James Bercegay
104 exploits
Active since Mar 2004
PHPLib < 7.4a - Remote Code Execution via Base64-Encoded Cookie
phpRPC <= 0.7 - Remote Code Execution via Base64 Tag in RPC Decoder
phpShop < 0.6.1-b - Multiple Vulnerabilities
PEAR LiveUser <= 0.16.8 - Directory Traversal via Remember Me Cookie
php-calendar < 0.10.1 - Remote Code Execution via phpc_root_path Parameter
Turnkey PHP Live Helper <2.0.1 - Code Injection
PhotoPost Classifieds < 2.01 - Multiple Vulnerabilities
PhotoPost PHP Pro < 4.85 - SQL Injection via cat or ppuser Parameter
PhotoPost PHP Pro 4.6.x - SQL Injection via Multiple Parameters
Phorum < 5.0.3 Beta - Cross Site Scripting
PEAR XML_RPC < 1.3.0 - Remote Code Execution
Open Bulletin Board <= 1.0.6 - Cross-Site Scripting via Multiple Parameters
osCommerce < 2.2-MS2 - Multiple Vulnerabilities
MySQL Eventum <= 1.5.5 - SQL Injection via Multiple Functions
Mambo 4.5.3, 4.5.3h - Path Traversal via mos_change_template Parameter
Mambo < 4.5.4 - SQL Injection
Mambo < 4.5 - Multiple Vulnerabilities
Invision Power Board (IP.Board) < 1.3 - SQL Injection
Invision Power Top Site List < 2.0 Alpha 3 - SQL Injection (PoC)
Invision Power Top Site List < 1.1 RC 2 - SQL Injection
Invision Power Board <= 2.0.3 - Cross-Site Scripting via Highlite Parameter
Invision Power Board (IP.Board) < 2.0 Alpha 3 - SQL Injection (PoC)
Invision Power Board (IP.Board) < 1.3.1 - Design Error
Invision Gallery 1.0.1 - SQL Injection via img/cat/sort_key/order_key/user/album Parameters
Gallery 2 up to 2.0.2 - Cross-Site Scripting via X-Forwarded-For Header