Alexander Kjäll

2 exploits Active since Apr 2016
CVE-2019-6690 NOMISEC HIGH WORKING POC
Python-gnupg < 0.4.4 - Improper Input Validation
python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg must be controlled by the adversary and the ciphertext should be trusted. Related to a "CWE-20: Improper Input Validation" issue affecting the affect functionality component.
1 stars
CVSS 7.5
CVE-2015-5347 NOMISEC MEDIUM WORKING POC
Apache Wicket <7.2.0 - XSS
Cross-site scripting (XSS) vulnerability in the getWindowOpenJavaScript function in org.apache.wicket.extensions.ajax.markup.html.modal.ModalWindow in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 might allow remote attackers to inject arbitrary web script or HTML via a ModalWindow title.
CVSS 6.1