GulfTech Security
165 exploits
Active since Mar 2004
Kayako SupportSuite <3.20.02 - SQL Injection
Kayako liveResponse 2.x - Cross-Site Scripting via Username Parameter or Name Field
Kayako liveResponse 2.x - SQL Injection via Calendar Year or Date Parameter
Kayako eSupport 2.x - SQL Injection via Multiple Parameters
Kayako eSupport 2.3 - Cross-Site Scripting via _i or _c Parameter
Invision Gallery 1.0.1 - SQL Injection via img/cat/sort_key/order_key/user/album Parameters
JamRoom < 3.4.0 - Unauthenticated Authentication Bypass via Serialized Cookie
Invision Power Top Site List < 2.0 Alpha 3 - SQL Injection (PoC)
Invision Power Top Site List < 1.1 RC 2 - SQL Injection
Invision Gallery - SQL Injection via Comment or Rating Parameter
Invision Power Board <= 2.0.3 - Cross-Site Scripting via Highlite Parameter
Invision Power Board (IP.Board) < 2.0 Alpha 3 - SQL Injection (PoC)
Invision Power Board (IP.Board) < 1.3.1 - Design Error
Invision Power Board (IP.Board) < 1.3 - SQL Injection
Invision Community Blog 1.0/1.1 - Multiple Input Validation Vulnerabilities
HiveMail <= 1.3 - Cross-Site Scripting via PHP_SELF Variable
HiveMail <= 1.3 - Remote Code Execution via Eval Injection in Multiple Parameters
HiveMail <= 1.3 - Remote Code Execution via Eval Injection in Multiple Parameters
Help Center Live - Cross-Site Scripting via Multiple Input Parameters
HelpCenter Live! 1.0/1.2.x - Multiple Input Validation Vulnerabilities
HAMweather 3.9.8 - 'template.php' Script Code Injection
Gregarius < 0.5.4 - SQL Injection via rsargs Array Parameter
Geeklog 1.4.0-1.4.0sr1 and 1.3.11-1.3.11sr4 - SQL Injection via Userid or Sessid Parameter
Gallery 2 up to 2.0.2 - Cross-Site Scripting via X-Forwarded-For Header
FusionBB 0.x - Multiple Input Validation Vulnerabilities