Matthew Aberegg
21 exploits
Active since Jun 2016
Rconfig 3.x Chained Remote Code Execution
CVSS 9.8
LimeSurvey < 4.3.10 - Stored Cross-Site Scripting in Survey Menu via Surveymenu Parameters
CVSS 5.4
LimeSurvey Zip Path Traversals
CVSS 9.8
Nagios XI 5.6.0-5.7.3 - Mibs.php Authenticated Remote Code Exection
CVSS 7.2
Apache James Server < 2.3.2.1 - OS Command Injection
CVSS 8.1
rconfig < 3.9.5 - OS Command Injection via nodeId Parameter
CVSS 9.8
Pandora FMS 7.0 NG 749 - Multiple Persistent Cross-Site Scripting Vulnerabilities
Pandora FMS 7.0 NG 750 - 'Network Scan' SQL Injection (Authenticated)
Pandora FMS 7.0 NG 749 - 'CG Items' SQL Injection (Authenticated)
osTicket 1.14.1 - 'Saved Search' Persistent Cross-Site Scripting
osTicket 1.14.1 - 'Ticket Queue' Persistent Cross-Site Scripting
Nagios XI 5.7.3 - 'Contact Templates' Persistent Cross-Site Scripting
Nagios XI 5.7.5 - Multiple Persistent Cross-Site Scripting
Nagios XI 5.7.3 - 'SNMP Trap Interface' Authenticated SQL Injection
Nagios XI 5.6.0-5.7.3 - Mibs.php Authenticated Remote Code Exection
CVSS 7.2
Nagios XI 5.7.3 - 'Manage Users' Authenticated SQL Injection
LimeSurvey 4.1.11 - 'Permission Roles' Persistent Cross-Site Scripting
LimeSurvey < 4.1.12+200324 - Stored Cross-Site Scripting in Survey Groups
CVSS 5.4
LimeSurvey < 4.1.12+200324 - Path Traversal in LimeSurveyFileManager
CVSS 9.8
Apache James Server < 2.3.2.1 - OS Command Injection
CVSS 8.1
pfSense < 2.4.5 - Stored Cross-Site Scripting via User Full Name Parameter
CVSS 5.4