · vulnerability record
CVE-2020-25362
Online Shopping Alphaware 1.0 — SQL injection
The id parameter in the product-details route was vulnerable to error-based blind SQL injection.
The referenced submission credits Moaaz Taha (0xStorm).
NVD record · Exploit-DB 48771
2020 · vulnerability record
CVE-2020-24862
Pharmacy Medical Store and Sale Point 1.0 — SQL injection
The catID parameter in the inventory route was vulnerable to time-based blind SQL injection.
The referenced submission credits Moaaz Taha (0xStorm).
NVD record · Exploit-DB 48752
How the records connect
SolarWinds names Moaaz Taha in its advisory. The four Exploit-DB submissions name the author as “Moaaz Taha (0xStorm)”; the matching NVD records cite those submissions as public references.
Product and vulnerability descriptions are short summaries of the linked records. The external records remain authoritative.