Brendan Coles
95 exploits
Active since Oct 2006
Open Flash Chart v2 Beta 1-v2 Lug Wyrm Charmer - RCE
Rejected
Rejected
Apache mod_cgi Bash Environment Variable Code Injection (Shellshock)
CVSS 9.8
Rejected
GNU Bash < 4.3 - Remote Code Execution via Malformed Environment Variable Function Definitions
CVSS 9.8
Rejected
Rejected
Serviio Media Server <1.8 - Command Injection
VICIdial <2.13 RC1 - Command Injection
ProcessMaker < 3.5.4 - Authenticated Remote Code Execution via Plugin Upload
QNAP Q'center Virtual Appliance <1.7.1063 - Info Disclosure
CVSS 8.8
Oracle Sun Systems Products Suite 11 - Privilege Escalation
CVSS 5.3
Oracle Sun Systems Products Suite Kernel - Takeover
CVSS 7.8
lastore-daemon <0.9.66-1 - Privilege Escalation
libuser < 0.56.13-8 and 0.60 < 0.60-7 - Denial of Service via GECOS Field Newline Injection
Simple E-Document 3.0-3.1 - File Upload
HybridAuth 2.0.9-2.2.2 - Unauthenticated Remote Code Execution via install.php Config Injection
Dell KACE K1000 <5.4.76849-5.5.90547 - File Upload
PHP-Charts 1.0 - Unauthenticated Remote Code Execution via GET Parameter Eval Injection
Glossword 1.8.8-1.8.12 - Authenticated Arbitrary File Upload and Remote Code Execution via Administrative Interface
Kordil EDMS v2.2.60rc3 - Unauthenticated RCE
WebTester 5.x - Unauthenticated OS Command Injection via install2.php Parameters
ProcessMaker Open Source 2.x - Code Injection
Kimai 0.9.2.x - Unauthenticated SQL Injection via db_restore.php dates[] Parameter