InjEctOr5
73 exploits
Active since May 2008
Easy Scripts Answer and Question Script - Unauthenticated Password Change via myaccount.php
Easy Scripts Answer and Question Script - Unauthenticated Arbitrary File Upload via myaccount.php
Easy Scripts Answer and Question Script - Authenticated SQL Injection via Userid Parameter
Easy Scripts Answer and Question Script - Cross-Site Scripting via questionid Parameter
WeBid 0.5.4 - Arbitrary CSS File Modification via file Parameter
WeBid 0.5.4 - SQL Injection via Admin Panel Username Parameter
AJ Auction Pro Platinum 2 - SQL Injection
Brim 2.0.0 - Authenticated SQL Injection via Tasks Plugin Search Action
cpLinks 1.03 - SQL Injection via Admin Username or Search Parameters
Hispah Text Links Ads 1.1 - SQL Injection via idcat Parameter
WeBid 0.5.4 - Unauthenticated Sensitive Information Exposure via Direct Request
W2B Restaurant 1.2 - 'conf.inc' Configuration File Disclosure
VidiScript - Authenticated Remote Code Execution via Avatar Upload
VidSharePro - Authenticated Arbitrary File Upload and Remote Code Execution
Ticket Support Script - 'ticket.php' Arbitrary File Upload
Umer Inc Songs Portal - SQL Injection
Tips Complete Website 1.2.0 - SQL Injection
spice_classifieds - SQL Injection via cat_path Parameter
Social Groupie - SQL Injection via id Parameter
Social Groupie - Authenticated Arbitrary File Upload via Photos/create_album.php
Riddles Website 1.2.1 - SQL Injection
PowerUpload 2.4 - Unauthenticated Authentication Bypass via MIME-Encoded Admin Cookie
phpEmployment - 'conf.inc' File Disclosure
PHPEasyData 1.5.4 - SQL Injection via annuaire.php cat_id Parameter
phpAdBoard - 'conf.inc' Remote Configuration File Disclosure