Alexandr Polyakov
35 exploits
Active since Dec 2007
XOOPS 2.0.18 - Path Traversal via Lang Parameter
BLOG:CMS 4.2.1b - Cross-Site Scripting via PATH_INFO to photo/admin.php or photo/index.php
RunCMS < 1.6 - Unauthenticated Password Change
RunCMS < 1.6 - Session Hijacking via Predictable Session ID
RunCMS < 1.6 - Cross-Site Scripting via News Subject Parameter
RunCMS - SQL Injection via lid Parameter
Oracle Fusion Middleware <10.1.3.5 - RCE
XOOPS 2.0.18 - Open Redirect via xoops_redirect Parameter
DivideConcept VHD Web Pack 2.0 - Remote File Inclusion via Page Parameter Path Traversal
Tuned Studios Classic Theme and others - Path Traversal via Page Parameter
RunCMS < 1.6 - Authenticated PHP Code Injection via Admin Parameters
PowerScripts PowerNews 2.5.6 - Path Traversal via Subpage Parameter
phpcms 1.2.2 - Path Traversal via File Parameter in parser.php
Nucleus CMS 3.31 - Cross-Site Scripting via PATH_INFO in action.php
MODx CMS 0.9.6.1-0.9.6.1p1 - XSS
Jinzora Media Jukebox 2.7.5 - Cross-Site Scripting via Multiple Parameters
Jinzora Media Jukebox 2.7.5 - Cross-Site Scripting via Multiple Parameters
Jinzora Media Jukebox 2.7.5 - Cross-Site Scripting via Multiple Parameters
Jinzora Media Jukebox 2.7.5 - Cross-Site Scripting via Multiple Parameters
Dokeos e-learning_system 1.8.4 - Cross-Site Scripting via Multiple Parameters
Dokeos 1.8.4 - SQL Injection via Multiple Parameters
Dokeos 1.8.4 - SQL Injection via Multiple Parameters
Dokeos 1.8.4 - SQL Injection via Multiple Parameters
Dokeos 1.8.4 - SQL Injection via Multiple Parameters
Dokeos e-learning_system 1.8.4 - Cross-Site Scripting via Multiple Parameters