hyp3rlinx
260 exploits
Active since Jun 2015
MantisBT < 1.3.11, 2.x < 2.3.3, 2.4.x < 2.4.1 - Cross-Site Request Forgery via Permalink Injection
CVSS 6.5
MantisBT < 2.3.0 - Unauthenticated Arbitrary Password Reset via Empty Confirm Hash
CVSS 8.8
mailcow 0.14 - Cross-Site Request Forgery
CVSS 8.8
Lepton CMS 2.2.0/2.2.1 - PHP Code Injection
Lepton CMS 2.2.0/2.2.1 - Directory Traversal
GeniXCMS 0.0.3 - Cross-Site Scripting via Posts Page Parameters
eXtplorer 2.1.9 - Path Traversal via Archive Extraction
CVSS 7.8
EasyPHP Devserver 16.1.1 - Cross-Site Request Forgery / Remote Command Execution
dirLIST 0.3.0 - Arbitrary File Upload
concrete5 8.1.0 - Cross-Site Scripting via Host Header Injection
CVSS 6.1
CF Image Host 1.65 - Cross-Site Request Forgery
CF Image Host 1.65 - PHP Command Injection
BoZoN 2.4 - Remote Code Execution
Apache2Triad 1.5.4 - Cross-Site Scripting via phpsftpd/users.php Account Parameter
CVSS 6.1
b374k 3.2.3/2.8 (Web Shell) - Cross-Site Request Forgery / Command Injection
Artica Web Proxy <3.06.112911 - XSS
CVSS 9.0
AjaxExplorer 1.10.3.2 - Multiple Vulnerabilities
Adminer 4.3.1 - Server-Side Request Forgery
Advanced Electron Forum 1.0.9 - Remote File Inclusion / Cross-Site Request Forgery
Advanced Electron Forum 1.0.9 - Persistent Cross-Site Scripting
Advanced Electron Forum 1.0.9 - Cross-Site Request Forgery
phpFileManager 0.9.8 - Remote Code Execution (Metasploit)
NAPC Xinet Elegant 6.1.655 - SQL Injection
CVSS 9.8
Splunk Enterprise <6.5.1 & Splunk Light <6.5.2 - Sensitive Info Exposure via Global Window Namespace
CVSS 3.5
mistserver < 2.13 - Unauthenticated Stored Cross-Site Scripting via Failed Authentication Alert
CVSS 6.1