karthikeyan V (karthithehacker)

3 exploits Active since Jun 2006
CVE-2020-17453 NOMISEC MEDIUM SCANNER
WSO2 Management Console <5.10 - XSS
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
5 stars
CVSS 6.1
CVE-2006-2842 NOMISEC SCANNER
SquirrelMail <1.4.6 - RCE
PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the plugins array parameter. NOTE: this issue has been disputed by third parties, who state that Squirrelmail provides prominent warnings to the administrator when register_globals is enabled. Since the varieties of administrator negligence are uncountable, perhaps this type of issue should not be included in CVE. However, the original developer has posted a security advisory, so there might be relevant real-world environments under which this vulnerability is applicable
3 stars
CVE-2021-31589 NOMISEC MEDIUM SCANNER
Beyondtrust Appliance Base Software < 6.0.1 - XSS
A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which allows the injection of unauthenticated, specially-crafted web requests without proper sanitization.
1 stars
CVSS 6.1