BlackFan
8 exploits
Active since Jul 2012
Cordova InAppBrowser < 3.0.0 - Arbitrary JavaScript Execution via gap-iab URI
Android < 7.0 - Privilege Escalation via Launcher Shortcut Creation
Apache Tomcat 7.0.23-7.0.90, 8.5.0-8.5.33, 9.0.0.M1-9.0.11 - Open Redirect via Default Servlet
PHP < 5.3.15 - open_basedir Protection Bypass via SQLite Functionality
21 stars
serve-static <1.7.2 - Open Redirect
21 stars
Apache HTTP Server <2.4.24, <2.2.32 - CRLF Injection
Bootstrap < 3.4.1 and 4.3.x < 4.3.1 - Cross-Site Scripting via Tooltip or Popover Data-Template Attribute
CVSS 6.1
Laravel Framework < 5.5.40 and 5.6.x < 5.6.30 - Remote Code Execution via Unserialize of X-XSRF-TOKEN
CVSS 8.1