Matthew Fulton
13 exploits
Active since Sep 2017
Apache Tomcat 7.0.0-7.0.79 - Unauthenticated Remote Code Execution via JSP Upload
ASUSTOR ADM < 3.1.2.rhg1 - Unauthenticated Remote Code Execution via script Parameter
CVSS 9.8
ASUSTOR AS6202T ADM < 3.1.0.RFQ3 - Unauthenticated Arbitrary File Upload via importuser.cgi
CVSS 7.2
ASUSTOR AS6202T ADM < 3.1.0.RFQ3 - Path Traversal via importuser.cgi filename Parameter
CVSS 7.2
ASUSTOR AS6202T ADM < 3.1.0.RFQ3 - Path Traversal via fileExplorer.cgi dest_folder Parameter
CVSS 4.3
ASUSTOR SoundsGood - Stored Cross-Site Scripting via Playlist Parameter
CVSS 5.4
ASUSTOR AS6202T ADM < 3.1.0.RFQ3 - Path Traversal via download.cgi file1 Parameter
CVSS 6.5
ASUSTOR AS6202T ADM < 3.1.0.RFQ3 - Unrestricted File Upload and Path Traversal via upload.cgi filename Parameter
CVSS 8.8
ASUSTOR AS6202T ADM 3.1.0.RFQ3 - Info Disclosure
CVSS 4.3
ASUSTOR ADM < 3.1.2.rhg1 - Unauthenticated Remote Code Execution via script Parameter
CVSS 9.8
ASUSTOR ADM 3.1.0.RFQ3 - Use of Hard-coded Credentials
CVSS 9.8
ASUSTOR ADM < 3.1.2.rhg1 - Unauthenticated Remote Code Execution via script Parameter
CVSS 9.8
ASUSTOR ADM 3.1.0.RFQ3 - SQL Injection via Photo Gallery Tree List Album ID or Scope Parameter
CVSS 9.8