bl4de
28 exploits
Active since May 2018
exceljs < 1.6 - Cross-Site Scripting via Cell Value
CVSS 6.1
m-server < 1.4.2 - Stored Cross-Site Scripting via Folder Name
CVSS 5.4
m-server < 1.4.1 - Path Traversal via URL Slash Manipulation
CVSS 6.5
serve < 6.4.9 - Path Traversal via URL-Encoded Dot-Slash Sequences
CVSS 6.5
angular-http-server < 1.6.0 - Path Traversal via possibleFilename
CVSS 6.5
node-srv < 2.1.1 - Path Traversal via URL Parameter
CVSS 6.5
glance < 3.0.4 - Path Traversal via Unvalidated Path Input
CVSS 6.5
simplehttpserver < 0.1.0 - Cross-Site Scripting via Unvalidated Filename
CVSS 5.4
Sencha Connect < 2.14.0 - Cross-Site Scripting in Directory Middleware
CVSS 5.4
general-file-server - Path Traversal via currpath Parameter
CVSS 7.5
hekto < 0.2.3 - Path Traversal via File Parameter
CVSS 7.5
crud-file-server < 0.8.0 - Cross-Site Scripting via File Name
CVSS 6.1
626 - Path Traversal via File Parameter
CVSS 7.5
localhost-now < 1.0.2 - Path Traversal via File Path Validation Bypass
CVSS 7.5
mcstatic - Path Traversal via filePath Parameter
CVSS 7.5
public.js < 0.1.3 - Path Traversal via filePath Parameter
CVSS 7.5
crud-file-server < 0.9.0 - Path Traversal via URL Validation Bypass
CVSS 7.5
stattic < 0.3.0 - Path Traversal
CVSS 7.5
html-pages - Path Traversal via cURL
CVSS 9.8
public.js < 0.1.3 - Cross-Site Scripting via HTML in Filename
CVSS 6.1
glance <= 3.0.5 - Stored Cross-Site Scripting via Crafted File Name
CVSS 6.1
query-mysql 0.0.0-0.0.2 - SQL Injection
CVSS 8.8
sexstatic <= 0.6.2 - Stored Cross-Site Scripting via Directory Name
CVSS 6.1
statics-server <= 0.0.9 - Cross-Site Scripting via Directory Index Filename
CVSS 6.1
metascraper <= 3.9.2 - Stored Cross-Site Scripting in Open Graph Meta Properties
CVSS 6.1