High-Tech Bridge Security Research Lab
113 exploits
Active since Jul 2012
WordPress AdRotate Pro/FREE <3.9.5/3.9.4 - SQL Injection
Vesta Control Panel < 0.9.8-14 - Authenticated Remote Code Execution via Backup Parameter
CVSS 8.8
Webmatic 3.1.1 - SQL Injection via Referer HTTP Header
webEdition CMS < 6.3.8.0 - Authenticated Path Traversal via showTempFile.php file Parameter
vtiger CRM < 5.4.0 - Authenticated SQL Injection via onlyforuser Parameter
web2project < 3.1 - Authenticated SQL Injection via Search String or Update Key Parameter
CVSS 8.8
umi.cms < 2.9 - Cross-Site Request Forgery via Admin User Addition
Template CMS < 2.1.1 - Cross-Site Request Forgery via Admin User Creation or Theme Editor
TestLink < 1.9.3 - Cross-Site Request Forgery via User Management
Subrion CMS 2.2.1 - Cross-Site Scripting via Multiple Parameters
SocialEngine 4.8.9 - SQL Injection
Sharetronix < 3.3 - Authenticated SQL Injection via invite_users[] Parameter
Roundcube Webmail < 1.0.8 and 1.1.x < 1.1.4 - Authenticated Path Traversal via _skin Parameter
CVSS 7.5
Piwigo < 2.4.7 - Path Traversal via Install.php DL Parameter
pfSense < 2.2 - Cross-Site Request Forgery via system_firmware_restorefullbackup.php deletefile Parameter
OpenDocMan <1.2.7.2 - SQL Injection
Oxwall < 1.7.4 - Cross-Site Request Forgery via Maintenance Mode Parameters
OrbitScripts Orbit Open Ad Server <1.1.1 - SQL Injection
OpenX 2.8.10 - Cross-Site Request Forgery via Plugin Preferences and Settings
Bitrix mcart.xls <6.5.2 - SQL Injection
CVSS 8.0
StackIdeas Komento < 1.7.3 - Cross-Site Scripting via Website or Latitude Parameter
KrisonAV CMS < 3.0.2 - Cross-Site Request Forgery via User Account Creation
Kasseler CMS < 2 - Cross-Site Request Forgery via Admin PHP Parameters
JV Comment (com_jvcomment) < 3.0.3 - Authenticated SQL Injection via id Parameter
ilch_cms < 2.0 - Cross-Site Scripting via Guestbook Text Parameter