Remi GASCOU (Podalirius)

2 exploits Active since Jul 2022
CVE-2022-36446 NOMISEC CRITICAL WORKING POC
Webmin < 1.997 - Remote Code Execution via Unescaped UI Command
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
116 stars
CVSS 9.8
CVE-2022-45771 NOMISEC HIGH WORKING POC
pwndoc v0.5.3 - Unauthenticated Arbitrary Code Execution via Crafted Audit File Upload
An issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary code via uploading a crafted audit file.
47 stars
CVSS 8.8