Navina Asrani

4 exploits Active since Feb 2018
CVE-2018-12529 EXPLOITDB HIGH text WORKING POC
Intex N150 - CSRF
An issue was discovered on Intex N150 devices. The router firmware suffers from multiple CSRF injection point vulnerabilities including changing user passwords and router settings.
CVSS 8.8
CVE-2018-12528 EXPLOITDB HIGH text WORKING POC
Intex N150 - Info Disclosure
An issue was discovered on Intex N150 devices. The backup/restore option does not check the file extension uploaded for importing a configuration files backup, which can lead to corrupting the router firmware settings or even the uploading of malicious files. In order to exploit the vulnerability, an attacker can upload any malicious file and force reboot the router with it.
CVSS 8.1
CVE-2018-6889 EXPLOITDB HIGH text WRITEUP
Typesetter - Code Injection
An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the web cache or perform advanced password reset attacks or even trigger arbitrary user re-direction.
CVSS 8.8
CVE-2018-6888 EXPLOITDB HIGH html WORKING POC
Typesetter - CSRF
An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using a forged HTTP request, a malicious user can lead a user to unknowingly create / delete or modify a user account due to the lack of an anti-CSRF token.
CVSS 8.0