Brendan Coles
95 exploits
Active since Oct 2006
ZoneMinder Video Server <1.25.0 - Command Injection
Linux Kernel <4.11.5 - Memory Corruption
CVSS 7.4
MVPower TV-7104HE and TV7108HE Firmware - Unauthenticated Remote Code Execution via Web Shell
CVSS 9.8
MiniWeb HTTP Server <= Build 300 - File Upload
Zenoss Core 3.x - Command Injection
Zenoss Core 3.x - Command Injection
WAN Emulator 2.3 - Unauthenticated OS Command Injection via result.php pc Parameter
Openfiler 2.x - Authenticated OS Command Injection via system.html Device Parameter
ZEN Load Balancer <3.0-rc1 - Command Injection
CuteFlow < 2.11.2 - Unauthenticated Arbitrary File Upload via restart_circulation_values_write.php
glibc LD_AUDIT Arbitrary DSO Load Privilege Escalation
Asterisk < 18.24.2 - Remote Code Execution
CVSS 7.4
SolidWorks Workgroup PDM 2014 - Unauthenticated Path Traversal and Arbitrary File Write via File Upload
Open-FTPD < 1.2 - Unauthenticated Authentication Bypass via FTP Command Injection
HPE Intelligent Management Center < 7.3 - Remote Code Execution
CVSS 9.8
HPE Intelligent Management Center < 7.3 - Remote Code Execution
CVSS 9.8
TFM MMPlayer - '.m3u' / '.ppl' Local Buffer Overflow (Metasploit)
Nitro Pro 11.0.3.173 - Remote Code Execution via Directory Traversal in saveAs and launchURL
CVSS 8.8
Solaris RSH Stack Clash Privilege Escalation
CVSS 5.3
Oracle Sun Systems Products Suite <10 - RCE
CVSS 7.8
Netscape Portable Runtime (NSPR) API <4.6.3 - Local File Creation
Actual Analyzer <2014-08-29 - Code Injection
CVSS 9.8
QNX QCONN - Remote Command Execution (Metasploit)
Quest KACE System Management Appliance 8.0.318 - Unauthenticated OS Command Injection via download_agent_installer.php
CVSS 9.8
ZoneMinder 1.24.x - Path Traversal via View Request or Action Parameter