jim-p
19 exploits
Active since Feb 2019
pfSense 2.4.4-p3 - Stored Cross-Site Scripting via ACME Account Name or Description Field
CVSS 6.1
netgate/haproxy < 0.59_16 - Cross-Site Scripting via Description or ACL Parameter
CVSS 6.1
netgate/haproxy < 0.59_16 - Cross-Site Scripting via Description or ACL Parameter
CVSS 6.1
pfSense < 2.4.5 - Stored Cross-Site Scripting via User Full Name Parameter
CVSS 5.4
Netgate pfSense <2.7.0 - Command Injection
CVSS 8.8
Netgate pfSense < 2.7.0 and pfSense Plus < 23.05.1 - Remote Code Execution via packet_capture.php
CVSS 8.8
apcupsd 0.3.91_5 - Cross-Site Scripting in apcupsd_status.php
CVSS 6.1
apcupsd 0.3.91_5 - OS Command Injection in apcupsd_status.php
CVSS 9.8
pfSense <= 2.4.4-p3 - Cross-Site Scripting via services_captiveportal_mac.php Parameters
CVSS 6.1
pfSense < 2.4.4 - Path Traversal via Unsanitized widgetkey Parameter
CVSS 9.8
pfSense-pkg-freeradius3 < 0.15.7_3 - Stored Cross-Site Scripting via Username or Password Field
CVSS 6.1
pfSense < 2.4.5 - Stored Cross-Site Scripting in diag_ping.php Hostname Field
CVSS 6.1
Netgate ACME 0.6.3 - Stored Cross-Site Scripting via RootFolder Parameter
CVSS 6.1
Netgate pfSense 2.4.4 and ACME package 0.6.3 - Stored Cross-Site Scripting via RootFolder Field
CVSS 9.6
pfSense 2.4.5-p1 - Authenticated Stored Cross-Site Scripting via load_balancer_monitor.php
CVSS 5.4
pfSense CE <2.6.0 - pfSense Plus <22.01 - XSS
CVSS 6.1
pfSense 2.5.2 - Stored Cross-Site Scripting in browser.php via File Name
CVSS 6.1
Netgate pfSense CE - Path Traversal
CVSS 8.8
pfSense < 2.8.0 - Reflected Cross-Site Scripting via showsticktablecontent Parameter
CVSS 6.1