Matthew Murphy
51 exploits
Active since Aug 2002
BadBlue - Unauthenticated Arbitrary File Read via Hex-Encoded Null Byte
BadBlue Enterprise Edition <1.74 - RCE
Working Resources 1.7.x/2.15 BadBlue - 'ext.dll' Command Execution
BadBlue Personal Edition 1.7.3 - Cross-Site Scripting via cleanSearchString() Function
BadBlue 1.7 and 1.7.2 - Cross-Site Scripting via ext.dll ISAPI
OmniHTTPd - Cross-Site Scripting via test.php, test.shtml, or redir.exe
OmniHTTPd 1.1/2.0.x/2.4 - Sample Application URL Encoded Newline HTML Injection
Perception LiteServe 2.0.1 - Cross-Site Scripting via Host Header or Directory Query String
Lil' HTTP Server - Cross-Site Scripting via urlcount.cgi REPORT Function
Lil' HTTP Server - Cross-Site Scripting via Name or E-mail Parameters
OmniHTTPd - Cross-Site Scripting via test.php, test.shtml, or redir.exe
SolarWinds TFTP Server <5.0.55 - Path Traversal
Perception LiteServe 2.0.1 - Cross-Site Scripting via Host Header or Directory Query String
Windows Media Player 9-10 - Remote Code Execution via Long EMBED src Attribute
Microsoft Foundation Class Library - Buffer Overflow in CHttpServer::OnParseError via Long Query String
Windows Media Player 9-10 - Remote Code Execution via Long EMBED src Attribute
Microsoft Internet Explorer 5 - Classic Mode FTP Client Cross Domain Scripting
Microsoft Outlook Express 5/6 - Spoofable File Extensions
Microsoft IE - Race Condition
Microsoft Internet Explorer 6 - Shell.Application Object Script Execution
Imatix Xitami 2.5b4 and 2.5b5 - Cross-Site Scripting via User-Agent Field
AN HTTPD 1.x - Count.pl Directory Traversal
acFTP 1.4 - Improper Authentication
BadBlue - Denial of Service via Empty HTTP GET Request
Microsoft Internet Explorer 5.0-6.0 - Denial of Service via Recursive HTML Object Handling