sinn3r
411 exploits
Active since Dec 2002
Project Pier <0.8.8 - Unauthenticated RCE
Narcissus backend.php - release Parameter Command Injection
Maxthon3 < 3.2.2 build 1000 - Cross-Context Scripting via about:history Page
BlazeVideo HDTV Player Pro v6.6.0.3 - Buffer Overflow
FreeFloat FTP Server - Unauthenticated RCE
CVSS 9.8
Nagios XI Network Monitor <1.3 - Command Injection
Netwin SurgeFTP <23c8 - Command Injection
RealArcade 2.6.0.445 ActiveX - Exec Method Command Execution
AOL Desktop < 9.6 - Stack-based Buffer Overflow via RTX Hyperlink Tag
Subtitle Processor 7.7.1 - Buffer Overflow
SPlayer < 3.7 (Build 2055) - Stack-Based Buffer Overflow via HTTP Content-Type Header
QuickShare File Server 1.2.1 - Path Traversal
AjaXplorer < 2.6 - Unauthenticated Remote Code Execution via access.ssh checkInstall.php destServer Parameter
HP Data Protector - Remote Code Execution via EXEC_CMD Argument Injection
Plixer Scrutinizer < 9.5.0 - Unauthenticated Administrative Account Creation via admin.cgi userprefs Action
Novell eDirectory < 8.7.3.10 - Unauthenticated Denial of Service and Arbitrary File Read via SOAP Interface
Solar FTP Server < 2.1.1 - Denial of Service via USER Command Format String
Microsoft IIS 5.1 on Windows XP SP3 - Directory Authentication Bypass via Crafted Request
MS15-034 HTTP Protocol Stack Request Handling Denial-of-Service
CVSS 9.8
Ruby on Rails 3.x < 3.2.16 and 4.x < 4.0.2 - Denial of Service via Invalid MIME Type Header
HP Data Protector Manager 6.11 - Denial of Service via Large Data Packet to RDS Service
Ipswitch TFTP Server 1.0.0.24 - Path Traversal via RRQ Filename Field
sws_simple_web_server 0.0.4-0.1.0 - Unauthenticated Directory Traversal via Dot-Dot Sequence
ClanSphere 2011.3 - Local File Inclusion
CVSS 7.5
Cisco Firepower Management Center 6.0.1 - Info Disclosure
CVSS 6.5