ka0x
23 exploits
Active since Apr 2007
Internet Information Services 5.1 and 6.0 - Authentication Bypass via Unicode %c0%af URI Obfuscation
astatsPRO 1.0 - SQL Injection via refer.php id Parameter
Microsoft Internet Information Services 5.0 - Authentication Bypass via WebDAV URL Decoding
WorkingOnWeb 2.0.1400 - SQL Injection
WebLeague 2.2.0 - SQL Injection via Username or Password Parameter
TutorialCMS 1.02 - SQL Injection via activate.php userName Parameter
Sports Clubs Web Panel 0.0.1 - Remote Game Delete
SmartPPC and SmartPPC Pro - SQL Injection via idDirectory Parameter
Rianxosencabos CMS 0.9 - SQL Injection
Rianxosencabos CMS 0.9 - Unauthenticated Authentication Bypass via Cookie Manipulation
PHPWebGallery 1.3.4 - Blind SQL Injection (2)
phpRealty < 0.03 - Remote Code Execution via INC Parameter
PHP Webquest 2.6 - SQL Injection via id_actividad Parameter
MapLab 2.2.1 - Remote Code Execution via gmapfactory/params.php gszAppPath Parameter
LulieBlog 1.0.1 and 1.0.2 - Unauthenticated Arbitrary Comment and Article Deletion via Admin Endpoints
astatsPRO 1.0.1 - SQL Injection via id Parameter
Free Links Directory Script 1.2a - SQL Injection
cpDynaLinks 1.02 - SQL Injection via Category Parameter
Blue Eye CMS <= 1.0.0 - SQL Injection via BlueEyeCMS_login Cookie Parameter
All Club CMS < 0.0.1f - SQL Injection via Name Parameter
Agares PhpAutoVideo 2.21 - SQL Injection via articlecat Parameter
Addalink < 1.0 - SQL Injection via category_id Parameter
Novus 1.0 - SQL Injection via nota_id Parameter