winterwolf32
20 exploits
Active since Aug 2016
PHPMailer Sendmail Argument Injection
CVSS 9.8
vBulletin <4.2.2 PL5 & <4.2.3 PL1 - SQL Injection
CVSS 9.8
Jboss Application Server - Code Injection
CVSS 9.8
Apache Tomcat 7.0.0-7.0.79 - Unauthenticated Remote Code Execution via JSP Upload
CVSS 8.1
Apache Tomcat 7.0.0-7.0.81, 8.0.0.RC1-8.0.46, 8.5.0-8.5.22, 9.0.0.M1-9.0.0 - Remote Code Execution via JSP Upload
CVSS 8.1
Redhat Enterprise Linux Desktop < 63.0.3239.84 - Use After Free
CVSS 8.8
Apache HTTP Server 2.2.x < 2.2.33 and 2.4.x < 2.4.26 - NULL Pointer Dereference in mod_ssl
CVSS 9.8
Internet Information Services 6.0 - Remote Code Execution via WebDAV PROPFIND Request
CVSS 9.8
Apache httpd <2.2.33, <2.4.26 - Buffer Overflow
CVSS 9.8
WordPress <= 4.7.4 - Unauthenticated Weak Password Recovery Mechanism via Host Header Manipulation
CVSS 5.9
Joomla! 3.7.x - SQL Injection
CVSS 9.8
Apache Struts 2.1.x and 2.3.x - Remote Code Execution via ActionMessage Field Value
CVSS 9.8
Apache httpd <2.4.28 - Use After Free
CVSS 7.5
Apache Struts 2 REST Plugin XStream RCE
CVSS 8.1
Libgcrypt < 1.7.10 and 1.8.x < 1.8.3 - ECDSA Key Discovery via Memory-Cache Side-Channel Attack
CVSS 4.7
iPhone OS < 12.0 - Memory Corruption via ICMP Error Handling
CVSS 8.8
Drupal Drupalgeddon 2 Forms API Property Injection
CVSS 9.8
Drupal 7.x < 7.59 - Remote Code Execution
CVSS 9.8
Apache HTTP Server 2.4.17-2.4.38 - Use-After-Free in Scoreboard
CVSS 7.8
Drupal 7.0.0-7.61.0 8.5.0-8.5.10 8.6.0-8.6.9 - Remote Code Execution via Unsanitized Field Data
CVSS 8.1