Michael Brooks
41 exploits
Active since Nov 2004
iGeneric iG Shop < 1.4 - SQL Injection via id or user_login_cookie Parameter
DD-WRT < 24 - Cross-Site Request Forgery via apply.cgi Parameters
Profense Web App Firewall <2.6.3 - XSS
Majordomo <20110131 - Path Traversal
XAMPP 1.6.8 - Cross-Site Request Forgery via xampppasswd Parameter
iGeneric iG Shop 1.4 - SQL Injection via compare_product.php id Parameter
hlstats 1.20-1.34 - SQL Injection via Login Form killLimit Parameter
XAMPP 1.6.8 - Remote Code Execution via SERVER Superglobal Variable Spoofing
Web On Windows ActiveX 2 - Arbitrary File Write and Code Execution via WriteIniFileString and ShellExecute Methods
Profense Web Application Firewall 2.6.2-2.6.3 - CSRF
ManageEngine Firewall Analyzer 5 - Cross-Site Request Forgery / Cross-Site Scripting
Yaws-Wiki 1.88-1 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
WordPress Core 2.3.1 - Unauthorized Post Access
Ultimate PHP Board 1.96 GOLD - Multiple Vulnerabilities
Torrentflux - Cross-Site Request Forgery
Simple Machines Forum 1.1.3 - SQL Injection via Userspec Parameter
SMF 1.1.4 - Audio CAPTCHA Security Bypass
Simple Directory Listing 2 - Cross-Site Arbitrary File Upload
phpvidz 0.9.5 - Administrative Credentials Disclosure
Pligg CMS 1.1.2 - Blind SQL Injection / Cross-Site Scripting
Pligg CMS 9.9.5 - Cross-Site Request Forgery / Protection Bypass / Captcha Bypass
phpay 2.02.01 - Path Traversal via Config Parameter
phpRPG 0.8 - Session Hijacking via Insecure Session File Storage
phpMyAdmin 2.11.x-2.11.9.3 and 3.x-3.1.0.9 - Cross-Site Request Forgery via tbl_structure.php
phpBB 2.x < 2.0.11 - Remote Code Execution via Double-Encoded Highlight Parameter