This Metasploit module exploits a directory traversal vulnerability found in Easy File Sharing FTP Server Version 3.6 and Earlier. This vulnerability allows an attacker to download arbitrary files from the server by crafting a RETR command that includes file system traversal strings such as ../.
3bee08b7593c9277bf2fd632fe9f39fdfed8b87e4110d42a4c1f38c2d6b74e66
SDL Web Content Manager version 8.5.0 suffers from an XML external entity injection vulnerability.
2fda5ec43bfad50bcce9b38c70c67bc1f66aa66e741a3d57bde74a938d39f699
SeoChecker Umbraco CMS plugin version 1.9.2 suffers from stored cross site scripting vulnerabilities.
808f40f5ea5a3289e8468fc166c306508c3e44f814da48677928b6dae6a49d9a
This Metasploit module exploits a file upload vulnerability in GetSimple CMS. By abusing the upload.php file, a malicious authenticated user can upload an arbitrary file, including PHP code, which results in arbitrary code execution.
93b94988b458fdd8ae88cd22f63db59e3b576b4062534971e43a8c37439ee4e2
GetSimple CMS versions 3.1.2 and 3.2.3 suffer from persistent cross site scripting vulnerabilities.
673085354c1aa7a5d4988c8b7f096e0d825a07b9c4a4d58be0153ed65f72251d
GetSimpleCMS version 3.2.1 suffers from a persistent cross site scripting vulnerability.
c104417689e0929e94e0ffb8bc8dcf34adf9b7f88d9438da13fcb5b0af45065d
GetSimpleCMS version 3.2.1 suffers from a remote arbitrary file upload vulnerability due to not using whitelisting.
6e6a12193bbda8bbf5d3e8f79bc113751942309e56cc2e70e3ea96dc597d99f5
Real-DRAW PRO version 5.2.4 import file crash exploit.
27f6a9f28a767c7934f513559eb717b27d3864cfb5ab167f652b55fde794f48a
DVD-Lab Studio version 1.25 DAL file denial of service exploit.
6c92ab45feabb5aded08e3f4832ee741f917bd89f4974e8f8422d5086af11be8
This is a whitepaper that gives a complete cross site scripting walkthrough.
7ccb4e719b298fb3680cb5feb24cf117a59343f4420b727273ea2fae0666e3a5
Multimedia Builder version 4.9.8 denial of service exploit that creates a malicious .mef file.
63a67975d994e1f50ae5d8977e3410cb4b3b122a865bbea9840fb034cf5d4fb0
SnackAmp version 3.1.3 suffers from a denial of service vulnerability.
fb721bd0f9a7872287da924f15eee6395e335393728f26fd885410494f190842
FoxPlayer version 2.6.0 suffers from a denial of service vulnerability.
eb67bb643c36f0d5ef65e3142b1d9981354485156c875ca3441c1efb51d3e0d9
Dalbum version 144 build 174 suffers from a cross site request forgery vulnerability.
00db7898e4448ebb13cb644498d530d22f039f12896633da126ec0a6476a7296
Family CMS versions 2.9 and below suffer from cross site request forgery and cross site scripting vulnerabilities.
1ec7f405de63ef5f7838d32c96dbfa4b6d6603c64200b6d6fa5153eb534bef34
FCMS versions 2.7.2 and below suffer from multiple cross site request forgery vulnerabilities.
09afb1bfca46b03a639f6d879a92455fc64819f72f67724e6c3a57992651ccb7
FCMS versions 2.7.2 and below suffer from multiple stored cross site scripting vulnerabilities.
5641389ba4d46095b9cb16cfd6582c834a7e0be27ded10a9f7f640eb355e4bf4