AmnPardaz Security Research & Penetration Testing Group
8 exploits
Active since Dec 2007
CandyPress Store < 4.1 - SQL Injection via idcust or tableName Parameter
CandyPress < 4.1.1.26 - Cross-Site Scripting via helpfield Parameter
CandyPress 4.1.1.26 - SQL Injection via idProduct or options Parameter
CandyPress 4.x and 3.x - SQL Injection via helpfield Parameter
CandyPress 4.1.1.26 - Path Exposure via FedExAccount Parameter
Jupiter 1.1.5ex - Privilege Escalation
PDFLib - Stack-Based Buffer Overflow via Long Filename in PDF_load_image Function
CandyPress < 4.1 - SQL Injection via FedExAccount Parameter