Matteo Cantoni
31 exploits
Active since Feb 1996
HP Operations Manager - Remote Code Execution via Default Credentials and File Upload
Apache Tomcat 5.5.0-5.5.28 and 6.0.0-6.0.20 - Unauthenticated Privilege Escalation via Default Blank Admin Password
HP Operations Dashboard - Unauthenticated Remote Code Execution via Default j2deployer Credentials
IBM Cognos Express 9.0 - Unauthenticated Denial of Service via Hardcoded Credentials
Red Hat JBoss EAP <4.2.0.CP09 and <4.3.0.CP08 - Info Disclosure
HP Operations Manager 8.10 - Unauthenticated Remote Code Execution via Tomcat Manager Upload
IBM Rational Quality Manager and Rational Test Lab Manager - Remote Code Execution via Default Tomcat ADMIN Password
HP-UX - Unauthenticated SNMP Community Name Exposure
CVSS 5.9
SNMP Community Name - Guessable Credential Exposure
FTP Server - Info Disclosure
WP Symposium < 15.7 - SQL Injection via Size Parameter
Usermin < 1.220 - Arbitrary File Read via Path Traversal with URL-Encoded Bypass
Tikiwiki 1.9.5 - Exposure of Sensitive Information via Empty sort_mode Parameter
RealVNC 4.1.1 - Unauthenticated Authentication Bypass via Insecure Security Type
Wireshark < 0.99.6 - Denial of Service via Crafted Chunked Encoding in HTTP Response
Echo/Chargen - DoS
Router/FW - Info Disclosure
HP-UX - Unauthenticated Remote Login via Default Null Password
JBoss Enterprise Application Platform < 4.2.0.CP03 and 4.3.0 < 4.3.0.CP01 - Information Disclosure via Status Servlet
awstats < 6.3 - Remote Code Execution via configdir Parameter
PAJAX 0.5.1 - Remote Code Execution via pajax_call_dispatcher.php Method and Args Parameters
phpMyAdmin <4.0.10.16, <4.4.15.7, <4.6.3 - RCE
CVSS 9.8
TikiWiki < 1.9.4 - Unauthenticated Arbitrary File Upload via jhot.php
TikiWiki 1.9.8 - Remote Code Execution via tiki-graph_formula.php f Parameter
Simple PHP Blog - Remote Code Execution via Unrestricted File Upload