Mr.tro0oqy

33 exploits Active since Jun 2008
EIP-2026-118191 EXPLOITDB perl WORKING POC
Yahoo Player 1.0 - '.m3u' / '.pls' / '.ypl' Local Buffer Overflow (SEH)
EIP-2026-115956 EXPLOITDB perl WORKING POC
NovaPlayer 1.0 - '.mp3' File Local Denial of Service (2)
EIP-2026-113385 EXPLOITDB perl WORKING POC
WebVision 2.1 - 'news.php?n' SQL Injection
EIP-2026-113121 EXPLOITDB html WORKING POC
VisionLms 1.0 - 'changePW.php' Remote Password Change
CVE-2009-1670 EXPLOITDB text WRITEUP
Tcpdb - Authentication Bypass
user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin accounts via unspecified vectors. NOTE: some of these details are obtained from third party information.
CVE-2009-1619 EXPLOITDB text WORKING POC
Teraway Filestream - Authentication Bypass
Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the twFSadmin cookie to 1.
CVE-2009-3531 EXPLOITDB perl WORKING POC
Universe Cms - SQL Injection
SQL injection vulnerability in vnews.php in Universe CMS 1.0.6 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2009-1618 EXPLOITDB text WORKING POC
Teraway Livehelp - Authentication Bypass
Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&usr=&alias=admin&userid=1 value for the TWLHadmin cookie.
CVE-2009-1617 EXPLOITDB text WORKING POC
Teraway Linktracker - Authentication Bypass
Teraway LinkTracker 1.0 allows remote attackers to bypass authentication and gain administrative access via a userid=1&lvl=1 value for the twLTadmin cookie.
EIP-2026-112255 EXPLOITDB text WORKING POC
SmilieScript 1.0 - Authentication Bypass
EIP-2026-112231 EXPLOITDB text WORKING POC
Smart PHP Poll - Authentication Bypass
CVE-2009-2209 EXPLOITDB text WORKING POC
RS-CMS 2.1 - SQL Injection
SQL injection vulnerability in rscms_mod_newsview.php in RS-CMS 2.1 allows remote attackers to execute arbitrary SQL commands via the key parameter.
EIP-2026-111346 EXPLOITDB text WORKING POC
Plogger - Remote File Disclosure
CVE-2009-3970 EXPLOITDB text WORKING POC
PHP Dir Submit - SQL Injection
SQL injection vulnerability in index.php in PHP Dir Submit (aka WebsiteSubmitter or Submitter Script) allows remote authenticated users to execute arbitrary SQL commands via the aid parameter in a showarticle action.
CVE-2009-1587 EXPLOITDB text WORKING POC
Kalptarudemos Php Site Lock - Authentication Bypass
index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by setting the login_id, group_id, login_name, user_id, and user_type cookies to certain values.
CVE-2009-2003 EXPLOITDB text WORKING POC
Ascad Networks Password Protector SD <1.3.1 - Auth Bypass
Ascad Networks Password Protector SD 1.3.1 allows remote attackers to bypass authentication and gain administrative access by setting the (1) c7portal and (2) cookname cookies to "admin."
CVE-2009-1739 EXPLOITDB text WORKING POC
Phpeasycode Pad Site Scripts - Improper Input Validation
PAD Site Scripts 3.6 allows remote attackers to bypass authentication and gain privileges as other users, including administrative privileges, by setting the authuser cookie parameter to a valid username.
CVE-2009-4876 EXPLOITDB text WRITEUP
Netrix Cms - Access Control
admin/cikkform.php in Netrix CMS 1.0 allows remote attackers to modify arbitrary pages via a direct request using the cid parameter.
EIP-2026-109812 EXPLOITDB text WORKING POC
MyWeight 1.0 - Arbitrary File Upload
CVE-2009-3975 EXPLOITDB text WORKING POC
Moa Gallery <1.2.0 - SQL Injection
SQL injection vulnerability in index.php in Moa Gallery 1.1.0 and 1.2.0 allows remote attackers to execute arbitrary SQL commands via the gallery_id parameter in a gallery_view action.
EIP-2026-108965 EXPLOITDB php SCANNER
Kamads Classifieds 2.0 - Admin Hash Disclosure
CVE-2008-2633 EXPLOITDB text WORKING POC
Joomla Com Joomradio - SQL Injection
Multiple SQL injection vulnerabilities in the EXP JoomRadio (com_joomradio) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) show_radio or (2) show_video action to index.php.
EIP-2026-108295 EXPLOITDB text WORKING POC
Joomla! Component com_calendario - Blind SQL Injection
EIP-2026-108412 EXPLOITDB text WORKING POC
Joomla! Component com_Joomlaoads - 'packageId' SQL Injection
EIP-2026-108527 EXPLOITDB text WORKING POC
Joomla! Component com_schools - SQL Injection