EmreOvunc
20 exploits
Active since May 2018
mySCADA myPRO 7 - Use of Hard-coded Credentials in myscadagate.exe
Nelson Open Source ERP 6.3.1 - SQL Injection via Query Parameter
mySCADA myPRO 7 - Unauthenticated Exposure of Sensitive Information via ProjectID Enumeration
Eaton Intelligent Power Manager <1.6 - Path Traversal
WebPort 1.19.1 - Cross-Site Scripting via Setup Type Parameter
CyBroHttpServer 1.0.3 - Path Traversal via URI
CVSS 5.3
CyBroHttpServer 1.0.3 - Cross-Site Scripting via URI
CVSS 6.1
WebPort 1.19.1 - Cross-Site Scripting via Setup Type Parameter
CVSS 6.1
WebPort 1.19.1 - Cross-Site Scripting via Log Type Parameter
CVSS 6.1
FileRun 2019.05.21 - Cross-Site Scripting via Filename Upload Parameter
CVSS 6.1
FHEM 6.0 - Local File Inclusion via FileLog_logWrapper File Parameter
CVSS 7.5
FileRun 2019.05.21 - Directory Listing in images/extjs
CVSS 5.3
FileRun 2019.05.21 - Directory Listing via css/ext-ux
CVSS 5.3
FileRun 2019.05.21 - Directory Listing in Audio Player Plugin
CVSS 5.3
Medintux 2.16.000 - Reflected Cross-Site Scripting via CCAM.php mot1 Parameter
CVSS 6.1
vtiger CRM 7.2.0 - Reflected Cross-Site Scripting via View Parameter
CVSS 6.1
vtiger CRM 7.2.0 - Unauthenticated Directory Listing via Libraries and Layout Endpoints
CVSS 6.5
OpenEMR 5.0.1 - Authenticated Unrestricted Upload of File with Dangerous Type via controller.php
CVSS 8.8
Nagios XI 5.7.1 - Cross-Site Scripting via returnUrl Parameter
CVSS 6.1
Nagios Log Server < 2.1.7 - Stored Cross-Site Scripting via Snapshot Name Parameter
CVSS 6.1