Salvatore "drosophila" Fresta
30 exploits
Active since Feb 2009
CelerBB 0.0.2 - Exposure of Sensitive Information via User Parameter
CelerBB 0.0.2 - SQL Injection via id Parameter
phpCommunity 2 2.1.8 - Cross-Site Scripting via msg Parameter in login.php
phpCommunity 2 2.1.8 - SQL Injection via forum_id or topic_id Parameter
EZ-Blog Beta 1 - Unauthenticated Arbitrary Post Creation and Deletion
Wili-CMS 0.4.0 - Local File Inclusion / Remote File Inclusion / Authentication Bypass
webEdition <= 6.0.0.4 - Remote File Inclusion via WE_LANGUAGE Parameter
Tiny Blogr 1.0.0 rc4 - SQL Injection via txtUsername Parameter
ritsblog 0.4.2 - Authentication Bypass / Cross-Site Scripting
Pragyan CMS 2.6.4 - SQL Injection via Fileget Parameter
phpCommunity 2 2.1.8 - Path Traversal via File or Path Parameter
PHP-Agenda 2.2.5 - Remote File Overwriting
multi-lingual E-Commerce system 0.2 - Multiple Vulnerabilities
nForum 1.5 - SQL Injection via id or user Parameter
Max.Blog 1.0.6 - 'submit_post.php' SQL Injection
Loggix Project 9.4.5 - 'refer_id' Blind SQL Injection
Max.Blog <= 1.0.6 - SQL Injection via Username Parameter
Max.Blog 1.0.6 - 'show_post.php' SQL Injection
com_bookjoomlas 0.1 - SQL Injection via gbid Parameter
Family Connections CMS 1.8.2 - Blind SQL Injection
Family Connections 1.8.2 - Arbitrary File Upload
Family Connections <1.8.2 - SQL Injection
EZ-Blog Beta 1 - SQL Injection via StoryID or Kill Parameter
dynamic flash forum 1.0 Beta - Multiple Vulnerabilities
creasito e-commerce content manager 1.3.16 - SQL Injection via Username Parameter