Pedro Ribeiro
213 exploits
Active since Jan 2014
NETGEAR ReadyNAS Surveillance 1.1.1-1.4.1 - Remote Code Execution via NTPServer Parameter
CVSS 9.8
NETGEAR ReadyNAS Surveillance 1.1.1-1.4.1 & NUUO NVRmini2/NVRsolo 1.7.5-3.0.0 - RCE via __debugging_center_utils___.php
CVSS 9.8
NETGEAR Management System NMS300 <1.5.0.11 - RCE
CVSS 9.6
Kaseya VSA <=9.1.0.8 Authenticated Path Traversal & Arbitrary File Write via json.ashx
CVSS 8.8
ManageEngine Password Manager Pro < 7.1 - Authenticated SQL Injection via BulkEditSearchResult.cc SEARCH_ALL Parameter
ZOHO WebNMS Framework 5.2-5.2 SP1 - Info Disclosure
CVSS 9.8
ZOHO WebNMS Framework <5.2-5.2 SP1 - Path Traversal
CVSS 7.5
ZOHO WebNMS Framework <5.2-5.2 SP1 - Path Traversal
CVSS 9.8
Micro Focus Novell Service Desk <7.2 - SQL Injection
CVSS 6.5
Micro Focus Novell Service Desk <7.2 - Info Disclosure
CVSS 6.5
Micro Focus Novell Service Desk <7.2 - Path Traversal
CVSS 7.2
IBM QRadar 7.2-7.3 - Improper Access Control
CVSS 4.2
NUUO NVRmini 2 & NVRsolo <3.0.0 - Info Disclosure
CVSS 9.8
NETGEAR WNR2000v5 Firmware < 1.0.0.34 - Unauthenticated Sensitive Information Exposure via BRS_netgear_success.html
CVSS 9.8
NETGEAR Multiple Routers - Unauthenticated Remote Code Execution via Hidden Lang AVI Parameter Buffer Overflow
CVSS 9.8
ManageEngine Desktop Central < 9.0 - Remote Code Execution via File Upload Path Traversal
ManageEngine Applications Manager <11.9/OpManager 8-11.5/IT360 <=10.5 - Unauthenticated Arbitrary File Read
CVSS 7.5
SysAid Help Desk Arbitrary File Download
Cisco Data Center Network Manager - Unauthenticated Remote Code Execution via Improper Session Management
CVSS 9.8
NETGEAR WNR2000v5 Firmware < 1.0.0.34 - Unauthenticated Remote Code Execution via apply_noauth.cgi
CVSS 9.8
ManageEngine Desktop Central < 90109 - Unauthenticated Administrator Account Creation via DCPluginServelet
CVSS 9.8
IBM Data Risk Manager 2.0.1-2.0.6 - Authentication Bypass via SAML Misconfiguration
CVSS 9.8
ZOHO WebNMS Framework <5.2-5.2 SP1 - Path Traversal
CVSS 7.5
ManageEngine Netflow Analyzer 8.6-10.2 and IT360 10.3 - Path Traversal via schFilePath Parameter
SysAid < 15.1 - Unauthenticated Arbitrary File Write via fileName Parameter