Ivano Binetti
29 exploits
Active since Feb 2012
Fork CMS 3.2.4 - Local File Inclusion / Cross-Site Scripting
Fork CMS 3.2.5 - Multiple Vulnerabilities
Wolf CMS <= 0.75 - Cross-Site Request Forgery via Admin Endpoints
Sitecom WLM-2501 - Cross-Site Request Forgery via pskValue Parameter
Sitecom WLM-2501 - Cross-Site Request Forgery via pskValue Parameter
Wolf CMS < 0.75 - Cross-Site Scripting via User Add Parameters
WordPress < 3.3.1 - Cross-Site Request Forgery via Nonce Reuse
Nikola Posa Webfoliocms1.0.2 - CSRF
Simple PHP Agenda < 2.2.8 - Cross-Site Request Forgery via Admin and Event Management
SyndeoCMS < 3.0.01 - Authenticated Stored Cross-Site Scripting via Email Parameter
SyndeoCMS < 3.0.00 - Cross-Site Request Forgery via User Account Creation
SocialCMS 1.0.2 - Cross-Site Request Forgery in Administrator Account Management
RazorCMS < 1.2.1 - Cross-Site Request Forgery via showcats Action
Plume CMS < 1.2.4 - Cross-Site Request Forgery via News Page Creation
Plume CMS <= 1.2.4 - Cross-Site Scripting via User Email, Name, or Comment Author Parameters
Fork CMS 3.2.4 - Cross-Site Scripting via Report or Error Parameter
FlexCMS < 3.2.1 - Cross-Site Request Forgery via Profile Edit and Page Creation
Drupal < 7.12 - Cross-Site Request Forgery via User Logout URI
DFLabs PTK < 1.0.5 - Cross-Site Request Forgery in Logout Function
Contao CMS < 2.11.0 - Cross-Site Request Forgery via User, News, or Newsletter Deletion
Axous < 1.1.1 - Cross-Site Request Forgery and Cross-Site Scripting
CVSS 8.8
Apache Tomcat < 5.5.25 - Cross-Site Request Forgery via Manager Application
Cisco Linksys WAG54GS - Cross-Site Request Forgery (Change Admin Password)
Sitecom WLM-2501 - Cross-Site Request Forgery in Multiple Admin Forms
D-Link DSL-2740B Firmware EU_1.0 - Unauthenticated Authentication Bypass via login.cgi