Skip to content
/ CVEs Public

The following is a list of my collected CVE's

Notifications You must be signed in to change notification settings

sT0wn-nl/CVEs

Repository files navigation

The following is a list of my collected CVE's

FortiClient for Windows

Uniguest Tripleplay

Tripleplay’s TripleSign Digital Signage is a fully integrated digital signage platform that allows users to dynamically control, update and deliver digital and video communications to a variety of end devices. During a pentest i've found multiple 0days that affacted the latest firmware:

Nagios XI

Nagios XI is an enterprise monitoring solution, see https://www.nagios.com/products/nagios-xi/ for more information. During an pentest i've found 4 0days:

  • CVE-2022-29270 No password conformation during e-mail change leads to account takeover
  • CVE-2022-29272 Open redirect in login form
  • CVE-2022-29269 HTML injection in schedueld report mails
  • CVE-2022-29271 Permissions issue where read-only users could schedule downtimes using downtime.php

Glory Systems, RBW-100

The Glory RBW-100 banknote recycling system controls cash and removes the need for manual note handling. I've found two vulnerabilities in the Font Circle Controller management interface that can lead to a reverse root-shell:

See a POC, combining these two vulnerabilities in action: https://youtu.be/MSKDfLpPOLw

About

The following is a list of my collected CVE's

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published