Hubert Wojciechowski
22 exploits
Active since Aug 2023
OpenCart 3.0.3.8 Session Fixation via OCSESSID Cookie
CVSS 9.8
Aero CMS 0.0.1 PHP Code Injection via posts.php
CVSS 8.8
Atom CMS 2.0 - SQL Injection
CVSS 7.5
WebTareas 2.4 - Unauthenticated SQL Injection via webTareasSID Cookie Parameter
CVSS 7.5
WebTareas 2.4 - Authenticated Remote Code Execution via Chat Photo Upload
CVSS 8.8
e107 2.3.2 - Cross-Site Scripting via SEO Project Description Function
CVSS 5.4
e107 CMS 3.2.1 - Authenticated Path Traversal and Arbitrary File Write via Media Manager Upload Caption
CVSS 7.2
e107 CMS 3.2.1 - Authenticated Arbitrary File Write via Media Manager Import URL Parameter
CVSS 7.2
e107 CMS <3.2.1 - Authenticated RCE
CVSS 7.2
e107 CMS 3.2.1 - Authenticated Stored Cross-Site Scripting via SVG Upload Bypass
CVSS 4.8
e107 CMS 3.2.1 - Authenticated Reflected Cross-Site Scripting via News Comment URL Parameter
CVSS 9.8
Orangescrum 1.8.0 - Session Cookie Account Takeover
CVSS 8.8
Orangescrum 1.8.0 - Authenticated SQL Injection via Multiple Parameters
CVSS 7.1
Orangescrum 1.8.0 - Authenticated Cross-Site Scripting via Input Parameters
CVSS 5.4
WebTareas 2.4 - Reflected XSS (Unauthorised)
Uvdesk 1.1.4 - Stored XSS (Authenticated)
Online Traffic Offense Management System 1.0 - Multiple SQL Injection (Unauthenticated)
Online Traffic Offense Management System 1.0 - Privilage escalation (Unauthenticated)
Online Traffic Offense Management System 1.0 - Multiple XSS (Unauthenticated)
Online Traffic Offense Management System 1.0 - Multiple RCE (Unauthenticated)
News Portal v4.0 - SQL Injection (Unauthorized)
Aero CMS v0.0.1 - SQL Injection (no auth)