mbadanoiu
62 exploits
Active since Dec 2014
VMware vCenter Server - Authenticated Appliance Shell Command Execution
BIG-IP TMOS Shell - Command Injection
F5 BIG-IP 15.1.0-15.1.10.6 - Authenticated OS Command Injection via iControl REST and TMOS Shell Save Command
Apache Superset < 3.1.3 - Authenticated File Read via MariaDB Connection with local_infile
vCenter Sudo Privilege Escalation
Hyland Alfresco Content Services < 7.2.0 - Server-Side Template Injection via folder.get.html.ftl
Apache NiFi 0.0.2-1.21.0 - Authenticated Remote Code Execution via H2 JDBC Database URL
Oracle Enterprise Manager <13.5.0.0 - Unauthorized Access
Apache NiFi 1.8.0-1.21.0 - Authenticated Deserialization of Untrusted Data via JNDI URL Configuration
VMware Cloud Foundation 4.0-5.1.0 - Authenticated Partial File Read
Apache James <3.7.3 - Privilege Escalation
Crafter CMS 3.1.0-3.1.22 - Authenticated Remote Code Execution via Groovy Sandbox Bypass
Apache ActiveMQ Jolokia - Authenticated MBean Code Execution
HSQLDB <2.7.1 - Remote Code Execution via Untrusted SQL Method Calls
Apache James <3.7.5, 3.8.0 - Privilege Escalation
Magnolia CMS < 6.2.4 - Remote Code Execution via Snake YAML Deserialization
Apache OFBiz < 18.12.06 - Remote Code Execution via Solr Plugin RMI Request
Y Soft SAFEQ 6 Build 53 - Privilege Escalation
Y Soft SAFEQ 6 Build 53 - Stored Cross-Site Scripting via Multiple Web Application Fields
Ansible-Tower - Privilege Escalation
GNU wget < 1.18 - Arbitrary File Write via HTTP-to-FTP Redirect
CrafterCMS 4.0.0-4.2.2 - Authenticated Remote Code Execution via Groovy Sandbox Bypass
CVSS 9.1
Apache OFBiz <18.12.18 - Info Disclosure
CVSS 3.5
Apache NiFi 1.21.0-1.23.0 - Authenticated Connection URL Validation Bypass via Custom Input Formatting
CVSS 6.5
Apache ActiveMQ Artemis < 2.29.0 - Authenticated Arbitrary File Write and Remote Code Execution via Log4J2 MBean
CVSS 8.8