sinn3r
411 exploits
Active since Dec 2002
Java AtomicReferenceArray Type Violation Vulnerability
CVSS 9.8
Java Applet Rhino Script Engine Remote Code Execution
CVSS 9.8
ManageEngine Security Manager Plus 5.5 build 5505 - SQL Injection (Metasploit)
Splunk 5.0 - Custom App Remote Code Execution (Metasploit)
Squiggle 1.7 - SVG Browser Java Code Execution (Metasploit)
Total.js CMS 12.0.0 - Authenticated RCE
CVSS 9.9
Mozilla Firefox < 18.0 - Remote Code Execution via SVG and Plugin Interaction
Dell SonicWall Scrutinizer 11.0.1 - SQL Injection
HipChat for JIRA <6.30.0 - Code Injection
Apache Struts < 2.2.3.1 - Remote Code Execution via ExceptionDelegator OGNL Expression Injection
CVSS 9.8
Apache Archiva 1.3-1.3.8 - Remote Code Execution via OGNL Expression Injection
CVSS 9.8
WebCalendar < 1.2.5 - Remote Code Execution via form_single_user_login Parameter
CVSS 9.8
Symantec Web Gateway <5.0.3.18 - RCE
Axis IP Cameras - Exposed Insecure Interface
CVSS 9.8
Cisco Firepower Mgmt Cntr <6.0.1 - RCE
CVSS 8.8
Cisco Prime Infrastructure/EPN Manager - RCE
CVSS 8.8
Github Enterprise - Default Session Secret and Deserialization (Metasploit)
Github Enterprise - Default Session Secret and Deserialization (Metasploit)
Ruby On Rails DoubleTap Development Mode secret_key_base Vulnerability
CVSS 9.8
Samba < 3.4.16, 3.5.x < 3.5.14, 3.6.x < 3.6.4 - Remote Code Execution via RPC Array Length Validation Bypass
Symantec Messaging Gateway < 9.5.4 - Default SSH Credentials
Symantec Web Gateway <5.2.2 - Command Injection
Symantec Web Gateway < 5.0.3 - Remote Code Execution via Management GUI Script Access
VICIDIAL dialer <2.8-403a, 2.7, 2.7RC1 - Info Disclosure
ZPanel 10.0.0.2 htpasswd Module - 'Username' Command Execution (Metasploit)