Michal Čihař
23 exploits
Active since Aug 2013
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
CVSS 5.0
Weblate: Arbitrary File Read via Symlink
CVSS 7.7
Weblate: SSRF via Project-Level Machinery Configuration
CVSS 5.0
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
CVSS 5.0
Weblate: Improper access control for pending tasks in API
CVSS 3.1
Weblate <5.16.1 - Info Disclosure
CVSS 4.3
Weblate <5.16.0 - Command Injection
CVSS 6.6
phpMyAdmin <4.0.5 - CSRF
phpMyAdmin <4.0.10.13, <4.4.15.3, <4.5.4 - Info Disclosure
CVSS 5.3
Weblate <4.11 - XSS
CVSS 5.4
Weblate <5.6.2 - Code Injection
CVSS 4.4
Weblate < 5.12 - Brute Force
CVSS 4.9
Weblate <5.12 - Info Disclosure
CVSS 5.3
Weblate <5.13.1 - Info Disclosure
CVSS 6.5
Weblate <5.13.2 - Open Redirect
CVSS 6.1
Weblate <5.13.2 - Open Redirect
CVSS 6.1
Weblate <5.15 - Info Disclosure
CVSS 9.8
Weblate < 5.15.1 - Path Traversal
CVSS 9.1
Weblate < 5.15.2 - Improper Access Control
CVSS 7.5
Weblate Wlc < 1.17.0 - Improper Certificate Validation
CVSS 2.5
Weblate Wlc < 1.17.0 - Information Disclosure
CVSS 5.3
wlc <1.17.2 - Path Traversal
CVSS 8.0
phpMyAdmin <4.0.10.16, <4.4.15.7, <4.6.3 - RCE
CVSS 9.8