Antonio "s4tan" Parata
18 exploits
Active since May 2008
matt_wright FormMail < 1.92 - Cross-Site Scripting via request and return_link_url Parameters
vtiger CRM 5.0.4 - Path Traversal and Arbitrary File Execution via Module Parameter
Vtiger Crm - Cross-Site Request Forgery
vtiger CRM 5.0.4 - Cross-Site Scripting via Activities Module Action Parameter
Collabtive 0.4.8 - Authenticated Remote Code Execution via Unrestricted File Upload
Collabtive 0.4.8 - Unauthenticated Authentication Bypass and Privilege Escalation via Admin User Creation
Collabtive 0.4.8 - Stored Cross-Site Scripting in Project Name via manageproject.php
Mantis < 1.1.2 - Cross-Site Scripting via return_dynamic_filters.php filter_target Parameter
Mantis 1.1.1 - Cross-Site Request Forgery via manage_user_create.php
Zabbix 1.6.2 Frontend - Multiple Vulnerabilities
vtiger CRM 5.0.4 - Authenticated Remote Code Execution via Compose Mail Attachment Filename
vtiger CRM 5.0.4 - Path Traversal and Arbitrary File Execution via Module Parameter
SugarCRM < 5.2f - Authenticated Remote Code Execution via Compose Email File Upload
Moodle 1.9.3 - Remote Code Execution
Mantis < 1.1.2 - Authenticated Remote Code Execution via adm_config_set.php Value Parameter
Matt Wright FormMail 1.92 - CRLF Injection via Redirect Parameter
Collabtive - Cross-Site Request Forgery
Mort Bay Jetty 6.x and 7.0.0 - Cross-Site Scripting via JSP Dump Query String or Session Dump Parameters