Alex Hernandez
40 exploits
Active since Apr 2001
VMware vCenter Server - Remote Code Execution via Virtual SAN Health Check Plugin
F5 BIG-IP iControl RCE via REST Authentication Bypass
VMware vCenter Server and Cloud Foundation - Remote Code Execution via vSphere Client Plugin
Spring Framework - Remote Code Execution via Data Binding
VMware vCenter Server and Cloud Foundation - Remote Code Execution via vSphere Client Plugin
CVSS 9.8
VMware vCenter Server - Remote Code Execution via Virtual SAN Health Check Plugin
CVSS 9.8
Cooolsoft PowerFTP Server 2.03 - Info Disclosure
Shambala 4.5 - Directory Traversal via CWD Command
Cooolsoft PowerFTP Server 2.03 - Directory Traversal via LS or GET Command
Cooolsoft PowerFTP Server 2.03 - Info Disclosure
ISC InterNetNews <2.3.0 - Privilege Escalation
Cyberstop Web Server 0.1 - Denial of Service via MS-DOS Device Name Request
Cyberstop Web Server 0.1 - Denial of Service via Long HTTP GET Request
Cobalt RAQ 4 - Cross-Site Scripting via service.cgi or alert.cgi
Cobalt RAQ 4 - Directory Traversal via Dot-Dot in HTTP Request
Cobalt RAQ 4 - Denial of Service and Possible Remote Code Execution via Long Service Argument
slrn - Local Privilege Escalation via Long -d Argument
HP CIFS/9000 Client <= A.01.06 - Local Buffer Overflow via Long Command Parameters
ISS Proventia Network IPS GX5008 and GX5108 - Cross-Site Scripting via Alert Reminder Parameter
IBM Proventia Network IPS GX5008 1.5 and GX5108 1.3 - Remote File Inclusion via main.php page Parameter
AirDefense Airsensor M520 4.3.1.1 and 4.4.1.4 - Authenticated Denial of Service via Crafted HTTPS Query String
March Networks DVR 3204 - Info Disclosure
Cisco VPN client for Windows <5.0.06.0100 - DoS
QPC QVT/Net 4.0 and AVT/Term 5.0 - Directory Traversal via LIST Command
Phusion Web Server 1.0 - Buffer Overflow via Long HTTP Request