Dolev Farhi
40 exploits
Active since May 2014
userSpice 4.3.24 Username Enumeration via existingUsernameCheck.php
CVSS 9.8
userSpice 4.3.24 Cross-Site Scripting via X-Forwarded-For Header
CVSS 6.1
WordPress Plugin WPGraphQL 1.3.5 Denial of Service
CVSS 7.5
VirtualTablet Server 3.0.2 - Denial of Service via Oversized Thrift Payload
CVSS 7.5
dirsearch 0.4.1 - CSV Injection via Redirect Endpoint Path
CVSS 9.8
Hasura GraphQL 1.3.3 - Remote Code Execution via SQL Query Manipulation in run_sql Endpoint
CVSS 9.8
Hasura GraphQL 1.3.3 - Server-Side Request Forgery via Remote Schema Injection
CVSS 5.3
Hasura GraphQL 1.3.3 - Local File Read via SQL Injection in Query Endpoint
CVSS 5.5
Hasura GraphQL 1.3.3 - Denial of Service via Malicious GraphQL Query
CVSS 7.5
M/Monit 3.7.4 - Privilege Escalation
CVSS 8.8
M/Monit 3.7.4 - Authenticated Password Hash Exposure via Admin API Endpoints
CVSS 6.5
Knockpy 4.1.1 - CSV Injection via Server Header Manipulation
CVSS 9.8
M/Monit <3.7.3 - Privilege Escalation
CVSS 9.8
M/Monit <3.3.2 - Privilege Escalation
Spiceworks < 7.2.00190 - Authenticated Cross-Site Scripting via Ticket Summary Field
ZOC SSH Client - Buffer Overflow (SEH) (PoC)
UserSpice 4.3 - Blind SQL Injection
userSpice 4.3 - Cross-Site Scripting
Usercake < 2.0.2 - Cross-Site Request Forgery via User Settings
Openfiler 2.99.1 - Cross-Site Request Forgery via System Shutdown/Reboot
Observium 0.16.7533 - (Authenticated) Arbitrary Command Execution
Observium 0.16.7533 - Cross-Site Request Forgery
m/monit < 3.3.2 - Cross-Site Request Forgery via User Update Endpoint
Cobbler 2.4.x-2.6.x - Authenticated Path Traversal via Kickstart Field
Adiscon LogAnalyzer < 3.6.6 - Cross-Site Scripting via Hostname Parameter