Trustwave's SpiderLabs
41 exploits
Active since Jun 2009
Electronic Arts Karotz Smart Rabbit <12.07.19.00 - Code Injection
CVSS 6.3
MiCasaVerde VeraLite <1.5.408 - SSRF
CVSS 9.8
MiCasaVerde VeraLite <1.5.408 - RCE
CVSS 8.8
MiCasaVerde VeraLite <1.5.408 - Privilege Escalation
CVSS 8.1
MiCasaVerde VeraLite <1.5.408 - Path Traversal
CVSS 6.5
Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204-9.0.1.19899 - Cross-Site Scripting via newUser Parameter
CVSS 6.1
Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204-9.0.1.19899 - SQL Injection via Multiple CGI Parameters
CVSS 9.8
Scrutinizer NetFlow & sFlow Analyzer < 9.0.1.19899 - Unauthenticated Privilege Escalation via User Preferences CGI
CVSS 6.5
WordPress < 3.3.1 - Cross-Site Scripting via Installation Setup Parameters
WordPress < 3.3.1 - Static Code Injection and Cross-Site Scripting via Database Configuration
WordPress < 3.3.1 - Unauthenticated Sensitive Information Exposure via Installation Error Messages
SMC SMCD3G-CCR Firmware < 1.4.0.49 - Cross-Site Request Forgery via Web Interface
SMC SMCD3G-CCR < 1.4.0.49 - Unauthenticated Administrative Access via Default Credentials
Tableau Server 8.0.x-8.0.6 and 8.1.x-8.1.1 - Authenticated SQL Injection
McAfee SuperScan 4.0 - Cross-Site Scripting via UTF-7 Encoded Server Response
DaumGame ActiveX Control 1.1.0.4 and 1.1.0.5 - Buffer Overflow via IconCreate Method
IBM Web Application Firewall - Bypass
WordPress < 3.3.1 - Denial of Service via MySQL Query Proxy in Setup-Config
IceWarp Mail Server <11.2 - Path Traversal
CVSS 7.5
FreePBX < 2.8.0 - Authenticated Path Traversal and Arbitrary File Write via System Recordings Component
bitweaver < 2.8.1 - Cross-Site Scripting via Path Info or Parameter Injection
CVSS 6.1
Rejected
Scrutinizer NetFlow & sFlow Analyzer < 8.6.2.16204 - Cross-Site Scripting via Standalone Parameter
CVSS 6.1
Oracle GlassFish Server Open Source Edition 4.1 - Path Traversal
CVSS 7.5
Apache Commons FileUpload <1.3.1 - DoS