Gjoko 'LiquidWorm' Krstic
684 exploits
Active since Nov 2005
Subrion CMS < 2.2.3 - Cross-Site Request Forgery
Stark CRM 1.0 - Stored Cross-Site Scripting via Multiple Parameters
Sports Accelerator Suite 2.0 - 'news_id' SQL Injection
Spitfire CMS 1.0.475 - PHP Object Injection
Snowfox CMS < 1.0 - Cross-Site Request Forgery via Admin Account Creation
SkaDate Lite 2.0 - Multiple Cross-Site Request Forgery / Persistent Cross-Site Scripting Vulnerabilities
SetSeed CMS < 5.11.2 - SQL Injection via loggedInUser Cookie
R-Scripts Vacation Rental Script 7R - Multiple Vulnerabilities
qEngine CMS 6.0.0 - Multiple Vulnerabilities
pyrocms 2.1.1 - Multiple Vulnerabilities
jetty 6.0.x beta16 - Path Traversal via Encoded URL
PRADO PHP Framework 3.2.0 - Arbitrary File Read
pointter PHP content management system 1.2 - Multiple Vulnerabilities
Pixelpost 1.7.3 - Authenticated SQL Injection via findfid, id, selectfcat, selectfmon, or selectftag Parameter
Piwigo < 2.4.7 - Path Traversal via Install.php DL Parameter
phplist < 2.10.18 - Cross-Site Scripting via Num Parameter in Reconcileusers Action
phlyLabs phlyMail Lite 4.03.04 - Full Path Disclosure / Persistent Cross-Site Scripting
pip < 1.5 - Man-in-the-Middle Attack via Insecure Mirror DNS Querying
CVSS 5.9
PG eLms Pro vDEC_2007_01 - Multiple Blind SQL Injections
PG eLms Pro vDEC_2007_01 - 'contact_us.php' Multiple POST Cross-Site Scripting Vulnerabilities
OV3 Online Administration 3.0 - SQL Injection
OV3 Online Administration 3.0 - Remote Code Execution
OV3 Online Administration 3.0 - Directory Traversal
Pacer Edition CMS 2.1 - 'rm' Arbitrary File Deletion
Pacer Edition CMS 2.1 - 'l' Local File Inclusion