Victor Hanna (9lyph)

2 exploits Active since Feb 2022
CVE-2022-29593 NOMISEC MEDIUM WORKING POC
Dingtian DT-R002 3.1.276A - Unauthenticated Authentication Bypass via HTTP Request Replay
relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post requests without the need for authentication or a valid signed/authorized request.
8 stars
CVSS 5.9
CVE-2021-45901 NOMISEC MEDIUM WORKING POC
ServiceNow Orlando - Info Disclosure
The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.
1 stars
CVSS 5.3