Dawid Golunski
78 exploits
Active since Nov 2009
Google AdWords API PHP client library 6.2.0 - Arbitrary PHP Code Execution
Google AdWords 6.2.0 API client libraries - XML eXternal Entity Injection
Zend Framework < 1.12.14, 2.x < 2.4.6, 2.5.x < 2.5.2 - XML External Entity Injection via Multibyte Encoded Characters
eBay Magento CE 1.9.2.1 - Unrestricted Cron Script (Code Execution / Denial of Service)
CakePHP < 3.2.4 - IP Spoofing via CLIENT-IP HTTP Header
CVSS 7.5
PHPMailer Sendmail Argument Injection
CVSS 9.8
Vanilla Forums <2.3.1 - Info Disclosure
CVSS 7.5
Zend Framework < 1.12.14, 2.x < 2.4.6, 2.5.x < 2.5.2 - XML External Entity Injection via Multibyte Encoded Characters
Rejected
Adobe ColdFusion <11-Update 10 - Info Disclosure
CVSS 8.6
Nagios Remote Plugin Executor <2.15 - RCE
wget < 1.17 - Race Condition in Recursive/Mirroring Mode
CVSS 8.1
PHPMailer Sendmail Argument Injection
CVSS 9.8
WordPress <= 4.7.4 - Unauthenticated Weak Password Recovery Mechanism via Host Header Manipulation
CVSS 5.9
GNU wget < 1.18 - Arbitrary File Write via HTTP-to-FTP Redirect
CVSS 8.8
SquirrelMail <20170427_0200-SVN - RCE
CVSS 8.8
Nagios < 4.2.1 - Arbitrary File Read and Write via Spoofed RSS Feed Response
CVSS 9.8
GNU wget < 1.18 - Arbitrary File Write via HTTP-to-FTP Redirect
CVSS 8.8
Exim <4.86.2 - Privilege Escalation
CVSS 7.0
nginx <1.6.2-5+deb8u3 - Privilege Escalation
CVSS 7.8
Nagios Plugins <2.0.2 - Info Disclosure
Nagios < 4.2.3 - Privilege Escalation via Symlink Attack on Log File
CVSS 7.8
Oracle MySQL, MariaDB, Percona Server, Percona XtraDB Cluster - Privilege Escalation via Symlink Attack
CVSS 7.0
Oracle MySQL <5.5.52, 5.6.x <5.6.33, 5.7.x <5.7.15, and 8.x <8.0.1 - Privilege Escalation
CVSS 7.0
Oracle MySQL, MariaDB, Percona Server - Privilege Escalation via my.cnf
CVSS 9.8