sinn3r
411 exploits
Active since Dec 2002
S40 CMS 0.4.2 - Unauthenticated Path Traversal via Index.php p Parameter
Sockso Music Host Server <=1.5 - Path Traversal
Yaws 1.91 - Authenticated Path Traversal via URL Request
CVSS 6.5
WPO WebPageTest 19.04 - Path Traversal via Unanchored Regular Expression
CVSS 7.5
sws_simple_web_server 0.0.4-0.1.0 - Unauthenticated Directory Traversal via Dot-Dot Sequence
bitweaver < 2.8.1 - Path Traversal via overlay_type Parameter
Oracle Sun GlassFish Enterprise Server <3.0.1 - Info Disclosure
Symantec Messaging Gateway 9.5.x - Authenticated Path Traversal via Log Export or Backup Restore
ClanSphere 2011.3 - Local File Inclusion
CVSS 7.5
Samba _netr_ServerPasswordSet Uninitialized Credential State
NetMechanica NetDecision < 4.5.1 - Denial of Service via Long URL
MS15-034 HTTP Protocol Stack Request Handling Denial-of-Service
CVSS 9.8
Windows Media Center - Arbitrary File Read via Crafted .mcl File
XBMC/Media Center < 11.0 - Authenticated Path Traversal via HTTP Server URI
Internet Explorer 9-11 - Universal Cross-Site Scripting via IFRAME Redirect and WindowProxy Eval
Advantech WebAccess 8.1 Post Authentication Credential Collector
CVSS 9.8
vBulletin 5.0.0 Beta 11 and earlier - Authenticated SQL Injection via nodeid Parameter
Internet Explorer - Information Disclosure via Microsoft.XMLDOM ActiveX Error Codes
CVSS 6.5
ZPanel < 10.0.0.2 - Authenticated Remote Code Execution via htpasswd Module Username Field
SugarCRM CE <= 6.3.1 - Code Injection
CVSS 9.8
Invision Power Board 3.1.x-3.3.x core.php - Impact Unknown
Adobe ColdFusion <10 - Info Disclosure
LibrettoCMS 1.1.7 - Unauthenticated RCE
Nagios XI Network Monitor <1.3 - Command Injection
Oracle Enterprise Manager Products Suite 13.3.0.1 - RCE
CVSS 6.3