zenofex
13 exploits
Active since Sep 2017
vBulletin 5.x /ajax/render/widget_tabbedcontainer_tab_panel PHP remote code execution.
CVSS 9.8
Live Helper Chat < 3.44 - Stored Cross-Site Scripting via BBCode in Chat Messages
CVSS 6.1
Live Helper Chat < 3.44 - Reflected Cross-Site Scripting via setsettingajax PATH_INFO
CVSS 6.1
vBulletin <5.5.6pl1, <5.6.0pl1, <5.6.1pl1 - Privilege Escalation
CVSS 9.8
vBulletin 5.5.4-5.6.2 - Remote Command Execution via subWidgets Data in AJAX Widget Renderer
CVSS 9.8
vBulletin <5.5.6pl1, <5.6.0pl1, <5.6.1pl1 - Privilege Escalation
CVSS 9.8
QNAP QTS Media Library < 4.2.6/4.3.3.0299 - Unauthenticated RCE via Transcoding
CVSS 9.8
Western Digital MyCloud PR4100 2.30.172 - Unauthenticated Arbitrary File Write and RCE via Multi Uploadify
CVSS 9.8
vBulletin 5.6.2 - 'widget_tabbedContainer_tab_panel' Remote Code Execution
vBulletin 5.6.1 - 'nodeId' SQL Injection
Western Digital MyCloud PR4100 2.30.172 - Unauthenticated Arbitrary File Write and RCE via Multi Uploadify
CVSS 9.8
QNAP Transcode Server - Command Execution (Metasploit)
Samsung Smart Home Camera SNH-P-6410 - Command Injection