Joxean Koret
31 exploits
Active since Sep 2004
Samba is_known_pipename() Arbitrary Module Load
Samba is_known_pipename() Arbitrary Module Load
CVSS 9.8
Samba is_known_pipename() Arbitrary Module Load
CVSS 9.8
eScan Web Management Console <5.5-2 - Command Injection
eScan Web Management Console <5.5-2 - Command Injection
Comodo Internet Security - HIPS/Sandbox Escape
WarFTPd 1.82.00-RC11 - Authenticated Denial of Service via Format String in FTP Commands
WFTPD Pro Server 3.23.1.1 - Authenticated Buffer Overflow via APPE Command
Microsoft Windows Media Digital Rights Management - ActiveX Control Buffer Overflow (PoC)
Firebird <1.5.2.4731 - Buffer Overflow
webcalendar 0.9.x - Multiple Vulnerabilities
TUTOS 1.1 - SQL Injection via file_overview.php link_id Parameter
TUTOS 1.1 - Cross-Site Scripting via Search Field or t Parameter
Mambo Open Source 4.5 (1.0.9) - Cross-Site Scripting via Itemid, mosmsg, or limit Parameters
Mambo 4.5 (1.0.9) - Remote File Inclusion via mosConfig_absolute_path Parameter
eGroupWare <= 1.0.00.003 - Cross-Site Scripting via Multiple Input Fields
Oracle E-Business Suite Financials 12 - 'jtfwcpnt.jsp' SQL Injection
OpenWFE 1.4.x - Cross-Site Scripting / Connection Proxy
Oracle Secure Backup 10g - 'exec_qr()' Command Injection
Oracle 10g - SYS.DBMS_CDC_IMPDP.BUMP_SEQUENCE PL / SQL Injection
Oracle Internet Directory 9.0.4.3, 10.1.2.3, 10.1.4.2 - Denial of Service via Malformed LDAP Request
Oracle TimesTen - Remote Format String (PoC)
Oracle Database 10.1.0.5 - SQL Injection in Change Data Capture and Data Pump Metadata API
Oracle 10g Release 1 - SQL Injection via Multiple Parameters in SYS.KUPV$FT and SYS.KUPV$FT_INT Packages
Inkscape 0.41-0.42.2 - Buffer Overflow in SVG Importer Style Property Handling