Search for hundreds of thousands of exploits

"Business Live Chat Software 1.0 - Cross-Site Request Forgery (Add Admin)"

Author

Exploit author

"Meisam Monsef"

Platform

Exploit platform

php

Release date

Exploit published date

2020-02-27

Release DateTitleTypePlatformAuthor
2020-05-29"Crystal Shard http-protection 0.2.0 - IP Spoofing Bypass"webappsmultiple"Halis Duraki"
2020-05-29"WordPress Plugin Multi-Scheduler 1.0.0 - Cross-Site Request Forgery (Delete User)"webappsphpUnD3sc0n0c1d0
2020-05-28"EyouCMS 1.4.6 - Persistent Cross-Site Scripting"webappsphp"China Banking and Insurance Information Technology Management Co."
2020-05-28"NOKIA VitalSuite SPM 2020 - 'UserName' SQL Injection"webappsmultiple"Berk Dusunur"
2020-05-28"QNAP QTS and Photo Station 6.0.3 - Remote Command Execution"webappsphpTh3GundY
2020-05-28"Online-Exam-System 2015 - 'fid' SQL Injection"webappsphp"Berk Dusunur"
2020-05-27"LimeSurvey 4.1.11 - 'Permission Roles' Persistent Cross-Site Scripting"webappsphp"Matthew Aberegg"
2020-05-27"osTicket 1.14.1 - 'Saved Search' Persistent Cross-Site Scripting"webappsphp"Matthew Aberegg"
2020-05-27"Kuicms PHP EE 2.0 - Persistent Cross-Site Scripting"webappsphp"China Banking and Insurance Information Technology Management Co."
2020-05-27"Online Marriage Registration System 1.0 - Persistent Cross-Site Scripting"webappsphp"that faceless coder"
Release DateTitleTypePlatformAuthor
2020-05-29"WordPress Plugin Multi-Scheduler 1.0.0 - Cross-Site Request Forgery (Delete User)"webappsphpUnD3sc0n0c1d0
2020-05-28"QNAP QTS and Photo Station 6.0.3 - Remote Command Execution"webappsphpTh3GundY
2020-05-28"Online-Exam-System 2015 - 'fid' SQL Injection"webappsphp"Berk Dusunur"
2020-05-28"EyouCMS 1.4.6 - Persistent Cross-Site Scripting"webappsphp"China Banking and Insurance Information Technology Management Co."
2020-05-27"Kuicms PHP EE 2.0 - Persistent Cross-Site Scripting"webappsphp"China Banking and Insurance Information Technology Management Co."
2020-05-27"osTicket 1.14.1 - 'Saved Search' Persistent Cross-Site Scripting"webappsphp"Matthew Aberegg"
2020-05-27"OXID eShop 6.3.4 - 'sorting' SQL Injection"webappsphpVulnSpy
2020-05-27"LimeSurvey 4.1.11 - 'Permission Roles' Persistent Cross-Site Scripting"webappsphp"Matthew Aberegg"
2020-05-27"Online Marriage Registration System 1.0 - Persistent Cross-Site Scripting"webappsphp"that faceless coder"
2020-05-27"osTicket 1.14.1 - 'Ticket Queue' Persistent Cross-Site Scripting"webappsphp"Matthew Aberegg"
Release DateTitleTypePlatformAuthor
2020-02-27"Business Live Chat Software 1.0 - Cross-Site Request Forgery (Add Admin)"webappsphp"Meisam Monsef"
2020-02-24"Real Web Pentesting Tutorial Step by Step - [Persian]"webappsmultiple"Meisam Monsef"
2019-02-21"EI-Tube 3 - SQL Injection"webappsphp"Meisam Monsef"
2018-10-29"MTGAS MOGG Web Simulator Script - SQL Injection"webappsphp"Meisam Monsef"
2018-05-27"Lyrist - 'id' SQL Injection"webappsphp"Meisam Monsef"
2018-05-27"Ingenious School Management System - 'id' SQL Injection"webappsphp"Meisam Monsef"
2017-10-04"ClipBucket 2.8.3 - Remote Code Execution"webappsphp"Meisam Monsef"
2017-08-02"Entrepreneur B2B Script - 'pid' SQL Injection"webappsphp"Meisam Monsef"
2016-07-19"NewsP Free News Script 1.4.7 - User Credentials Disclosure"webappsphp"Meisam Monsef"
2016-07-19"newsp.eu PHP Calendar Script 1.0 - User Credentials Disclosure"webappsphp"Meisam Monsef"
2016-07-08"PHP Real Estate Script 3 - Arbitrary File Disclosure"webappsphp"Meisam Monsef"
2016-06-23"Alibaba Clone B2B Script - Arbitrary File Disclosure"webappsphp"Meisam Monsef"
2016-05-30"Open Source Real Estate Script 3.6.0 - SQL Injection"webappsphp"Meisam Monsef"
2016-05-27"PHP Realestate Script Script 4.9.0 - SQL Injection"webappsphp"Meisam Monsef"
2016-05-04"Alibaba Clone B2B Script - Admin Authentication Bypass"webappsphp"Meisam Monsef"
2015-09-02"SphereFTP Server 2.0 - Crash (PoC)"doswindows"Meisam Monsef"
2015-08-15"Security IP Camera Star Vision DVR - Authentication Bypass"webappshardware"Meisam Monsef"
2015-08-07"PHP News Script 4.0.0 - SQL Injection"webappsphp"Meisam Monsef"
import requests
response = requests.get('https://www.nmmapper.com/api/exploitdetails/48141/?format=json')

For full documentation follow the link above

Cipherscan. A very simple way to find out which SSL ciphersuites are supported by a target.

Identify and fingerprint Web Application Firewall (WAF) products protecting a website.