Christian Mehlmauer
31 exploits
Active since Jul 2009
Drupal Drupalgeddon 2 Forms API Property Injection
Apache Tomcat < 5.5.35, 6.x < 6.0.35, 7.x < 7.0.23 - Denial of Service via Hash Collision in Form Parameters
Oracle Glassfish < 3.1.1 - Denial of Service via Predictable Hash Collisions
Apache Geronimo < 2.2.1 - Denial of Service via Predictable Hash Collisions
PHP < 5.3.9 - Denial of Service via Hash Collision in Form Parameter Handling
Oracle Glassfish < 3.1.1 - Denial of Service via Predictable Hash Collisions
MantisBT < 1.2.17 - Unauthenticated Arbitrary File Upload and Information Disclosure via XML Import/Export Plugin
Joomla! 1.5.x-3.4.5 - Unauthenticated Remote Code Execution via HTTP User-Agent Header
MantisBT - Remote Code Execution via XmlImportExport Plugin Preg Replace
Apache Tomcat < 5.5.35, 6.x < 6.0.35, 7.x < 7.0.23 - Denial of Service via Hash Collision in Form Parameters
Apache Geronimo < 2.2.1 - Denial of Service via Predictable Hash Collisions
PHP < 5.3.9 - Denial of Service via Hash Collision in Form Parameter Handling
LimeSurvey <2.06+ Build 151014 - Info Disclosure
WordPress < 3.9.2 - Denial of Service via Large XML Document in IXR Library
Exim GHOST (glibc gethostbyname) Buffer Overflow
WordPress < 2.8.1 - Username Enumeration via Failed Login Behavior
WordPress < 3.5.1 - Server-Side Request Forgery via XMLRPC Pingback
OpenSSL 1.0.1-1.0.1f - Out-of-bounds Read via Heartbeat Extension
CVSS 7.5
W3 Total Cache < 0.9.2.8 - Remote PHP Code Execution
CVSS 9.8
MailPoet Newsletters <2.6.7 - Auth Bypass
Joomla HTTP Header Unauthenticated Remote Code Execution
CVSS 9.8
Apache Struts <2.3.1.2 - Command Injection
CVSS 9.8
MantisBT - Remote Code Execution via XmlImportExport Plugin Preg Replace
Platform theme <1.4.4 - Privilege Escalation
CVSS 9.8
Drupal 7.0-7.31 - SQL Injection via Array Key in Database API