GulfTech Security
165 exploits
Active since Mar 2004
D-Link DNS-343 ShareCenter <1.05 - Command Injection
CVSS 9.8
Pligg CMS < 9.9 - Path Traversal via Trackback URL or Template Parameter
Pligg CMS < 9.9.0 - Cross-Site Scripting via Search Keyword Parameter
Turnkey PHP Live Helper <2.0.1 - Code Injection
Turnkey PHP Live Helper <2.0.1 - SQL Injection
WebSVN < 2.0 - Path Traversal and Arbitrary File Write via RSS Rev Parameter
WebSVN <= 2.0 - Cross-Site Scripting via PATH_INFO
Xedus 1.0 - Cross-Site Scripting via Username or Param Parameter
Xedus 1.0 - Cross-Site Scripting via Username or Param Parameter
Xedus 1.0 - Directory Traversal via URL
Trillian Pro < 2.01 - Design Error
Psychostats < 2.2.4 - Cross-Site Scripting via Login Parameter
dBpowerAMP Audio Player and Music Converter - Buffer Overflow via Long Filename in Playlist
PeerCast < 0.1211 - Remote Code Execution via Format String in URL
BadBlue 2.5 - Denial of Service via Excessive Connections
efs_web_server 1.25 - Denial of Service via Large HTTP Requests
EmuLive Server4 Commerce Edition Build 7560 - Denial of Service via Carriage Return Sequence to TCP Port 66
Zen Cart < 1.3.0.2 - Remote Code Execution via autoLoadConfig Parameter
Qualiteam X-Cart < 4.1.3 - Remote Code Execution via cmpi.php Dynamic Variable Evaluation
xpcom - Denial of Service via Nested DIV Tags
XOOPS <= 2.0.11 - Cross-Site Scripting via Order or CID Parameter
Yappa-ng 1.x/2.x - Cross-Site Scripting
Yappa-ng 1.x/2.x - Remote File Inclusion
XMB 1.9.3 - Cross-Site Scripting via u2u.php Username Parameter
WordPress <= 1.5.1.2 - SQL Injection via HTTP_RAW_POST_DATA