Patrick Hener
15 exploits
Active since Jul 2020
Kardex Mlog MCC 5.7.12+0-a203c2a213-master - Remote Code Execution via Path Traversal and T4 Template Injection
CVSS 9.8
INNEO Startup TOOLS 12.0.66.3784-13.0.70.3804 - Unauthenticated Path Traversal via sut_srv.exe Web Application
CVSS 9.8
goshs < 2.1.1 - Unauthenticated Bulk Download ACL Bypass
CVSS 7.5
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
CVSS 9.1
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
CVSS 9.1
goshs has a Path Traversal issue
CVSS 6.5
goshs has ACL Bypass & Path Traversal
CVSS 5.3
Kardex Mlog MCC 5.7.12+0-a203c2a213-master - Remote Code Execution via Path Traversal and T4 Template Injection
CVSS 9.8
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS
CVSS 6.5
goshs 0.3.4-1.0.4 - Unauthenticated Remote Code Execution via WebSocket Command Injection
CVSS 9.4
goshs is Missing Write Protection for Parametric Data Values
CVSS 7.7
goshs <2.0.0-beta.4 State-Changing Routes - Authorization Bypass
CVSS 9.8
goshs has Auth Bypass via Share Token
CVSS 8.1
Kardex Mlog MCC 5.7.12+0-a203c2a213-master - Remote Code Execution via Path Traversal and T4 Template Injection
CVSS 9.8
INNEO Startup TOOLS 12.0.66.3784-13.0.70.3804 - Unauthenticated Path Traversal via sut_srv.exe Web Application
CVSS 9.8