StAkeR
100 exploits
Active since Jan 2006
e107 easyshop_plugin - SQL Injection via category_id Parameter
e107 < 2.1.4 - 'keyword' Blind SQL Injection
e107 <= 0.7.15 - SQL Injection via usersettings.php Hide Parameter
e-vision CMS <= 2.0.2 - Path Traversal via Adminlang Cookie or Module Parameter
DeluxeBB < 1.2 - SQL Injection via Delete Action Parameter
CzarNews < 1.20 - SQL Injection via recook Cookie
CzarNews < 1.20 - SQL Injection via recook Cookie
Coppermine Photo Gallery 1.4.20 - 'IMG' Privilege Escalation
CuteNews 1.4.6 - 'ip ban' Authorized Cross-Site Scripting / Command Execution
CSPartner 0.1 - SQL Injection via Pseudo or Passe Parameters
Crux Gallery < 1.32 - Remote File Inclusion via Theme Parameter
cpCommerce 1.2.0-1.2.8 - Remote File Inclusion and Directory Traversal via GLOBALS[prefix] Parameter
CVSS 9.8
Coppermine Photo Gallery 1.4.20 - BBCode IMG Privilege Escalation
CAT2 - 'spaw_root' Local File Inclusion
Nodstrum MySQL Calendar <1.2 - SQL Injection
All Club CMS <= 0.0.2 - Exposure of Sensitive Information via Direct Request to accms.dat
Agoko CMS < 0.4 - Unauthenticated Arbitrary File Upload via admintools/editpage-2.php
2532/Gigs 1.2.2 Stable - Remote Command Execution
ADN Forum 1.0b - SQL Injection via fid or pagid Parameter
AdaptCMS 1.3 - SQL Injection via Check User Feature
Insane Visions AdaptBB 1.0 - SQL Injection via topic_id Parameter
2532gigs 1.2.2 - SQL Injection via Username and Password Parameters
SeaMonkey 1.1.14 - Denial of Service
Konqueror 4.1 - Cross-Site Scripting / Remote Crash
Openasp 3.0 - SQL Injection via idpage Parameter