Gjoko 'LiquidWorm' Krstic
684 exploits
Active since Nov 2005
RealtyScript 4.0.2 Stored Cross-Site Scripting via text Parameter in pages.php
CVSS 6.4
RealtyScript 4.0.2 Stored Cross-Site Scripting via location_name Parameter
CVSS 7.2
RealtyScript 4.0.2 Cross-Site Request Forgery Unauthorized User Creation
CVSS 5.3
Telesquare SKT LTE Router SDT-CS3B1 Insecure Direct Object Reference
CVSS 9.8
Telesquare SKT LTE Router SDT-CS3B1 Unauthenticated Remote Reboot
CVSS 7.5
Telesquare SKT LTE Router SDT-CS3B1 CSRF System Command Execution
CVSS 4.3
IBM DS Storage Manager < 10.83 Authenticated SQL Injection
Huawei EC156, EC176, and EC177 Firmware - Untrusted Search Path via Mobile Partner Directory
CVSS 7.8
Corel PHOTO-PAINT and CorelDRAW X5 15.1.0.588 - Privilege Escalation
Corel PHOTO-PAINT and CorelDRAW X5 15.1.0.588 - Privilege Escalation
Stark CRM 1.0 - Cross-Site Request Forgery in Admin Page
Jetty < 5.1.6 - Unauthenticated Source Code Exposure via URL-Encoded Backslash
Rejected
Ovidentia 6.6.5 - SQL Injection via Search Field Parameter
Open Flash Chart v2 Beta 1-v2 Lug Wyrm Charmer - RCE
MantisBT < 1.2.4 - Cross-Site Scripting via db_type Parameter
Gnew 2013.1 - SQL Injection via Multiple Parameters
Gnew 2013.1 - SQL Injection via news_id, thread_id, or user_email Parameter
ABB ASPECT/Enterprise/NEXUS/MATRIX Firmware < 3.08.03 - Remote Code Execution
CVSS 10.0
ABB ASPECT Enterprise, NEXUS Series, and MATRIX Series <3.08.02 <3 - Data Validation
CVSS 10.0
Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 - Authenticated Cross-Site Request Forgery
Mango Automation 2.5.x and 2.6.x < 2.6.0 build 430 - Authenticated Cross-Site Scripting
Infinite Automation Mango Automation <2.6.0-430 - Info Disclosure
Infinite Automation Mango Automation <2.6.0-430 - Command Injection
Mango Automation <2.6.0-430 - Info Disclosure