John Dyer

2 exploits Active since Mar 2013
CVE-2013-1967 WRITEUP WRITEUP
Mediaelementjs Mediaelement.js < 2.11.1 - XSS
Cross-site scripting (XSS) vulnerability in flashmediaelement.swf in MediaElement.js before 2.11.2, as used in ownCloud Server 5.0.x before 5.0.5 and 4.5.x before 4.5.10, allows remote attackers to inject arbitrary web script or HTML via the file parameter.
CVE-2013-2506 WRITEUP WRITEUP
Spree <1.1.6, 1.2.x, 1.3.x - Privilege Escalation
app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updating a user, which allows remote authenticated users to assign arbitrary roles to themselves.