High-Tech Bridge
43 exploits
Active since Jun 2012
Samsung Kies < 2.5.0.12114_1 - Remote Code Execution via SyncService.dll PrepareSync Password Argument
Xaraya < 2.4.0 - Cross-Site Scripting via id/interface/name/tabmodule Parameters
Wysija Newsletters < 2.2.1 - Authenticated SQL Injection via Search or Orderby Parameter
Duplicator < 0.4.5 - Cross-Site Scripting via Package Parameter
CommentLuv < 2.92.4 - Cross-Site Scripting via _ajax_nonce Parameter
web@all 2.0 - Cross-Site Scripting via _text[title] Parameter
DeWeS web server <0.4.2 - Path Traversal
TAO 2.5.6 - Cross-Site Request Forgery via Users/add Endpoint
Symphony CMS < 2.3.2 - Cross-Site Request Forgery via SQL Injection in Authors Sort Parameter
Symphony CMS <2.3.2 - SQL Injection
Open Solution Quick.Cms 5.0 and Quick.Cart 6.0 - Cross-Site Scripting via PATH_INFO to admin.php
PrestaShop < 1.4.9.0 - Cross-Site Scripting via product[] Parameter in ajax.php
CVSS 6.1
PBBoard 2.1.4 - SQL Injection via Multiple Parameters
Phorum < 5.2.19 - Cross-Site Scripting via Group Parameter
PBBoard 2.1.4 - Unauthenticated Arbitrary Password Change via member_id and new_password Parameters
PBBoard 2.1.4 - Authenticated Arbitrary PHP File Upload via admin.php
OrangeHRM 2.7.1 RC 1 - SQL Injection
ocPortal < 7.1.6 - Cross-Site Scripting via Code Editor Path or Line Parameters
Open Journal Systems < 2.3.7 - Cross-Site Scripting via iBrowser Plugin Parameters
Open Journal Systems < 2.3.7 - Cross-Site Scripting via iBrowser Plugin Parameters
Open Journal Systems < 2.3.6 - Authenticated Path Traversal via iBrowser Plugin rfiles.php param Parameter
Open Journal Systems < 2.3.7 - Authenticated Remote Code Execution via Executable File Upload
OpenX 2.8.10 - Cross-Site Scripting via Parent Parameter in admin/plugin-index.php
Magnolia Form module <1.4.7-2.0.2 - XSS
Kayako Fusion 4.40.1148 - Cross-Site Scripting via PATH_INFO in PHPExcel Download Script