Hessam-x
26 exploits
Active since Jan 2006
Light Weight Calendar (LWC) <1.0 - Code Injection
IceBB 1.0-rc5 - Authenticated SQL Injection via Avatar Upload Filename
nVIDIA nView - Denial of Service via Long Command Line Argument
Wikepage 2006.2a Opus 10 - Directory Traversal via lng Parameter
Vikingboard 0.1b - SQL Injection via Topic s Parameter
Vikingboard 0.1b - Cross-Site Scripting via act and p Parameters
Vikingboard 0.1b - Cross-Site Scripting via act and p Parameters
TinyPHPForum 3.6 - Multiple Cross-Site Scripting Vulnerabilities (1)
tinyphpforum < 3.6 - Directory Traversal and Arbitrary File Execution via Profile UName Parameter
RCblog 1.03 - 'POST' Remote Command Execution
RCBlog 1.0.3 - 'index.php' Directory Traversal
PBlang 4.66z - Remote Code Execution
PBlang 4.66z - Remote Create Admin
OlateDownload 3.4.0 - SQL Injection
OlateDownload 3.4.0 - SQL Injection
MyBulletinBoard (MyBB) 1.1.3 - 'usercp.php' Create Admin
Light Weight Calendar (LWC) 1.0 - Code Injection
Internet Photoshow 1.3 - Remote File Inclusion via Page Parameter
IwebNegar 1.1 - SQL Injection via Comments.php id Parameter
IceBB 1.0-rc5 - Authenticated SQL Injection via Avatar Upload Filename
IceBB 1.0-rc5 - Authenticated Arbitrary File Upload via Avatar Function
GreyMatter WebLog 1.21d - Remote Command Execution (2)
FarsiNews 2.5 - Directory Traversal and Arbitrary File Read via Archive Parameter
EJ3 TOPo 2.2 - 'descripcion' Remote Command Execution
deluxebb < 1.07 - SQL Injection via cp.php xmsn Parameter