Metin Yunus Kandemir
37 exploits
Active since Apr 2019
klog_server < 2.4.1 - Authenticated OS Command Injection via async.php Source Parameter
CVSS 8.8
klog_server 2.4.1 - OS Command Injection via User Parameter
CVSS 9.8
Hospital Management System 4.0 - Authentication Bypass
Dolibarr < 10.0.2 - Stored Cross-Site Scripting via User-Agent Header
CVSS 6.1
EA Origin 10.5.36 - Remote Code Execution via Origin2 URI Handler Template Injection
CVSS 7.8
Complaint Management System 4.0 - Remote Code Execution
ManageEngine ADSelfService Plus 6.1 - CSV Injection
ManageEngine ADManager Plus <= 7203 - Privilege Escalation via Modify Computers Option
CVSS 8.8
Cockpit Version 234 - Server-Side Request Forgery (Unauthenticated)
Supermicro X10DRH-iT BIOS 2.0a and IPMI Firmware 03.40 - Cross-Site Request Forgery via cgi/config_user.cgi
CVSS 8.8
Supermicro X10DRH-iT BIOS 2.0a and IPMI Firmware 03.40 - Cross-Site Request Forgery via cgi/config_user.cgi
CVSS 8.8
Seagate BlackArmor NAS sg2000-2000.1331 - Command Injection