Brandon Perry
58 exploits
Active since Aug 2005
Gitlist - Remote Code Execution via Shell Metacharacters in File Name
Rejected
eTouch SamePage Enterprise Edition 4.4.0.0.239 - SQL Injection via catId Parameter
Sophos Web Appliance Firmware < 3.8.2 - Authenticated Admin Password Change
McAfee Asset Manager 6.6 - SQL Injection
McAfee Cloud Single Sign On - Stored Cross-Site Scripting via Login Audit Form Password Field
Unitrends Enterprise Backup 7.3.0 - Authenticated OS Command Injection via SNMPD Comm Parameter
Openbravo ERP <= 3.0 - Authenticated XML External Entity Injection via /ws/dal/XXX Interfaces
McAfee ePolicy Orchestrator < 4.6.9 and 5.x < 5.1.2 - Authenticated Credential Exposure via Shared Secret Key
Joomla! 3.1.x-3.2.x - SQL Injection
MantisBT 1.2.13-1.2.16 - Authenticated SQL Injection via filter_config_id Parameter
AlienVault OSSIM < 4.3 - SQL Injection via RadarReport Date Parameter
Solarwinds Orion Platform <11.5 - SQL Injection
EMC Cloud Tiering Appliance 10-SP1 - XML External Entity Injection via API Login Request
Drupal 7.0-7.31 - SQL Injection via Array Key in Database API
openmediavault - Authenticated Remote Code Execution via Cron Service Username Parameter
CVSS 8.8
MediaWiki <1.22.2/<1.21.5/<1.19.11 - RCE
NAS4Free <= 9.1.0.1.804 - Authenticated Remote Code Execution via Advanced Execute Command Feature
vtiger CRM 5.3 and 5.4 - Unrestricted Upload of File with Dangerous Type
CVSS 8.8
Zabbix 2.0.9 - Remote Command Execution
CVSS 8.8
ISPConfig 3.0.5.2 - Arbitrary PHP Code Execution
CVSS 8.8
Moodle < 2.2.11, 2.3.x < 2.3.9, 2.4.x < 2.4.6, 2.5.x < 2.5.2 - Cross-Site Scripting via RSS Feed Blog Link
ActFax Server <4.32 - Buffer Overflow
GNU inetutils < 1.9 - Remote Code Execution via Long Encryption Key
Gitlist < 0.5.0 - Remote Code Execution via Shell Metacharacters in URI