sinn3r
411 exploits
Active since Dec 2002
Microsoft Windows - Denial of Service via EPATHOBJ::bFlatten Path Traversal
MS12-005 Microsoft Office ClickOnce Unsafe Object Package Handling Vulnerability
MS11-021 Microsoft Office 2007 Excel .xlb Buffer Overflow
HP Intelligent Management Center < 5.1 - Stack-based Buffer Overflow in User Access Manager
Apple QuickTime <7.7.2 - Buffer Overflow
Aviosoft Digital TV Player Professional 1.0 - Local Stack Buffer Overflow (Metasploit)
Ipswitch IMAIL 11.01 - Reversible Encryption + weak ACL
IP2location.dll 1.0.0.1 - Function 'Initialize()' Local Buffer Overflow
DVD X Player 4.1 Professional - Stack-Based Buffer Overflow via PLF Playlist Filename
Adobe Acrobat and Reader < 10.1.1 - Remote Code Execution via U3D Memory Corruption
CVSS 9.8
SSH Tectia Server 6.0.4-6.3.2 - Authentication Bypass via Blank Password
WikkaWiki 1.3.1 and 1.3.2 - Arbitrary PHP Code Execution via File Upload with Multiple Extensions
SugarCRM CE <= 6.3.1 - Code Injection
CVSS 9.8
qdPM 7.0 - Arbitrary '.PHP' File Upload (Metasploit)
Ajax File and Image Manager < 1.1 - Remote Code Execution via PHP Code Injection in data.php
Basilic 1.5.14 - Remote Command Execution via Config/diff.php File Parameter
appRain CMF <= 0.1.5 - Unauthenticated Arbitrary File Upload and Remote Code Execution
AutoSec Tools V-CMS 1.0 - Remote Code Execution via Unrestricted File Upload in Inline Image Upload
Apple Safari - Remote Code Execution via File URL Policy Bypass
Invision Power Board 3.1.x-3.3.x core.php - Impact Unknown
LotusCMS 3.0 - 'eval()' Remote Command Execution (Metasploit)
Network Shutdown Module 3.21 - 'sort_values' Remote PHP Code Injection (Metasploit)
Sflog! CMS 1.0 - Arbitrary File Upload (Metasploit)
Bludit 3.9.2 - Remote Code Execution via Image Upload Path Traversal
CVSS 8.8
Java storeImageArray() Invalid Array Indexing Vulnerability
CVSS 9.8