Stas Svistunovich
15 exploits
Active since Dec 2007
XOOPS 2.0.18 - Path Traversal via Lang Parameter
BLOG:CMS 4.2.1b - Cross-Site Scripting via PATH_INFO to photo/admin.php or photo/index.php
RunCMS < 1.6 - Unauthenticated Password Change
RunCMS < 1.6 - Session Hijacking via Predictable Session ID
RunCMS < 1.6 - Cross-Site Scripting via News Subject Parameter
RunCMS - SQL Injection via lid Parameter
XOOPS 2.0.18 - Open Redirect via xoops_redirect Parameter
DivideConcept VHD Web Pack 2.0 - Remote File Inclusion via Page Parameter Path Traversal
Tuned Studios Classic Theme and others - Path Traversal via Page Parameter
RunCMS < 1.6 - Authenticated PHP Code Injection via Admin Parameters
PowerScripts PowerNews 2.5.6 - Path Traversal via Subpage Parameter
phpcms 1.2.2 - Path Traversal via File Parameter in parser.php
BLOG:CMS 4.2.1b - SQL Injection via blogid, user, or field Parameter
aria 0.99-6 - Path Traversal via Page Parameter
WEBrick <1.8.5-p115, 1.8.6-p114, 1.9-1.9.0-1 - Path Traversal