JosS
86 exploits
Active since Dec 2005
pPIM 1.01 - 'notes.php' Remote Command Execution
Proverbs Web Calendar <1.1 - SQL Injection
Pre Real Estate Listings - SQL Injection via Search Parameter
Pre Job Board - SQL Injection via JobSearch.php Position or Keyword Parameter
pppblog < 0.3.8 - Directory Traversal via File Array Parameter
Phlatline Personal Information Manager 1.01 - Path Traversal via Notes.php ID Parameter
phpabook < 0.8.8b - Remote File Inclusion via UserInfo Cookie
PHPEcho CMS <2.0-rc3 - SQL Injection
PHP JOBWEBSITE PRO - SQL Injection via JobSearch3.php kw or position Parameter
Multiple Time Sheets <5.0 - Path Traversal
myWebland myStats - IP Address Restriction Bypass via X-Forwarded-For Header
MySQL Quick Admin 1.5.5 - Path Traversal via Language Cookie
myEvent 1.6 - SQL Injection via viewevent.php eventdate Parameter
My PHP Indexer 1.0 - Path Traversal via d and f Parameters
Multi-lingual E-Commerce System 0.2 - RCE
Maran PHP Shop - Unauthenticated Authentication Bypass via User Cookie
LokiCMS 0.3.4 - Unauthenticated Path Traversal via Language Parameter
LokiCMS <= 0.3.4 - Path Traversal via Page Parameter
Maran PHP Shop - SQL Injection via prod.php cat Parameter
MiNBank 1.5.0 - Remote Command Execution
LightOpenCMS 0.1 - Path Traversal via cwd Parameter
LightBlog 9.8 - Path Traversal and Arbitrary File Execution via Username Parameter
Kure 0.6.3 - Path Traversal via Post and Doc Parameters
IP Reg <= 0.4 - SQL Injection via location_id or vlan_id Parameter
FOSS Gallery 1.0 beta - Unauthenticated Arbitrary File Upload via processFiles.php