juan vazquez
645 exploits
Active since Sep 2005
Viscosity 1.4.1 - Privilege Escalation via ViscosityHelper Path Validation Issue
CVSS 9.8
NETGEAR ReadyNAS <4.1.12 & <4.2.24 - Code Injection
Raidsonic IB-NAS5220 and IB-NAS4220 - Unauthenticated OS Command Injection via timeHandler.cgi timeZone Parameter
D-Link DIR-600 Firmware < 2.16ww - Cross-Site Request Forgery via hedwig.cgi, pigwidgeon.cgi, or diagnostic.php
CVSS 8.0
Symantec Web Gateway < 5.0.3 - Remote Code Execution via Management GUI Script Access
Realtek SDK - Remote Code Execution
CVSS 9.8
Linksys WRT54G <4.20.7 - Buffer Overflow
Cisco Linksys WRT110 Firmware - Cross-Site Request Forgery
CVSS 8.8
Netgear routers <1.1.00.45 - Command Injection
CVSS 7.2
D-Link DIR-300 rev B & DIR-600 <2.13/2.14b01 - Command Injection
CVSS 9.8
PineApp Mail-SeCure - Remote Code Execution via Ping Host Parameter
Linksys E-Series - Command Injection
Symantec Web Gateway 5.0.x - Remote Code Execution via File Management Scripts
Sophos Web Appliance <3.7.9.1, <3.8.1.1 - Command Injection
Kloxo < 6.1.12 - Unauthenticated SQL Injection via Login-Name Parameter
E-Mail Security Virtual Appliance ESVA_2057 - Unauthenticated OS Command Injection via learn-msg.cgi id Parameter
GroundWork Monitor Enterprise 6.7.0 - Authenticated Remote Code Execution via monarch_scan.cgi
Mutiny < 5.0-1.11 - Authenticated Path Traversal and Arbitrary File Write via EditDocument Servlet
D-Link DIR-300/615 - Command Injection
CVSS 8.8
WeBid < 1.0.2 - Unauthenticated Remote Code Execution via Converter.php to Parameter
Netgear router <1.0.0.36 - Command Injection
CVSS 7.2
Centreon 2.5.1 and Centreon Enterprise Server 2.2 - SQL Injection via Multiple Parameters
Supermicro Onboard IPMI CGI Vulnerability Scanner
Sophos Web Appliance <3.7.9.1, <3.8-3.8.1.1 - Privilege Escalation
ZPanel - Local Privilege Escalation via zsudo Sudoers Misconfiguration