Gjoko 'LiquidWorm' Krstic
684 exploits
Active since Nov 2005
Thrive Smart Home 1.1 - SQL Injection
CVSS 8.2
INIM Electronics Smartliving SmartLAN/G/SI <=6.x - Info Disclosure
CVSS 7.5
HomeAutomation 3.3.2 - Authentication Bypass via X-Forwarded-For Header Spoofing
CVSS 9.8
HomeAutomation 3.3.2 - Authenticated OS Command Injection via Custom Command Plugin
CVSS 8.0
iWT FaceSentry Access Control System 6.4.8 - Authenticated OS Command Injection via strInIP Parameter
CVSS 8.8
AVE DOMINAplus <=1.10.x - Unauthenticated Denial of Service via Reboot Command Execution
CVSS 7.5
Inim Smartliving Firmware < 6.0 - Use of Hard-coded Credentials
CVSS 9.8
AVE DOMINAplus <=1.10.x - Unauthenticated Credential Disclosure via /xml/authClients.xml
CVSS 9.8
AVE DOMINAplus <= 1.10.x - Unauthenticated Authentication Bypass via changeparams.php autologin Parameter
CVSS 9.8
HomeAutomation 3.3.2 - Cross-Site Request Forgery
CVSS 8.8
HomeAutomation 3.3.2 - Stored Cross-Site Scripting via Input Parameter
CVSS 6.1
Leica Geosystems GR10/GR25/GR30/GR50 4.30.063 - CSRF
CVSS 5.3
LogicalDOC Enterprise 7.7.4 - Info Disclosure
CVSS 7.5
LogicalDOC Enterprise 7.7.4 - Command Injection
CVSS 6.5
VideoFlow Digital Video Protection DVP 2.10 - Path Traversal
CVSS 6.5
VideoFlow DVP 2.10 - Authenticated RCE
CVSS 4.3
KYOCERA Net Admin 3.4.0906 - Cross-Site Request Forgery via Administrative User Creation
CVSS 8.8
KYOCERA Net Admin 3.4.0906 - XXE Injection
CVSS 7.5
Teradek VidiU Pro 3.0.3 - Cross-Site Request Forgery via Password Change Request
CVSS 4.3
Teradek VidiU Pro 3.0.3 - Server-Side Request Forgery via URL Parameter
CVSS 6.5
Beward N100 M2.1.6.04C014 - Info Disclosure
CVSS 7.5
Beward N100 H.264 VGA IP Camera M2.1.6 - CSRF
CVSS 5.3
Beward N100 H.264 VGA IP Camera M2.1.6 - Info Disclosure
CVSS 8.8
Ross Video DashBoard 8.5.1 - Privilege Escalation
CVSS 8.8
Legrand BTicino Driver Manager F454 1.0.51 - CSRF, XSS
CVSS 5.3