Vulnerable Web Applications
Software | Version | Vulnerability | References | Msf |
---|---|---|---|---|
Pfsense | <= 2.2.6 | Command Injection | exploit-db | |
Pfsense | < 2.1.4 | Command Injection | exploit-db | |
Drupal | 7.x | RCE | exploit-db | |
October CMS | 1.0.412 | RCE, PHP object injection | exploit-db | |
NibbleBlog | 0 | Usernames | /nibbleblog/content/private/users.xml | |
Apache Struts | 2 2.3.x before 2.3.32 2.5.x before 2.5.10.1 |
RCE | CVE-2017-5638 https://github.com/mazen160/struts-pwn |
|
PHPLiteAdmin | 1.9.2 | RCE | exploit-db Rename Database page show the full path |
Pfsense issues
- PfSense Vulnerabilities Part 2: Command Injection - https://www.proteansec.com/linux/pfsense-vulnerabilities-part-2-command-injection/
- PfSense Vulnerabilities Part 3: Local File Inclusion - https://www.proteansec.com/linux/pfsense-vulnerabilities-part-3-local-file-inclusion/
- PfSense Vulnerabilities Part 4: Directory Traversal - https://www.proteansec.com/linux/pfsense-vulnerabilities-part-4-directory-traversal/