High-Tech Bridge Security Research Lab
113 exploits
Active since Jul 2012
iTop 2.2.1 - Cross-Site Request Forgery
ISPConfig < 3.0.5.4 - Cross-Site Request Forgery via Admin User Creation
InstantCMS < 1.10.3 - SQL Injection via OrderBy Parameter
ImageCMS < 4.2 - Authenticated SQL Injection via Admin Search Parameter
Horizon Quick Content Management System <= 4.0 - SQL Injection via Download Category Parameter
GLPI < 0.84.2 - Cross-Site Request Forgery and SQL Injection via Install Script
Horde Groupware < 5.2.11 - Cross-Site Request Forgery via Admin Shell Parameters
Gnew 2013.1 - SQL Injection via news_id, thread_id, or user_email Parameter
GLPi 0.90.2 - SQL Injection
glFusion < 1.2.2.pl4 - Cross-Site Scripting via Multiple Parameters
Exponent CMS <2.2.0 - SQL Injection
Eventum < 2.3.5 - Unauthenticated Application Reinstallation via Direct Setup Request
CVSS 7.5
Elite Bulletin Board < 2.1.22 - SQL Injection via PATH_INFO
EGroupware < 1.6.001 and < 1.8006 - Cross-Site Request Forgery via Admin User Creation or Settings Modification
Dating Pro Genie 2015.7 - Cross-Site Request Forgery
doorGets CMS <= 5.2 - Authenticated SQL Injection via _position_down_id Parameter
Dokeos < 2.2 - SQL Injection via Language Parameter
ClipBucket < 2.6 - SQL Injection via Multiple Parameters
CubeCart 6.0.10 - Multiple Vulnerabilities
Cotonti Siena < 0.9.14 - SQL Injection via RSS Module c Parameter
CosCMS < 1.822 - Authenticated OS Command Injection via Uploaded File Name
bitrix.mpbuilder < 1.0.11 - Authenticated Path Traversal via Work Array Parameter
Chamilo LMS < 1.9.6 - Authenticated SQL Injection via Password Parameter
Cerb < 7.0.3 - Cross-Site Request Forgery via ajax.php saveWorkerPeek Action
burden < 1.8.1 - Unauthenticated Authentication Bypass via Remember Me Cookie
CVSS 9.8