Shayan Sadigh
17 exploits
Active since Aug 2014
status2k - Cross-Site Scripting via Username Parameter in login.php
status2k - Authenticated SQL Injection via log Parameter
status2k - Authenticated Command Injection via Admin Panel Log Location Field
status2k - Remote Command Execution via admin/options/editpl.php
CVSS 8.8
status2k - Insufficiently Protected Credentials via Unremoved Install Directory
CVSS 9.8
sphider < 1.3.6 - SQL Injection via site_id or url Parameter
sphider < 1.3.6 - Remote Code Execution via fwrite to conf.php
CVSS 8.8
Sphider Pro 3.2 - Remote Code Execution via fwrite Parameter Injection
CVSS 8.8
Sphider Plus 3.2 - Remote Code Execution via fwrite to conf.php
CVSS 8.8
Sphider Pro and Sphider Plus < 3.2 - Remote Code Execution via fwrite to conf.php
CVSS 8.8
status2k 2.5 - Remote Code Execution via Multies Parameter
CVSS 9.8
sphider < 1.3.6, sphider-pro < 3.2, sphider-plus < 3.2 - Authentication Bypass
CVSS 9.8
Seagate BlackArmor NAS - Remote Code Execution via Session or Auth Name Parameter
CVSS 9.8
Seagate BlackArmor NAS 220 and 110 Firmware - Use of Hard-coded Credentials
CVSS 9.8
Sphider < 1.3.6 - Remote Code Execution via admin/spiderfuncs.php
CVSS 9.8
status2k - Unauthenticated Sensitive Information Exposure via phpinfo Action
Epic MyChart - XPath Injection via Help Topic Parameter
CVSS 7.5