Cold z3ro
37 exploits
Active since Jan 2006
PhotoPost vBGallery < 2.4.1 - Unauthenticated Arbitrary File Upload
FreePBX 16 - Authenticated Remote Code Execution via API Module Generatedocs Endpoint
CVSS 8.8
Liberum Help Desk <= 0.97.3 - SQL Injection via id or uid Parameter
vBulletin vbBux/vbPlaza 2.x - 'vbplaza.php' Blind SQL Injection
vBulletin ajaxReg Module - SQL Injection
vbzoom 1.11 - SQL Injection via MainID Parameter
vBGSiteMap 2.41 - Remote File Inclusion via Base Parameter
MiniBB < 1.5a - Remote File Inclusion via absolute_path Parameter
SimpCMS - SQL Injection via Search Keyword Parameter
Picturesolution < 2.1 - Remote Code Execution via Path Parameter in install/config.php
Longino Jacome php-Revista 1.1.2 - SQL Injection via Multiple Parameters
phpRaid 3.0.6 - Remote File Inclusion via phpraid_dir Parameter
htmltonuke 2.0 alpha - Remote Code Execution via filnavn Parameter
PHP-NUKE iFrame Module - Remote File Inclusion via iframe.php file Parameter
PhotoPost vBGallery 2.4.2 - Authenticated Arbitrary File Upload via Executable Extension Bypass
eMetrix Online Keyword Research Tool - Path Traversal via Download Filename Parameter
osDate 2.0.8 - Remote Code Execution via php121dir Parameter
OmniStar Article Manager - SQL Injection via Page ID Parameter
MyPHPCommander 2.0 - Code Injection
NFN Address Book - Remote File Inclusion via mosConfig_absolute_path Parameter
Antonis Ventouris Weather <mod_weather.php - RCE
Mambo Calendar Module 1.5.5 - Remote File Inclusion via absolute_path Parameter
JoomlaPack 1.0.4a2 RE - Remote Code Execution via mosConfig_absolute_path Parameter
Liberum Help Desk 0.97.3 - Info Disclosure
Restaurante Component for Joomla! - Unauthenticated Arbitrary PHP File Upload via Double Extension Bypass