jet-pentest
20 exploits
Active since Aug 2020
Wekan < 6.84 - Authenticated Stored Cross-Site Scripting via Reaction to Comment Feature
Systematic FIX Adapter Firmware 2.4.0.25 - Path Traversal via UNC Share Pathname
Pryaniki 6.44.3 - Authenticated Stored Cross-Site Scripting via File Upload
Revisor Video Management System < 2.0.0 - Path Traversal
Sovremennye Delovye Tekhnologii FX Aggregator Terminal Client 1 - Cleartext Password Storage
Sovremennye Delovye Tekhnologii FX Aggregator Terminal Client 1 - DoS via Excessive Authentication Attempts
Open-AudIT <3.5.3 - Info Disclosure
1C:Enterprise 8 < 8.3.17.1851 - Inadequate Encryption Strength via Base64 Credential Exposure
Lan ATMService M3 ATM Monitoring System 6.1.0 - Info Disclosure
Click Studios Passwordstate 8.9 Build 8973 - Unauthenticated Brute Force Attack via Mobile PIN Code
TranzWare Payment Gateway 3.1.12.3.2 - Unauthenticated Reflected Cross-Site Scripting via Crafted URL
TranzWare Payment Gateway 3.1.12.3.2 - Unauthenticated Reflected Cross-Site Scripting via Crafted URL
Lan ATMService M3 ATM Monitoring System 6.1.0 - Info Disclosure
LPAR2RRD/STOR2RRD 2.70 - Command Injection
Rubetek RV-3406, RV-3409, and RV-3411 Firmware v339, v342 - Unauthenticated Access to RTSP and ONFIV Services
Rubetek RV-3406, RV-3409, and RV-3411 Firmware v342, v339 - Cleartext Transmission of Sensitive Information
Rubetek RV-3406, RV-3409, RV-3411 Firmware v339, v342 - Use of Hard-coded Credentials in Telnet Service
kickdler < 1.107.0 - Cross-Site Scripting via HTTP Response Splitting
CVSS 6.1
remark42 < 1.12.1 - Server-Side Request Forgery via Newsletter Import URL Parameter
CVSS 7.5
Solar appScreener <= 3.10.4 - XML External Entity Injection and Server-Side Request Forgery via Crafted XML Document
CVSS 9.8