x0r
54 exploits
Active since Oct 2008
pHNews Alpha 1 - 'mod' SQL Injection
PHP Krazy Image Host Script 1.01 - 'id' SQL Injection
Online Grades 3.2.4 - SQL Injection
Nenriki CMS 0.5 - 'ID' Cookie SQL Injection
MyNews 0.10 - SQL Injection via Username or Passwd Parameter
MyKtools 2.4 - Remote File Inclusion via Language Parameter Path Traversal
Mole Group Vacation Estate Listing Script - Blind SQL Injection
Iamma Simple Gallery <=2.0 - Unauthenticated Arbitrary File Upload RCE via pages/download.php
Goople CMS 1.7 - Unauthenticated Authentication Bypass via Loggedin Cookie
Gobbl CMS 1.0 - Unauthenticated Authentication Bypass via auth Cookie
Grestul 1.x - Cookie Authentication Bypass
gravy media CMS 1.07 - Multiple Vulnerabilities
Graugon PHP Article Publisher 1.0 - Unauthenticated Authentication Bypass via g_admin Cookie
Graugon Gallery 1.0 - Cross-Site Scripting / SQL Injection / Cookie Bypass
Goople CMS 1.7 - Arbitrary File Upload
EggBlog 3.1.10 - Cross-Site Request Forgery (Change Admin Password)
FlexPHPSite 0.0.1 and 0.0.7 - SQL Injection via User Check Parameters
FlexPHPLink Pro 0.0.6 and 0.0.7 - SQL Injection via Usercheck Parameters
FlexPHPDirectory 0.0.1 - Unauthenticated Arbitrary File Upload via add.php
InSun Feed CMS 1.7.3 19Beta - Path Traversal via Lang Parameter
Fast FAQs System - Authentication Bypass
E-topbiz Link Back Checker 1 - Unauthenticated Authentication Bypass via Auth Cookie
doop CMS 1.4.0b - Cross-Site Request Forgery / Arbitrary File Upload
BlueBird Prelease - SQL Injection via Username or Passwd Parameter
Chipmunk Blogger Script - SQL Injection