Hamid Ebadi
24 exploits
Active since Feb 2006
ASP Stats Generator <2.1.2 - Code Injection
MiniWeb HTTP Server 0.8.19 - Remote Code Execution via Long URI
Really Simple PHP and Ajax 2007-03-23 - Remote File Inclusion via __class Parameter
MiniWeb HTTP Server 0.8.19 - Path Traversal via Partially Encoded Dot Dot Sequences
Pi3Web < 2.0.3_pl1 - Denial of Service via ISAPI Directory File Request
stud.ip < 1.3.0-2 - Remote File Inclusion via _PHPLIB[libdir] or ABSOLUTE_PATH_STUDIP Parameter
RunCMS 1.2 and 1.3a - SQL Injection via pmlite.php to_userid Parameter
really_simple_php_and_ajax < 2007-03-23 - Remote File Inclusion
phpTrafficA <1.4.1 - Path Traversal
phpTrafficA <1.4.1 - Path Traversal
Jonathan Beckett PluggedOut Nexus 0.1 - SQL Injection via Forgotten Password Email Parameter
Plume CMS 1.1.3 - Remote Code Execution via _PX_config[manager_path] Parameter
phpkit < 1.6.1 - SQL Injection via contentid Parameter
PHP <5.2.11 & 5.3.x <5.3.1 - Command Injection
Exponent CMS <= 0.96.6 - Cross-Site Scripting via Multiple Parameters
Exponent CMS <= 0.96.6 - Cross-Site Scripting via Multiple Parameters
Exponent CMS 0.96.6 Alpha - Directory Traversal via iconspopup.php icodir Parameter
evoTopsites 2.x and evoTopsites Pro 2.x - SQL Injection via cat_id or id Parameter
FarsiNews 2.5 - Directory Traversal and Arbitrary File Read via Archive Parameter
FarsiNews < 2.1_beta2 - Remote File Inclusion via loginout.php cutepath Parameter
CuteNews 1.4.1 - 'function.php' Local File Inclusion
Blursoft Blur6ex 0.3.462 - 'index.php' Local File Inclusion
PHP < 5.2.8 - Exposure of Sensitive Information via imageRotate Function
asp_stats_generator < 2.1.1 - SQL Injection via order Parameter