John Page aka hyp3rlinx
64 exploits
Active since Jan 2016
PHPfileNavigator 2.3.3 - Cross-Site Request Forgery
PHP PEAR HTTP_Upload 1.0.0b3 - Arbitrary File Upload
PEAR Base System 1.10.1 - Arbitrary File Overwrite via Unvalidated Redirect Response
CVSS 7.5
eXtplorer 2.1.9 - Path Traversal via Archive Extraction
CVSS 7.8
EasyPHP Devserver 16.1.1 - Cross-Site Request Forgery / Remote Command Execution
Apache2Triad 1.5.4 - Cross-Site Scripting via phpsftpd/users.php Account Parameter
CVSS 6.1
Splunk Enterprise <6.5.1 & Splunk Light <6.5.2 - Sensitive Info Exposure via Global Window Namespace
CVSS 3.5
Yaws 1.91 - Unauthenticated Path Traversal via HTTP Directory Traversal with /%5C../
CVSS 7.5
ntopng < 2.4 - Cross-Site Request Forgery via User Management Endpoints
CVSS 8.8
WSO2 Carbon 4.4.5 - Stored Cross-Site Scripting via Multiple Parameters
CVSS 6.1
WSO2 Carbon 4.4.5 - Authenticated Path Traversal via LogViewer Admin Service LogFile Parameter
CVSS 4.9
WSO2 Carbon 4.4.5 - Cross-Site Request Forgery via Server Shutdown Action
CVSS 5.7
WSO2 Identity Server 5.1.0 - Authenticated XML External Entity Injection via XACML Request
CVSS 7.5
Trend Micro Deep Discovery Inspector 3.8/3.7 - Cross-Site Request Forgery