Roberto Suggi Liverani
26 exploits
Active since May 2008
Trend Micro Threat Discovery Appliance 2.6.1062r1 - Path Traversal & File Deletion via Session ID
CVSS 9.8
Rejected
Rejected
Apache mod_cgi Bash Environment Variable Code Injection (Shellshock)
CVSS 9.8
Rejected
GNU Bash < 4.3 - Remote Code Execution via Malformed Environment Variable Function Definitions
CVSS 9.8
Rejected
Rejected
Kemp Load Master < 7.1.20b - Cross-Site Request Forgery in Administrative Pages
CVSS 8.8
Kemp LoadMaster < 7.1-16 - Bash Script Injection via Web User Interface
CVSS 8.8
Maxthon3 < 3.2.2 build 1000 - Cross-Context Scripting via about:history Page
Opera - Stored Cross-Site Scripting via History Search Database
Trend Micro Threat Discovery Appliance admin_sys_time.cgi Remote Command Execution
CVSS 9.8
Maxthon3 < 3.2.2 build 1000 - Cross-Context Scripting via about:history Page
Oracle Java SE <7u4 & <6u32 - Info Disclosure
Oracle Sun Products Suite GlassFish Enterprise Server 3.1.1 - Info ...
Oracle Java SE/Jav for Bus <6-5 - Info Disclosure
Opera Browser 9.52 - Stored Cross-Site Scripting via History Search Query String
Opera 11.51 - Use-After-Free Crash (PoC)
SugarCRM 4.5.1 and 5.0.0 - Path Traversal via URL Parameter in Feed.php
Oracle WebLogic Server Servlet Container - Confidentiality and Integrity Impact
Google Chrome < 39.0.2171.65 - Denial of Service or Other Impact
BlazeDS < 3.2 - Information Disclosure via XML External Entity Injection
CVSS 6.5
Trend Micro Threat Discovery Appliance 2.6.1062r1 - 'dlp_policy_upload.cgi' Remote Code Execution
Oracle iPlanet Web Server <7.0 - Info Disclosure