joernchen
24 exploits
Active since Mar 2011
Malicious Git HTTP Server For CVE-2017-1000117
Malicious Git HTTP Server For CVE-2017-1000117
rubyonrails/web_console < 2.1.2 and rubygems/web-console < 2.1.3 - Improper Access Control via X-Forwarded-For Header
2 stars
Debian Linux < 3.2.22.1 - Improper Input Validation
CVSS 7.3
Malicious Git HTTP Server For CVE-2017-1000117
CVSS 8.8
Malicious Git HTTP Server For CVE-2017-1000117
CVSS 8.8
Distributed Ruby <1.8 - Code Injection
CVSS 9.8
Distributed Ruby <1.8 - Buffer Overflow
CVSS 9.8
Spreecommerce < 0.50.x - Unauthenticated Remote Code Execution via API Search Parameter
CVSS 9.8
Spreecommerce < 0.60.2 - Unauthenticated Remote Code Execution via Search Parameter
CVSS 9.8
Devise <1.5.4, <2.0.5, <2.1.3, <2.2.3 - Unauthenticated Security Bypass
Wireshark 1.0.x 1.2.0-1.2.14 1.4.0-1.4.3 - Denial of Service via SMB or CLDAP Packet
Spreecommerce < 0.60.2 - Unauthenticated Remote Code Execution via Search Parameter
CVSS 9.8
Spreecommerce < 0.50.x - Unauthenticated Remote Code Execution via API Search Parameter
CVSS 9.8
Redmine 0.9.x-1.0.x - Remote Code Execution via Bazaar Repository Adapter
rubyonrails/web_console < 2.1.2 and rubygems/web-console < 2.1.3 - Improper Access Control via X-Forwarded-For Header
rubyonrails/web_console < 2.1.2 and rubygems/web-console < 2.1.3 - Improper Access Control via X-Forwarded-For Header
Redmine SCM Repository 0.9.x/1.0.x - Arbitrary Command Execution (Metasploit)
Gitorious - Arbitrary Command Execution (Metasploit)
Redmine 0.9.x-1.0.x - Remote Code Execution via Bazaar Repository Adapter
Malicious Git HTTP Server For CVE-2018-17456
CVSS 9.8
JRuby Sandbox 0.2.2 - Sandbox Escape
Malicious Git HTTP Server For CVE-2018-17456
CVSS 9.8
sudo 1.8.0-1.8.3p1 - Local Use-After-Free via Format String in sudo_debug