Gjoko 'LiquidWorm' Krstic
684 exploits
Active since Nov 2005
VideoFlow Digital Video Protection DVP 10 Authenticated Directory Traversal 2.10 (X-Prototype-Version: 1.6.0.2)
CVSS 6.5
VideoFlow Digital Video Protection DVP 10 Authenticated Remote Code Execution
CVSS 4.3
RealtyScript 4.0.2 Stored Cross-Site Scripting via CSV File Upload Filename
CVSS 6.1
RealtyScript 4.0.2 Stored Cross-Site Scripting via File Upload Parameter
CVSS 7.2
RealtyScript 4.0.2 Cross-Site Scripting via Multiple Parameters
CVSS 6.1
RealtyScript 4.0.2 Multiple Cross-Site Request Forgery and Persistent Cross-Site Scripting Vulnerabilities
CVSS 5.3
Qool CMS Multiple Persistent Cross-Site Scripting Vulnerabilities
CVSS 7.5
Qool CMS 2.0 RC2 Cross-Site Request Forgery via adduser
CVSS 5.3
Serviio PRO 1.8 Unauthenticated Password Change via REST API
CVSS 7.5
Serviio PRO 1.8 Local Privilege Escalation via Unquoted Path
CVSS 7.8
Serviio PRO 1.8 REST API Information Disclosure
CVSS 7.5
Wowza Streaming Engine 4.5.0 Multiple Cross-Site Scripting Vulnerabilities
CVSS 6.1
Wowza Streaming Engine 4.5.0 CSRF via user edit endpoint
CVSS 5.3
Wowza Streaming Engine 4.5.0 Privilege Escalation via user edit
CVSS 8.8
Wowza Streaming Engine 4.5.0 Local Privilege Escalation via nssm_x64.exe
CVSS 7.8
ZKTeco ZKAccess Security System 5.3.1 Stored XSS
CVSS 7.2
ZKTeco ZKBioSecurity 3.0 Local Authorization Bypass via visLogin.jsp
CVSS 5.5
ZKTeco ZKBioSecurity 3.0 File Path Manipulation Vulnerability
CVSS 6.2
ZKTeco ZKBioSecurity 3.0 Cross-Site Request Forgery Superadmin
CVSS 4.3
ZKTeco ZKBioSecurity 3.0 Hardcoded Credentials Remote Code Execution
CVSS 9.8
ZKTeco ZKAccess Professional 3.5.3 Privilege Escalation via Insecure Permissions
CVSS 8.8
ZKTeco ZKTime.Net 3.0.1.6 Insecure File Permissions Privilege Escalation
CVSS 9.8
RealtyScript 4.0.2 SQL Injection via u_id and agent Parameters
CVSS 8.2
RealtyScript 4.0.2 Multiple Time-based Blind SQL Injection
CVSS 8.2
RealtyScript 4.0.2 Stored Cross-Site Scripting via text Parameter in pages.php
CVSS 6.4