iglocska
99 exploits
Active since Sep 2016
MISP < 2.4.121 - Time-of-check Time-of-use Race Condition in Brute-Force Protection
CVSS 5.9
MISP < 2.4.121 - Brute-Force Attack via Username Canonicalization Bypass
CVSS 5.9
MISP < 2.4.121 - Brute-Force Protection Bypass via HTTP PUT Method
CVSS 8.1
MISP < 2.4.158 - Deserialization of Untrusted Data via PHAR
CVSS 9.8
MISP < 2.4.167 - SQL Injection via IndexFilterComponent Parameter Handling
CVSS 9.8
MISP < 2.4.166 - Improper Handling of Exceptional Conditions via Order Parameter
CVSS 9.8
Malware Information Sharing Platform < 2.3.91 - Unrestricted File Upload in TemplatesController
CVSS 9.8
Malware Information Sharing Platform < 2.3.90 - Cross-Site Scripting in Template Creation
CVSS 6.1
Malware Information Sharing Platform < 2.3.89 - PHP Object Injection via Serialized Data
CVSS 9.8
MISP < 2.4.78 - Stored Cross-Site Scripting via Comment Field
CVSS 6.1
MISP < 2.4.80 - Unauthenticated Arbitrary User Access via CertAuth with External API
CVSS 8.1
MISP < 2.4.80 - Reflected Cross-Site Scripting via QuickDelete Action
CVSS 6.1
MISP 2.4.82 - Stored Cross-Site Scripting via Organisation Name in Sharing Group Population
CVSS 5.4
MISP 2.4.82 - Sensitive Information Disclosure in Audit Log
CVSS 4.9
MISP < 2.4.68 - Cross-Site Scripting in Index Filter Tool and Organisation Landing Page
CVSS 6.1
MISP 2.4.91 - DOM-Based Cross-Site Scripting via Cortex Type Attributes
CVSS 6.1
MISP 2.4.91 - Reflected Cross-Site Scripting via Event View Deleted Attributes Filter
CVSS 6.1
MISP 2.4.92 - Brute-Force Protection Bypass via PUT HTTP Method
CVSS 9.8
MISP 2.4.87 - Authenticated OS Command Injection via Server Setting Path Override
CVSS 7.2
MISP < 2.4.89 - Cross-Site Scripting via Malicious MISP Module
CVSS 6.1
MISP <2.4.89 - Privilege Escalation
CVSS 4.3
MISP < 2.4.105 - Reflected Cross-Site Scripting in Default Layout Template
CVSS 6.1
MISP < 2.4.107 - Stored Cross-Site Scripting in Discussion Interface
CVSS 6.1
MISP < 2.4.107 - Stored Cross-Site Scripting via Link Type Attribute
CVSS 6.1
MISP < 2.4.107 - Stored Cross-Site Scripting via Image Names in Titles
CVSS 6.1