Creditee: Aung Khant

Known Contact Information:

  • (as of 2008-03-01)
  • (as of 2009-07-23)
  • (as of 2009-12-01)
  • (as of 2010-04-25)
  • (as of 2011-08-15)
  • (as of 2011-08-26)

Known Affiliations:

Disclosed Vulnerabilities (222):

Disc. DateOSVDB IDCVEIDTitle
2013-01-07 89409 TomatoCart /admin/tocdesktop.php Token Object Multiple Admin Action CSRF
2013-01-04 88917 TomatoCart /admin/json.php File Creation Arbitrary Code Execution
2013-01-01 88904 CubeCart index.php Multiple Parameter XSS
2012-12-28 88821 CubeCart Predictable File Name Generation Backup Configuration File Disclosure
2012-12-25 88771 Open-Realty /admin/ajax.php Multiple Parameter XSS
2012-12-25 88864 Open-Realty /admin/ajax.php Password Manipulation CSRF
2012-12-24 88743 CubeCart admin.php redir Parameter Arbitrary Site Redirection
2012-12-24 88740 CubeCart index.php Referer HTTP Header XSS
2012-12-24 88738 CubeCart admin.php Multiple Function CSRF
2012-12-24 88742 CubeCart index.php Multiple Parameter Arbitrary Site Redirect
2012-12-24 88741 CubeCart admin.php Multiple Parameter XSS
2012-12-24 88739 CubeCart admin.php Multiple Parameter SQL Injection
2012-12-24 88737 CubeCart admin.php loc Parameter Local File Inclusion
2012-12-24 88736 CubeCart Persistent Setup Directory Remote Privilege Escalation
2012-12-22 88673 CubeCart /admin/categories/languages.php cat_master_id Parameter XSS
2012-12-22 88675 CubeCart /admin/docs/home.php Multiple Parameter XSS
2012-12-22 88676 CubeCart /admin/docs/languages.php doc_master_id Parameter XSS
2012-12-22 88677 CubeCart /admin/docs/siteDocs.php FCKeditor Parameter XSS
2012-12-22 88678 CubeCart /admin/filemanager/upload.php filename Parameter XSS
2012-12-22 88679 CubeCart /admin/index.php User-Agent HTTP Header XSS
2012-12-22 88680 CubeCart /admin/modules/affiliate/* Multiple Parameter XSS
2012-12-22 88681 CubeCart /admin/modules/gateway/AsianPay/index.php Multiple Parameter XSS
2012-12-22 88682 CubeCart /admin/modules/gateway/* Multiple Parameter XSS
2012-12-22 88683 CubeCart /admin/modules/shipping/* Multiple Parameter XSS
2012-12-22 88684 CubeCart /admin/products/extraCats.php Multiple Parameter XSS
2012-12-22 88685 CubeCart /admin/products/index.php Multiple Parameter XSS
2012-12-22 88686 CubeCart /admin/products/languages.php prod_master_id Parameter XSS
2012-12-22 88687 CubeCart /admin/products/options.php Multiple Parameter XSS
2012-12-22 88688 CubeCart /admin/settings/currency.php Multiple Parameter XSS
2012-12-22 88689 CubeCart /admin/settings/geo.php Multiple Parameter XSS
2012-12-22 88690 CubeCart /cart.php HTTP Referer Header XSS
2012-12-22 88691 CubeCart /index.php Multiple Parameter XSS
2012-12-22 88692 CubeCart /admin/adminusers/permissions.php adminId Parameter XSS
2012-12-22 88693 CubeCart /admin/categories/index.php cat_name Parameter XSS
2012-12-22 88674 CubeCart /admin/customers/index.php Multiple Parameter XSS
2012-12-22 88730 CubeCart /cube/admin/products/options.php masterProduct Parameter SQL Injection
2012-12-22 88729 CubeCart /cube/admin/settings/currency.php active Parameter SQL Injection
2012-12-22 88728 CubeCart /admin/filemanager/upload.php File Upload Arbitrary Code Execution
2012-12-22 88727 CubeCart /cube/admin/products/extraCats.php add Parameter SQL Injection
2012-12-22 88726 CubeCart /cube/admin/products/index.php Multiple Parameter SQL Injection
2012-11-17 87798 Open-Realty Multiple Admin Function CSRF
2012-10-20 86565 F5 FirePass SSL VPN my.activation.cns.php3 refreshURL Parameter Arbitrary Site Redirect
2012-10-15 88076 SilverStripe CMS /index.php/Security/login BackURL Parameter Arbitrary Site Redirect
2012-10-15 88075 SilverStripe CMS /index.php/admin/security/EditForm/field/Roles/AddForm Title Parameter XSS
2012-10-15 88074 SilverStripe CMS /index.php/admin/RootForm Title Parameter XSS
2012-09-04 86580 F5 FirePass my.activation.cns.php3 refreshURL Parameter XSS
2012-08-19 88069 ocPortal /adminzone/index.php Admin User Creation CSRF
2012-08-19 88068 ocPortal Session ID Brute Force Weakness
2012-05-20 82431 Acuity CMS /admin/file_manager/browse.asp path Parameter Traversal Arbitrary File Access
2012-05-20 82430 Acuity CMS /admin/file_manager/file_upload_submit.asp Multiple Parameter File Upload ASP Code Execution
2012-04-17 81198 2012-4745 Acuity CMS admin/login.asp UserName Parameter XSS
2012-04-15 81183 Fastpath WebChat webapp/agentinfo.jsp Multiple Parameter XSS
2012-04-15 81195 Beatz Component for Joomla! index.php Multiple Parameter XSS
2012-04-15 81184 Fastpath WebChat webapp/chat-ended.jsp workgroup Parameter XSS
2012-04-15 81185 Fastpath WebChat webapp/chatmain.jsp Multiple Parameter XSS
2012-04-15 81186 Fastpath WebChat webapp/chatroom.jsp Multiple Parameter XSS
2012-04-15 81187 Fastpath WebChat webapp/contact-agent.jsp email Parameter XSS
2012-04-15 81188 Fastpath WebChat webapp/email/leave-a-message.jsp workgroup Parameter XSS
2012-04-15 81189 Fastpath WebChat webapp/email/offline-mail.jsp workgroup Parameter XSS
2012-04-15 81190 Fastpath WebChat webapp/queue_updater.jsp Multiple Parameter XSS
2012-04-15 81191 Fastpath WebChat webapp/style.jsp workgroup Parameter XSS
2012-04-15 81192 Fastpath WebChat webapp/transcriptmain.jsp Multiple Parameter XSS
2012-04-15 81193 Fastpath WebChat webapp/transcriptsrc.jsp Multiple Parameter XSS
2012-03-05 79827 2012-1110 Etano join.php Multiple Parameter XSS
2012-03-05 79828 2012-1110 Etano search.php Multiple Parameter XSS
2012-03-05 79829 2012-1110 Etano photo_search.php Multiple Parameter XSS
2012-03-05 79830 2012-1110 Etano photo_view.php return Parameter XSS
2012-03-05 80081 2012-1112 Open Realty index.php select_users_template Parameter Traversal Local File Inclusion
2012-02-20 79638 2012-0872 OxWall /join Multiple Parameter XSS
2012-02-20 79639 2012-0872 OxWall /contact Multiple Parameter XSS
2012-02-20 79640 2012-0872 OxWall /blogs/browse-by-tag tag Parameter XSS
2012-02-20 79641 2012-0872 OxWall /viewlist URI XSS
2012-02-20 79602 2012-0873 Dolphin viewFriends.php Multiple Parameter XSS
2012-02-19 79375 2012-0865 CubeCart Multiple Script redir Parameter Arbitrary Site Redirect
2012-02-11 79141 2012-0865 CubeCart admin/login.php goto Parameter Arbitrary Site Redirect
2012-02-11 79140 2012-0865 CubeCart switch.php r Parameter Arbitrary Site Redirect
2011-10-05 76138 2011-4559 vtiger CRM index.php onlyforuser Parameter SQL Injection
2011-10-04 76005 2011-4670 vtiger CRM index.php Multiple Parameter XSS
2011-10-04 76006 2011-4670 vtiger CRM phprint.php Multiple Parameter XSS
2011-09-26 74043 2011-2710 Joomla! index.php Multiple Parameter XSS
2011-08-26 74819 Jcow index.php g Parameter XSS
2011-08-26 75481 Jcow index.php attachment Parameter Arbitrary PHP Code Execution
2011-08-15 74543 Elgg tag_names Parameter SQL Error Message Information Disclosure
2011-08-13 74502 2011-2917 Mambo CMS administrator/index2.php zorder Parameter SQL Injection
2011-08-13 76618 2011-2934 WebsiteBaker /admin/users/add.php Admin Addition CSRF
2011-08-13 76619 2011-2933 WebsiteBaker /admin/media/upload.php Arbitrary File Upload
2011-07-30 74194 Elgg mod/file/search.php page_owner Parameter XSS
2011-07-30 74195 Elgg mod/riverdashboard/index.php content Parameter XSS
2011-07-30 74196 Elgg engine/handlers/pagehandler.php Multiple Parameter XSS
2011-06-29 73491 2011-2509 Joomla! index.php Multiple Parameter XSS
2011-06-28 73488 Joomla! com_content Component index.php Multiple Parameter Path Disclosure
2011-06-27 74503 Mambo CMS Content Component (com_content) index.php task Parameter XSS
2011-06-27 74504 Mambo CMS Menu Manager Component (com_menumanager) administrator/index2.php menu Parameter XSS
2011-06-27 74505 Mambo CMS Menus Component (com_menus) administrator/index2.php menutype Parameter XSS
2011-06-27 74506 Mambo CMS administrator/index2.php Multiple Parameter XSS
2011-06-27 74507 Mambo CMS Modules Component (com_modules) administrator/index2.php client Parameter XSS
2011-06-27 74508 Mambo CMS Categories Component (com_categories) administrator/index2.php section Parameter XSS
2011-05-20 72431 phpMyAdmin index.php db Parameter XSS
2011-03-25 74351 Parallels Plesk at_domains_index.html Query String Parameter Arbitrary Site Redirect
2011-03-23 73335 2011-1480 PHP-Nuke admin.php chng_uid Parameter SQL Injection
2011-03-23 73336 2011-1482 PHP-Nuke mainfile.php HTTP_REFERER Check CSRF
2011-03-23 74501 PHP-Nuke Feedback Module Multiple Parameter XSS
2011-03-18 71228 XOOPS /modules/system/admin.php Multiple Parameter XSS
2011-03-13 71133 2011-1150 bbPress bb-login.php re Parameter XSS
2011-02-25 73516 PHPShop index.php page Parameter XSS
2011-02-01 70751 2011-0535 Zikula Application Framework User Permissions Modification CSRF
2011-02-01 75741 2011-3703 AneCMS Multiple Script Direct Request Path Disclosure
2011-02-01 75742 2011-3704 appRain Multiple Script Direct Request Path Disclosure
2011-02-01 75745 2011-3708 Automne Multiple Script Direct Request Path Disclosure
2011-01-31 75734 2011-3696 60cycleCMS Multiple Script Direct Request Path Disclosure
2011-01-31 75735 2011-3697 Achievo Multiple Script Direct Request Path Disclosure
2011-01-31 75739 2011-3701 AlegroCart Multiple Script Direct Request Path Disclosure
2011-01-31 75894 2011-3801 SimpleTest Multiple Script Direct Request Path Disclosure
2011-01-30 75733 2011-3695 111WebCalendar Multiple Script Direct Request Path Disclosure
2011-01-30 75747 2011-3710 bbPress Multiple Script Direct Request Path Disclosure
2011-01-30 75821 2011-3747 Joomla! Multiple Script Direct Request Path Disclosure
2011-01-28 75906 2011-3818 WordPress Multiple Script Direct Request Path Disclosure
2011-01-27 75869 2011-3781 PHPIDS Multiple Script Direct Request Path Disclosure
2011-01-27 75872 2011-3784 PHP-Nuke Multiple Script Direct Request Path Disclosure
2011-01-27 75874 2011-3786 PHProjekt htdocs/Setup/Controllers/IndexController.php Direct Request Path Disclosure
2011-01-27 70677 2011-0526 Vanilla Forums index.php Target Parameter XSS
2011-01-22 75765 2011-3729 dotProject Multiple Script Direct Request Path Disclosure
2011-01-22 75860 2011-3772 phpCollab Multiple Script Direct Request Path Disclosure
2011-01-22 75870 2011-3782 phpLD Multiple Script Direct Request Path Disclosure
2011-01-22 75873 2011-3785 PHP Point Of Sale (POS) Multiple Script Direct Request Path Disclosure
2011-01-22 75885 2011-3797 ProjectPier Multiple Script Direct Request Path Disclosure
2011-01-22 75896 2011-3803 SugarCRM Multiple Script Direct Request Path Disclosure
2011-01-22 75899 2011-3811 TomatoCart Multiple Script Direct Request Path Disclosure
2011-01-21 75851 2011-3763 OpenCart Multiple Script Direct Request Path Disclosure
2011-01-21 75854 2011-3766 OrangeHRM Multiple Script Direct Request Path Disclosure
2011-01-21 75855 2011-3767 osCommerce redirect.php Direct Request Path Disclosure
2011-01-21 75743 2011-3706 ATutor Multiple Script Direct Request Path Disclosure
2011-01-21 75750 2011-3713 cFTP Multiple Script Direct Request Path Disclosure
2011-01-21 75754 2011-3717 ClipBucket Multiple Script Direct Request Path Disclosure
2011-01-21 75756 2011-3719 CodeIgniter Multiple Script Direct Request Path Disclosure
2011-01-21 75817 2011-3742 HelpCenter Live Multiple Script Direct Request Path Disclosure
2011-01-21 75818 2011-3743 Hesk Multiple Script Direct Request Path Disclosure
2011-01-21 75871 2011-3783 phpMyFAQ Multiple Script Direct Request Path Disclosure
2011-01-21 75876 2011-3788 PhpSecInfo Multiple Script Direct Request Path Disclosure
2011-01-21 75884 2011-3796 PrestaShop Multiple Script Direct Request Path Disclosure
2011-01-21 75892 2011-3809 TheHostingTool Multiple Script Direct Request Path Disclosure
2011-01-20 75763 2011-3727 DokuWiki Multiple Script Direct Request Path Disclosure
2011-01-20 75849 2011-3761 NuSOAP Multiple Script Direct Request Path Disclosure
2011-01-20 75856 2011-3768 Phorum Multiple Script Direct Request Path Disclosure
2011-01-20 75902 2011-3814 WebCalendar Multiple Script Direct Request Path Disclosure
2011-01-20 75738 2011-3700 Advanced Electron Forum Multiple Script Direct Request Path Disclosure
2011-01-20 75764 2011-3728 Dolphin Multiple Script Direct Request Path Disclosure
2011-01-20 75804 2011-3733 Elgg Multiple Script Direct Request Path Disclosure
2011-01-20 75820 2011-3746 Jcow Multiple Script Direct Request Path Disclosure
2011-01-20 75833 2011-3759 MyBB Multiple Script Direct Request Path Disclosure
2011-01-20 75900 2011-3812 Vanilla Multiple Script Direct Request Path Disclosure
2011-01-20 75909 2011-3821 xajax Multiple Script Direct Request Path Disclosure
2011-01-19 75850 2011-3762 OpenBlog Multiple Script Direct Request Path Disclosure
2011-01-19 75881 2011-3793 Pixie CMS Multiple Script Direct Request Path Disclosure
2011-01-19 75905 2011-3817 WebsiteBaker Multiple Script Direct Request Path Disclosure
2011-01-19 75744 2011-3707 JanRain PHP OpenID Library Multiple Script Direct Request Path Disclosure
2011-01-19 75755 2011-3718 CMS Made Simple Multiple Script Direct Request Path Disclosure
2011-01-19 75758 2011-3721 concrete Multiple Script Direct Request Path Disclosure
2011-01-19 75812 2011-3737 eyeOS Multiple Script Direct Request Path Disclosure
2011-01-19 75828 2011-3754 Mambo Multiple Script Direct Request Path Disclosure
2011-01-19 75877 2011-3789 phpwcms Multiple Script Direct Request Path Disclosure
2011-01-19 75882 2011-3794 Pligg Multiple Script Direct Request Path Disclosure
2011-01-19 75893 2011-3800 Serendipity Multiple Script Direct Request Path Disclosure
2011-01-19 75910 2011-3822 XOOPS Multiple Script Direct Request Path Disclosure
2011-01-19 75914 2011-3825 Zend Framework / Server Multiple Script Direct Request Path Disclosure
2011-01-19 75915 2011-3826 Zikula Multiple Script Direct Request Path Disclosure
2011-01-18 75848 2011-3760 Nucleus Multiple Script Direct Request Path Disclosure
2011-01-18 75825 2011-3751 LifeType Multiple Script Direct Request Path Disclosure
2011-01-14 83011 Drupal Multiple Admin Function XSS
2011-01-05 70369 2011-0005 com_search Module for Joomla! index.php ordering Parameter XSS
2011-01-04 70245 2011-4942
2011-5159
Geeklog admin/configuration.php Multiple Parameter XSS
2010-12-24 70013 2010-5096 MyBB search.php keywords Parameter SQL Injection
2010-12-24 70014 2010-5096 MyBB private.php keywords Parameter SQL Injection
2010-12-20 69979 2010-4522 MyBB member.php url Parameter XSS
2010-12-20 69980 2010-4522 MyBB newreply.php posthash Parameter XSS
2010-12-20 70279 2010-4522 MyBB editpost.php Unspecified Parameter XSS
2010-11-17 69266 2010-4647 Eclipse Help Server help/index.jsp URI XSS
2010-11-16 69267 2010-4647 Eclipse Help Server help/advanced/content.jsp URI XSS
2010-11-05 69026 2010-4166
2010-4696
2011-1151
Joomla index.php Multiple Parameter SQL Injection
2010-10-09 68625 2010-3712 Joomla! index.php Query String Parameter XSS
2010-09-14 68014 ALZip Path Subversion Arbitrary DLL Injection Code Execution
2010-09-14 68017 2010-5205
2010-5206
e-press ONE Office Multiple Product Path Subversion Arbitrary DLL Injection Code Execution
2010-09-14 68013 2010-5208 Kingsoft Office 2010 Path Subversion Arbitrary DLL Injection Code Execution
2010-09-13 68012 2010-5210 Sorax Reader Path Subversion Arbitrary DLL Injection Code Execution
2010-09-13 68011 2010-5209 Nuance PDF Reader Path Subversion Arbitrary DLL Injection Code Execution
2010-09-13 68010 2010-5204 IBM Lotus Symphony Path Subversion Arbitrary DLL Injection Code Execution
2010-09-13 67977 Microsoft Visual C++ Redistributable Path Subversion Arbitrary DLL Injection Code Execution
2010-09-13 68118 2010-5211 ALSee Path Subversion Arbitrary DLL Injection Code Execution
2010-09-13 68374 Nitro PDF Reader Path Subversion Arbitrary DLL Injection Code Execution
2010-09-12 68015 ALShow Path Subversion Arbitrary DLL Injection Code Execution
2010-09-12 67995 2010-3402 UltraEdit Path Subversion Arbitrary DLL Injection Code Execution
2010-09-10 68736 2010-3976 Adobe Flash Player (IE Version) Path Subversion Arbitrary DLL Injection Code Execution
2010-09-02 67782 2010-3397 Symantec PGP Desktop Path Subversion Arbitrary DLL Injection Code Execution
2010-09-01 67781 2010-5196
2010-5200
KeePass Password Safe Path Subversion Arbitrary DLL Injection Code Execution
2010-08-29 67694 2010-5246 Maxthon Browser Path Subversion Arbitrary DLL Injection Code Execution
2010-08-28 68858 Notepad++ Path Subversion Arbitrary DLL Injection Code Execution
2010-08-26 67575 BlastChat Client Component for Mambo / Joomla! (com_blastchatc) index.php Itemid Parameter XSS
2010-08-26 67591 Apple QuickTime PictureViewer Path Subversion Arbitrary DLL Injection Code Execution
2010-08-20 67316 2010-3056 phpMyAdmin db_search.php field_str Parameter XSS
2010-08-20 67317 2010-3056 phpMyAdmin db_sql.php delimiter Parameter XSS
2010-08-20 67318 2010-3056 phpMyAdmin db_structure.php sort Parameter XSS
2010-08-20 67319 2010-3056 phpMyAdmin js/messages.php db Parameter XSS
2010-08-20 67320 2010-3056 phpMyAdmin server_databases.php sort_by Parameter XSS
2010-08-20 67321 2010-3056 phpMyAdmin server_privileges.php Multiple Parameter XSS
2010-08-20 67322 2010-3056 phpMyAdmin setup/config.php DefaultLang Parameter XSS
2010-08-20 67323 2010-3056 phpMyAdmin sql.php Multiple Parameter XSS
2010-08-20 67324 2010-3056 phpMyAdmin tbl_replace.php fields[multi_edit][] Parameter XSS
2010-08-09 67165 2Wire Broadband Gateway Insecure Session ID Generation
2010-04-25 64146 2010-1586 HP System Management Homepage (SMH) red2301.html RedirectUrl Parameter Arbitrary Site Redirect
2009-12-01 56579 2010-4879 dompdf dompdf.php input_file Parameter Traversal Arbitrary File Access
2009-07-27 56603 TinyBrowser Uploaded File Deletion CSRF
2009-07-27 56602 TinyBrowser upload.php Multiple Parameter XSS
2009-07-23 62159 PHP Support Tickets include/config.php tri_debug Parameter Error Message Path Disclosure
2009-07-23 62160 PHP Support Tickets classes/class.phpmailer.php PHPMailer Class Remote Code Execution
2009-07-23 62158 PHP Support Ticket Unspecified Config File Overwrite Remote DoS
2008-07-28 47486 2008-3456 phpMyAdmin setup.php Cross-Frame Scripting
2008-07-28 47487 2008-3457 phpMyAdmin setup.php Configuration Manipulation Based XSS
2008-07-15 47321 2008-3197 phpMyAdmin db_create.php db Parameter CSRF
2008-07-15 47322 2008-3197 phpMyAdmin index.php Multiple Parameter CSRF
2008-03-01 66884 Gmail-Lite compose.php Arbitrary Mail Relay
2008-01-01 66885 Gmail-Lite Unspecified XSS
2007-12-01 61995 CodeIgniter user_agent Global XSS Filter Bypass

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2002 - 2013 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use