Kacper SzurekTagsPolishNewsletterAbout
YouTubeWebinaryFacebookTwitter
Kacper Szurek
TagsPolishNewsletterAboutYouTubeWebinaryFacebookTwitter

Vulnerabilities

Duplicator 0.5.8 Privilege Escalation

Package functions are accessible to every registered users because admin privileges are not checked properly.

18-02-2015

1 MIN READ

Vulnerabilities

WonderPlugin Audio Player 2.0 Blind SQL Injection and XSS

wp_ajax_save_item() is accessible for every registered user (admin privileges are not checked).

16-02-2015

1 MIN READ

Vulnerabilities

Chamilo LMS 1.9.8 Blind SQL Injection

There is few places where `Database

09-02-2015

2 MIN READ

Vulnerabilities

Photo Gallery 1.2.5 Unrestricted File Upload

Every registered user can access UploadHandler.php.

26-01-2015

2 MIN READ

Vulnerabilities

Pie Register 2.0.13 Privilege escalation

Anyone can import CSV file. Pie Register will import users from this file.

17-01-2015

1 MIN READ

Vulnerabilities

Contact Form DB 2.8.19 Reflected XSS

It's possible to inject specially crafted reflected XSS even if strip_tags and addslashes is used.

13-01-2015

1 MIN READ

Vulnerabilities

WordPress Shopping Cart 3.0.4 Unrestricted File Upload

Any registered user can upload any file.

08-01-2015

1 MIN READ

Vulnerabilities

MP3-jPlayer 1.8.11 Reflected XSS

$_GET['mp3'] is not escaped.

05-01-2015

1 MIN READ

© 2022 Kacper Szurek
Disclosure Policy
YouTube
Facebook
Twitter