High-Tech Bridge SA
441 exploits
Active since Apr 2010
SweetRice CMS <0.6.7.1 - SQL Injection
OpenX < 2.8.10 - Cross-Site Scripting via Package or Group Parameter
Piwigo < 2.4.7 - Cross-Site Request Forgery via LocalFiles Editor Plugin
Banana Dance <B.2.6 - Info Disclosure
Banana Dance <B.2.6 - Path Traversal
TheCartPress eCommerce Shopping Cart < 1.3.9 - Cross-Site Request Forgery via tcp_box_path Parameter
TheCartPress <1.3.9.3 - Path Traversal
TheCartPress eCommerce Shopping Cart < 1.3.9 - Cross-Site Scripting via Multiple Input Parameters
XCloner < 3.5 - Cross-Site Request Forgery via Administrator Password Change or Database Backup
X2Engine X2CRM < 3.5 - Authenticated Path Traversal via Translation Manager File Parameter
Gnew 2013.1 - SQL Injection via Multiple Parameters
Gnew < 2013.1 - Path Traversal via gnew_language Cookie
Nero MediaHome < 4.5.8.0 - Denial of Service via Long HTTP Request or Referer Header
Template CMS < 2.1.1 - Cross-Site Scripting via themes_editor Parameter
Piwigo < 2.3.3 - Remote File Inclusion via Upgrade Language Parameter
Newscoop 3.5.x < 3.5.5 and 4.x < 4 RC4 - Cross-Site Scripting via Back Parameter or Token/Email Parameters
Newscoop - SQL Injection via f_country_code Parameter
Newscoop 3.5.x < 3.5.5 and 4 < RC4 - Remote Code Execution via GLOBALS[g_campsiteDir] Parameter
ISPConfig < 3.0.5.4 - Authenticated SQL Injection via server Parameter
pfSense < 2.2.1 - Cross-Site Scripting via Multiple WebGUI Parameters
KrisonAV CMS < 3.0.2 - Cross-Site Scripting via Content Parameter
Hycus CMS 1.0.3 - SQL Injection via user_name, usr_email, useremail, or q Parameter
Html-edit CMS 3.1.8 - Cross-Site Scripting via Error Parameter
Html-edit CMS 3.1.8 - SQL Injection via nuser Parameter
Habari 0.6.5 - Cross-Site Scripting via additem_form and status_data Parameters