kamal-marouane

2 exploits Active since Jan 2022
CVE-2022-21907 NOMISEC CRITICAL WORKING POC
Windows 10, 11, and Server - Remote Code Execution
HTTP Protocol Stack Remote Code Execution Vulnerability
1 stars
CVSS 9.8
CVE-2022-28346 NOMISEC CRITICAL WORKING POC
Django 2.2-2.2.27, 3.2-3.2.12, 4.0-4.0.3 - SQL Injection via QuerySet Column Alias Dictionary Expansion
An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.
1 stars
CVSS 9.8