Esteban Zárate
9 exploits
Active since Sep 2018
FUEL CMS < 1.4.2 - Unauthenticated Remote Code Execution via Pages Filter or Preview Data Parameter
CVSS 9.8
Pluck CMS < 4.7.13 - Authenticated Remote Code Execution via File Upload Restriction Bypass
CVSS 7.2
magnusbilling 6.0.0-7.2.9 - Unauthenticated OS Command Injection
CVSS 9.8
SPIP < 4.2.1 - Remote Code Execution via Form Value Deserialization
CVSS 9.8
Camaleon CMS < 2.9.1 - Privilege Escalation via Mass Assignment in UsersController
Wing FTP Server NULL-byte Authentication Bypass (CVE-2025-47812)
CVSS 10.0
elFinder < 2.1.48 - OS Command Injection in PHP Connector
CVSS 9.8
Unauthenticated Remote Code Execution - Bricks <= 1.9.6
CVSS 10.0
elFinder < 2.1.48 - OS Command Injection in PHP Connector
CVSS 9.8