Brandon Perry
58 exploits
Active since Aug 2005
Sophos Web Appliance Firmware < 3.8.2 - Authenticated Admin Password Change
GNU inetutils < 1.9 - Remote Code Execution via Long Encryption Key
HP Release Control <9.13-9.21 - Info Disclosure
Solarwinds Orion Platform <11.5 - SQL Injection
ActiveFax (ActFax) 4.3 - Client Importer Buffer Overflow (Metasploit)
Gaim < 1.5.0 - Buffer Overflow via AIM/ICQ Away Message Substitution Strings
CVSS 9.8
Unitrends Enterprise Backup 7.3.0 - Unauthenticated Authentication Bypass via SNMPD Auth Parameter
Sophos Web Appliance Firmware < 3.8.2 - Authenticated OS Command Injection via Network Interface Address Parameter
OS Solution OSProperty 2.8.0 - SQL Injection
LifeSize UVC 1.2.6 - (Authenticated) Remote Code Execution
Web-Dorado ECommerce WD for Joomla! search_category_id SQL Injection Scanner
eTouch SamePage Enterprise Edition 4.4.0.0.239 - Authenticated Path Traversal via filepath Parameter
Alienvault 4.5.0 - (Authenticated) SQL Injection (Metasploit)
NAS4Free <= 9.1.0.1.804 - Authenticated Remote Code Execution via Advanced Execute Command Feature
vtiger CRM 5.3 and 5.4 - Unrestricted Upload of File with Dangerous Type
CVSS 8.8
ISPConfig 3.0.5.2 - Arbitrary PHP Code Execution
CVSS 8.8
MediaWiki <1.22.2/<1.21.5/<1.19.11 - RCE
EMC Cloud Tiering Appliance 10-SP1 - XML External Entity Injection via API Login Request
Gitlist < 0.5.0 - Remote Code Execution via Shell Metacharacters in URI
Thunderbird <60.7.1 - Buffer Overflow
CVSS 9.8
Thunderbird <60.7.1 - Buffer Overflow
CVSS 9.8
Raritan Power IQ <4.2.1 - SQL Injection
Moodle SpellChecker Path Authenticated Remote Command Execution
Zabbix 2.0.9 - Remote Command Execution
CVSS 8.8
openmediavault - Authenticated Remote Code Execution via Cron Service Username Parameter
CVSS 8.8