Egidio Romano aka EgiX
37 exploits
Active since Dec 2011
1C-Bitrix through 25.100.500 - Remote Code Execution
CVSS 9.8
Bitrix24 through 25.100.300 - Remote Code Execution
CVSS 6.3
WikkaWiki 1.3.1 and 1.3.2 - SQL Injection via default_comment_display Parameter
WikkaWiki 1.3.1 and 1.3.2 - Arbitrary PHP Code Execution via File Upload with Multiple Extensions
WikkaWiki 1.3.1 and 1.3.2 - Path Traversal via File Parameter
WikkaWiki 1.3.1 and 1.3.2 - Arbitrary PHP Code Write via User-Agent HTTP Header
UNA CMS <14.0.0-RC4 - Code Injection
TikiWiki CMS/Groupware < 8.2 - Exposure of Sensitive Information via Direct Request
Kish Guest Posting Plugin < 1.2 - Unauthenticated Arbitrary File Upload via uploadify.php
WebCalendar < 1.2.5 - Remote Code Execution via form_single_user_login Parameter
CVSS 9.8
Traq Project Issue Tracking System 2.0-2.3 - Unauthenticated Remote Code Execution via Admin Plugin Injection
Support Incident Tracker 3.45-3.65 - Remote Code Execution via Lang Parameter in translate.php
Ajax File and Image Manager < 1.1 - Remote Code Execution via PHP Code Injection in data.php
WordPress Plugin Zingiri 2.2.3 - 'ajax_save_name.php' Remote Code Execution
WikkaWiki 1.3.1 and 1.3.2 - Cross-Site Request Forgery in AdminUsers Component
Kish Guest Posting plugin 1.2 - RCE
vBulletin <= 5.5.4 - Remote Code Execution via Custom Avatar Handling
CVSS 9.8
WebCalendar < 1.2.5 - Local File Inclusion
CVSS 8.8
TikiWiki CMS/Groupware < 6.7 LTS & < 8.4 - RCE
CVSS 9.8
Tiki < 8.2 - Authenticated Remote Code Execution via Regex Parameters
CVSS 7.2
Support Incident Tracker 3.45-3.65 - Information Disclosure via translate.php save action
SugarCRM CE <= 6.3.1 - Code Injection
CVSS 9.8
PmWiki 2.x < 2.2.35 - Remote Code Execution via PageListSort Order Parameter
PHPFox 3.0.1 - 'ajax.php' Remote Command Execution
Ajax File and Image Manager < 1.1 - Remote Code Execution via PHP Code Injection in data.php