Robert Giruckas

2 exploits Active since Jun 2014
CVE-2014-4306 EXPLOITDB WRITEUP
WebTitan < 4.01 - Path Traversal via Logfile Parameter
Directory traversal vulnerability in logs-x.php in WebTitan before 4.04 allows remote attackers to read arbitrary files via a .. (dot dot) in the logfile parameter in a download action.
CVE-2014-4307 EXPLOITDB text WRITEUP
WebTitan < 4.01 - SQL Injection via categories-x.php sortkey Parameter
SQL injection vulnerability in categories-x.php in WebTitan before 4.04 allows remote attackers to execute arbitrary SQL commands via the sortkey parameter.