Ulf Harnhammar
23 exploits
Active since Oct 2002
WordPress Plugin Enable Media Replace - Multiple Vulnerabilities
Voxel Dot Net CBMS < 0.7 - Unauthenticated SQL Injection via dltclnt.php
JAWmail 1.0-rc1 - Cross-Site Scripting via Attached File Names and HTML Mail Attributes
phpBB <= 2.0.3 - SQL Injection via privmsg.php mark[] Parameter
phprojekt 2.0-3.1 - Authentication Bypass via PATH_INFO Manipulation
PHP-Nuke 6.0 - Web Mail Remote PHP Script Execution
PHP-Nuke 6.0 - Web Mail Script Injection
kmMail 1.0, 1.0a, 1.0b - Cross-Site Scripting via HTML Attributes or Subject Field
FUDforum - Unauthenticated Arbitrary File Read via tmp_view.php file Parameter
FUDforum - Unauthenticated Arbitrary File Creation and Deletion via admbrowse.php Path Parameters
Geeklog 1.3.5 - HTML Attribute Cross-Site Scripting
BasiliX Webmail 1.10 - Stored Cross-Site Scripting via Subject or Message Fields
lynx < 2.8.6 - Remote Code Execution via HTrjis Asian Character Handling
CVSS 9.8
xine-lib 1-beta-1.0.2 and 1.1.1 - Remote Code Execution via CDDB Metadata Format String
e-merge unace 1.2b - Directory Traversal and Arbitrary File Write via ACE Archive
Metamail < 2.7 - Remote Code Execution via Format String Vulnerability
Lynx <2.8.4 - CRLF Injection
Lynx 2.8.6dev.13 - Remote Buffer Overflow
GNU Anubis 3.6.0-3.6.2, 3.9.92-3.9.93 - Remote Code Execution via Format String Vulnerability
Emil 2.x - Multiple Buffer Overrun / Format String Vulnerabilities
Typespeed <0.4.1 - Privilege Escalation
Zabbix - Format String Vulnerability via Log Functions
unalz - Buffer Overflow via Long File Names in ALZ Archives