Egidio Romano
39 exploits
Active since Feb 2013
Joomla! <2.5.10-3.0.4 - Code Injection
Joomla! 2.5.x-3.0.2 - PHP Object Injection via Highlight Parameter
ImpressCMS < 1.4.3 - SQL Injection via findusers.php Groups Parameter
CVSS 9.8
Invision Power Board < 4.1.13 - Remote Code Execution via content_class Parameter
CVSS 8.1
DataLife Engine <9.7 - Info Disclosure
Concrete5 CMS 5.7.3.1 - 'Application::dispatch' Method Local File Inclusion
CubeCart 5.0.0-5.2.0 - Remote Code Execution via Unserialization in Shipping Parameter
CVSS 9.8
MantisBT - Remote Code Execution via XmlImportExport Plugin Preg Replace
vtiger CRM < 5.4.0 - PHP Code Injection via vtigerolservice.php
CVSS 9.8
Invision Community 4.7.20 - (calendar/view.php) SQL Injection
MantisBT < 1.2.17 - Unauthenticated Arbitrary File Upload and Information Disclosure via XML Import/Export Plugin
SugarCRM <13.0.4 and 14.x <14.0.1 - Server-Side Request Forgery via API Module Code Injection
CVSS 7.2
Invisioncommunity < 5.0.7 - Remote Code Execution
CVSS 10.0
Symantec Web Gateway <5.2.2 - Command Injection