Evgeny Velikoivanenko

4 exploits Active since Sep 2024
CVE-2024-8651 WRITEUP MEDIUM WRITEUP
NetCat CMS <6.4.0.24248 - Info Disclosure
A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whether a user exists in the system, which could be a basis for further attacks. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch.
CVSS 5.3
CVE-2024-8652 WRITEUP MEDIUM WRITEUP
NetCat CMS <6.4.0.24248 - XSS
A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific path on the site. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch.
CVSS 6.1
CVE-2024-8653 WRITEUP MEDIUM WRITEUP
NetCat CMS <6.4.0.24248 - XSS
A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific paths on the site. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch.
CVSS 6.1
CVE-2025-9060 WRITEUP CRITICAL WRITEUP
MSoft MFlash <8.2-653 - RCE
A vulnerability has been found in the  MSoft MFlash application that allows execution of arbitrary code on the server. The issue occurs in the integration configuration functionality that is only available to MFlash administrators. The vulnerability is related to insufficient validation of parameters when setting up security components. This issue affects MFlash v. 8.0 and possibly others. To mitigate apply 8.2-653 hotfix 11.06.2025 and above.
CVSS 9.1