Metin Yunus Kandemir
37 exploits
Active since Apr 2019
klog_server < 2.4.1 - Authenticated OS Command Injection via async.php Source Parameter
PhreeBooks ERP 5.2.3 Remote Code Execution via Image Manager
CVSS 8.8
Dolibarr ERP/CRM 10.0.1 - SQL Injection
CVSS 7.5
Dolibarr ERP/CRM 10.0.1 - SQL Injection
CVSS 7.5
Zoho ManageEngine ADSelfService Plus <6.2.02 - Info Disclosure
CVSS 5.3
Asp.Net Zero < 12.3.0 - Open Redirect via WebSocket Message HTML Injection
CVSS 6.1
Exagate Sysguard 6001 - Cross-Site Request Forgery via /kulyon.php Admin Account Creation
CVSS 5.3
PhreeBooks 5.2.3 - Authenticated RCE
CVSS 8.8
Brother BRAdmin Professional 3.75 - Local Privilege Escalation
CVSS 7.8
Thecus N4800Eco - Command Injection
CVSS 8.8
OpenLiteSpeed 1.7.8 - Privilege Escalation to Root via Command Injection
CVSS 8.8
CSZ CMS 1.2.7 - Stored Cross-Site Scripting via Private Message User-Agent Header
CVSS 5.4
CSZ CMS 1.2.7 - Authenticated HTML Injection via Member Messaging System
CVSS 5.4
Snipe-IT 4.7.5 - XSS
CVSS 6.4
WEB STUDIO Ultimate Loan Manager 2.0 - XSS
CVSS 6.1
klog_server 2.4.1 - OS Command Injection via User Parameter
CVSS 9.8
ManageEngine ADManager Plus Build < 7183 - Recovery Password Disclosure
Zohocorp ManageEngine ADAudit Plus - NTLM Hash Disclosure
CVSS 8.8
ManageEngine ADSelfService Plus 6.1 - User Enumeration
Microsoft 365 Apps and Office - Exposure of Sensitive Information via Spoofing
CVSS 6.5
Intel(r) Management and Security Application 5.2 - User Notification Service Unquoted Service Path
Free SMTP Server 2.5 - Denial of Service (PoC)
Shopping Portal ProVersion 3.0 - Authentication Bypass
Online Course Registration 2.0 - Remote Code Execution
MyT 1.5.1 Username - Cross-Site Scripting
CVSS 6.1