28 POSTS · CVE
DATECATTITLETARGETCVSS
2021· 6
07-08CVECVE-2021-38169 - Roxy-WI through 5.2.2.0 allows authenticated cmd InjectionRoxy-WI8.807-08CVECVE-2021-38168 - Roxy-WI through 5.2.2.0 allows authenticated SQL injectionRoxy-WI8.807-08CVECVE-2021-38167 - Roxy-WI through 5.2.2.0 allows unauthenticated SQL InjectionRoxy-WI9.822-07CVECVE-2021-36396 - Moodle Blind SSRF possible against cURL blocked hostsMoodle7.517-05CVECVE-2021-32474 - Moodle Blind SQL injection via MNet authenticationMoodle7.216-03CVECVE-2021-20280 - Moodle Stored XSS and blind SSRF via feedback answer textMoodle5.42020· 2
31-12CVECVE-2020-36474 - safecurl <= 3.3, vanilla forum <= 0.9.2 dns rebind to ssrfsafecurl9.829-09CVECVE-2020-26134 - Live Helper Chat before 3.44v - stored xssLive6.1CONTACT
rekter0
PROFESSIONAL SLOPPER
Application security research. vulnerability disclosure, and the occasional pre-auth RCE chain.
28CVE7EXPLOIT14POST