Carsten Schmitz
19 exploits
Active since Jun 2015
LimeSurvey < 2.06+ - Authenticated SQL Injection via sid Parameter
LimeSurvey < 2.06+ - Authenticated SQL Injection via sid Parameter
LimeSurvey 2.06+ - Authenticated SQL Injection via Closedate Parameter
Limesurvey <3.17.14 - Code Injection
CVSS 8.8
LimeSurvey < 3.17.14 - Clickjacking
CVSS 4.3
Limesurvey <3.17.14 - Info Disclosure
CVSS 5.3
Limesurvey <3.17.14 - Info Disclosure
CVSS 7.5
LimeSurvey < 3.17.14 - Authenticated Stored Cross-Site Scripting via Admin Box Button Titles
CVSS 5.4
Limesurvey <3.17.14 - Info Disclosure
CVSS 5.3
Limesurvey <3.17.14 - Info Disclosure
CVSS 5.3
Limesurvey <3.17.14 - Info Disclosure
CVSS 2.7
LimeSurvey < 3.17.14 - Reflected Cross-Site Scripting via Uploaded File Extensions
CVSS 6.1
Limesurvey <3.17.14 - Info Disclosure
CVSS 2.7
Limesurvey <3.17.14 - Command Injection
CVSS 9.8
Limesurvey <3.17.14 - Info Disclosure
CVSS 7.2
Limesurvey <3.17.14 - Privilege Escalation
CVSS 7.2
LimeSurvey < 3.17.14 - Unauthenticated Cookie Access via Missing HttpOnly Flag
CVSS 7.5
LimeSurvey <4.0.0-RC4 - SQL Injection
CVSS 9.8
LimeSurvey < 5.3.9 - Cross-Site Scripting via uploadConfirm.php
CVSS 6.1