Janek Vind "waraxe"
45 exploits
Active since May 2007
phpMyAdmin <3.5.8 and <4.0.0-rc3 - Authenticated RCE
phpMyAdmin <3.5.8 and <4.0.0-rc3 - Authenticated RCE
phpMyAdmin <4.0.0-rc3 - Path Traversal
php-fusion < 7.02.06 - SQL Injection via Multiple Parameters
php-fusion < 7.02.06 - Cross-Site Scripting via Multiple Parameters
Rejected
php-fusion < 7.02.06 - Authenticated Path Traversal and Arbitrary File Execution
php-fusion < 7.02.06 - Information Disclosure via Predictable Backup Filename
Coppermine Photo Gallery < 1.5.20 - Authenticated Cross-Site Scripting via Keywords Parameter
TorrentTrader Classic 1.09 - Info Disclosure
TorrentTrader Classic 1.09 - Info Disclosure
TorrentTrader Classic 1.09 - Info Disclosure
CVSS 7.5
TorrentTrader Classic 1.09 - SQL Injection
TorrentTrader Classic 1.09 - Authenticated Cross-Site Scripting via Multiple Input Fields
RavenNuke 2.30 - Authenticated Remote Code Execution via Your Account Module Avatarlist preg_replace
RavenNuke 2.30 - Path Disclosure via aFonts Array Parameter
RavenNuke 2.30 - Authenticated PHP Code Injection via Your Account Custom Fields
RavenNuke 2.30 - Authenticated SQL Injection via Resend_Email Module user_prefix Parameter
Coppermine Photo Gallery < 1.4.14 - Remote Code Execution via ImageMagick Picture Processing Parameters
Orbit Downloader <= 2.8.7 - Arbitrary File Write via ActiveX Control Argument Injection
ZenPhoto 1.4.3.3 - Multiple Vulnerabilities
WordPress Plugin Spider Catalog 1.4.6 - Multiple Vulnerabilities
WordPress Plugin social discussions 6.1.1 - Multiple Vulnerabilities
WordPress Plugin Spider Event Calendar 1.3.0 - Multiple Vulnerabilities
WordPress < 2.2 - SQL Injection via Cookie Parameter