Brendan Coles
95 exploits
Active since Oct 2006
WANem - Multiple Cross-Site Scripting Vulnerabilities
SugarCRM Community Edition 6.5.2 (Build 8410) - Multiple Vulnerabilities
SugarCRM Community Edition - Multiple Information Disclosure Vulnerabilities
OpenFiler 2.3 - Multiple Cross-Site Scripting / Information Disclosure Vulnerabilities
iGiveTest 2.1.0 - SQL Injection
iSupport 1.8 - SQL Injection
Cachelogic Expired Domains Script 1.0 - Multiple Vulnerabilities
BrewBlogger 2.3.2 - Multiple Vulnerabilities
IBM Informix Open Admin Tool <12.1 - RCE
CVSS 9.8
TestLink 1.9.3 - Arbitrary File Upload (Metasploit)
ProjectSend r100-r561 - Unauthenticated Arbitrary File Upload and Remote Code Execution via process-upload.php
iTop 1.1.181 and 1.2.0-RC-282 - Cross-Site Scripting via Multiple Input Vectors
eXtplorer 2.1 - Arbitrary File Upload (Metasploit)
DuckDuckGo 4.2.0 - Private IP Address Exposure via WebRTC STUN Request
CVSS 4.3
Zenoss 3.2.1 - (Authenticated) Remote Command Execution
VMware Hyperic HQ 4.6.6 - Authenticated Remote Code Execution via Groovy Script Console
xorg-x11-server <1.20.3 - Privilege Escalation
CVSS 6.6
MagniComp SysInfo mcsiwrapper Privilege Escalation
CVSS 6.7
HID discoveryd - 'command_blink_on' Remote Code Execution (Metasploit)
Samba is_known_pipename() Arbitrary Module Load
CVSS 9.8
QNAP Q'center < 1.7.1063 - Authenticated OS Command Injection via Change Password
CVSS 7.2
openSIS 4.5-5.2 - Remote Code Execution via ajax.php modname Parameter
HID discoveryd - 'command_blink_on' Remote Code Execution (Metasploit)
Google Chrome < 39.0.2171.65 - Denial of Service or Other Impact
glibc LD_AUDIT Arbitrary DSO Load Privilege Escalation