High-Tech Bridge Security Research Lab
113 exploits
Active since Jul 2012
XCloner < 3.5 - Cross-Site Request Forgery via Administrator Password Change or Database Backup
X2Engine X2CRM < 3.5 - Authenticated Path Traversal via Translation Manager File Parameter
Gnew 2013.1 - SQL Injection via Multiple Parameters
Gnew < 2013.1 - Path Traversal via gnew_language Cookie
Nero MediaHome < 4.5.8.0 - Denial of Service via Long HTTP Request or Referer Header
Template CMS < 2.1.1 - Cross-Site Scripting via themes_editor Parameter
ISPConfig < 3.0.5.4 - Authenticated SQL Injection via server Parameter
pfSense < 2.2.1 - Cross-Site Scripting via Multiple WebGUI Parameters
KrisonAV CMS < 3.0.2 - Cross-Site Scripting via Content Parameter
DeWeS web server <0.4.2 - Path Traversal
Samsung Kies < 2.5.0.12114_1 - Remote Code Execution via SyncService.dll PrepareSync Password Argument
McAfee Virtual Technician and ePO-MVT < 6.5.0.2101 - Arbitrary File Write via McHealthCheck.dll Save Method
TVMOBiLi <2.1.0.3974 - Buffer Overflow
Nero MediaHome < 4.5.8.0 - Denial of Service via HTTP Header Without Name
Firefly Media Server 1.0.0.1359 - Denial of Service via Crafted HTTP Headers
Zen Cart 1.5.4 - Remote File Inclusion via AJAX act Parameter Path Traversal
CVSS 9.8
XCloner < 3.1.1 - Cross-Site Request Forgery via Backup Creation
X2Engine X2CRM < 3.5 - Cross-Site Scripting via Model Parameter
VideoWhisper Live Streaming <4.29.5 - Info Disclosure
XCloner < 3.5 - Authenticated Command Injection via dbbackup_comp Parameter
xEpan CMS <= 1.0.4.1 - Cross-Site Request Forgery via Administrative Account Creation
TheCartPress <1.3.9.3 - Info Disclosure
CVSS 7.5
All In One WP Security & Firewall <3.8.3 - SQL Injection
WordPress Count Per Day <3.4.1 - SQL Injection
CVSS 7.2
WordPress AdRotate Pro/FREE <3.9.5/3.9.4 - SQL Injection