halilkirazkaya
45 exploits
Active since Sep 2019
Gladinet CentreStack/Triofox Path Traversal
Post SMTP < 3.6.0 - Unauthenticated Arbitrary Email Log Access via Missing Capability Check
Stop User Enumeration <1.7.3 - Auth Bypass
Oracle Configurator 12.2.3-12.2.14 - Unauthenticated CRLF Injection via Runtime UI
Ditty < 3.1.58 - Unauthenticated Server-Side Request Forgery via displayItems Endpoint
Trinity Audio - Text to Speech AI <5.21.0 - Info Disclosure
bj_lazy_load < 1.0 - Remote File Inclusion
QNAP Photo Station - Path Traversal
Rank Math SEO < 1.0.40.2 - Unauthenticated Arbitrary Metadata Update via rankmath/v1/updateMeta Endpoint
Rank Math SEO < 1.0.40.2 - Unauthenticated Arbitrary URI Creation via rankmath/v1/updateRedirection Endpoint
WP Fastest Cache <0.9.0.2 - Privilege Escalation
IBM Data Risk Manager 2.0.1-2.0.6 - Use of Hard-coded Credentials
Wipro Holmes Orchestrator <20.4.1 - Path Traversal
Wipro Holmes Orchestrator 20.4.1 - Info Disclosure
Pinterest Automatic <1.14.3 - Auth Bypass
The Popup by Supsystic WordPress <1.10.9 - Info Disclosure
Site Offline WordPress plugin < 1.5.3 - Authorization Bypass via URL Query
ECTouch v2 - SQL Injection via $arr['id'] Parameter
WordPress <4.1.10 - Info Disclosure
Hotel Booking Lite < 4.8.5 - Unauthenticated Path Traversal and Arbitrary File Deletion
Quttera Web Malware Scanner WP <3.4.2.1 - Info Disclosure
WordPress Toolbar <2.2.6 - Open Redirect
Prime Mover < 1.9.3 - Directory Listing in Export File Directories
Payment Gateway for Telcell < 2.0.4 - Open Redirect via api_url Parameter
Shield Security < 18.5.10 - Unauthenticated Local File Inclusion via render_action_template Parameter