Pedro Ribeiro
213 exploits
Active since Jan 2014
ManageEngine Password Manager Pro 5-7 build 7003 - SQL Injection via MetadataServlet sv Parameter
ManageEngine <9-0.90043 - SQL Injection
ManageEngine OpManager 11.3-11.4, IT360 10.3-10.4, Social IT Plus 11.0 SQL Injection
ManageEngine OpManager 8-11.5 - SQL Injection via FailOverHelperServlet Parameters
ManageEngine Netflow Analyzer 8.6-10.2 and IT360 10.3 - Path Traversal via DisplayChartPDF Filename Parameter
ManageEngine EventLog Analyzer 7-9.9 - Credentials Disclosure
CVSS 7.5
ManageEngine Desktop Central < 90109 - Unauthenticated Administrator Account Creation via DCPluginServelet
CVSS 9.8
ManageEngine EventLog Analyzer 9.0/8.2 - Remote Code Execution via ZIP Traversal
Micro Focus Novell Service Desk <7.2 - Path Traversal
CVSS 7.2
IBM Planning Analytics <2.0.9 - Privilege Escalation
CVSS 9.8
D-Link DIR Routers - Stack-Based Buffer Overflow via Malformed SOAP HNAP Login Action
CVSS 9.8
Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilities
Cisco Prime Infrastructure - Path Traversal
CVSS 9.8
Apple Mac OS X < 10.10.4 - Numeric Error
TP-Link Archer A7 Firmware <190726 - RCE
CVSS 8.8
ZOHO WebNMS Framework 5.2-5.2 SP1 - Auth Bypass
CVSS 9.8
Cisco Prime Infrastructure - Runrshell Privilege Escalation (Metasploit)
ManageEngine ServiceDesk Plus MSP 5-9.0.9030 Path Traversal
CVSS 8.8
Micro Focus Novell Service Desk <7.2 - XSS
CVSS 5.4
Novell ZENworks Configuration Management < 11.3.2 - Remote Code Execution via UploadServlet uid Parameter
ManageEngine Desktop Central 7.0-9.0 - Path Traversal & Arbitrary File Write via AgentLogUploader
CVSS 9.8
SysAid < 15.1 - Remote Code Execution via RdsLogsEntry File Upload
ManageEngine OpManager 8.8-11.3, Social IT Plus 11.0, IT360 <=10.4 - Path Traversal & Arbitrary File Write
ManageEngine OpManager 11.3-11.4, IT360 10.3-10.4, Social IT Plus 11.0 SQL Injection
Novell ZENworks Configuration Management < 11.3.2 - Remote Code Execution via UploadServlet uid Parameter