Portcullis
24 exploits
Active since May 2008
Oracle Demantra Demand Management - SQL Injection
pimcore < build 3473 - Authenticated Path Traversal and Arbitrary File Write via Admin Asset Compatibility Endpoint
Oracle Demantra Demand Management - SQL Injection
Oracle Demantra Demand Management - Info Disclosure
Oracle Demantra Demand Management <12.2.1 - Info Disclosure
X2Engine X2CRM < 5.0.8 - Authenticated Arbitrary File Upload via .pht Extension
X2Engine X2CRM < 5.0.9 - Cross-Site Request Forgery via User Creation
vtiger CRM < 6.0.0 - Authenticated Path Traversal via KCFinder File Parameter
TestLink 1.9.11 - Authenticated SQL Injection via Name or ID Parameter
ScrewTurn Wiki <2.0.29-2.0.30 - XSS
PHPCompta/NOALYSS <6.7.2 - Command Injection
OpenEMR < 4.1.2 - Authenticated SQL Injection via Multiple Parameters
Enalean Tuleap <7.2 - Info Disclosure
Tuleap < 7.5.99.6 - Remote Code Execution via User-Agent Header
Enalean Tuleap <7.5.99.4 - SQL Injection
dompdf < 0.6.1 - Arbitrary File Read via PHP Wrapper in input_file Parameter
ownCloud < 5.0 - Authenticated Remote Code Execution via Alternate Data Stream Filename Bypass
Viprinet Multichannel VPN Router 300 - XSS
CVSS 6.1
Broadcom Ltd PIPA C211 rev2 - Info Disclosure
SAP Internet Transaction Server 6.20 - Cross-Site Scripting via WGate ~service Parameter
SAP Internet Transaction Server 6.20 - Cross-Site Scripting via WGate ~service Parameter
Procentia IntelliPen <1.1.18.1658 - SQL Injection
BlueDragon < 7.1.1 - Path Traversal via CFChart Servlet QUERY_STRING
IBM AIX 6.1/7.1 & VIOS 2.2.x - Local Privilege Escalation