ikki
17 exploits
Active since Sep 2007
TYPO3 <4.2.16, 4.3.9, 4.4.5 - Path Traversal
TYPO3 4.2.0-4.2.14, 4.3.0-4.3.6, 4.4.0-4.4.3 - Unauthenticated Arbitrary File Read via jumpUrl Hash Comparison
Philips Electronics VOIP841 DECT Phone 1.0.4.50 and 1.0.4.80 - Authenticated Path Traversal via GET Request
Philips Electronics VOIP841 DECT Phone - Hardcoded Backdoor Account
Oracle Secure Backup 10.2.0.3 - Info Disclosure
Rejected
DFLabs PTK 0.1, 0.2, and 1.0 - Remote Command Execution via Filename Shell Metacharacters
NetSupport Manager Agent <=11.00 Remote Code Execution via Long Control Hostname
Zend Java Bridge - Remote Code Execution
Mortbay Jetty 7.0.0-pre5 Dispatcher Servlet - Denial of Service
GCALDaemon 1.0-beta13 - Denial of Service via Large Content-Length Header
Boa Webserver 0.93.15 - Remote Admin Password Change via Long Username in HTTP Basic Authentication
JBoss JMXInvokerServlet JMXInvoker 0.3 - Remote Command Execution
ZeroShell <1.0beta11 - Command Injection
Nokia Mini Map Browser - 'Array Sort' Silent Crash
Philips Electronics VOIP841 DECT Phone - Cross-Site Scripting via Request URL
3Com OfficeConnect Wireless Cable/DSL Router - Authentication Bypass