Evgeny Fadeev

2 exploits Active since Mar 2014
CVE-2014-2236 WRITEUP WRITEUP
askbot < 0.7.49 - Cross-Site Scripting via Tag or User Search Forms
Multiple cross-site scripting (XSS) vulnerabilities in Askbot before 0.7.49 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) tag or (2) user search forms.
CVE-2026-1213 WRITEUP MEDIUM WRITEUP
askbot <= 0.12.2 - Authenticated Profile Picture Modification
All versions of askbot before and including 0.12.2 allow an attacker authenticated with normal user permissions to modify the profile picture of other application users.This issue affects askbot: 0.12.2.
CVSS 4.3