James Bercegay
104 exploits
Active since Mar 2004
Help Center Live - Cross-Site Scripting via Multiple Input Parameters
Gregarius < 0.5.4 - SQL Injection via rsargs Array Parameter
Geeklog 1.4.0-1.4.0sr1 and 1.3.11-1.3.11sr4 - SQL Injection via Userid or Sessid Parameter
e107 < 0.7.11 - Arbitrary Variable Overwriting
CubeCart < 3.0.12 - Cross-Site Scripting via Links Array
CS-Cart <= 1.3.5 - SQL Injection via cs_cookies[customer_user_id] Cookie Parameter
Crafty Syntax Live Help <2.14.6 - SQL Injection
Claroline < 1.7.7 - Remote Code Execution via extAuthSource Parameter
Woltlab Burning Board 2.x and earlier - SQL Injection via Email Verification
AZ Bulletin Board 1.0.07a-1.0.07c - Remote File Inclusion via dir_src or abs_layer Parameter
AutoRank PHP < 2.0.4 - SQL Injection (PoC)
Aardvark Topsites < 4.1.0 - Multiple Vulnerabilities
Advanced Electron Forum < 1.0.7 - Remote Code Execution via BBCode Email Parameter
ADOdb 4.71 - Cross-Site Scripting via next_page Parameter
MetaDot < 5.6.5.4b5 - Multiple Vulnerabilities
Max Web Portal < 1.30 - Multiple Vulnerabilities
WinMX < 2.6 - Design Error
Snitz Forums 2000 < 3.4.0.3 - Multiple Vulnerabilities
phpLinks < 2.1.2 - Multiple Vulnerabilities
PHP Topsites < 2.2 - Multiple Vulnerabilities
P-Synch < 6.2.5 - Multiple Vulnerabilities
MegaBrowser < 0.71b - Multiple Vulnerabilities
FTP Service < 1.2 - Multiple Vulnerabilities
Zen Cart 1.2.0-1.3.8a - SQL Injection via Shopping Cart ID Parameter
Webmin < 1.920 - 'rpc.cgi' Remote Code Execution (Metasploit)