AkkuS <Özkan Mustafa Akkuş>
28 exploits
Active since Jan 2019
CutePHP CuteNews 2.1.2 - Code Injection
Rejected
Webmin < 1.910 - Authenticated Remote Command Execution via Package Updates Module
CVSS 8.8
Zoho ManageEngine Applications Manager <14.0 - Privilege Escalation
CVSS 9.8
Rukovoditel 2.3.1 - Authenticated Remote Code Execution via Malicious Background Image Upload
CVSS 8.8
Feng Office 3.7.0.5 - Unauthenticated Remote Code Execution via .shtml File Upload
CVSS 9.8
phpscheduleit Booked Scheduler <2.7.5 - RCE
CVSS 8.8
ATutor < 2.2.4 - Authenticated Arbitrary File Upload via File Manager
CVSS 8.8
php-fusion < 9.03.00 - Authenticated Remote Code Execution via Avatar Upload
CVSS 8.8
Rejected
CutePHP CuteNews 2.1.2 - Code Injection
CVSS 8.8
TeemIp < 2.4.0 - Remote Code Execution via exec.php new_config Parameter
CVSS 7.2
AROX School-ERP Pro - Unauthenticated Remote Code Execution via import_stud.php and upload_fille.php
CVSS 9.8
Liferay Portal CE 7.1.2 GA3 - Command Injection
CVSS 7.2
Ericsson Network Location <2021-07-31 - Command Injection
CVSS 8.8
ManageEngine Applications Manager < 14.2 - SQL Injection via NewThresholdConfiguration.jsp resourceid Parameter
CVSS 8.8
ManageEngine OpManager < 12.4.034 - Unauthenticated Remote Command Execution via Default Credential Bypass
CVSS 9.8
ManageEngine Applications Manager 12.0-13.9 - SQL Injection via NewThresholdConfiguration.jsp resourceid Parameter
CVSS 8.8
Zoho ManageEngine Apps Mgr <15 - SQL Injection
CVSS 9.8
TerraMaster Operating System <= 4.2.06 - Unauthenticated Remote Code Execution via Event Parameter in makecvs.php
CVSS 9.8
Webmin <= 1.962 - Authenticated Remote Command Execution via Package Updates Module
CVSS 8.8
Usermin 1.750 - Remote Command Execution (Metasploit)
Jenkins 2.150.2 - Remote Command Execution (Metasploit)
Webmin < 1.910 - Authenticated Remote Command Execution via Package Updates Module
CVSS 8.8
Webmin <= 1.920 - OS Command Injection via password_change.cgi Old Parameter
CVSS 9.8