mr_me
214 exploits
Active since Dec 2002
Maian Gallery 2 - Local File Download
Maian Weblog 4.0 - Blind SQL Injection
LotusCMS Fraise 3.0 - Path Traversal and Arbitrary Local File Inclusion via System Parameter
Joomla! Component com_virtuemart 1.1.7/1.5 - Blind SQL Injection (Metasploit)
Joomla! Component com_xcloner-backupandrestore - Remote Command Execution
Joomla! Component com_virtuemart 1.1.7 - Blind SQL Injection
JAKCMS 2.01 RC1 - Blind SQL Injection
JAKCMS 2.01 - Code Execution
Family Connections CMS 2.5.0-2.7.1 - Remote Code Execution via dev/less.php argv[1] Parameter
Family Connections CMS 2.5.0-2.7.1 - Remote Code Execution via dev/less.php argv[1] Parameter
DoceboLMS < 4.0.4 - Authenticated SQL Injection via coursereportuiconfig Parameters
Concrete CMS 5.4.1.1 - Cross-Site Scripting / Remote Code Execution
Chipmunk NewsLetter - Persistent Cross-Site Scripting
ATutor < 2.2.1 - Cross-Site Request Forgery via install_modules.php
CVSS 8.8
amoeba CMS 1.01 - Multiple Vulnerabilities
activeCollab Chat Module < 1.5.2 - Authenticated Remote Code Execution via Message Text Parameter
Shopware < 5.3.4 - PHP Object Instantiation and XXE via ProductStream Controller
CVSS 6.5
Lepide Auditor Suite - 'createdb()' Web Console Database Injection / Remote Code Execution
EasyLogin Pro < 1.3.0 - Remote Code Execution via Encryptor.php Unserialize
CVSS 8.1
ATutor 2.2.1 - SQL Injection via searchFriends Function
CVSS 9.8
ATutor 2.2.1 - Directory Traversal / Remote Code Execution (Metasploit)
Castripper 2.50.70 - '.pls' File Stack Buffer Overflow (DEP Bypass)
ManageEngine Desktop Central - 'FileStorage getChartImage' Deserialization / Unauthenticated Remote Code Execution
Ruby on Rails Dynamic Render File Upload Remote Code Execution
CVSS 7.5
ManageEngine Desktop Central < 10.0.479 - Remote Code Execution via Java Deserialization in FileStorage
CVSS 9.8