bcoles
168 exploits
Active since Mar 1998
Dell KACE K1000 <5.4.76849-5.5.90547 - File Upload
openSIS 4.5-5.2 - Remote Code Execution via ajax.php modname Parameter
WebTester 5.x - Unauthenticated OS Command Injection via install2.php Parameters
Xymon Daemon Gather Information
CVSS 7.5
PHP-Charts 1.0 - Unauthenticated Remote Code Execution via GET Parameter Eval Injection
Kimai 0.9.2.x - Unauthenticated SQL Injection via db_restore.php dates[] Parameter
ProjectSend r100-r561 - Unauthenticated Arbitrary File Upload and Remote Code Execution via process-upload.php
Quest KACE System Management Appliance 8.0.318 - Unauthenticated OS Command Injection via download_agent_installer.php
CVSS 9.8
Actual Analyzer <2014-08-29 - Code Injection
CVSS 9.8
FusionPBX 4.4.3 - Command Injection
CVSS 8.8
Simple E-Document 3.0-3.1 - File Upload
Xymon 4.1.x-4.3.x - Authenticated Command Injection via adduser_name Argument
CVSS 8.8
Kordil EDMS v2.2.60rc3 - Unauthenticated RCE
Glossword 1.8.8-1.8.12 - Authenticated Arbitrary File Upload and Remote Code Execution via Administrative Interface
FreeSWITCH <1.10.1 - Info Disclosure
CVSS 9.8
eXtplorer < 2.1.2 - Unauthenticated Authentication Bypass via Empty Password Array
CVSS 9.8
TestLink <1.9.3, 1.8.5b - SQL Injection
CuteFlow < 2.11.2 - Unauthenticated Arbitrary File Upload via restart_circulation_values_write.php
QEMU < 4.0.0 - OS Command Injection via QMP Migrate Command
CVSS 9.8
GNU Bash through 4.3 bash43-026 - Remote Code Execution via Environment Variable Function Parsing
CVSS 8.8
ProcessMaker Open Source 2.x - Code Injection
elFinder < 2.1.48 - OS Command Injection in PHP Connector
CVSS 9.8
ProcessMaker < 3.5.4 - Authenticated Remote Code Execution via Plugin Upload
ZoneMinder Video Server <1.25.0 - Command Injection
VICIdial <2.13 RC1 - Command Injection