mhaskar
16 exploits
Active since Apr 2019
Cacti 1.2.8 - Authenticated Remote Code Execution via Cookie Shell Metacharacter Injection
OCS Inventory NG 2.7 - Remote Code Execution via Shell Metacharacters in SNMP MIB File Handling
Open-AudIT 3.3.1 - OS Command Injection via Discovery Settings Exclude IP Parameter
Pandora FMS 7.0NG - Authenticated OS Command Injection via netflow_get_stats ip_src Parameter
rconfig 3.9.2 - OS Command Injection via ajaxServerSettingsChk.php rootUname Parameter
Centreon 18.x < 18.10.6, 19.x < 19.04.3 - Authenticated Remote Code Execution via Monitoring Engine Binary Configuration
Pandora FMS authenticated command injection leading to RCE via LDAP using default DB password
LibreNMS 1.46 - OS Command Injection via $_POST['community'] Parameter
froxlor/froxlor <2.0.8 - Command Injection
FusionPBX 4.4.8 - Authenticated Remote Code Execution via service_edit.php Command Injection
rconfig 3.9.2 - OS Command Injection via catCommand Parameter
Centreon 18.x < 18.10.6, 19.x < 19.04.3 - Authenticated Remote Code Execution via Monitoring Engine Binary Configuration
rconfig 3.9.2 - OS Command Injection via ajaxServerSettingsChk.php rootUname Parameter
CVSS 9.8
LibreNMS 1.46 - OS Command Injection via $_POST['community'] Parameter
CVSS 9.8
rconfig 3.9.2 - OS Command Injection via ajaxServerSettingsChk.php rootUname Parameter
CVSS 9.8
LibreNMS 1.46 - OS Command Injection via $_POST['community'] Parameter
CVSS 9.8