tarantula-team
8 exploits
Active since Jun 2019
pfSense 2.4.4-p2 and 2.4.4-p3 - Authenticated Remote Code Execution via XSS in diag_command.php and rrd_fetch_json.php
ManageEngine ServiceDesk Plus 9.3 - Stored Cross-Site Scripting via SolutionSearch.do searchText Parameter
CVSS 6.1
ManageEngine ServiceDesk Plus 9.3 - Cross-Site Scripting via SearchN.do userConfigID Parameter
CVSS 6.1
Zoho ManageEngine ServiceDesk Plus 9.3 - Stored Cross-Site Scripting via PurchaseRequest.do serviceRequestId Parameter
CVSS 6.1
Oniguruma <6.9.4_rc2 - Memory Corruption
CVSS 9.8
Oniguruma 6.x <6.9.4_rc2 - Memory Corruption
CVSS 7.5
Zoho ManageEngine ServiceDesk Plus 9.3 - Cross-Site Scripting via SiteLookup.do Search Field
CVSS 6.1
Oniguruma <6.9.4_rc2 - Buffer Overflow
CVSS 7.5