Exploit catalog results

Showing 19 PoCs on this page

Metasploit

openSIS Unauthenticated PHP Code Execution

Metasploit exploitAdded to Metasploit 2020-06-30
Not analyzedCVE-2020-13381CVE-2020-13382CVE-2020-133831 file

exploit_unix/webapp/opensis_chain_exec · Ruby

Metasploit

Mantis manage_proj_page PHP Code Execution

Metasploit exploitby Lars SorensonAdded to Metasploit 2018-04-14
Not analyzedCVE-2008-46871 file

exploit_multi/http/mantisbt_manage_proj_page_rce · Ruby

Metasploit

Tuleap 9.6 Second-Order PHP Object Injection

Metasploit exploitAdded to Metasploit 2017-11-01
Not analyzedCVE-2017-74111 file

exploit_unix/webapp/tuleap_rest_unserialize_exec · Ruby

Metasploit

SugarCRM REST Unserialize PHP Code Execution

Metasploit exploitAdded to Metasploit 2016-09-06
Not analyzedCVE-2025-250341 file

exploit_unix/webapp/sugarcrm_rest_unserialize_exec · Ruby

Metasploit

Tuleap PHP Unserialize Code Execution

Metasploit exploitAdded to Metasploit 2014-12-09
Not analyzedCVE-2014-87911 file

exploit_unix/webapp/tuleap_unserialize_exec · Ruby

Metasploit

Horde Framework Unserialize PHP Code Execution

Metasploit exploitby juan vazquez <juan.vazquez@metasploit.com>Added to Metasploit 2014-03-18
Not analyzedCVE-2014-16911 file

exploit_unix/webapp/horde_unserialize_exec · Ruby

Metasploit

OpenSIS 'modname' PHP Code Execution

Metasploit exploitby bcoles <bcoles@gmail.com>Added to Metasploit 2013-12-19
Not analyzedCVE-2013-13491 file

exploit_unix/webapp/opensis_modname_exec · Ruby

Metasploit

DataLife Engine preview.php PHP Code Injection

Metasploit exploitby juan vazquez <juan.vazquez@metasploit.com>Added to Metasploit 2013-01-31
Not analyzedCVE-2013-14121 file

exploit_unix/webapp/datalife_preview_exec · Ruby

Metasploit

Invision IP.Board unserialize() PHP Code Execution

Metasploit exploitby juan vazquez <juan.vazquez@metasploit.com>, plus 1 additional contributorAdded to Metasploit 2012-11-10
Not analyzedCVE-2012-56921 file

exploit_unix/webapp/invision_pboard_unserialize_exec · Ruby

Metasploit

Tiki Wiki unserialize() PHP Code Execution

Metasploit exploitby juan vazquez <juan.vazquez@metasploit.com>Added to Metasploit 2012-07-05
Not analyzedCVE-2012-09111 file

exploit_unix/webapp/tikiwiki_unserialize_exec · Ruby

Metasploit

SugarCRM unserialize() PHP Code Execution

Metasploit exploitby juan vazquez <juan.vazquez@metasploit.com>, plus 1 additional contributorAdded to Metasploit 2012-06-25
Not analyzedCVE-2012-06941 file

exploit_unix/webapp/sugarcrm_unserialize_exec · Ruby

Metasploit

Log1 CMS writeInfo() PHP Code Injection

Metasploit exploitby Adel SBM, plus 1 additional contributorAdded to Metasploit 2012-06-02
Not analyzedCVE-2011-48251 file

exploit_multi/http/log1cms_ajax_create_folder · Ruby

Metasploit

WeBid converter.php Remote PHP Code Injection

Metasploit exploitby juan vazquez <juan.vazquez@metasploit.com>Added to Metasploit 2012-05-25
Not analyzedCVE-2011-100111 file

exploit_linux/http/webid_converter · Ruby

Metasploit

appRain CMF Arbitrary PHP File Upload Vulnerability

Metasploit exploitby sinn3r <sinn3r@metasploit.com>Added to Metasploit 2012-05-23
Not analyzedCVE-2012-11531 file

exploit_multi/http/apprain_upload_exec · Ruby

Metasploit

WikkaWiki 1.3.2 Spam Logging PHP Injection

Metasploit exploitby sinn3r <sinn3r@metasploit.com>Added to Metasploit 2012-05-10
Not analyzedCVE-2011-44511 file

exploit_multi/http/wikka_spam_exec · Ruby

Metasploit

WebCalendar 1.2.4 Pre-Auth Remote Code Injection

Metasploit exploitby sinn3r <sinn3r@metasploit.com>Added to Metasploit 2012-04-28
Not analyzedCVE-2012-14951 file

exploit_linux/http/webcalendar_settings_exec · Ruby

Metasploit

PmWiki pagelist.php Remote PHP Code Injection Exploit

Metasploit exploitby TecR0c <roccogiovannicalvi@gmail.com>Added to Metasploit 2011-12-13
Not analyzedCVE-2011-44531 file

exploit_multi/http/pmwiki_pagelist · Ruby

Metasploit

Traq admincp/common.php Remote Code Execution

Metasploit exploitby TecR0c <roccogiovannicalvi@gmail.com>Added to Metasploit 2011-12-12
Not analyzedCVE-2011-100131 file

exploit_multi/http/traq_plugin_exec · Ruby

Metasploit

phpScheduleIt PHP reserve.php start_date Parameter Arbitrary Code Injection

Metasploit exploitby juan vazquez <juan.vazquez@metasploit.com>Added to Metasploit 2011-10-26
Not analyzedCVE-2008-61321 file

exploit_multi/http/phpscheduleit_start_date · Ruby