John Page a.k.a hyp3rlinx
10 exploits
Active since Apr 2017
Subsonic 6.1.1 - Cross-Site Request Forgery in Podcast Feature
CVSS 8.8
Subsonic 6.1.1 - Cross-Site Request Forgery in Podcast Subscription
CVSS 8.8
subsonic 6.1.1 - Cross-Site Request Forgery via userSettings.view
CVSS 7.5
Mako Web Server 2.5 - Multiple Vulnerabilities
Symantec Endpoint Protection <SEP 14 RU1 - Privilege Escalation
CVSS 7.1
Subsonic 6.1.1 - Server-Side Request Forgery via Import Playlist Feature
CVSS 7.4
MantisBT < 1.3.11, 2.x < 2.3.3, 2.4.x < 2.4.1 - Cross-Site Request Forgery via Permalink Injection
CVSS 6.5
MantisBT < 2.3.0 - Unauthenticated Arbitrary Password Reset via Empty Confirm Hash
CVSS 8.8
mailcow 0.14 - Cross-Site Request Forgery
CVSS 8.8
concrete5 8.1.0 - Cross-Site Scripting via Host Header Injection
CVSS 6.1