rgod
471 exploits
Active since Jul 2005
CutePHP CuteNews 1.4.6 - Code Injection
CuteNews < 1.4.0 - Remote Code Execution via HTTP_CLIENT_IP Header Injection
CubeCart 3.0.x - Multiple Input Validation Vulnerabilities
CubeCart <= 3.0.11 - SQL Injection via oid or x_invoice_num Parameter
CPG-Nuke Dragonfly CMS 9.0.6.1 - Directory Traversal and Arbitrary File Execution via newlang and installlang Parameters
Coppermine Photo Gallery 1.4.3 - Remote Command Execution
Clever Copy <= 3.0 - SQL Injection via mailarticle.php ID Parameter
Class-1 Forum 0.24.4 - Remote Code Execution
Claroline < 1.7.4 - Cross-Site Scripting and Arbitrary File Read via rqmkhtml.php File Parameter
Claroline < 1.7.4 - Cross-Site Scripting and Arbitrary File Read via rqmkhtml.php File Parameter
BLOG:CMS < 4.0.0k - SQL Injection via NP_SEO Plugin id Parameter
Chipmunk CMS 1.3 - Fontcolor Cross-Site Scripting
Cacti 0.8.6i - 'copy_cacti_user.php' SQL Injection Create Admin
blur6ex 0.3.462 - SQL Injection via ID Parameter in Blog Shard
Bitweaver 1.3 - HTTP Response Splitting
ATutor < 1.5.3.1 - Authenticated SQL Injection via Desc or Asc Parameters
AzDGDatingLite 2.1.3 - Remote Code Execution via Directory Traversal in l Parameter
ATutor 1.5.1 pl2 - SQL Injection via NULL-Terminated Email Address
ATutor 1.5.1 - Unauthenticated Sensitive Information Exposure via Predictable Chat Log Filenames
ATutor - SQL Injection via Password Reminder Email Field
Asn Guestbook 1.5 - 'header.php?version' Cross-Site Scripting
Asn Guestbook 1.5 - 'footer.php?version' Cross-Site Scripting
ADODB < 4.70 - 'tmssql.php' Denial of Service
ADODB < 4.70 (PHPOpenChat 3.0.x) - 'Server.php' SQL Injection
devscripts admbook < 1.2.2 - Remote Code Execution via X-Forwarded-For Header Injection