milw0rm
75 exploits
Active since May 1997
Invision Community Blog Mod 1.2.4 - SQL Injection
Gallery 1.2.5 - 'GALLERY_BASEDIR' Multiple Remote File Inclusions
Graffiti CMS 1.x - Arbitrary File Upload
Globsy 1.0 - Path Traversal via File Parameter
GForge 4.5.19 - SQL Injection via Offset Parameter
ExtCalendar < 2 - Unauthenticated Password Change via register.php
CVSS 9.8
e107 plugin fm pro 1 - File Disclosure / Arbitrary File Upload / Directory Traversal
Built2Go PHP Movie Review <2B - RCE
ASPapp Knowledge Base - 'CatId' SQL Injection (2)
Ax Developer CMS 0.1.1 - Remote File Inclusion via Module Parameter Path Traversal
Sophos Anti-Virus and Endpoint Security < 6.0.5 - Remote Code Execution via Malformed CHM File
Adobe Acrobat 9.1.1 (OSX/Windows) - Stack Overflow Crash (PoC)
Perl 4.x and 5.x - Buffer Overflow in suidperl
rdesktop 1.5.0 - Integer Underflow in iso_recv_msg Function
xine-lib < 1.1.12 - Stack-based Buffer Overflow via Long NSF Title
SGI IRIX - Local Command Execution via runpriv Shell Metacharacter Injection
Linksys SPA941 - Denial of Service via SIP INVITE From Header
Netgear WNR2000 FW 1.2.0.8 - Information Disclosure
ASMAX AR 804 gu Web Management Console - Arbitrary Command Execution
Linksys WAG54G2 - Web Management Console Arbitrary Command Execution
Thomson ST 2030 SIP Phone 1.52.1 - Denial of Service via Malformed Via Header
Linksys SPA941 - Denial of Service via SIP INVITE From Header
MuOnline Loopholes Web Server - 'pkok.asp' SQL Injection
Enthrallweb eNews - Authenticated Profile Field Modification via MM_recordId Parameter
IBM AIX <5.3.0 - Privilege Escalation