drone
23 exploits
Active since Mar 2014
Gitlist - Remote Code Execution via Shell Metacharacters in File Name
Gitlist - Remote Code Execution via Shell Metacharacters in File Name
IBM Tealeaf CX 7.x, 8.x-8.6, 8.7-8.8 - Authenticated Path Traversal via Log Parameter
Kimai 0.9.2.x - Unauthenticated SQL Injection via db_restore.php dates[] Parameter
Kimai 0.9.2.x - Unauthenticated SQL Injection via db_restore.php dates[] Parameter
Gitlist < 0.5.0 - Remote Code Execution via Shell Metacharacters in URI
Kimai 0.9.2.x - Unauthenticated SQL Injection via db_restore.php dates[] Parameter
Gitlist < 0.5.0 - Remote Code Execution via Shell Metacharacters in URI
Liferay Portal 7.0.0 M1/7.0.0 M2/7.0.0 M3 - Remote Code Execution
DjVuLibre 3.5.25.3 - Out of Bounds Access Violation
PHD Help Desk 2.12 - SQL Injection
OpenDocMan 1.2.6.5 - Persistent Cross-Site Scripting
IBM Tealeaf CX 7.x, 8.x-8.6, 8.7-8.8 - Authenticated OS Command Injection via testconn_host Parameter
Dolibarr ERP/CRM 3.4.0 - 'exportcsv.php?sondage' SQL Injection
Collabtive 1.0 - 'manageuser.php' SQL Injection
aMSN 0.98.9 Web App - Multiple Vulnerabilities
Ntpdc 4.2.6p3 - Local Buffer Overflow
Gitter/Gitlist <Repository.php - Command Injection
Gitlist < 0.5.0 - Remote Code Execution via Shell Metacharacters in URI
LShell 0.9.15 - Remote Code Execution
Ganib Project Management 2.3 - SQL Injection
OpenEMM-2013 8.10.380.hf13.0.066 - SOAP SQL Injection / Persistent Cross-Site Scripting
ASUS RT-AC68U and T-Mobile TM-AC1900 - Authenticated OS Command Injection via Network Analysis Target Field