Roberto Soares Espreto
30 exploits
Active since Aug 2014
Showbiz Pro < 1.7.1 - Unauthenticated PHP File Upload via ZIP Archive
CVSS 9.8
WP Attachment Export < 0.2.4 - Unauthenticated Sensitive Data Exposure via XML Export
CVSS 7.5
RIPS Scanner <0.54 - Path Traversal
mTheme-Unus < 2.3 - Path Traversal via CSS File Parameter
CVSS 7.5
NextGEN Gallery < 2.1.15 - Path Traversal via Path Selection
CVSS 6.5
EmbedThis GoAhead <3.4.1 - Path Traversal
Subscribe to Comments for WordPress <=2.1.2 - Local File Inclusion
CVSS 7.2
dukapress < 2.5.3 - Path Traversal via src Parameter in dp_image.php
WordPress Mobile Pack < 2.0.2 - Unauthenticated Information Disclosure via Export Articles Action
GI-Media Library <3.0 - Path Traversal
CVSS 7.5
Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation
CVSS 9.8
WildFly Directory Traversal
Simple Backup <2.7.10 - Arbitrary File Download
CVSS 7.5
Tribulant Slideshow Gallery < 1.4.7 - Authenticated Arbitrary File Upload
WPshop 2 - E-Commerce < 1.3.9.6 - Unauthenticated Arbitrary File Upload via ajaxUpload Function
CVSS 9.8
Ajax Load More <2.8.1.2 - Auth Bypass
CVSS 8.8
The Work The Flow File Upload plugin - Path Traversal
CVSS 9.8
Front End Editor <2.3 - File Upload
CVSS 9.8
Website Contact Form With File Upload <1.3.4 - RCE
CVSS 9.8
Bolt < 2.2.5 - Authenticated Remote Code Execution via Theme Editor File Rename
reflex_gallery < 3.1.3 - Unauthenticated Arbitrary PHP File Upload via FileUploader
Creative Contact Form < 1.0.0 - Unauthenticated Arbitrary File Upload via jQuery File Upload Plugin
CVSS 9.8
Nibbleblog < 4.0.4 - Remote Code Execution via My Image Plugin File Upload
Bolt < 2.2.5 - Authenticated Remote Code Execution via Theme Editor File Rename
WordPress Plugin Work The Flow - Arbitrary File Upload (Metasploit)