James Bercegay
104 exploits
Active since Mar 2004
dBpowerAMP Audio Player and Music Converter - Buffer Overflow via Long Filename in Playlist
PeerCast < 0.1211 - Remote Code Execution via Format String in URL
xpcom - Denial of Service via Nested DIV Tags
XOOPS <= 2.0.11 - Cross-Site Scripting via Order or CID Parameter
Qualiteam X-Cart < 4.1.3 - Remote Code Execution via cmpi.php Dynamic Variable Evaluation
WordPress <= 1.5.1.2 - SQL Injection via HTTP_RAW_POST_DATA
WHM AutoPilot <= 2.4.6.5 - Cross-Site Scripting via site_title or http_images Parameter
vBulletin < 3.0.0 RC4 - Cross Site Scripting
ViArt Shop < 3.5 - SQL Injection via products_rss.php category_id Parameter
vtiger CRM < 4.2 - SQL Injection via HelpDesk user_name and date Parameters
WebSVN 1.x - Remote Code Execution via Username preg_replace Eval Switch
Turnkey Web Tools SunShop <4.1.5 - SQL Injection
Synology Photostation 6.7.2-3429 - Remote Code Execution (Metasploit)
SquirrelMail <= 1.4.4 - Remote Code Execution via Extract Function
SquirrelMail <1.4.7 - Code Injection
ReviewPost PHP Pro < 2.84 - Cross-Site Scripting via si, cat, page, or report Parameter
Plogger <= 3.0 - SQL Injection via checked Parameter
PostNuke < 0.726 Phoenix - Multiple Vulnerabilities
Pligg CMS < 9.9.0 - SQL Injection via Multiple Parameters
PEAR XML_RPC < 1.3.0 and PHPXMLRPC < 1.1 - Remote Code Execution via Unsanitized XML Input
PHPX 3.0-3.2.6 - Cross-Site Request Forgery via Admin URL Execution
phpGedView < 2.65 beta 5 - Multiple Vulnerabilities
phpBB < 2.0.6d - Cross Site Scripting
phpRPC <= 0.7 - Remote Code Execution via Base64 Tag in RPC Decoder
phpShop < 0.6.1-b - Multiple Vulnerabilities