hyp3rlinx
260 exploits
Active since Jun 2015
IBM i 7.3, 7.4, and 7.5 - Server-Side Request Forgery
CVSS 5.4
IBM i 7.3-7.5 - Authenticated Authentication Bypass via Navigator for i Interface
CVSS 4.3
Hawkeye-G 3.0.1.4912 - Persistent Cross-Site Scripting / Information Leakage
Hexis HawkEye G 3.0.1.4912 - Cross-Site Request Forgery via Multiple Endpoints
CVSS 8.8
Ericom Access Server x64 9.2.0 - Server-Side Request Forgery
HFS Http File Server 2.3m Build 300 - Buffer Overflow (PoC)
dotDefender Firewall 5.00.12865/5.13-13282 - Cross-Site Request Forgery
Avaya IP Office 9.x, 10.0-10.1.0.7, 11.0-11.0.4.3 - Insufficiently Protected Credentials
CVSS 5.5
Yaws 1.91 - Unauthenticated Path Traversal via HTTP Directory Traversal with /%5C../
CVSS 7.5
WyreStorm Apollo VX20 - Information Disclosure
CVSS 9.1
WyreStorm Apollo VX20 Firmware < 1.3.58 - Unauthenticated User Enumeration via TELNET Service
CVSS 7.5
Trend Micro Deep Discovery Inspector IDS - Security Bypass
WyreStorm Apollo VX20 Firmware < 1.3.58 - Unauthenticated Denial of Service via Reboot Endpoint
CVSS 7.5
ntopng < 2.4 - Cross-Site Request Forgery via User Management Endpoints
CVSS 8.8
op5 7.1.9 - Configuration Command Execution (Metasploit)
WSO2 Carbon 4.4.5 - Authenticated Path Traversal via LogViewer Admin Service LogFile Parameter
CVSS 4.9
ZCMS 1.1 - Cross-Site Scripting
CVSS 4.8
WSO2 Identity Server 5.1.0 - Authenticated XML External Entity Injection via XACML Request
CVSS 7.5
WSO2 Carbon 4.4.5 - Stored Cross-Site Scripting via Multiple Parameters
CVSS 6.1
WSO2 Carbon 4.4.5 - Cross-Site Request Forgery via Server Shutdown Action
CVSS 5.7
JSP/MySQL Administrador Web 1 - Cross-Site Scripting via bd Parameter
Openfire 3.10.2 - Unrestricted Arbitrary File Upload
Openfire 3.10.2 - Remote File Inclusion
Ignite Realtime Openfire 3.10.2 - Privilege Escalation
Ignite Realtime Openfire 3.10.2 - Cross-Site Scripting via Multiple Parameters