Kacper Szurek
72 exploits
Active since Nov 2014
IVPN Client 2.6.1 - Local Privilege Escalation
WordPress Plugin Simple Ads Manager 2.9.4.116 - SQL Injection
WP EasyCart < 3.0.8 - Authenticated Arbitrary File Upload via Banner Upload Script
Shareaholic < 7.6.0.9 - Authenticated Cross-Site Scripting via location[id] Parameter
WonderPlugin Audio Player < 2.0 - Cross-Site Scripting via item[name] or item[customcss] Parameter
WordPress Plugin WP Support Plus Responsive Ticket System 7.1.3 - Privilege Escalation
WP EasyCart < 3.0.8 - Authenticated Arbitrary File Upload via Banner Upload Script
WordPress Plugin Video Gallery 2.7 - SQL Injection
WP Symposium <14.11 - SQL Injection
Photo Gallery 1.2.5 - Info Disclosure
CVSS 8.8
WordPress Plugin Admin Management Xtended 2.4.0 - Privilege escalation
Cart66 Lite < 1.5.1.17 - Authenticated SQL Injection via id Parameter
WordPress Plugin Double Opt-In for Download 2.0.9 - SQL Injection
WordPress <2.7.3 - Authenticated RCE
CVSS 8.8
dukapress < 2.5.3 - Path Traversal via src Parameter in dp_image.php
Wordpress <0.5.10 - Authenticated RCE
CVSS 8.2
Google Doc Embedder <2.5.15 - SQL Injection
WP Marketplace <2.4.1 - Path Traversal
CVSS 4.3
Nextend Facebook Connect <1.5.1 - XSS
Paid Memberships Pro <1.7.15 - Path Traversal
WordPress Pie Register <2.0.14 - RCE
Tiny Tiny RSS - Blind SQL Injection
Tiki Wiki CMS 15.0 - Arbitrary File Download
QNAP PhotoStation 5.2.4 / MusicStation 4.8.4 - Authentication Bypass
QNAP QTS Helpdesk < 1.1.12 - Unauthenticated SQL Injection
CVSS 7.5