GammaC0de
20 exploits
Active since Jan 2023
pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)
CVSS 8.8
pyLoad has Improper Neutralization of Special Elements used in an OS Command
CVSS 8.8
pyLoad <=0.5.0b3.dev96 - Flask Session Store Code Execution
CVSS 7.5
pyLoad has SSRF in parse_urls API endpoint via unvalidated URL parameter
CVSS 7.7
pyLoad has SSRF fix bypass via HTTP redirect
CVSS 9.1
pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltration
CVSS 6.5
pyload <0.5.0b3.dev32 - Info Disclosure
CVSS 5.3
pyload <0.5.0b3.dev33 - Info Disclosure
CVSS 6.1
pyload <0.5.0b3.dev36 - Info Disclosure
CVSS 6.5
pyload < 0.5.0b3.dev40 - Improper Input Validation
CVSS 7.5
pyload/pyload <0.5.0b3.dev41 - Info Disclosure
CVSS 9.8
pyload < 0.5.0b3.dev42 - Stored Cross-Site Scripting
CVSS 5.4
pyload < 0.5.0b3.dev44 - Improper Certificate Validation
CVSS 7.4
pyload 0.5.0 - Open Redirect via Login Next Parameter
CVSS 6.1
pyload < 0.5.0b3.dev77 - Unauthenticated Log Injection
CVSS 5.3
pyload < 0.5.0 - Open Redirect via Login Redirect Validation
CVSS 4.7
pyLoad CAPTCHA Processing - Unsafe JavaScript Evaluation Code Execution
CVSS 9.8
pyload-ng < 0.5.0b3.dev90 - Unauthenticated Path Traversal and Arbitrary File Write via CNL Blueprint Package Parameter
CVSS 9.8
pyLoad <0.5.0b3.dev91 - SQL Injection
pyload-ng < 0.5.0b3.dev91 - Cross-Site Scripting via Captcha Script Endpoint and Click'N'Load Blueprint
CVSS 8.1