High-Tech Bridge Security Research Lab
113 exploits
Active since Jul 2012
WordPress VideoWhisper Live Streaming Integration <4.29.5 - RCE
VideoWhisper Live Streaming Integration <4.29.5 - XSS
VideoWhisper Live Streaming Integration <4.29.5 - Path Traversal
Subrion CMS < 2.2.3 - Cross-Site Scripting via id or group Parameter
Subrion CMS < 2.2.3 - SQL Injection via Register Plan ID Parameter
Subrion CMS < 2.2.3 - Cross-Site Request Forgery
Sharetronix < 3.3 - Cross-Site Request Forgery via Admin Privilege Assignment
OpenX < 2.8.10 - Directory Traversal via Plugin Preferences and Settings
OpenDocMan <1.2.7.2 - SQL Injection
Kasseler CMS < 2 - Authenticated SQL Injection via groups[] Parameter
kasseler-cms < 2 - Authenticated Cross-Site Scripting via cat Parameter
Eventum < 2.3.5 - Remote Code Execution via Hostname Parameter
CVSS 8.1
BigTree CMS < 4.0 - Cross-Site Request Forgery via User Creation
BigTree CMS <4.0 RC2 - SQL Injection
babygekko < 1.2.4 - SQL Injection
CVSS 8.8
babygekko < 1.2.4 - PHP File Inclusion
CVSS 9.8
ATutor AContent <1.2 - SQL Injection
Bonita BPM Portal <6.5.3 - Path Traversal
OpenX < 2.8.10 - Cross-Site Scripting via Package or Group Parameter
Piwigo < 2.4.7 - Cross-Site Request Forgery via LocalFiles Editor Plugin
Banana Dance <B.2.6 - Info Disclosure
Banana Dance <B.2.6 - Path Traversal
TheCartPress eCommerce Shopping Cart < 1.3.9 - Cross-Site Request Forgery via tcp_box_path Parameter
TheCartPress <1.3.9.3 - Path Traversal
TheCartPress eCommerce Shopping Cart < 1.3.9 - Cross-Site Scripting via Multiple Input Parameters