murataydemir
27 exploits
Active since Feb 2016
DotNetNuke < 9.1.1 - Remote Code Execution via Cookie Deserialization
Telerik UI ASP.NET AJAX RadAsyncUpload Deserialization
GeoServer < 2.18.7 and 2.18.7-2.21.4 - SQL Injection via OGC Filter and CQL Expressions
SAP NetWeaver AS JAVA - Missing Authentication Check
Oracle WebLogic Server <14.1.1.0.0 - RCE
Apache Flink JobManager Traversal
Cisco ASA 9.6-9.6.4.42 & FTD 6.2.3-6.2.3.16 Unauthenticated Path Traversal
VMware vCenter Server and Cloud Foundation - Remote Code Execution via vSphere Client Plugin
FortiWeb 5.9.0-6.2.3 - Authenticated OS Command Injection via SAML Server Configuration
SAP NetWeaver AS JAVA <7.50 - Path Traversal
Spring Data MongoDB - Code Injection
Apache Solr < 8.8.2 - Server-Side Request Forgery via ReplicationHandler masterUrl Parameter
Amazon AWS Redshift JDBC Driver <2.1.0.8 - Code Injection
VMware vRealize Operations Manager < 8.4 - Server-Side Request Forgery via API
Microsoft Exchange Server - Remote Code Execution via Memory Corruption
Apache Flink <1.11.3-1.12.0 - Path Traversal
Oracle WebLogic Server <14.1.1.0.0 - RCE
BIG-IP 11.6.1-11.6.5.1 - Remote Code Execution via TMUI Undisclosed Pages
SAP NetWeaver Application Server Java 7.40 - SQL Injection
SAP NetWeaver JAVA AS 7.4 - XML External Entity Injection in UDDI Component
lanproxy 0.1 - Path Traversal and Credential Exposure via config.properties
Netlogon Weak Cryptographic Authentication
SAM CLI <v1.133.0 - Privilege Escalation
CVSS 6.5
Jenkins cli Ampersand Replacement Arbitrary File Read
CVSS 9.8
GeoTools < 24.7 and 28.0-28.2 - SQL Injection via OGC Filter Execution
CVSS 9.8