Craig Heffner
26 exploits
Active since Nov 2006
Linksys WRT120N 1.0.07 - Unauthenticated Stack-based Buffer Overflow via TM_Block_URL Parameter
D-Link DSP-W215 1.02 - Unauthenticated Stack-based Buffer Overflow via /common/info.cgi HTTP POST Request
CVSS 9.8
D-Link DIR-605L Wireless N300 Cloud Router <1.13 - Buffer Overflow
CVSS 9.8
Grok Developments NetProxy 4.03 - CSRF
Linksys WRT120N 1.0.07 - Unauthenticated Stack-based Buffer Overflow via TM_Block_URL Parameter
D-Link DIR-605L Wireless N300 Cloud Router <1.13 - Buffer Overflow
CVSS 9.8
D-Link DSP-W215 <1.01b06 - Buffer Overflow
D-Link DSP-W215 1.02 - Unauthenticated Stack-based Buffer Overflow via /common/info.cgi HTTP POST Request
CVSS 9.8
D-Link DIR-645 < 1.04B11 - Cross-Site Scripting via Parental Controls Bind Parameter
D-Link DIR-645 < 1.04B11 - Cross-Site Scripting via Parental Controls Bind Parameter
D-Link DIR-645 Firmware < 1.05b01 - Remote Code Execution via HNAP GetDeviceSettings Action
CVSS 8.8
Grok Developments NetProxy 4.03 - Info Disclosure
php_upload_tool 1.0 - Directory Traversal via Filename Parameter
Upload Tool for PHP 1.0 - Unauthenticated Arbitrary File Upload via main_user.php
DoSePa 1.0.4 - Unauthenticated Directory Traversal via File Parameter
BrewBlogger 1.3.1 - SQL Injection via printLog.php id Parameter
D-Link WBR-1310 - Authentication Bypass
D-Link Routers - Authentication Bypass (1)
D-Link Devices - 'Authentication.cgi' Remote Buffer Overflow (Metasploit)
D-Link DIR-100 - Authenticated Stack-Based Buffer Overflow via Ping Diagnostic Parameter
Belkin F5D8233-4 Wireless N Router (Multiple Scripts) - Authentication Bypass
DD-WRT 24-preSP2 - Information Disclosure
D-Link DSP-W215 <1.01b06 - Buffer Overflow
D-Link DIR-645 Firmware < 1.05b01 - Remote Code Execution via HNAP GetDeviceSettings Action
CVSS 8.8
D-Link Devices - 'hedwig.cgi' Remote Buffer Overflow in Cookie Header (Metasploit)