r0~
28 POSTS · CVE
DATECATTITLE
2021· 6
07-08CVECVE-2021-38169 - Roxy-WI through 5.2.2.0 allows authenticated cmd Injection07-08CVECVE-2021-38168 - Roxy-WI through 5.2.2.0 allows authenticated SQL injection07-08CVECVE-2021-38167 - Roxy-WI through 5.2.2.0 allows unauthenticated SQL Injection22-07CVECVE-2021-36396 - Moodle Blind SSRF possible against cURL blocked hosts17-05CVECVE-2021-32474 - Moodle Blind SQL injection via MNet authentication16-03CVECVE-2021-20280 - Moodle Stored XSS and blind SSRF via feedback answer text
2020· 2
31-12CVECVE-2020-36474 - safecurl <= 3.3, vanilla forum <= 0.9.2 dns rebind to ssrf29-09CVECVE-2020-26134 - Live Helper Chat before 3.44v - stored xss
CONTACT
rekter0
PROFESSIONAL SLOPPER

Application security research. vulnerability disclosure, and the occasional pre-auth RCE chain.

28CVE7EXPLOIT14POST