Fernando Catoira

2 exploits Active since Aug 2018
CVE-2020-13851 METASPLOIT HIGH ruby WORKING POC
Pandora FMS Events Remote Command Execution
Artica Pandora FMS 7.44 allows remote command execution via the events feature.
CVSS 8.8
CVE-2018-14417 EXPLOITDB CRITICAL text WORKING POC
SoftNAS Cloud <4.0.3 - Command Injection
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the 'recentVersion' parameter from the snserv endpoint, allowing an unauthenticated attacker to execute arbitrary commands with root permissions.
CVSS 9.8