dnr6419
9 exploits
Active since Apr 2018
phpipam 1.4.4 - Authenticated SQL Injection via Subnet Parameter
WordPress 5.6.0-5.7.0 - Authenticated XML External Entity Injection via Media Library File Upload
Modern Events Calendar Lite < 5.16.5 - Arbitrary File Upload via CSV Import
Webmin 1.973 - Stored Cross-Site Scripting via Scheduled Cron Jobs Feature
Kibana Timelion Prototype Pollution RCE
Ampache 4.x.y - Authenticated Code Injection in random.php
CVSS 6.4
WP HTML Author Bio < 1.2.0 - Authenticated Stored Cross-Site Scripting via User Bio
CVSS 5.4
LogonTracer < 1.2.0 - OS Command Injection
CVSS 9.8
TYPO3 < 8.7.11 and 9.1.0 - Stored Cross-Site Scripting via Site Name Configuration
CVSS 4.8