Andreas Guth

2 exploits Active since Mar 2013
CVE-2013-1814 METASPLOIT ruby WORKING POC
Apache Rave < 0.20.1 - Information Disclosure
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.
CVE-2013-1814 EXPLOITDB text WRITEUP
Apache Rave < 0.20.1 - Information Disclosure
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.