Ünsal Furkan Harani (Zemarkhos)

2 exploits Active since Jan 2026
CVE-2022-50912 EXPLOITDB CRITICAL text WRITEUP
ImpressCMS 1.4.4 - Unrestricted File Upload via Weak Extension Sanitization Bypass
ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. Attackers can bypass file upload restrictions by using alternative file extensions .php2.php6.php7.phps.pht to execute arbitrary PHP code on the server.
CVSS 9.8
EIP-2026-114675 EXPLOITDB text WORKING POC
aaPanel 6.6.6 - Privilege Escalation & Remote Code Execution (Authenticated)