Charles Fol
36 exploits
Active since May 2007
GNU C Library <2.39 - Buffer Overflow
PrestaShop <1.6.1.20 & <1.7.3.4 - Info Disclosure
Apache HTTP Server 2.4.17-2.4.38 - Use-After-Free in Scoreboard
Apache HTTP Server 2.4.17-2.4.38 - Use-After-Free in Scoreboard
CVSS 7.8
Adobe Commerce and Magento - XML External Entity Injection to Code Execution
CVSS 9.8
Simple Machines Forum 1.0-1.0.15 and 1.1-1.1.7 - Cross-Site Request Forgery via Package Installation
peel < 3.0 - Exposure of Sensitive Information via phpinfo.php
PEEL - SQL Injection via Email Parameter or Timestamp Parameter
PEEL - Authenticated Arbitrary File Upload via Modified Content Type in administrer/produits.php
TYPO3 News module <5.3.2 - SQL Injection
CVSS 9.8
Drupal 7.0.0-7.61.0 8.5.0-8.5.10 8.6.0-8.6.9 - Remote Code Execution via Unsanitized Field Data
CVSS 8.1
vBulletin <5.5.6pl1, <5.6.0pl1, <5.6.1pl1 - Privilege Escalation
CVSS 9.8
vBulletin <5.5.6pl1, <5.6.0pl1, <5.6.1pl1 - Privilege Escalation
CVSS 9.8
GNU C Library <2.39 - Buffer Overflow
CVSS 7.3
zKup CMS 2.0-2.3 - Unauthenticated Privilege Escalation via Direct Admin Configuration Access
zKup CMS 2.0-2.3 - Unauthenticated Privilege Escalation via Direct Admin Configuration Access
TYPO3 Extension News - SQL Injection
Simple Machines Forum 1.0-1.0.14 and 1.1-1.1.6 - Authenticated Path Traversal via Package Parameter
PrestaShop <1.6.1.20 & <1.7.3.4 - Info Disclosure
CVSS 9.1
PrestaShop <1.6.1.20 & <1.7.3.4 - Info Disclosure
CVSS 9.1
phpTournois G4 - Arbitrary File Upload / Code Execution
phpMyNewsletter <0.8 beta 5 - SQL Injection
PHP-Nuke Platinium 7.6.b.5 - Remote Code Execution
PEEL < 3.0 - Default Credentials for Admin Access
Nuked-klaN 1.7.6 - SQL Injection via X-Forwarded-For Header