Denis Chenu
28 exploits
Active since Jun 2015
TCPDF < 6.2.22 - Remote Code Execution via PHAR Deserialization
CVSS 9.8
LimeSurvey 3.17.7+190627 - Cross-Site Scripting via Boxes or Label Title
CVSS 6.1
LimeSurvey < 3.17.14 - Stored Cross-Site Scripting via Survey Group Title
CVSS 5.4
LimeSurvey < 3.17.14 - Reflected Cross-Site Scripting in Survey_Common_Action.php
CVSS 5.4
LimeSurvey < 4.1.12+200324 - Stored Cross-Site Scripting in Survey Groups
CVSS 5.4
LimeSurvey < 2.06+ - Authenticated SQL Injection via sid Parameter
LimeSurvey < 3.14.7 - Authenticated Arbitrary File Read via File Upload Question
CVSS 4.9
LimeSurvey < 3.15.6 - Stored Cross-Site Scripting via Survey Resource Zip Upload
CVSS 6.1
LimeSurvey 3.17.7+190627 - Cross-Site Scripting via Boxes or Label Title
CVSS 6.1
Limesurvey < 3.17.10 - Unauthenticated Arbitrary File Upload via Image MIME Type Bypass
CVSS 7.5
Limesurvey <3.17.14 - Code Injection
CVSS 8.8
LimeSurvey < 3.17.14 - Clickjacking
CVSS 4.3
Limesurvey <3.17.14 - Info Disclosure
CVSS 5.3
Limesurvey <3.17.14 - Info Disclosure
CVSS 7.5
LimeSurvey < 3.17.14 - Authenticated Stored Cross-Site Scripting via Admin Box Button Titles
CVSS 5.4
Limesurvey <3.17.14 - Info Disclosure
CVSS 5.3
Limesurvey <3.17.14 - Info Disclosure
CVSS 5.3
Limesurvey <3.17.14 - Info Disclosure
CVSS 2.7
LimeSurvey < 3.17.14 - Reflected Cross-Site Scripting via Uploaded File Extensions
CVSS 6.1
Limesurvey <3.17.14 - Info Disclosure
CVSS 2.7
Limesurvey <3.17.14 - Command Injection
CVSS 9.8
Limesurvey <3.17.14 - Info Disclosure
CVSS 7.2
Limesurvey <3.17.14 - Privilege Escalation
CVSS 7.2
LimeSurvey < 3.17.14 - Unauthenticated Cookie Access via Missing HttpOnly Flag
CVSS 7.5
LimeSurvey <4.0.0-RC4 - SQL Injection
CVSS 9.8