sinn3r
411 exploits
Active since Dec 2002
Symantec Web Gateway <5.2.2 - Command Injection
Cisco Firepower Mgmt Cntr <6.0.1 - RCE
CVSS 8.8
Axis IP Cameras - OS Command Injection
CVSS 9.8
Dolibarr ERP/CRM <= 3.1.1-3.2.0 - Command Injection
ZPanel - Local Privilege Escalation via zsudo Sudoers Misconfiguration
Cisco Small Business Switches - Unauthenticated Bypass via Hard-coded Credentials
CVSS 9.8
Samba < 3.4.16, 3.5.x < 3.5.14, 3.6.x < 3.6.4 - Remote Code Execution via RPC Array Length Validation Bypass
Symantec Messaging Gateway < 9.5.4 - Default SSH Credentials
Apple Safari - Remote Code Execution via File URL Policy Bypass
Wireshark <1.4.9, <1.6.2 - Privilege Escalation
VideoLAN VLC Media Player <1.1.8 - RCE
MS14-064 Microsoft Windows OLE Package Manager Code Execution
CVSS 7.8
Distinct Intranet Servers <3.10 - Path Traversal
CVSS 9.1
Ziepod+ 1.0 - CrossApplication Scripting
XFTP 3.0 Build 0239 - 'Filename' Remote Buffer Overflow
VLC media player < 2.0.1 - Remote Code Execution via Crafted MMS Stream
NetMechanica NetDecision < 4.5.1 - Denial of Service via Long URL
SeaMonkey through 2.0.14 - Remote Code Execution via Array.reduceRight Integer Overflow
TRENDnet SecurView TV-IP121WN - Buffer Overflow
Synactis PDF In-The-Box - ConnectToSynactic Stack Buffer Overflow (Metasploit)
SolarWinds Firewall Security Manager < 6.6.5 - Remote Code Execution via Client Session Handling
Siemens FactoryLink 8 - CSService Logging Path Parameter Buffer Overflow (Metasploit)
Ricoh DC Software DL-10 <4.5.0.1 - Buffer Overflow
RealPlayer 11.0-11.1 and RealPlayer SP 1.0-1.1.4 - Remote Code Execution via CDDA URI Parsing
Plixer Scrutinizer <= 9.0.1.19899 - Unauthenticated SQL Injection via Default MySQL Credentials