Spencer McIntyre
131 exploits
Active since Mar 1998
ManageEngine OpManager < 125203 - Remote Code Execution via Smart Update Manager Servlet
CVSS 9.8
PHPMailer Sendmail Argument Injection
CVSS 9.8
pgAdmin4 < 8.4 - Unauthenticated Path Traversal and Remote Code Execution via Session Deserialization
CVSS 9.9
Fortinet Forticlient Endpoint Management Server - SQL Injection
CVSS 9.8
Microsoft SharePoint - Remote Code Execution via Unsafe Control and ViewState
CVSS 8.8
Microsoft Exchange Server - Remote Code Execution via Untrusted Data Deserialization
CVSS 8.0
.NET Framework, SharePoint Server, and Visual Studio - Remote Code Execution via XML Input Deserialization
CVSS 7.8
.NET Framework - Remote Code Execution via XML Injection
CVSS 9.8
Telerik UI for ASP.NET AJAX < 2017.1.118 - Remote Code Execution via Weak RadAsyncUpload Encryption
CVSS 9.8
Progress Telerik Report Server < 10.0.24.130 - Remote Code Execution via Insecure Deserialization
CVSS 9.9
Microsoft Exchange Server - Remote Code Execution
CVSS 9.1
MyLittleAdmin 3.8 - Unauthenticated Remote Code Execution via Hardcoded MachineKey
CVSS 9.8
Microsoft Exchange Server - Privilege Escalation
CVSS 9.0
Advantech iView <5.7.03.6112 - Code Execution
CVSS 9.8
Microsoft SQL Server Reporting Services - Remote Code Execution via ViewState Deserialization
CVSS 8.8
SolarWinds Platform - Code Injection
CVSS 7.2
Firebird <2.1.5-2.5.3 - Buffer Overflow
Lianja SQL Server < 1.0 - Stack-Based Buffer Overflow via TCP Port 8001
Ivanti Endpoint Manager < 2022 - Privilege Escalation or Remote Code Execution
CVSS 9.8
Apache mod_cgi Bash Environment Variable Code Injection (Shellshock)
CVSS 9.8
HP-UX - Unauthenticated Remote Login via Default Null Password
Atlassian Confluence SSTI Injection
CVSS 9.8
Log4Shell HTTP Header Injection
CVSS 10.0
Microsoft Windows XP SP3 - Privilege Escalation
Windows 7 SP1 and Windows Server 2008 R2 SP1 - Local Privilege Escalation via Win32k NULL Page