ZoRLu
253 exploits
Active since Feb 2007
ComScripts Quick Classifieds 1.0 - Remote File Inclusion via DOCUMENT_ROOT Parameter
S-Cms 1.1 Stable and 1.5.2 - Path Traversal via Page Parameter
PHPStore Complete Classifieds - Authenticated Arbitrary File Upload and Remote Code Execution via Logo Upload
PHPStore Job Search - Authenticated Remote Code Execution via Resume Photo Upload
plx Auto Reminder 3.7 - SQL Injection
Poplar Gedcom Viewer 2.0 - Cross-Site Scripting via Text and UL Parameters
PHPStore Auto Classifieds - Authenticated Arbitrary File Upload via Logo Upload
PHPStore Real Estate - Authenticated Arbitrary File Upload via Logo Image
pigyard art Gallery - Multiple Vulnerabilities
PG Roommate Finder Solution - SQL Injection
RSS module 0.1 - Remote Code Execution via lib Parameter
PG Roommate Finder Solution - SQL Injection
pixel_motion_blog - Cross-Site Scripting via jours Parameter
Cedric CLAIRE PortailPhp 2 - Remote File Inclusion via chemin Parameter
PicsEngine 1.0 - 'index.php' Cross-Site Scripting
QT-cute QuickTalk Guestbook 1.6 - Multiple Cross-Site Scripting Vulnerabilities
phpgkit 0.9 - Remote Code Execution via DOCUMENT_ROOT Parameter
phpInstantGallery 2.0 - Cross-Site Scripting via Gallery and Imgnum Parameters
PHPAuctions - Unauthenticated Authentication Bypass via Cookie Manipulation
PHPizabi 0.848b C1 HFP1 - Unauthenticated Arbitrary File Upload and Remote Code Execution via Event Page Image Upload
phpMyChat 0.14.5 - Cross-Site Scripting via Lang Parameter
PHP-Nuke Yellow_Pages Module - 'cid' SQL Injection
phpInstantGallery 2.0 - Cross-Site Scripting via Gallery and Imgnum Parameters
PHPmyGallery 1.5 beta - Remote File Inclusion via conf[lang] Parameter
php-stats 0.1.9.1 - Cross-Site Scripting via sel_mese and sel_anno Parameters