indoushka
307 exploits
Active since Apr 2004
Easy2Pilot 7 Cross-Site Request Forgery via admin.php
CVSS 4.3
Web Server Creator - Web Portal 0.1 - XSS
paFileDB 3.1 Final - Cross-Site Scripting via ID Parameter
paFileDB 3.1 - Cross-Site Scripting via Category Module id Parameter
AMSS++ 4.31 - SQL Injection via Mail Module id Parameter
CVSS 8.2
AMSS++ 4.7 - Authentication Bypass via Hardcoded Credentials
CVSS 7.5
PhpIX 2012 Professional - SQL Injection
CVSS 7.1
Yamamah (Dove Photo Album) 1.00 - SQL Injection
WikyBlog 1.7.3rc2 - Authenticated Remote Code Execution via Unrestricted File Upload
WikyBlog 1.7.3 rc2 - Session Fixation
WikyBlog 1.7.3 rc2 - Remote Code Execution via LangFile Parameter
WikyBlog 1.7.2 and 1.7.3 rc2 - Cross-Site Scripting via which Parameter
Arab Cart 1.0.2.0 - SQL Injection via showimg.php id Parameter
SurgeFTP 2.x - 'surgeftpmgr.cgi' Multiple Cross-Site Scripting Vulnerabilities
Microsoft Office Communicator - Denial of Service via SIP INVITE Request Flood
CVSS 5.3
Zyke CMS 1.0 - Arbitrary File Upload
Zyke CMS 1.1 - Bypass
XT-Commerce 1.0 Beta 1 - Pass / Create and Download Backup
Yamamah Photo Gallery 1.00 - SQL Injection via News Parameter
WMNews - '/admin/wmnews.php' Cross-Site Scripting
Rejected
Winn Guestbook 2.4 - Cross-Site Scripting via PATH_INFO
Web Server Creator - Web Portal 0.1 - RCE
VirtuaSystems VirtuaNews Pro 1.0.4 - 'admin.php' Cross-Site Scripting
VisionGate 1.6 - 'login.php' Cross-Site Scripting