Javier Olmedo
19 exploits
Active since Feb 2018
Google Map Landkarten <= 4.2.3 - SQL Injection via cid/id/map Parameters
WordPress < 4.9.2 - Unauthenticated Denial of Service via Repeated JavaScript File Loading
Export Users to CSV < 1.1.1 - CSV Injection
CVSS 8.6
AbiSoft Ticketly 1.0 - Unauthenticated Privilege Escalation via add_user Action
CVSS 9.8
Easy XML Editor <1.7.8 - XML External Entity Injection
CVSS 8.1
Sentrifugo HRMS 3.2 - 'deptid' SQL Injection
XMLBlueprint <16.191112 - XML External Entity Injection
CVSS 8.1
all_in_one_favicon < 4.6 - Persistent Cross-Site Scripting via Favicon Text Fields
CVSS 4.8
Webtoffee WordPress Users & WooCommerce Customers Import Export <1....
CVSS 7.3
Ticketly 1.0 - 'name' SQL Injection
AbiSoft Ticketly 1.0 - SQL Injection via Multiple Parameters
CVSS 9.8
Rukovoditel < 2.4.1 - Cross-Site Scripting
CVSS 6.1
PHP Server Monitor 3.3.1 - Cross-Site Request Forgery
Jorani 0.6.5 - Stored Cross-Site Scripting via Language Parameter
CVSS 5.4
Jorani 0.6.5 - SQL Injection via Startdate or Enddate Parameter
CVSS 5.4
Artica Integria IMS 5.0.83 - Cross-Site Scripting via search_string Parameter
CVSS 6.1
Artica Integria IMS 5.0.83 - Cross-Site Request Forgery in User List Management
CVSS 6.5
Event Registration System with QR Code 1.0 - Authentication Bypass
Joplin < 1.0.184 - Stored Cross-Site Scripting and Arbitrary File Read
CVSS 5.4