Kacper (a.k.a Rahim)
112 exploits
Active since Mar 2006
Csaba Godor SAPID Blog Beta 2 - RCE
phpbp RC3 (2.204) and earlier - SQL Injection via Comment Forum
JAF CMS 4.0 RC1 - Remote File Inclusion via Forum Website Parameter
Php Blue Dragon <2.9.1 - SQL Injection
Php Blue Dragon <= 2.9.1 - Cross-Site Scripting via m Parameter
David Bennett PHP-Post <1.0 - Path Traversal
F3Site 2.1 - Cross-Site Scripting via News Comment Autor Field
Dmitry Sheiko SAPID Shop <1.2 - RCE
SAPID CMS 123 rc3 - Remote Code Execution via root_path Parameter
Xtreme/Ditto News 1.0 - 'post.php' Remote File Inclusion
YapBB < 1.2_beta2 - Remote File Inclusion via GLOBALS[include_Bit] Parameter
WSN Forum < 1.3.4 - Remote Code Execution via Avatar Image Path Manipulation
Wikiwig - Remote File Inclusion via WK[wkPath] Parameter
WebprojectDB <= 0.1.3 - Remote File Inclusion via INCDIR Parameter
VideoDB 2.2.1 - Remote File Inclusion via config[pdf_module] Parameter
Webspotblogging 3.0.1 - Remote Code Execution via Path Parameter in Multiple Scripts
WebText CMS <0.4.5.2 - Code Injection
ttCMS 4 and earlier - Remote File Inclusion via lib_path Parameter
Ultimate PHP Board < 2.0 - Remote File Inclusion via _CONFIG[skin_dir] Parameter
The Bible Portal Project <2.12 - RCE
T.G.S. CMS < 0.1.7 - SQL Injection via myauthorid Cookie
Dan Jensen Travelsized CMS <0.4 - RCE
Socketwiz Bookmarks < 2.0 - Remote File Inclusion via smarty_config.php root_dir Parameter
SolidState < 0.4 - Remote File Inclusion via base_path Parameter
SportsPHool 1.0 - Remote File Inclusion via mainnav Parameter