Egidio Romano
39 exploits
Active since Feb 2013
ISPConfig language_edit.php PHP Code Injection
Invisioncommunity < 5.0.7 - Remote Code Execution
SugarCRM <13.0.4 and 14.x <14.0.1 - Server-Side Request Forgery via API Module Code Injection
ISPConfig language_edit.php PHP Code Injection
CVSS 7.2
MantisBT < 1.2.17 - Unauthenticated Arbitrary File Upload and Information Disclosure via XML Import/Export Plugin
vtiger CRM 5.1.0-5.4.0 - Authentication Bypass via Improper Session Validation
CVSS 9.8
vtiger CRM 5.0.0-5.4.0 - SQL Injection via Picklist Name or Email Address Parameter
vtiger CRM < 5.4.0 - PHP Code Injection via vtigerolservice.php
CVSS 9.8
Rejected
MantisBT - Remote Code Execution via XmlImportExport Plugin Preg Replace
UNA CMS <14.0.0-RC4 - Code Injection
SugarCRM - Unauthenticated Remote Code Execution via PHP Object Injection
DataLife Engine 9.7 - Remote Code Execution via catlist[] Parameter
vtiger CRM < 5.4.0 - Local File Inclusion and Remote Code Execution via customerportal.php
CVSS 8.1
vtiger CRM < 5.4.0 - PHP Code Injection via vtigerolservice.php
CVSS 9.8
MantisBT - Remote Code Execution via XmlImportExport Plugin Preg Replace
Cacti Import Packages RCE
CVSS 9.1
Control Web Panel /admin/index.php Unauthenticated RCE
CVSS 7.3
ISPConfig language_edit.php PHP Code Injection
CVSS 7.2
Symantec Web Gateway <5.2.2 - Command Injection
vtiger CRM 5.1.0-5.4.0 - Authentication Bypass via Improper Session Validation
CVSS 9.8
Vanilla Forums <2.0.18.8 - Code Injection
SugarCRM 6.5.18 - PHP Code Injection
Piwik 2.16.0 - 'layout' PHP Object Injection
phpFox < 4.8.13 - (redirect) PHP Object Injection Exploit