Daniel Fabian

9 exploits Active since Jan 2005
EIP-2026-119329 EXPLOITDB text WORKING POC
Yaws 1.5x - Source Code Disclosure
CVE-2006-1193 EXPLOITDB perl WORKING POC
Microsoft Exchange Server 2000 - XSS
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing."
CVE-2005-3819 EXPLOITDB text WRITEUP
Vtiger Crm < 4.2 - SQL Injection
Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary SQL commands and bypass authentication via the (1) user_name and (2) date parameter in the HelpDesk module.
CVE-2005-3818 EXPLOITDB text WRITEUP
Vtiger Crm < 4.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) various input fields, including the contact, lead, and first or last name fields, (2) the record parameter in a DetailView action in the Leads module for index.php, (3) the $_SERVER['PHP_SELF'] variable, which is used in multiple locations such as index.php, and (4) aggregated RSS feeds in the RSS aggregation module.
CVE-2005-3818 EXPLOITDB text WRITEUP
Vtiger Crm < 4.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) various input fields, including the contact, lead, and first or last name fields, (2) the record parameter in a DetailView action in the Leads module for index.php, (3) the $_SERVER['PHP_SELF'] variable, which is used in multiple locations such as index.php, and (4) aggregated RSS feeds in the RSS aggregation module.
EIP-2026-112476 EXPLOITDB text WRITEUP
sugarsales 1.x/2.0 - Multiple Vulnerabilities
CVE-2004-1020 EXPLOITDB text WRITEUP
PHP 4.3.9 - Info Disclosure
The addslashes function in PHP 4.3.9 does not properly escape a NULL (/0) character, which may allow remote attackers to read arbitrary files in PHP applications that contain a directory traversal vulnerability in require or include statements, but are otherwise protected by the magic_quotes_gpc mechanism. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.
EIP-2026-104695 EXPLOITDB text WRITEUP
PHP 4.3.x - Microsoft Windows Shell Escape functions Command Execution
CVE-2005-4197 EXPLOITDB text WORKING POC
Nortel SSL VPN 4.2.1.6 - Command Injection
tunnelform.yaws in Nortel SSL VPN 4.2.1.6 allows remote attackers to execute arbitrary commands via a link in the a parameter, which is executed with extra privileges in a cryptographically signed Java Applet.