Skip to content

Vulnerable Web Applications

Software Version Vulnerability References Msf
Pfsense <= 2.2.6 Command Injection exploit-db
Pfsense < 2.1.4 Command Injection exploit-db
Drupal 7.x RCE exploit-db
October CMS 1.0.412 RCE, PHP object injection exploit-db
NibbleBlog 0 Usernames /nibbleblog/content/private/users.xml
Apache Struts 2 2.3.x before 2.3.32
2.5.x before 2.5.10.1
RCE CVE-2017-5638
https://github.com/mazen160/struts-pwn
PHPLiteAdmin 1.9.2 RCE exploit-db
​ Rename Database​ page
show the full path

Pfsense issues