Thomas pollet moved to bintest.com

This page lists some software security vulnerabilites I discovered 

  • CVE-2008-4729: Hummingbird Exceed XWeb Activex Buffer Overflow
  • CVE-2008-3130: Opencart Script Insertion
  • CVE-2008-2064: phpGedView Script Insertion
  • CVE-2008-1965: Lotus Expeditor Uri Handler Command Execution 
  • CVE-2008-1833: ClamAV Heap Overflow
  • CVE-2008-1722: CUPS PNG Filter Integer Overflow
  • CVE-2008-1469: Gallarific Multiple Vulnerabilities
  • CVE-2008-0516: SQLiteManager Remote File Inclusion
  • CVE-2007-2434: Aventail Connect Hostname Buffer Overfow 
  • CVE-2006-4563: PHP-Nuke MyHeadlines Module "myh_op" Cross-Site Scripting 
  • CVE-2006-4299: TikiWiki "highlight" Cross-Site Scripting
  • CVE-2006-0886: DEV web management system Cross-Site Scripting and Script Insertion 
  • CVE-2006-0933: PHPX "url" XCode Script Insertion 
  • CVE-2006-0934: WEBInsta Limbo Contact Form Script Insertion 
  • CVE-2006-0842: @Mail Webmail Image Tag Script Insertion 
  • CVE-2006-0796: Clever Copy Private Message "Subject" Script Insertion
  • CVE-2006-0682: e107 script insertion
  • CVE-2006-0499: phpBB Rlink Module "url" Cross-Site Scripting
  • CVE-2006-0091: Open-Xchange Webmail HTML Attachment Script Insertion
  • osCmax Cross-Site scripting  
  • Papoo Username Script Insertion Vulnerability
  • EncapsGallery Cross-Site Scripting and File Upload
  • Atlassian JIRA Cross Site Scripting and HTML Injection
  • Exponent Cms script insertion

http://www.bintest.com/about.php