rgod
471 exploits
Active since Jul 2005
Woltlab Burning Board Lite 1.0.2 - SQL Injection via Thread Visit Cookie Parameter
WordPress <= 2.0.6 - SQL Injection via tb_id Parameter
WordPress < 2.0.2 - Remote Code Execution via Profile Update Displayname Injection
Woltlab Burning Board Lite <1.0.2 - SQL Injection
Jelsoft vBulletin <3.5.8-3.6.5 - SQL Injection
vbPortal 3.0.2-3.6.0 Beta 1 - Unauthenticated Directory Traversal and Remote Code Execution via bbvbplang Cookie
versatileBulletinBoard 1.0.0 RC2 - SQL Injection via Multiple Input Parameters
w-Agora 4.2.0 - 'quicklist.php' Remote Code Execution
Web Content Management News System - Cross-Site Scripting via strRootpath or strTable Parameter
Web Content Management News System - Cross-Site Scripting via strRootpath or strTable Parameter
WebAlbum < 2.02 - Directory Traversal and Remote Code Execution via Skin2 Cookie Parameter
Website Baker 2.6.0 - SQL Injection via Username Parameter
TCExam < 4.0.011 - Cross-Site Scripting via Dynamic Variable Evaluation
Utopia News Pro 1.1.3 - SQL Injection
Utopia News Pro 1.1.3-1.1.4 - Cross-Site Scripting via sitetitle, version, and query_count Parameters
Utopia News Pro 1.1.3-1.1.4 - Cross-Site Scripting via sitetitle, version, and query_count Parameters
Unclassified NewsBoard < 1.5.3d - Directory Traversal via design_path Parameter
Unclassified NewsBoard < 1.5.3_patch3 - SQL Injection via DateFrom or DateUntil Parameter
TikiWiki < 1.9.4 - Unauthenticated Arbitrary File Upload via jhot.php
ThWboard < 3.0_beta_2.84 - SQL Injection via board[styleid] Parameter
Sugar Suite < 4.0 beta - Remote Code Execution via acceptDecline.php beanFiles Parameter
Sugar Suite < 4.0 beta - Directory Traversal via acceptDecline.php beanFiles Parameter
SugarCRM 4.2 - Remote File Inclusion and Directory Traversal via GLOBALS Override
SPIP 1.8.2g - SQL Injection via spip_acces_doc.php3 file Parameter
SPIP 1.8.2g - Directory Traversal and Remote Code Execution via GLOBALS[type_urls] Parameter