Claudio Viviani
59 exploits
Active since May 2014
WordPress Plugin wpDataTables 1.5.3 - Arbitrary File Upload
WP Symposium 14.11 - Unauthenticated Arbitrary File Upload via UploadHandler.php
WordPress Plugin Work The Flow File Upload 2.5.2 - Arbitrary File Upload
WordPress Plugin N-Media Website Contact Form with File Upload 1.3.4 - Arbitrary File Upload (2)
Creative Contact Form < 1.0.0 - Unauthenticated Arbitrary File Upload via jQuery File Upload Plugin
CVSS 9.8
WordPress Plugin Ajax Store Locator 1.2 - Arbitrary File Download
WordPress Plugin Ajax Store Locator 1.2 - SQL Injection
WordPress Plugin All In One WP Security & Firewall 3.9.0 - SQL Injection
BSK PDF Manager 1.3.2 - SQL Injection
CP Multi View Event Calendar 1.01 - SQL Injection via calid Parameter
WordPress Plugin Download Manager 2.7.4 - Remote Code Execution
WordPress Plugin Duplicator 0.5.14 - SQL Injection / Cross-Site Request Forgery
Gallery Objects 0.4 - SQL Injection via viewid Parameter
gb_gallery_slideshow 1.5 - Authenticated SQL Injection via selected_group Parameter
Huge-IT Image Gallery <1.0.1 - SQL Injection
WP Marketplace <2.4.1 - Path Traversal
CVSS 4.3
WordPress Plugin N-Media Website Contact Form with File Upload 1.3.4 - Arbitrary File Upload (1)
WordPress Plugin NEX-Forms < 3.0 - SQL Injection
Joomla! Component spidervideoplayer - 'theme' SQL Injection
Joomla! Component Spider Contacts 1.3.6 - 'contacts_id' SQL Injection
Joomla! Component Spider Calendar 3.2.6 - SQL Injection
Joomla! Component com_formmaker 3.4 - SQL Injection
Joomla! Component com_facegallery 1.0 - Multiple Vulnerabilities
Joomla! Component com_macgallery 1.5 - Arbitrary File Download
Joomla! Component com_hdflvplayer < 2.1.0.1 - Arbitrary File Download