Kacper Szurek
72 exploits
Active since Nov 2014
phpMyFAQ 2.9.0 - Persistent Cross-Site Scripting
MiniBB < 3.1 - SQL Injection via Unsubscribe Code Parameter
GitList 0.6 - Remote Code Execution
GLPI < 0.85 - Authenticated SQL Injection via Dropdown Condition Parameter
GitStack 2.3.10 - Remote Code Execution
GitStack <2.3.10 - Privilege Escalation
CVSS 9.8
FreiChat 9.6 - SQL Injection via Time Parameter
e107 CMS 2.1.2 - Privilege Escalation
Dolphin 7.3.0 - Error-Based SQL Injection
Codoforum 2.5.1 - Path Traversal via Path Parameter
Chamilo LMS 1.9.8 - Blind SQL Injection
GitList 0.6.0 - Argument Injection (Metasploit)
AbanteCart 1.2.7 - Cross-Site Scripting
GitList 0.6.0 - Argument Injection (Metasploit)
Gitea 1.4.0 - Remote Code Execution
Manage Engine Exchange Reporter Plus - Remote Code Execution (Metasploit)
ManageEngine Exchange Reporter Plus < Build 5311 - Remote Code Execution
ManageEngine Desktop Central < 10.0 - Remote Code Execution via Help Desk Video Upload
CVSS 9.8
Manage Engine Exchange Reporter Plus - Remote Code Execution (Metasploit)
WD My Cloud Mirror 2.11.153 - Authentication Bypass / Remote Code Execution
Synology Photo Station < 6.7.3-3432 and 6.3-2967 - Exposure of Sensitive System Information via index.php
CVSS 7.5
HomeMatic Zentrale CCU2 - Remote Code Execution