Maximilian Marx

2 exploits Active since Oct 2014
CVE-2014-7205 NOMISEC WORKING POC
hapi Server Framework - Code Injection
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server framework for Node.js allows remote attackers to execute arbitrary Javascript code via unspecified vectors.
3 stars
CVE-2016-2555 NOMISEC CRITICAL WORKING POC
Atutor - SQL Injection
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.
1 stars
CVSS 9.8