Michael Kaufmann
44 exploits
Active since Jun 2018
Froxlor <2.3.7 DNS Record Validation - Zone File Injection
Froxlor < 0.10.14 - Remote Code Execution via Database Configuration Options
CVSS 8.8
froxlor < 0.10.30 - SQL Injection via Custom DB Name
CVSS 9.8
froxlor/froxlor <2.0.8 - Command Injection
CVSS 8.8
Froxlor has Local File Inclusion via path traversal in API `def_language` parameter that leads to Remote Code Execution
CVSS 9.9
Froxlor <2.3.6 MysqlServer API - PHP Code Injection
CVSS 9.1
Froxlor <2.3.6 DomainZones::add() - BIND Zone File Injection
CVSS 8.5
Froxlor has Incomplete Symlink Validation in DataDump.add() that Allows Arbitrary Directory Ownership Takeover via Cron
CVSS 7.5
Froxlor <2.3.6 EmailSender::add() - Domain Ownership Bypass
CVSS 5.0
Froxlor <2.3.6 Domains.add() - Reseller Quota Bypass
CVSS 5.4
Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones API
CVSS 8.8
froxlor < 2.3.4 - Authenticated Remote Code Execution via Email Validation Bypass
CVSS 9.1
Froxlor <0.9.39.5 - Privilege Escalation
CVSS 7.5
Froxlor < 0.10.14 - Remote Code Execution via Database Configuration Options
CVSS 8.8
Froxlor < 0.10.14 - Information Disclosure and Denial of Service via Static /tmp File Creation
CVSS 6.1
froxlor < 0.10.38 - Cross-Site Request Forgery
CVSS 6.5
froxlor < 0.10.39 - Code Injection
CVSS 4.6
froxlor/froxlor <0.10.38.2 - Code Injection
CVSS 6.1
froxlor/froxlor <2.0.0-beta1 - Command Injection
CVSS 5.4
froxlor/froxlor <2.0.0-beta1 - CSRF
CVSS 4.3
GitHub froxlor/froxlor <2.0.0-beta1 - Info Disclosure
CVSS 4.3
froxlor/froxlor <2.0.0 - Path Traversal
CVSS 5.5
GitHub froxlor/froxlor <2.0.10 - Info Disclosure
CVSS 5.4
froxlor/froxlor <2.0.10 - Info Disclosure
CVSS 5.5
froxlor < 2.0.10 - Cross-Site Scripting
CVSS 6.2