sonyy
22 exploits
Active since Feb 2012
Zimbra Collaboration Suite 6.x-6.0.15 7.x-7.1.3 - Cross-Site Scripting via Calendar View Parameter
xClick Cart 1.0.1 and 1.0.2 - Cross-Site Scripting via shopping_url Parameter
W-Agora 4.1.6 - 'modules.php?File' Traversal Arbitrary File Access
W-Agora 4.1.6 - 'index.php?bn' Traversal Arbitrary File Access
TikiWiki CMS/Groupware 8.3 - Frame Injection via URL Parameter
UBB.threads <= 7.5.6 - Cross-Site Scripting via Loginname Parameter
SkaDate - 'blogs.php' Cross-Site Scripting
Otterware StatIt 4 - Cross-Site Scripting via Multiple Parameters
SMW+ 1.5.6 - 'target' HTML Injection
RabbitWiki - 'title' Cross-Site Scripting
ProWiki - 'id' Cross-Site Scripting
Pendulab ChatBlazer 8.5 - 'Username' Cross-Site Scripting
Omnistar Live - Cross-Site Scripting / SQL Injection
Invision Power Board (IP.Board) 4.2.1 - 'searchText' Cross-Site Scripting
CONTIMEX Impulsio CMS - SQL Injection via id Parameter
GForge 5.7.1 - Multiple Cross-Site Scripting Vulnerabilities
Gregarius 0.6.1 - Multiple SQL Injections / Cross-Site Scripting
FuseTalk Forums < 3.2 - Cross-Site Scripting via login.cfm windowed Parameter
ButorWiki 3.0 - 'service' Cross-Site Scripting
Bontq - 'user/' URI Cross-Site Scripting
JaWiki - 'versionNo' Cross-Site Scripting
JavaBB 0.99 - 'userId' Cross-Site Scripting