Bl@ckbe@rD
25 exploits
Active since Dec 2004
ASP Inline Corporate Calendar - SQL Injection
ASP Inline Corporate Calendar - XSS
QuadComm Q-Shop 3.0 - SQL Injection via UserID or Pwd Parameter
Philboard 1.14 and 1.2 - SQL Injection via forum.asp forumid Parameter
Todd Woolums ASP News Mgmt 2.2 - SQL Injection
EvansFTP - 'EvansFTP.ocx' Remote Buffer Overflow (PoC)
aspWebCalendar - SQL Injection via Username Field or EventID Parameter
WebCal 3.04 - SQL Injection via event_id Parameter
Web Calendar System 3.40 - Cross-Site Scripting / SQL Injection
Philboard 1.14 and 1.2 - Cross-Site Scripting via search.asp searchterms Parameter
NatterChat 1.1 and 1.12 - SQL Injection via Username and Password Parameters
GO4I.NET ASP Forum 1.0 - SQL Injection via iFor Parameter
WebBlizzard CMS - SQL Injection via Page Parameter
battleblog <= 1.25 - SQL Injection via comment.asp Entry Parameter
MVC-Web CMS 1.0/1.2 - 'newsid' SQL Injection
WebEyes Guest Book 3 - SQL Injection
Todd Woolums ASP News Management 2.2 - Info Disclosure
QuadComm Q-Shop < 3.0 - Cross-Site Scripting via search.asp srkeys Parameter
Systementor PostcardMentor - SQL Injection via cat_fldAuto Parameter
asp talk - SQL Injection / Cross-Site Scripting
DUdForum 3.0 - 'iFor' SQL Injection
DUcalendar < 1.0 - SQL Injection via iEve Parameter
Comersus ASP Shopping Cart - File Disclosure / Cross-Site Scripting
pilot_cart 7.3 - SQL Injection via Article Parameter
ASP Inline Corporate Calendar - SQL Injection