High-Tech Bridge SA
441 exploits
Active since Apr 2010
vam_shop <= 1.6.1 - Cross-Site Request Forgery in Admin User Management
Eclime 1.1.2b - SQL Injection via ref poll_id or country Parameter
Enano CMS <1.1.8-1.0.6pl3 - SQL Injection
BLOG:CMS 4.2.1.e - Cross-Site Scripting via Multiple Parameters
DynPG CMS 4.2.0 - SQL Injection via giveRights_UserId Parameter
DynPG CMS 4.1.1 and 4.2.0 - Path Traversal via CHG_DYNPG_SET_LANGUAGE Parameter
Tomaz Muraus Open Blog 1.2.1 - CSRF
DeWeS web server <0.4.2 - Path Traversal
Microsoft SharePoint Server 2007 <12.0.0.6421 - XSS
Samsung Kies <2.5.0.12094 - Privilege Escalation
CVSS 7.5
StudioLine Photo Basic 3.70.34.0 - 'NMSDVDXU.dll' ActiveX Control Arbitrary File Overwrite
Pro Softnet IDrive Online Backup 3.4.0 - ActiveX 'SaveToFile()' Arbitrary File Overwrite
LeadTools Imaging LEADSmtp - ActiveX Control 'SaveMessage()' Insecure Method
McAfee Virtual Technician and ePO-MVT < 6.5.0.2101 - Arbitrary File Write via McHealthCheck.dll Save Method
CygniCon CyViewer - ActiveX Control 'SaveData()' Insecure Method
threedify designer 5.0.2 - Multiple Vulnerabilities
Sony VAIO PC Wireless LAN Wizard 1.0-4.11 - Buffer Overflow
TVMOBiLi <2.1.0.3974 - Buffer Overflow
Nero MediaHome < 4.5.8.0 - Denial of Service via HTTP Header Without Name
HP Protect Tools Device Access Manager <6.1.0.1 - RCE
Easewe FTP OCX ActiveX Control 4.5.0.9 - 'EaseWeFtp.ocx' Multiple Insecure Method Vulnerabilities
Firefly Media Server 1.0.0.1359 - Denial of Service via Crafted HTTP Headers
Zikula Application Framework 1.2.2 - Cross-Site Scripting via Func or Lang Parameter
Zikula Application Framework 1.2.2 - Cross-Site Scripting via Func or Lang Parameter
Zen Cart 1.5.4 - Remote File Inclusion via AJAX act Parameter Path Traversal
CVSS 9.8