RedTeam Pentesting
38 exploits
Active since Feb 2005
Moodle Remote Code Execution (CVE-2024-43425)
Decoda < 3.3.3 - Cross-Site Scripting via Video Directive
Ladon 0.6.1-0.9.39 - XML External Entity Injection in SOAP Request Handlers
CVSS 9.8
ke_dompdf < 0.0.3 - Remote Code Execution
Akronymmanager < 0.5.0 - Authenticated SQL Injection via id Parameter
milesj/decoda < 3.3 - Cross-Site Scripting via img Tag URL
Papoo CMS 3.7.3 - (Authenticated) Arbitrary Code Execution
Mapbender 2.4.4 - SQL Injection via mod_gazetteer_edit.php gaz Parameter
Mapbender 2.4-2.4.4 - Remote Code Execution via mapFiler.php Factor Parameter
IceWarp eMail Server < 9.3.0 - Authenticated SQL Injection via XML Search Query
IceWarp eMail Server < 9.3.0 - Cross-Site Scripting via Email Body or RSS Feed Elements
CitrusDB < 0.3.6 - SQL Injection via CSV File Import
citrusdb <= 0.3.6 - Unauthenticated Authentication Bypass via Predictable MD5 Hash
CVSS 9.8
CitrusDB < 0.3.6 - Directory Traversal via Load Parameter
CitrusDB < 0.3.6 - Unauthenticated Sensitive Information Exposure via Import/Upload Endpoints
CitrusDB < 0.3.6 - Unauthenticated Sensitive Information Exposure via Import/Upload Endpoints
activeWeb contentserver <5.6.2964 - XSS
Python 2.7.5 and 3.3.4 - Path Traversal via URL-Encoded Path Separators
CVSS 9.8
Oracle Endeca Server - Info Disclosure
Apache HTTP Server < 2.2.14 - Plaintext Injection via TLS Renegotiation
CVSS 9.8
Apache HTTP Server <2.4.24 - Info Disclosure
CVSS 7.5
Websockify (C Implementation) 0.8.0 - Buffer Overflow (PoC)
perlpodder < 0.5 - Remote Code Execution via Podcast URL Shell Metacharacters
Dovecot with Exim - 'sender_address' Remote Command Execution
CyberArk Password Vault < 9.7 - Exposure of Sensitive Information via Logon Message Replay
CVSS 5.3