High-Tech Bridge Security Research Lab
113 exploits
Active since Jul 2012
bitrix.xscan < 1.0.3 - Authenticated Path Traversal via File Parameter
BigTree CMS < 4.0 - Cross-Site Scripting via Module Parameter
ArticleFR 11.06.2014 - Privilege Escalation
CVSS 9.8
Banana Dance < b.2.6 - SQL Injection via Multiple Parameters
Baby Gekko < 1.2.2 - Cross-Site Scripting via Admin ID or Login Credentials
b2evolution < 4.1.7 - Authenticated SQL Injection via show_statuses[] Parameter
AWS XMS 2.5 - Path Traversal via 'what' Parameter
CVSS 7.5
AuraCMS <= 2.3 - Authenticated SQL Injection via Search Parameter or HTTP Headers
ATutor AContent <1.2 - SQL Injection
appRain CMF < 3.0.2 - SQL Injection via PATH_INFO to blog-by-cat/
Achievo 1.4.5 - Authenticated SQL Injection via Activity ID Parameter
Novell GroupWise <8.0.3-2012 - RCE/DoS
Bonita BPM Portal <6.5.3 - Open Redirect
CVSS 6.1