juan vazquez
645 exploits
Active since Sep 2005
EGallery 1.2 - Unauthenticated Arbitrary File Upload via uploadify.php
Hastymail2 2.1.1 - Remote Code Execution via rs or rsargs[] Parameter
W3 Total Cache < 0.9.2.8 - Remote PHP Code Execution
CVSS 9.8
InduSoft Web Studio <7.0+Patch 1 - Path Traversal
Basilic 1.5.14 - Remote Command Execution via Config/diff.php File Parameter
vBulletin 5.0.0 Beta 11 and earlier - Authenticated SQL Injection via nodeid Parameter
Joomla! <2.5.14, <3.1.5 - Auth Bypass
TikiWiki CMS/Groupware < 6.7 LTS & < 8.4 - RCE
CVSS 9.8
InstantCMS < 1.6 - Remote PHP Code Execution via Search View Handler
CVSS 9.8
VICIDIAL dialer <2.8-403a, 2.7, 2.7RC1 - Command Injection
DataLife Engine 9.7 - Remote Code Execution via catlist[] Parameter
TWiki MAKETEXT Remote Command Execution
XODA 0.4.5 - Unauthenticated Arbitrary PHP File Upload via Multipart Form Data
Persistent Systems Radia Client Automation <9.1 - RCE
VMware vCenter Server 5.0-5.5 and 6.0 - Remote Code Execution via JMX RMI MBean Registration
Elasticsearch <1.3.8, <1.4.3 - Command Injection
CVSS 9.8
Apache Struts 2.0.0-2.3.16 - Remote Code Execution via DebuggingInterceptor
Support Incident Tracker Remote Command Execution
Elasticsearch < 1.2 - Remote Code Execution via Dynamic Scripting
CVSS 8.1
MoinMoin < 1.9.6 - Authenticated Remote Code Execution via File Upload
Apache Struts < 2.2.3.1 - Remote Code Execution via ExceptionDelegator OGNL Expression Injection
CVSS 9.8
Visual Mining NetCharts Server - Unrestricted File Upload and Remote Code Execution
CVSS 9.8
Splunk 4.2.x - Authenticated Remote Code Execution via mappy.py Python Class Access
DELL SonicWALL Analyzer 7.0, GMS 4.1-7.0, UMA 5.1-7.0, ViewPoint 4.1-6.0 - Authentication Bypass
CVSS 9.8
phpScheduleIt <1.2.10 - Code Injection