Kacper SzurekTagsPolishNewsletterAbout
YouTubeWebinaryFacebookTwitter
Kacper Szurek
TagsPolishNewsletterAboutYouTubeWebinaryFacebookTwitter

Vulnerabilities

e107 CMS 2.1.1 Privilege Escalation

Datas from $_POST['updated_data'] inside usersettings.php are not properly validated so we can set user_admin value in database using this input.

09-11-2016

1 MIN READ

Vulnerabilities

MantisBT 1.2.19 Reflected XSS

strip_tags() function doesn't strip incomplete HTML tags.

26-10-2016

1 MIN READ

Vulnerabilities

Dolphin 7.3.0 Error Based SQL Injection

$_REQUEST['key'] is not escaped.

20-09-2016

1 MIN READ

Vulnerabilities

Tiki Wiki CMS 15.0 Arbitrary File Download

Using flv_stream.php file from vendor directory we can download any file.

11-07-2016

1 MIN READ

Vulnerabilities

LimeSurvey 2.06 Build 160123 Reflected XSS

$_GET['name'] is not escaped and then displayed inside pop_editor_view.

29-06-2016

1 MIN READ

Vulnerabilities

OptionTree 2.5.5 Reflected XSS

Items from $_REQUEST['settings'] are not escaped.

23-06-2016

3 MIN READ

Vulnerabilities

Lingotek Translation 1.1.8 Reflected XSS

$_GET['sm'] is not escaped.

20-06-2016

1 MIN READ

Vulnerabilities

phpMyFAQ 2.9.0 Stored XSS

PHP filter_input() function with FILTER_VALIDATE_URL flag is used to validate url inside savefaq functionality.

09-06-2016

1 MIN READ

From 0 to pentesting hero

Don't use assert in PHP

Why you shouldn't pass variables to assert function in PHP.

02-07-2019

6 MIN READ

© 2025 Kacper Szurek
Disclosure Policy
YouTube
Facebook
Twitter