sinn3r
411 exploits
Active since Dec 2002
Total.js CMS 12.0.0 - Authenticated RCE
CVSS 9.9
Basilic 1.5.14 - Remote Command Execution via Config/diff.php File Parameter
VICIDIAL dialer <2.8-403a, 2.7, 2.7RC1 - Command Injection
MobileCartly 1.0 - Unauthenticated Arbitrary File Creation via savepage.php
Havalite CMS 1.1.7 - Unauthenticated RCE
HP SAN/iQ < 9.5 - Authenticated OS Command Injection via Ping Parameter
SSH Tectia Server 6.0.4-6.3.2 - Authentication Bypass via Blank Password
Project Pier <0.8.8 - Unauthenticated RCE
Netwin SurgeFTP <23c8 - Command Injection
Apache Struts < 2.2.3.1 - Remote Code Execution via ExceptionDelegator OGNL Expression Injection
CVSS 9.8
PHP Volunteer Management System v1.0.2 - Code Injection
Dell SonicWall Scrutinizer 11.0.1 - SQL Injection
Apache Archiva 1.3-1.3.8 - Remote Code Execution via OGNL Expression Injection
CVSS 9.8
Log4Shell HTTP Header Injection
CVSS 10.0
HP System Management Homepage - Authenticated OS Command Injection via PATH_INFO to smhutil/snmpchp.php.en
WikkaWiki 1.3.1 and 1.3.2 - Arbitrary PHP Code Write via User-Agent HTTP Header
Ajax File and Image Manager < 1.1 - Remote Code Execution via PHP Code Injection in data.php
Sflog! CMS 1.0 - Authenticated Arbitrary File Upload via Blog Management Interface
PhpTax 0.8 - Unauthenticated Remote Code Execution via drawimage.php pfilez Parameter
Oracle Sun GlassFish Enterprise Server <3.0.1 - Info Disclosure
qdPM 9.1 Authenticated Arbitrary PHP File Upload (RCE)
CVSS 8.8
Narcissus backend.php - release Parameter Command Injection
appRain CMF <= 0.1.5 - Unauthenticated Arbitrary File Upload and Remote Code Execution
HipChat for JIRA <6.30.0 - Code Injection
LotusCMS Fraise 3.0 - Path Traversal and Arbitrary Local File Inclusion via System Parameter