girex
27 exploits
Active since Dec 2007
DeluxeBB <= 1.3 - SQL Injection via qorder Parameter
LightNEasy - Path Traversal and Arbitrary File Access via thumbsup.php Image Parameter
Unclassified NewsBoard 1.6.4 - Path Traversal and Arbitrary File Read via GLOBALS Parameter
Unclassified NewsBoard (UNB) 1.6.4 - SQL Injection
1024 CMS 1.3.1 - Path Traversal via Lang or Theme Parameters
miniBB < 2.2 - Exposure of Sensitive Information via glang Parameter
miniBB < 2.2 - Cross-Site Scripting via glang[] Parameter
Unclassified NewsBoard (UNB) <1.6.4 - Info Disclosure
Triton CMS Pro < 1.0.6 - SQL Injection via X-Forwarded-For Header
TopperMod 2.0 - SQL Injection via Localita Parameter
TopperMod 1.0 - Path Traversal via 'to' Parameter in mod.php
Quicksilver Forums <= 1.4.2 - Remote Code Execution via Lang Parameter Backslash Bypass
LokiCMS 0.3.4 - Unauthenticated Configuration Modification via LokiACTION Parameter
LokiCMS < 0.3.3 - Remote Code Execution via Default Parameter
miniBB < 2.2 - SQL Injection via xtr Parameter
LightNEasy SQLite <= 1.2.2 - SQL Injection via dlid Parameter
LightNEasy 1.2 - Unauthenticated Administrator Password Hash Exposure via Setup Action
IceBB - SQL Injection via Username Parameter in Members Module
EggBlog 4.0 - SQL Injection
Flatnux 2009-03-27 - Arbitrary File Upload / Information Disclosure
DokuWiki 2009-02-14, rc2009-02-06, rc2009-01-30 - Remote Code Execution via config_cascade Parameter
e107 < 0.7.13 - Authenticated SQL Injection via ue[] Parameter
DeluxeBB 1.3 - SQL Injection via xthedateformat Parameter
coppermine photo Gallery 1.4.22 - Multiple Vulnerabilities
CPCommerce 1.2.6 - URL Rewrite Input Variable Overwrite / Authentication Bypass