Ivan Sanchez
21 exploits
Active since Oct 2007
http4k-format-xml 5.0.0.0-5.41.0.0 - XML External Entity Injection
CVSS 9.8
Microsoft Organization Chart 2.00 - DoS/Code Injection
Apple QuickTime 7.6.9 - 'QuickTimePlayer.dll' ActiveX Buffer Overflow
Microsoft Word 2000 9.0.2812 and 2003 11.8106.8172 - Denial of Service or Remote Code Execution via Crafted .doc File
Zen Cart 2008 - Cross-Site Scripting via Advanced Search Keyword Parameter
Zen Cart 2008 - SQL Injection via Advanced Search Keyword Parameter
SocketMail 2.2.1 - Cross-Site Scripting via lostpwd.php lost_id Parameter
SocketKB 1.1.5 - Cross-Site Scripting via art_id or node Parameter
NTSOFT BBS E-Market Professional - Cross-Site Scripting via Page, bt_code, or b_no Parameters
NTSOFT BBS E-Market Professional - Multiple Cross-Site Scripting Vulnerabilities (2)
Ovidentia 6.7.5 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
Horde Groupware - Cross-Site Scripting via Timestamp Parameter
Horde Groupware - Cross-Site Scripting via Timestamp Parameter
Helios Calendar 1.2.1 Beta - Cross-Site Scripting via Username Parameter
GeeCarts - Cross-Site Scripting via id Parameter
GeeCarts - Cross-Site Scripting via id Parameter
Horde Groupware - Cross-Site Scripting via Timestamp Parameter
GeeCarts - Cross-Site Scripting via id Parameter
MailBee WebMail < 3.4 - Cross-Site Scripting via Login Mode Parameters
MailBee WebMail < 3.4 - Cross-Site Scripting via Login Mode Parameters
Novell Open Enterprise Server 1.x - XSS