LiquidWorm
790 exploits
Active since Jun 2006
MTP Guestbook 1.0 - Multiple Cross-Site Scripting Vulnerabilities
Moodle < 2.5.9, 2.6.x < 2.6.9, 2.7.x < 2.7.6, 2.8.x < 2.8.4 - XSS via IMG Alt/Title
Manx 1.0.1 - '/admin/admin_pages.php?Filename' Traversal Arbitrary File Access
Manx 1.0.1 - '/admin/admin_blocks.php?Filename' Traversal Arbitrary File Access
MantisBT < 1.2.4 - Remote Code Execution via db_type Parameter in admin/upgrade_unattended.php
MantisBT < 1.2.4 - Information Disclosure via Invalid db_type Parameter
Lunar CMS < 3.3 - Cross-Site Request Forgery
Lunar CMS 3.3 - Remote Command Execution
Microweber 1.0.3 - Persistent Cross-Site Scripting / Cross-Site Request Forgery (Add Admin)
Microweber 1.0.3 - Arbitrary File Upload / Filter Bypass / PHP Remote Code Execution
MG2 0.5.1 - Multiple Cross-Site Scripting Vulnerabilities
Manx 1.0.1 - '/admin/tiny_mce/plugins/ajaxfilemanager_OLD/ajax_get_file_listing.php' Multiple Cross-Site Scripting Vulnerabilities
Manx 1.0.1 - '/admin/tiny_mce/plugins/ajaxfilemanager/ajax_get_file_listing.php' Multiple Cross-Site Scripting Vulnerabilities
Kemana Directory 1.5.6 - 'qvc_init()' Cookie Poisoning CAPTCHA Bypass
LimeSurvey 2.00+ (build 131107) - Multiple Vulnerabilities
KindEditor - 'name' Cross-Site Scripting
Kemana Directory 1.5.6 - Remote Code Execution
Kemana Directory 1.5.6 - kemana_admin_passwd Cookie User Password Hash Disclosure
Kemana Directory 1.5.6 - Database Backup Disclosure
Kemana Directory 1.5.6 - 'task.php' Local File Inclusion
CMScout IBrowser TinyMCE Plugin <1.4.1 - Path Traversal
Intel Modular Server System 10.18 - Cross-Site Request Forgery (Change Admin Password)
InfraPower PPS-02-S Q213V1 - Multiple Cross-Site Scripting Vulnerabilities
InfraPower PPS-02-S Q213V1 - Local File Disclosure
InfraPower PPS-02-S Q213V1 - Insecure Direct Object Reference