Khashayar Fereidani
102 exploits
Active since Sep 2007
Lanai Core 0.6 - Path Traversal via Download Module f Parameter
Fantastico De Luxe Module for cPanel - Path Traversal and Arbitrary File Execution via scriptpath_show Parameter
ezphotogallery 2.1 - SQL Injection via gallery.php Username Parameter
ezphotogallery 2.1 - Cross-Site Scripting via galleryid, size, or imageid Parameters
devalcms 1.4a - Cross-Site Scripting via currentpath Parameter
phpwebgallery 1.3.4 - Cross-Site Scripting via lang[access_forbiden] and lang[ident_title] Parameters
Affiliate Market 0.1 BETA - Cross-Site Scripting via sideblock4 Parameter
Softbiz Freelancers Script 1 - Stored Cross-Site Scripting via signin.php errmsg Parameter
DMCMS 0.7.4 - SQL Injection via Page Parameter
Siteman 2.0.x2 - Authenticated Path Traversal via Module Parameter
Virtual Design Studio vlbook 1.21 - Cross-Site Scripting via l Parameter
EasyNews 4.0 - SQL Injection via read Parameter in edp_Help_Internal_News Action
EasyNews 4.0 - Cross-Site Scripting via Read Parameter in edp_pupublish Action
BlogPHP 2.0 - SQL Injection via id Parameter
A-Blog 2 - Cross-Site Scripting via Search Words Parameter
DeeEmm.com DM CMS 0.7.0.Beta and 0.7.4 - SQL Injection via id Parameter
COMRaider - File Creation/Overwrite
vlbook 1.21 - Path Traversal via l Parameter
Softbiz Ad Management plus Script 1 - SQL Injection
Siteman 2.0.x2 - Cross-Site Scripting via Module Parameter
Softbiz Link Directory Script - SQL Injection
Stash 1.0.3 - SQL Injection via Username or Download Parameter
Softbiz Banner Exchange Network Script 1.0 - SQL Injection
Softbiz Jobs and Recruitment Script - SQL Injection via browsecats.php cid Parameter
Softbiz Auctions Script - SQL Injection