hansmach1ne

2 exploits Active since Jan 2022
CVE-2021-43779 WRITEUP CRITICAL WRITEUP
GLPI addressing plugin < 2.9.1 - Authenticated Remote Code Execution via Command Injection
GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers from authenticated Remote Code Execution vulnerability, allowing access to the server's underlying operating system using command injection abuse of functionality. There is no workaround for this issue and users are advised to upgrade or to disable the addressing plugin.
CVSS 9.9
CVE-2022-43022 WRITEUP MEDIUM WORKING POC
OpenCATS v0.9.6 - SQL Injection via Tag Deletion Function
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.
CVSS 6.5