Stefan Esser
61 exploits
Active since Dec 2002
PHP < 5.4.37 - Use-After-Free via Unserialize Duplicate Numerical Keys
PHP < 4.4.4 - Remote Code Execution via Long String to unserialize Function
Apple OS X <10.10.5 - Privilege Escalation
eMule 0.2x Client - OP_SERVERIDENT Heap Overflow
eMule 0.2x - AttachToAlreadyKnown Double-Free
MySQL 3.x < 3.23.54 and 4.x <= 4.0.6 - Remote Code Execution via COM_CHANGE_USER Command
WordPress < 2.0.6 - SQL Injection via Multibyte Charset Bypass
Squirrelmail G/PGP Plugin 2.1 - RCE
PunBB 1.x - 'profile.php' User Profile Edit Module SQL Injection
PunBB 1.2.4 - Authenticated SQL Injection via Profile ID Parameter
PHP 4.4.0 and 5.0.5 phpinfo - Cross-Site Scripting
Jaws 0.x - Remote File Inclusion
efront < 3.6.2 - SQL Injection via chatrooms_ID Parameter
Drupal 7.0-7.31 - SQL Injection via Array Key in Database API
DeluxeBB < 1.3 - SQL Injection via membercookie Cookie
Campsite 3.x - 'article_id' SQL Injection
PHP 4 < 4.4.5 and 5 < 5.2.1 - Buffer Overflow in imap_mail_compose
PHP 4.x-5.0.0RC3 - XSS
PHP 4 < 4.4.5 and PHP 5 < 5.2.1 - Integer Overflow in msg_receive Function
Zend Platform <2.2.3 - Local Privilege Escalation
PHP 5.3 - Format String Vulnerability in phar Extension
PHP 4 - Remote Code Execution via ZIP Archive Entry Length Overflow
PHP 5.3.0-5.3.2 - Denial of Service via Negative Chunk Size in HTTP Chunked Encoding Decoder
CVSS 9.8
PHP 5.3.9 - Remote Code Execution via Large Number of Variables
PHP < 4.4.4 - Remote Code Execution via Long String to unserialize Function