Yogesh Phadtare

2 exploits Active since Oct 2013
CVE-2013-6872 EXPLOITDB text WORKING POC
Collabtive < 1.2 - Authenticated SQL Injection via managetimetracker.php id Parameter
SQL injection vulnerability in managetimetracker.php in Collabtive before 1.2 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a projectpdf action.
CVE-2013-5028 EXPLOITDB text WRITEUP
Kwoksys Kwok Info Server <2.8.5 - SQL Injection
SQL injection vulnerability in IT/hardware-list.dll in Kwoksys Kwok Information Server before 2.8.5 allows remote authenticated users to execute arbitrary SQL commands via the (1) hardwareType, (2) hardwareStatus, or (3) hardwareLocation parameter in a search command.