Metasploit
1,875 exploits
Active since Aug 1990
SugarCRM CE <= 6.3.1 - Code Injection
CVSS 9.8
Red Hat Piranha - Command Injection
qdPM 7.0 - Arbitrary '.PHP' File Upload (Metasploit)
PmWiki 2.x < 2.2.35 - Remote Code Execution via PageListSort Order Parameter
phpMyAdmin 2.11.0-2.11.9.4 and 3.x < 3.1.3.1 - Remote Code Injection via Setup Configuration Save
CVSS 9.8
phpMyAdmin 3.5.2.2 - Remote Code Execution via Trojaned server_sync.php
phpScheduleIt <1.2.10 - Code Injection
phpBB <= 2.0.15 - Remote File Inclusion in viewtopic.php
phpLDAPadmin < 1.2.2 - Remote Code Execution via Orderby Parameter
PAJAX 0.5.1 - Remote Code Execution via pajax_call_dispatcher.php Method and Args Parameters
Oracle Secure Backup 10.3.0.1 - Info Disclosure
Mambo < 4.6.4 - Remote Code Execution via mosConfig_absolute_path Parameter
Ajax File and Image Manager < 1.1 - Remote Code Execution via PHP Code Injection in data.php
Joomla! Plugin tinybrowser 1.5.12 - Arbitrary File Upload / Code Execution (Metasploit)
Joomla! 3.7.x - SQL Injection
CVSS 9.8
trixbox < 2.6.1 - Remote File Inclusion via langChoice Parameter
FreePBX < 2.10 - Remote Code Execution via callmenum Parameter
Hastymail2 2.1.1 - Remote Code Execution via rs or rsargs[] Parameter
Family Connections CMS 2.5.0-2.7.1 - Remote Code Execution via dev/less.php argv[1] Parameter
Coppermine Photo Gallery < 1.4.14 - Remote Code Execution via ImageMagick Picture Processing Parameters
ClipBucket - 'beats_uploader' Arbitrary File Upload (Metasploit)
ClipBucket - 'beats_uploader' Arbitrary File Upload (Metasploit)
CakePHP 1.2.8-1.3.5 - Remote Code Execution via Unserialize in Security Component
Basilic 1.5.14 - Remote Command Execution via Config/diff.php File Parameter
appRain CMF <= 0.1.5 - Unauthenticated Arbitrary File Upload and Remote Code Execution