Gjoko 'LiquidWorm' Krstic
684 exploits
Active since Nov 2005
Infinite Automation Mango Automation <2.6.0 - SQL Injection
EnGenius EnShare Cloud Service <1.4.11 - Command Injection
CVSS 9.8
Selea Targa IP OCR-ANPR - Path Traversal
Selea Targa IP OCR-ANPR Camera - Server-Side Request Forgery via JSON POST Parameters
R Radio Network FM Transmitter 1.07 - Info Disclosure
Screen SFT DAB 600/C Firmware 1.9.3 - Auth Bypass
CVSS 7.5
Screen SFT DAB 600/C Firmware 1.9.3 - Auth Bypass
CVSS 9.8
Screen SFT DAB 600/C 1.9.3 - Auth Bypass
CVSS 7.5
SOUND4 Server Service 4.1.102 - Privilege Escalation
CVSS 8.4
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Command Injection
CVSS 9.8
Anevia Flamingo XL 3.2.9 - OS Command Injection via Traceroute Command
CVSS 10.0
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Auth Bypass
CVSS 9.8
Ateme TITAN File 3.9.12.4 - Authenticated Server-Side Request Forgery via Job Callback URL Parameter
CVSS 6.5
Screen SFT DAB 1.9.3 - Authentication Bypass via Session Fixation
CVSS 8.8
MiniDVBLinux < 5.4 - Unauthenticated Live Stream Snapshot Generation via tv_action.sh
CVSS 5.3
MiniDVBLinux 5.4 - Unauthenticated Root Password Change via System Setup Endpoint
CVSS 9.8
MiniDVBLinux 5.4 - Unauthenticated Sensitive Configuration Download via Backup Endpoint
CVSS 7.5
Screen SFT DAB Series - Compact Radio DAB Transmitter 1.9.3 - Authentication Bypass via IP Session Reuse
CVSS 8.1
Screen SFT DAB Series 1.9.3 - Unauthenticated Authentication Bypass via userManager.cgx Endpoint
CVSS 9.8
Aquatronica Controller System <= 5.1.6 - Information Disclosure
Screen SFT DAB 600/C Firmware <= 1.9.3 - Unauthenticated Information Disclosure via User Management API
CVSS 5.3
H3C SSL VPN 1.1 - User Enumeration via Login Script Credential Verification
CVSS 7.5
Fetch Softworks Fetch FTP Client 5.8.2 - Denial of Service via Long FTP Server Response
CVSS 7.5
P5 FNIP-8x16A/FNIP-4xSH <1.0.20, 1.0.11 - XSS
CVSS 3.5
P5 FNIP-8x16A FNIP-4xSH 1.0.20 - CSRF
CVSS 3.5