Darren King

2 exploits Active since Nov 2020
CVE-2020-15929 EXPLOITDB CRITICAL text WORKING POC
Ortussolutions Testbox < 4.1.0 - Path Traversal
In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow an attacker to write an arbitrary CFM file (within the application's context) containing attacker-defined CFML tags, leading to Remote Code Execution.
CVSS 9.8
CVE-2020-15928 EXPLOITDB MEDIUM text WRITEUP
Ortussolutions Testbox < 4.1.0 - Path Traversal
In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters to test-browser/index.cfm allow directory traversal.
CVSS 5.3