Gjoko 'LiquidWorm' Krstic
684 exploits
Active since Nov 2005
Oxwall 1.7.0- SkaDate Lite 2.0 - CSRF
Ovidentia 6.6.5 - SQL Injection via Item Parameter in Contact Modify Action
NUUO NVRmini 2 3.0.8 - Multiple OS Command Injections
NUUO NVRmini 2 3.0.8 - Local File Disclosure
NUUO NVRmini 2 3.0.8 - Cross-Site Request Forgery (Add Admin)
NUUO NVRmini 2 3.0.8 - 'strong_user.php' Backdoor Remote Shell Access
NULL NUKE CMS 2.2 - Multiple Vulnerabilities
iTop 1.1.181 and 1.2.0-RC-282 - Cross-Site Scripting via Multiple Input Vectors
Omeka < 2.2.1 - Cross-Site Request Forgery
NUUO NVRmini 2 3.0.8 - Remote Code Execution
MODx REvolution CMS 2.0.4-pl2 - POST injection Cross-Site Scripting
MTP Poll 1.0 - Multiple Cross-Site Scripting Vulnerabilities
MTP Image Gallery 1.0 - 'edit_photos.php?title' Cross-Site Scripting
MTP Guestbook 1.0 - Multiple Cross-Site Scripting Vulnerabilities
Moodle < 2.5.9, 2.6.x < 2.6.9, 2.7.x < 2.7.6, 2.8.x < 2.8.4 - XSS via IMG Alt/Title
MantisBT < 1.2.4 - Information Disclosure via Invalid db_type Parameter
Lunar CMS < 3.3 - Cross-Site Request Forgery
Microweber 1.0.3 - Persistent Cross-Site Scripting / Cross-Site Request Forgery (Add Admin)
Microweber 1.0.3 - Arbitrary File Upload / Filter Bypass / PHP Remote Code Execution
MantisBT < 1.2.4 - Remote Code Execution via db_type Parameter in admin/upgrade_unattended.php
Lunar CMS 3.3 - Remote Command Execution
Kemana Directory 1.5.6 - kemana_admin_passwd Cookie User Password Hash Disclosure
LimeSurvey 2.00+ (build 131107) - Multiple Vulnerabilities
Kemana Directory 1.5.6 - Remote Code Execution
Kemana Directory 1.5.6 - Database Backup Disclosure