k1tk4t
46 exploits
Active since Apr 2005
AuraCMS 2.1 - Unauthenticated Arbitrary File Upload via mod/contak.php Image Parameter
AuraCMS 1.x and 2.x - Remote Code Execution via pilih Parameter URL Injection
wzdftpd 0.8.0 0.8.2 - Denial of Service via Long USER Command
Yvora 1.0 - SQL Injection via ID Parameter
woliocms - SQL Injection via Member ID or Admin Login Parameters
Webace-Linkscript 1.3 SE - SQL Injection via start.php id Parameter
TOKOKITA - 'produk_id' SQL Injection
Toko Instan 7.6 - SQL Injection via id or katid Parameter
TLM CMS 3.2 - SQL Injection via Multiple Parameters
Trawler Web CMS < 1.8.1 - Remote File Inclusion via Multiple PHP Script Parameters
TagIt! Tagboard 2.1.B Build 2 - Remote Code Execution via configpath Parameter
TurnkeyWebTools SunShop <4.0 RC 6 - SQL Injection
SpeedBerg 1.2beta1 - Remote File Inclusion via SPEEDBERG_PATH Parameter
Softerra PHP Developer Library 1.5.3 - 'Grid3.lib.php' Remote File Inclusion
rw_download_lite 2.0.3 - SQL Injection via dlid or cid Parameter
Les Visiteurs 2.0.1 - Remote Code Execution via lvc_include_dir Parameter
Softerra PHP Developer Library < 1.5.3 - Remote File Inclusion via cfg_dir or lib_dir Parameters
Open Conference Systems <1.1.6 - RCE
MultiCart 1.0 - SQL Injection via catid or ddlCategory Parameter
FreeWebshop 2.2.1 - SQL Injection via prod/cat/group Parameters
Mambo SimpleFAQ Component - SQL Injection via aid Parameter
Rejected
PHP <include/common_function.php - RCE
Mark Van Bellen Detailed User Registration <4.1 - RCE
Coppermine Photo Gallery <1.0 - RCE