Manuel García Cárdenas
23 exploits
Active since Sep 2014
SyncBreeze < 10.2.12 - Denial of Service via Host Header Buffer Overflow
CVSS 7.5
PyroBatchFTP < 3.19 - Buffer Overflow
Zoph < 0.9.1 - Cross-Site Scripting via photographer_id or _crumb Parameter
WordPress Plugin Spider Event Calendar 1.5.51 - Blind SQL Injection
Wechat Broadcast < 1.2.0 - Path Traversal via Image.php URL Parameter
CVSS 9.8
XAMPP 1.8.1 - Cross-Site Scripting via WriteIntoLocalDisk Method
Pie Register < 3.0.10 - SQL Injection via Invitation Codes Grid
CVSS 9.8
WordPress Media Player 1.0 - Local File Inclusion
CVSS 9.8
Localize My Post 1.0 - Path Traversal via AJAX Include File Parameter
CVSS 7.5
WebsiteBaker 2.8.3 - Cross-Site Scripting via QUERY_STRING or section_id Parameter
Textpattern < 4.6.2 - SQL Injection via qty Parameter
CVSS 9.8
telaen < 1.3.1 - Exposure of Sensitive Information via Crafted URL Request
CVSS 5.3
telaen < 1.3.1 - Cross-Site Scripting via f_email Parameter
CVSS 6.1
Telaen < 1.3.1 - Open Redirect via redir.php URL Parameter
CVSS 6.1
UliCMS v9.8.1 - SQL Injection
Piwigo <2.5.5, <2.6.x before 2.6.4, <2.7.x before 2.7.2 - SQL Injec...
phpMyAdmin 4.9.0.1 - Cross-Site Request Forgery in Setup Page
CVSS 6.5
PHP-Fusion 7.02.07 - Blind SQL Injection
ImpressCMS 1.3.9 - SQL Injection
Exponent CMS < 2.3.9 - SQL Injection via id, title, or content_id Parameter
CVSS 9.8
Composr CMS 10.0.30 - Persistent Cross-Site Scripting
Asteriskguru Queue Statistics - 'warning' Cross-Site Scripting
Kodi < 17.6 - Stored Cross-Site Scripting via Playlist
CVSS 6.1