James Bercegay
104 exploits
Active since Mar 2004
D-Link DNS-343 ShareCenter <1.05 - Command Injection
CVSS 9.8
XOOPS <= 2.0.11 - SQL Injection via XMLRPC LoginUser Function
WHM AutoPilot <2.4.6.5 - Info Disclosure
WHM AutoPilot <= 2.4.6.5 - Remote File Inclusion via server_inc Parameter
ReviewPost PHP Pro < 2.84 - Unauthenticated Arbitrary File Upload via Multiple Extensions Bypass
ReviewPost PHP Pro < 2.84 - SQL Injection via showcat.php cat Parameter or addfav.php product Parameter
Pligg CMS 9.9.5 - SQL Injection via Category or ID Parameter
PHPLib < 7.4a - SQL Injection via id Variable
PhotoPost PHP Pro < 4.85 - Cross-Site Scripting via showgallery.php Parameters
PhotoPost PHP Pro 4.6.x - Cross-Site Scripting via Multiple Parameters
Mambo < 4.5.3h - SQL Injection via mosGetParam and mosMenuCheck Functions
Invision Power Board <= 2.0.3 - SQL Injection via Cookie Password Hash
Help Center Live - Cross-Site Request Forgery via view.php
CVSS 6.5
Help Center Live - SQL Injection via Multiple Parameters
Gallery 2 up to 2.0.2 - Directory Traversal via Session Cookie
AZ Bulletin board <1.0.08 - Path Traversal
D-Link DNS-343 ShareCenter <1.05 - Command Injection
CVSS 9.8
Pligg CMS < 9.9 - Path Traversal via Trackback URL or Template Parameter
Pligg CMS < 9.9.0 - Cross-Site Scripting via Search Keyword Parameter
Turnkey PHP Live Helper <2.0.1 - Code Injection
Turnkey PHP Live Helper <2.0.1 - SQL Injection
WebSVN < 2.0 - Path Traversal and Arbitrary File Write via RSS Rev Parameter
WebSVN <= 2.0 - Cross-Site Scripting via PATH_INFO
Trillian Pro < 2.01 - Design Error
Psychostats < 2.2.4 - Cross-Site Scripting via Login Parameter