Anton Tananaev
9 exploits
Active since Jan 2019
Traccar Client: silent configuration hijack via unverified deep link redirects all GPS telemetry
CVSS 9.3
traccar allows CSV formula injection via exported position data
CVSS 6.5
traccar allows XML injection in KML and GPX exports
CVSS 5.4
Traccar - Unrestricted File Upload
CVSS 8.5
Traccar 5.1-5.12 - Unauthenticated Arbitrary File Upload via Device Image API
CVSS 9.6
Traccar Server 4.2 - XML External Entity Injection in Spot Protocol Decoder
CVSS 9.8
Traccar < 4.9 - LDAP Injection via User Input in LDAP Search Filter
CVSS 7.7
Traccar <4.12 - Privilege Escalation
CVSS 5.5
Traccar <6.8.1-6.0 - Local File Inclusion