Jens Vagelpohl
12 exploits
Active since Mar 2021
Products.PluggableAuthService < 2.6.1 - Open Redirect via Login Form
CVSS 5.7
Zope 4.0-4.8.10 - Stored Cross-Site Scripting in Title Property
CVSS 3.1
Products.PluggableAuthService < 2.6.0 - Unauthenticated Role Information Disclosure via ZODB Role Manager Plugin
CVSS 6.5
Plone < 4.3.20 - Path Traversal
CVSS 6.8
Zope < 4.6.1 and 5.0-5.2.1 - Authenticated Path Traversal via TAL Expression
CVSS 8.8
AccessControl 4.0-4.2 - Remote Code Execution via String Formatter Override
CVSS 4.4
Zope 4.0-4.6.2 and 5.0-5.2 - Remote Code Execution via Python Script Object Modification
CVSS 7.5
Products.CMFCore < 3.2 - Unauthenticated Denial of Service via Marshal Module Input Handling
CVSS 7.5
RestrictedPython <6.1, 5.3 - Code Injection
CVSS 8.4
AccessControl < 4.4 - Exposure of Sensitive Information via str.format_map
CVSS 6.8
Zope 4.0-4.8.10 - Stored Cross-Site Scripting in Title Property
CVSS 3.1
Products.SQLAlchemyDA < 2.2 - Unauthenticated SQL Injection
CVSS 9.8