Vsevolod Shamov

3 exploits Active since Aug 2020
CVE-2021-3130 NOMISEC MEDIUM WRITEUP
Open-AudIT <3.5.3 - Info Disclosure
Within the Open-AudIT up to version 3.5.3 application, the web interface hides SSH secrets, Windows passwords, and SNMP strings from users using HTML 'password field' obfuscation. By using Developer tools or similar, it is possible to change the obfuscation so that the credentials are visible.
1 stars
CVSS 5.9
CVE-2020-24032 NOMISEC CRITICAL WRITEUP
LPAR2RRD/STOR2RRD 2.70 - Command Injection
tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharacters in a timezone.
1 stars
CVSS 9.8
CVE-2024-38909 WRITEUP CRITICAL WRITEUP
Std42 Elfinder - Improper Access Control
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
CVSS 9.8