SunCSR Team
10 exploits
Active since Feb 2020
Apache Tomcat 7.0.0-7.0.99, 8.5.0-8.5.50, 9.0.0.M1-9.0.0.30 - Remote Code Execution via AJP File Read and JSP Processing
CVSS 9.8
Apache Tomcat 7.0.0-7.0.99, 8.5.0-8.5.50, 9.0.0.M1-9.0.0.30 - Remote Code Execution via AJP File Read and JSP Processing
CVSS 9.8
Simple Board Job < 2.9.3 - Authenticated Path Traversal via sjb_file Parameter
CVSS 7.7
WordPress Plugin W3 Total Cache - Unauthenticated Arbitrary File Read (Metasploit)
Wordpress Plugin wpDiscuz 7.0.4 - Unauthenticated Arbitrary File Upload (Metasploit)
Wordpress Plugin Autoptimize 2.7.6 - Arbitrary File Upload (Authenticated)
WordPress Plugin Autoptimize 2.7.6 - Authenticated Arbitrary File Upload (Metasploit)
Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read (Metasploit)
Ignition < 2.5.2 - Unauthenticated Remote Code Execution via file_get_contents() and file_put_contents()
CVSS 9.8
Apache Flink JobManager Traversal
CVSS 7.5