Milad Khoshdel

3 exploits Active since Oct 2019
CVE-2019-19491 EXPLOITDB MEDIUM text WORKING POC
TestLink 1.9.19 - XSS
TestLink 1.9.19 has XSS via the lib/testcases/archiveData.php edit parameter, the index.php reqURI parameter, or the URI in a lib/testcases/tcEdit.php?doAction=doDeleteStep request.
CVSS 6.1
CVE-2019-17382 EXPLOITDB CRITICAL text WORKING POC
Zabbix < 4.4 - IDOR
An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/Password (i.e., anonymously). All created elements (Dashboard/Report/Screen/Map) are accessible by other users and by an admin.
CVSS 9.1
EIP-2026-113506 EXPLOITDB text WORKING POC
WordPress Core 5.2.4 - Cross-Origin Resource Sharing