Creditee: Gjoko Krstic

Known Contact Information:

  • (as of 2006-11-29)
  • (as of 2010-01-31)

Known Affiliations:

Disclosed Vulnerabilities (175):

Disc. DateOSVDB IDCVEIDTitle
2012-02-08 78986 SciTools Understand Path Subversion Arbitrary DLL Injection Code Execution
2012-02-07 78902 ManageEngine ADManager Plus DomainConfig.do operation Parameter XSS
2012-02-07 78901 ManageEngine ADManager Plus jsp/AddDC.jsp domainName Parameter XSS
2012-01-31 78725 MindManager Path Subversion Arbitrary DLL Injection Code Execution
2012-01-04 78093 Limny admin/login.php URI XSS
2011-12-21 78294 2011-5039 Infoproject Biznis Heroj login.php Multiple Parameter SQL Injection
2011-12-21 78295 2011-5039 Infoproject Biznis Heroj widget.dokumenti_lista.php filter Parameter SQL Injection
2011-12-21 78296 2011-5039 Infoproject Biznis Heroj nalozi_naslov.php fin_nalog_id Parameter SQL Injection
2011-12-21 78297 2011-5040 Infoproject Biznis Heroj nalozi_naslov.php config Parameter XSS
2011-12-21 78298 2011-5040 Infoproject Biznis Heroj widget.dokumenti_lista.php config Parameter XSS
2011-12-05 77724 2011-5044 SopCast SopPlayer Insecure Permissions Diagnose.exe Overwrite
2011-12-01 77462 Hero Framework Template File Events month Parameter XSS
2011-11-28 77403 Manx admin/login.php URI XSS
2011-11-28 77404 Manx admin/tiny_mce/plugins/ajaxfilemanager/ajax_get_file_listing.php Multiple Parameter XSS
2011-11-28 77405 Manx admin/tiny_mce/plugins/ajaxfilemanager_OLD/ajax_get_file_listing.php Multiple Parameter XSS
2011-11-28 77408 Manx admin/admin_blocks.php editorChoice Parameter XSS
2011-11-28 77409 Manx admin/admin_pages.php editorChoice Parameter XSS
2011-11-28 77410 Manx admin/admin_css.php theme Parameter XSS
2011-11-28 77411 Manx admin/admin_js.php theme Parameter XSS
2011-11-28 77412 Manx admin/admin_templates.php theme Parameter XSS
2011-11-28 77406 Manx /admin/admin_blocks.php fileName Parameter Traversal Arbitrary File Access
2011-11-28 77407 Manx /admin/admin_pages.php fileName Parameter Traversal Arbitrary File Access
2011-11-13 77095 2011-4709 Search Plugin for Hotaru CMS index.php Multiple Parameter XSS
2011-11-13 77680 2011-4709 Search Plugin for Hotaru CMS admin_index.php SITE_NAME Parameter XSS
2011-11-02 76801 SetSeed index.php loggedInUser Cookie SQL Injection
2011-09-30 76001 2011-2443 Adobe Photoshop Elements Brush (ABR) File Handling Overflow
2011-09-30 76002 2011-2443 Adobe Photoshop Elements Gradient (GRD) File Handling Overflow
2011-09-19 75599 Toko Lite CMS EditNavBar.php Multiple Parameter XSS
2011-09-17 75601 iManager scripts/random.php dir Parameter XSS
2011-09-17 75603 iManager phpThumb.demo.random.php dir Parameter XSS
2011-09-16 75602 iManager scripts/phpCrop/crop.php d Parameter Traversal Arbitrary File Deletion
2011-09-16 75604 iManager Multiple Script lang Parameter Traversal Local File Inclusion
2011-08-23 74713 ManageEngine ServiceDesk Plus WorkOrder.do Multiple Parameter XSS
2011-08-23 74714 ManageEngine ServiceDesk Plus Problems.cc reqName Parameter XSS
2011-08-23 74715 ManageEngine ServiceDesk Plus AddNewProblem.cc reqName Parameter XSS
2011-08-23 74716 ManageEngine ServiceDesk Plus ChangeDetails.cc reqName Parameter XSS
2011-08-23 74717 ManageEngine ServiceDesk Plus AddSolution.do Multiple Parameter XSS
2011-08-23 74718 ManageEngine ServiceDesk Plus ContractDef.do Multiple Parameter XSS
2011-08-23 74719 ManageEngine ServiceDesk Plus VendorDef.do organizationName Parameter XSS
2011-08-23 74720 ManageEngine ServiceDesk Plus MarkUnavailability.jsp COMMENTS Parameter XSS
2011-08-06 74468 AContent /documentation/search.php Multiple Unspecified Parameter SQL Injection
2011-08-06 74413 AChecker updater/patch_edit.php myown_patch_id Parameter SQL Injection
2011-08-06 74414 AChecker user/user_create_edit.php id Parameter SQL Injection
2011-08-06 74415 AChecker themes/default/language/language_add_edit.tmpl.php id Parameter XSS
2011-08-06 74416 AChecker themes/default/user/user_group_create_edit.tmpl.php id Parameter XSS
2011-08-06 74417 AChecker documentation/frame_header.php p Parameter XSS
2011-08-06 74418 AChecker updater/patch_edit.php myown_patch_id Parameter XSS
2011-08-06 74419 AChecker user/user_create_edit.php id Parameter XSS
2011-08-06 74455 AContent /documentation/frame_header.php p Parameter XSS
2011-08-06 74456 AContent /documentation/frame_content.php p Parameter XSS
2011-08-06 74457 AContent /register.php password_error Parameter XSS
2011-08-06 74458 AContent /user/user_create_edit.php id Parameter XSS
2011-08-06 74459 AContent /updater/patch_edit.php myown_patch_id Parameter XSS
2011-08-06 74460 AContent /themes/default/login.tmpl.php Multiple Parameter XSS
2011-08-06 74461 AContent /themes/default/user/user_group_create_edit.tmpl.php id Parameter XSS
2011-08-06 74462 AContent /themes/default/language/language_add_edit.tmpl.php id Parameter XSS
2011-08-06 74463 AContent Multiple Script URI XSS
2011-08-06 74454 AContent /course_category/index.php category_name Parameter XSS
2011-08-06 74481 AContent /home/search.php Multiple Unspecified Parameter SQL Injection
2011-08-06 74469 AContent /search.php Multiple Unspecified Parameter SQL Injection
2011-08-06 74470 AContent /user/index_inline_editor_submit.php Multiple Unspecified Parameter SQL Injection
2011-08-06 74471 AContent /user/user_group_inline_editor_submit.php Multiple Unspecified Parameter SQL Injection
2011-08-06 74472 AContent /updater/myown_patches_inline_editor_submit.php Multiple Unspecified Parameter SQL Injection
2011-08-06 74473 AContent /updater/patch_creator.php Multiple Unspecified Parameter SQL Injection
2011-08-06 74474 AContent /updater/patch_edit.php Multiple Unspecified Parameter SQL Injection
2011-08-06 74475 AContent /tests/import_test.php Multiple Unspecified Parameter SQL Injection
2011-08-06 74476 AContent /tests/question_import.php Multiple Unspecified Parameter SQL Injection
2011-08-06 74477 AContent /oauth/authorization.php Multiple Unspecified Parameter SQL Injection
2011-08-06 74478 AContent /oauth/register_consumer.php Multiple Unspecified Parameter SQL Injection
2011-08-06 74479 AContent /language/index_inline_editor_submit.php Multiple Unspecified Parameter SQL Injection
2011-08-06 74480 AContent /home/ims/ims_import.php Multiple Unspecified Parameter SQL Injection
2011-07-13 73810 TCExam /admin/code/tce_colorpicker.php Multiple Parameter XSS
2011-07-13 73824 TCExam /admin/code/tce_edit_backup.php backup_file Parameter XSS
2011-07-13 73811 TCExam /admin/code/tce_edit_group.php Multiple Parameter XSS
2011-07-13 73812 TCExam /admin/code/tce_edit_module.php Multiple Parameter XSS
2011-07-13 73813 TCExam /admin/code/tce_edit_rating.php test_id Parameter XSS
2011-07-13 73814 TCExam /admin/code/tce_edit_subject.php Multiple Parameter XSS
2011-07-13 73815 TCExam /admin/code/tce_edit_test.php test_id Parameter XSS
2011-07-13 73816 TCExam /admin/code/tce_filemanager.php file Parameter XSS
2011-07-13 73817 TCExam /admin/code/tce_select_mediafile.php Multiple Parameter XSS
2011-07-13 73818 TCExam /admin/code/tce_select_users.php new_group_id Parameter XSS
2011-07-13 73819 TCExam /admin/code/tce_show_all_questions.php subject_module_id Parameter XSS
2011-07-13 73820 TCExam /admin/code/tce_show_result_user.php test_id Parameter XSS
2011-07-13 73821 TCExam /public/code/tce_user_change_email.php xl_user_email Parameter XSS
2011-07-13 73822 TCExam /public/code/tce_user_change_password.php xl_newpassword Parameter XSS
2011-07-13 73823 TCExam /public/code/tce_user_registration.php Multiple Parameter XSS
2011-07-13 74081 TCExam Multiple Script URI XSS
2011-06-23 73479 NetServe Web Server admin/host_0/ssioptions.html Multiple Parameter XSS
2011-06-23 73480 NetServe Web Server admin/mimetypes.html Multiple Parameter XSS
2011-06-23 73481 NetServe Web Server Multiple Unspecified Remote File Inclusion
2011-06-23 73482 NetServe Web Server Multiple Unspecified Local File Inclusion
2011-06-23 73483 NetServe Web Server Multiple Unspecified Remote DoS
2011-06-21 73201 Sitemagic CMS index.php SMExt Parameter XSS
2011-06-02 72675 Ushahidi application/controllers/admin/dashboard.php range Parameter SQL Injection
2011-05-31 72731 Kentico CMS examples/webparts/membership/users-viewer.aspx userContextMenu_parameter Parameter XSS
2011-05-22 72844 Tugux CMS contact.php Multiple Parameter XSS
2011-05-22 72845 Tugux CMS comments.php nid Parameter SQL Injection
2011-05-22 72846 Tugux CMS contact.php Multiple Parameter SQL Injection
2011-05-22 72847 Tugux CMS latest.php Multiple Parameter SQL Injection
2011-05-12 72326 2011-0614 Adobe Audition SES Session File Processing Overflow
2011-04-20 72137 docuFORM Mercury f_state.php Multiple Parameter XSS
2011-04-20 72138 docuFORM Mercury f_list.php Multiple Parameter XSS
2011-04-20 72139 docuFORM Mercury f_job.php Multiple Parameter XSS
2011-04-20 72140 docuFORM Mercury f_header.php Multiple Parameter XSS
2011-04-14 71829 Help & Manual ijl15.dll Path Subversion Arbitrary DLL Injection Code Execution
2011-04-06 71704 Anfibia Reactor reactor/login.do email Parameter XSS
2011-04-05 71562 TutorialMS tutorials.php show Parameter SQL Injection
2011-04-03 71455 DoceboLMS index.php Multiple Parameter XSS
2011-03-16 71194 Pointter PHP Content Management System admin/functions/createcategory.php category Parameter XSS
2011-03-16 71195 Pointter PHP Content Management System pointtercms/admin/functions/createcategory.php category Parameter Traversal Local File Inclusion
2011-03-16 71196 Pointter PHP Content Management System pointtercms/admin/functions/createpage.php pageurl Parameter Traversal Local File Inclusion
2011-03-16 71197 Pointter PHP Content Management System pointtercms/admin/functions/createproduct.php producturl Parameter Traversal Local File Inclusion
2011-03-16 71198 Pointter PHP Content Management System pointtercms/admin/functions/editsettings.php Multiple Parameter SQL Injection
2011-03-11 71113 Constructr CMS backend/login.php Multiple Parameter XSS
2011-03-11 71114 Constructr CMS xmlOutput/constructrXmlOutput.content.xml.php page_id Parameter SQL Injection
2011-02-17 71088 Gazie modules/root/login_admin.php Login Parameter XSS
2011-02-17 71089 Gazie modules/root/login_admin.php Login Parameter SQL Injection
2011-02-11 70960 MySQL Eventum forgot_password.php URI XSS
2011-02-11 70961 MySQL Eventum list.php Multiple Parameter XSS
2011-02-11 70877 2011-1062 TaskFreak index.php Multiple Parameter XSS
2011-02-11 70878 2011-1062 TaskFreak print_list.php Multiple Parameter XSS
2011-02-11 70932 2011-1062 TaskFreak rss.php HTTP Referer Header XSS
2011-01-22 70631 CultBooking cultbooking.php Multiple Parameter XSS
2011-01-22 70632 CultBooking cultbooking.php lang Parameter Traversal Local File Inclusion
2010-12-23 70086 Embedthis Appweb Ejscript Web Framework XSS
2010-12-15 70155 2010-4348 MantisBT admin/upgrade_unattended.php db_type Parameter XSS
2010-12-15 70157 2010-4350 MantisBT admin/upgrade_unattended.php db_type Parameter Traversal Local File Inclusion
2010-12-15 70156 2010-4349 MantisBT admin/upgrade_unattended.php db_type Parameter Path Disclosure
2010-12-06 69643 MODx manager/index.php Multiple Parameter XSS
2010-11-20 69486 Reaktor 5 Player Path Subversion Arbitrary DLL Injection Code Execution
2010-11-20 69487 Kontakt Player Path Subversion Arbitrary DLL Injection Code Execution
2010-11-20 69464 Traktor Pro Playlist File Parsing Overflow
2010-11-20 69485 MASSIVE KSP File Parsing Memory Corruption
2010-10-15 69173 2010-4155 eXV2 CMS manual/caferss/example.php rssfeedURL Parameter XSS
2010-10-15 69174 2010-4155 eXV2 CMS modules/news/archive.php sumb Parameter XSS
2010-10-15 69175 2010-4155 eXV2 CMS modules/news/topics.php sumb Parameter XSS
2010-10-15 69176 2010-4155 eXV2 CMS modules/contact/index.php sumb Parameter XSS
2010-09-29 68298 Zen Cart option_name_manager.php option_order_by Parameter SQL Injection
2010-09-29 68299 Zen Cart Admin Panel Multiple XSS
2010-09-29 68300 Zen Cart index.php typefilter Parameter Traversal Local File Inclusion
2010-09-17 68128 2010-3489 Digital Workroom netautor/napro4/home/login2.php goback Parameter XSS
2010-09-08 67850 Textpattern index.php q Parameter XSS
2010-09-06 67838 2010-4901 MySource Matrix char_map.php Multiple Parameter XSS
2010-08-28 67692 LEADTOOLS LEAD RasterTwain LtocxTwainu.dll ActiveX AppName Property Overflow
2010-08-26 67588 2010-3138 Microsoft Windows Indeo Filter Path Subversion Arbitrary DLL Injection Code Execution
2010-08-25 67566 2010-3154 Adobe Extension Manager CS5 Path Subversion Arbitrary DLL Injection Code Execution
2010-08-25 67550 2010-3155 Adobe ExtendedScript Toolkit CS5 Path Subversion Arbitrary DLL Injection Code Execution
2010-08-25 67538 CorelDRAW Path Subversion Arbitrary DLL Injection Code Execution
2010-08-25 67582 Corel PHOTO-PAINT Path Subversion Arbitrary DLL Injection Code Execution
2010-08-25 67551 Media Player Classic Path Subversion Arbitrary DLL Injection Code Execution
2010-08-02 66858 RaidenTUNES music_out.php p Parameter XSS
2010-06-29 65915 2010-2204 Adobe Reader / Acrobat Unspecified DoS (2010-2204)
2010-06-04 65140 2010-2321 Adobe InDesign Crafted INDD File Handling Overflow
2010-05-26 65082 2010-1296 Adobe Photoshop CS4 Multiple Crafted File Handling Overflows
2010-05-11 64646 2010-1280 Adobe Shockwave Player Crafted DIR File Dereference Memory Corruption
2010-03-05 62728 2011-1087 VLC Media Player Bookmark Creation Crafted File Handling Memory Corruption
2010-03-05 64864 2010-2009 BS.Player Media Library MP3 File Handling Overflow
2010-03-04 62736 Media Jukebox MP3 File Handling Overflow
2010-02-22 62481 2010-0700 WampServer index.php lang Parameter XSS
2010-01-31 67539 2010-3134 Google Earth Path Subversion Arbitrary DLL Injection Code Execution
2009-07-15 55861 2009-3811 Music Tag Editor MP3 File ID3 Tag Handling Overflow
2009-07-10 55744 2009-3859 eEye Retina Network Security Scanner RWS File Handling Overflow
2009-06-16 55317 2009-2173 Carom3D LAN Game Feature Crafted HTTP Request Handling DoS
2009-06-01 54810 2009-4201 Mp3 Tag Assistant Professional MP3 ID3 Tag Handling Overflow
2009-05-29 54812 2009-1944 AIMP MP3 ID3 Tag Handling Overflow
2009-05-08 54557 2009-1660 ViPlay3 VPL File Handling Overflow
2009-03-17 64582 Talkative IRC Response String Handling Overflow
2009-02-04 51825 2009-0450 BlazeVideo HDTV Player PLF File Handling Overflow
2009-01-22 51510 2009-0349 FTPShell Server License Key Handling Overflow
2008-11-24 50199 2008-7079 ShowTime M3U File Handling Overflow
2008-10-24 49352 2008-4748 KVIrc Crafted irc:// URI Handling Format String
2008-10-14 49184 2008-4588 Etype Eserv FTP Server ABOR Command Handling Overflow
2008-10-03 50829 2008-5667 VirusBlokAda VBA32 Personal Antivirus Scanning Engine Malformed RAR File Handling DoS
2008-04-28 44612 2008-2032 Femitter Server FTP Server Crafted RETR Command Remote DoS
2006-11-29 30770 2006-6199 BlazeDVD PLF Playlist Filename Parsing Overflow

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2012 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use