juan vazquez
645 exploits
Active since Sep 2005
Lenovo ThinkManagement Console 9.0.3 - Path Traversal and Arbitrary File Deletion via VulCore Web Service
Apache mod_cgi Bash Environment Variable Code Injection (Shellshock)
CVSS 9.8
TWiki MAKETEXT Remote Command Execution
VICIDIAL < 2.7 - SQL Injection via Campaign Variable in SCRIPT_multirecording_AJAX.php
vtiger CRM 5.1.0-5.4.0 - Authentication Bypass via Improper Session Validation
CVSS 9.8
Windows Adobe Type Manager Library - RCE
CVSS 8.8
Support Incident Tracker 3.65 - Authenticated Sensitive Information Exposure via FTP Upload Filename
Centreon 2.5.1 and Centreon Enterprise Server 2.2 - Remote Code Execution via session_id or template_id Parameter
Oracle VirtualBox < 4.3.8 Local Guest-to-Host RCE via 3D Acceleration
Microsoft Expression Design - Privilege Escalation
Rejected
Lenovo ThinkManagement Console 9.0.3 - Unauthenticated Remote Code Execution via ServerSetup Web Service File Upload
HP LeftHand Virtual SAN Appliance <10.0 - RCE
Adobe Flash Player <10.3.183.51-11.5.502.149 - Buffer Overflow
MS14-060 Microsoft Windows OLE Package Manager Code Execution
CVSS 7.8
MS14-060 Microsoft Windows OLE Package Manager Code Execution
CVSS 7.8
Rejected
Windows - Local Privilege Escalation via EPATHOBJ::pprFlattenRec Pointer Initialization
CVSS 7.8
Microsoft Silverlight <5.1.20913.0 - Info Disclosure
CVSS 5.5
TWiki MAKETEXT Remote Command Execution
Open Flash Chart v2 Beta 1-v2 Lug Wyrm Charmer - RCE
Oracle Java SE <7.7 - Info Disclosure
Centreon 2.5.1 and Centreon Enterprise Server 2.2 - SQL Injection via Multiple Parameters
MoinMoin < 1.9.6 - Authenticated Remote Code Execution via File Upload
Oracle Java SE <7.6 - Info Disclosure