Am!r
29 exploits
Active since Sep 2008
KMPlayer 3.0.0.1440 - '.avi' File Local Denial of Service
WordPress Plugin TagGator - 'tagid' SQL Injection
WordPress Plugin WPsc MijnPress - 'rwflush' Cross-Site Scripting
WordPress Plugin The Welcomizer 1.3.9.4 - 'twiz-index.php' Cross-Site Scripting
Adminimize < 1.7.22 - Cross-Site Scripting via Page Parameter
Flexible Custom Post Type < 0.1.7 - Cross-Site Scripting via edit-post.php id Parameter
WordPress Plugin flash-album-gallery - 'flagshow.php' Cross-Site Scripting
WordPress Plugin flash-album-gallery - 'facebook.php' Cross-Site Scripting
X-Cart Gold 4.5 - Cross-Site Scripting via products_map.php symb Parameter
Alert Before Your Post < 0.1.1 - Cross-Site Scripting via Name Parameter
WordPress Plugin GRAND FlAGallery 1.57 - 'flagshow.php' Cross-Site Scripting
ZooEffect plugin 1.01 for WordPress - Cross-Site Scripting via Page Parameter
Caseproof Prettylinks - XSS
CVSS 6.1
WordPress Plugin NextGEN Gallery - 'test-head' Cross-Site Scripting
vBulletin 4.1.12 - 'blog_plugin_useradmin.php' SQL Injection
vBulletin 4.1.10 - SQL Injection via Announcement ID Parameter
Simple Machines Forum 2.0.2 - Cross-Site Scripting via Scheduled Parameter
starCMS - Cross-Site Scripting via q Parameter
SMF - 'view' Cross-Site Scripting
PHP-Fusion 7.2.4 - 'weblink_id' SQL Injection
php-fusion 7.02.04 - Cross-Site Scripting via downloads.php cat_id Parameter
MataChat - Stored Cross-Site Scripting via Nickname and Color Parameters
Joomla! Component com_rokdownloads - Arbitrary File Upload
bizdirectory < 2.04 - Cross-Site Scripting via Search Page Parameter
Ignite Solutions CMS - 'car-details.php' SQL Injection