rgod
471 exploits
Active since Jul 2005
GuppY < 4.5.16 - Remote Code Execution via Error Handler Cookie Injection
exV2 content_management_system < 2.0.4.3 - Remote Code Execution via $xoopsOption['pagetype'] Variable Manipulation
CVSS 9.8
sysinfo 1.21 - Remote Code Execution via Name Parameter in systemdoc Action
phpwebsite < 0.10.2 - Directory Traversal and Remote Code Execution via hub_dir Parameter
simplog < 0.9.2 - Cross-Site Scripting via btag Parameter
simplog < 0.9.2 - SQL Injection via Multiple Parameters
simplog < 0.9.2 - Remote File Inclusion via Directory Traversal in s Parameter
simplog < 0.9.2 - Remote File Inclusion via s Parameter
Cacti < 0.8.6i - SQL Injection via cmd.php Arguments
ADOdb for PHP < 4.70 - Remote Code Execution via tests/tmssql.php do Parameter
tcexam < 4.0.011 - Unauthenticated Arbitrary File Write via SessionUserLang Cookie
XAMPP < 1.6.0a - Remote Code Execution via ADONewConnection Host Parameter
php-update < 2.7 - Authenticated Arbitrary File Upload via userfile Parameter
myWebland myBloggie <2.1.4 - Info Disclosure
papoo < 3 RC3 - Cross-Site Scripting via Hilfe.php Titel or Ausgabe Parameters
FCKeditor mcpuk - Unrestricted File Upload
bitweaver 1.3 - Remote Code Execution via Double Extension File Upload
phpHeaven Team PHPMyChat <0.14.5 - SQL Injection
Claroline <= 1.7.4 - Remote File Inclusion via includePath Parameter
Claroline < 1.7.4 - Cross-Site Scripting and Arbitrary File Read via rqmkhtml.php File Parameter
Claroline < 1.7.4 - Directory Traversal and Remote Code Execution via File Parameter
gCards < 1.45 - SQL Injection via Username Parameter
gCards < 1.45 - Remote File Inclusion via Directory Traversal in lang Parameter
phpwebthings 1.4 - SQL Injection via Forum Message Parameter
Advantech WebAccess < 7.1 - SQL Injection via DBVisitor.dll SOAP Interface