Search results

  1. badboyhelper

    WordPress PHPMailer 4.6 - Host Header Command Injection (Metasploit)

    ## # This module requires Metasploit: http://metasploit.com/download # Current source: https://github.com/rapid7/metasploit-framework ## class MetasploitModule < Msf::Exploit::Remote   Rank = AverageRanking   include Msf::Exploit::Remote::HTTP::Wordpress   include Msf::Exploit::CmdStager  ...
  2. badboyhelper

    WordPress Theme Holding Pattern - Arbitrary File Upload (Metasploit)

    ## # This module requires Metasploit: http://www.metasploit.com/download # Current source: https://github.com/rapid7/metasploit-framework ## require 'msf/core' require 'socket' class MetasploitModule < Msf::Exploit::Remote   Rank = ExcellentRanking   include Msf::Exploit::FileDropper  ...
  3. badboyhelper

    WordPress Plugin Ninja Forms 2.9.36 < 2.9.42 - File Upload (Metasploit)

    ## # This module requires Metasploit: http://www.metasploit.com/download # Current source: https://github.com/rapid7/metasploit-framework ## require 'msf/core' class MetasploitModule < Msf::Exploit::Remote   Rank = ExcellentRanking   include Msf::Exploit::FileDropper   include...
  4. badboyhelper

    WordPress Plugin NewStatPress 1.2.4 - Cross-Site Scripting

    Source: https://sumofpwn.nl/advisory/2016/persistent_cross_site_scripting_in_the_wordpress_newstatpress_plugin.html Abstract A persistent Cross-Site Scripting (XSS) vulnerability has been found in the WordPress NewStatPress plugin. By using this vulnerability an attacker can inject malicious...
  5. badboyhelper

    WordPress Plugin Corner Ad 1.0.7 - Cross-Site Scripting

    # Exploit Title: Authorized Stored XSS at WordPress Corner-Ad plugin. # Google Dork: inurl:/wp-content/plugins/corner-ad # Date: 16-02-17 # Exploit Author: Atik Rahman # Vendor Homepage: https://wordpress.org/plugins/corner-ad/ # Software Link...
  6. badboyhelper

    Wordpress Plugin Survey & Poll 1.5.7.3 - 'sss_params' SQL Injection

    # Exploit Title: Wordpress Plugin Survey & Poll 1.5.7.3 - 'sss_params' SQL Injection # Date: 2018-09-09 # Exploit Author: Ceylan Bozogullarindan # Vendor Homepage: http://modalsurvey.pantherius.com/ # Software Link: https://downloads.wordpress.org/plugin/wp-survey-and-poll.zip # Version: 1.5.7.3...
  7. badboyhelper

    WordPress Plugin Plainview Activity Monitor 20161228 - (Authenticated) Command Inject

    <!-- About: =========== Component: Plainview Activity Monitor (Wordpress plugin) Vulnerable version: 20161228 and possibly prior Fixed version: 20180826 CVE-ID: CVE-2018-15877 CWE-ID: CWE-78 Author: - LydA(c)ric Lefebvre (https://www.linkedin.com/in/lydericlefebvre) Timeline: =========== -...
  8. badboyhelper

    WordPress Plugin Gift Voucher 1.0.5 - (Authenticated) 'template_id' SQL Injection

    # Exploit Title: WordPress Plugin Gift Voucher 1.0.5 - 'template_id' SQL Injection # Google Dork: intext:"/wp-content/plugins/gift-voucher/" # Date: 2018-08-23 # Exploit Author: Renos Nikolaou # Software Link: https://wordpress.org/plugins/gift-voucher/ # Vendor Homepage...
  9. badboyhelper

    WordPress Plugin Responsive Thumbnail Slider - Arbitrary File Upload (Metasploit)

    ## # This module requires Metasploit: https://metasploit.com/download # Current source: https://github.com/rapid7/metasploit-framework ## class MetasploitModule < Msf::Exploit::Remote   Rank = ExcellentRanking   include Msf::Exploit::Remote::HTTP::Wordpress   include Msf::Exploit::PhpEXE  ...
  10. badboyhelper

    WordPress Plugin Form Maker 1.12.20 - CSV Injection

    # Exploit Title: Wordpress Plugin Form Maker version 1.12.20 vulnerable to to Formula Injection (CSV Injection) # Google Dork: N/A # Date: 27-04-2018 ################################ # Exploit Author: Jetty Sairam ################################ # Software Link...
  11. badboyhelper

    Wordpress Plugin Site Editor 1.1.1 - Local File Inclusion

    Product: Site Editor Wordpress Plugin - https://wordpress.org/plugins/site-editor/ Vendor: Site Editor Tested version: 1.1.1 CVE ID: CVE-2018-7422 ** CVE description ** A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to retrieve...
  12. badboyhelper

    Wordpress Plugin Site Editor 1.1.1 - Local File Inclusion

    Product: Site Editor Wordpress Plugin - https://wordpress.org/plugins/site-editor/ Vendor: Site Editor Tested version: 1.1.1 CVE ID: CVE-2018-7422 ** CVE description ** A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to retrieve...
  13. badboyhelper

    Wordpress Plugin Site Editor 1.1.1 - Local File Inclusion

    Product: Site Editor Wordpress Plugin - https://wordpress.org/plugins/site-editor/ Vendor: Site Editor Tested version: 1.1.1 CVE ID: CVE-2018-7422 ** CVE description ** A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to retrieve...
  14. badboyhelper

    Wordpress Plugin Site Editor 1.1.1 - Local File Inclusion

    Product: Site Editor Wordpress Plugin - https://wordpress.org/plugins/site-editor/ Vendor: Site Editor Tested version: 1.1.1 CVE ID: CVE-2018-7422 ** CVE description ** A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to retrieve...
  15. badboyhelper

    WordPress Plugin Email Subscribers & Newsletters 3.4.7 - Information Disclosure

    # Exploit Title: WordPress Plugin Email Subscribers & Newsletters 3.4.7 - Information Disclosure # Google Dork: # Date: 2018-01-23 # Exploit Author: ThreatPress Security # Vendor Homepage: http://icegram.com/ # Software Link: https://wordpress.org/plugins/email-subscribers/ # Version: 3.4.7 #...
  16. badboyhelper

    WordPress Plugin Smart Google Code Inserter < 3.5 - Authentication Bypass / SQL Injec

    Exploit Title: Smart Google Code Inserter < 3.5 - Auth Bypass/SQLi Google Dork: inurl:wp-content/plugins/smart-google-code-inserter/ Date: 26-Nov-17 Exploit Author: Benjamin Lim Vendor Homepage: http://oturia.com/ Software Link: https://wordpress.org/plugins/smart-google-code-inserter/ Version...
  17. badboyhelper

    WordPress Plugin Easy Modal 2.0.17 - SQL Injection

    DefenseCode ThunderScan SAST Advisory WordPress Easy Modal Plugin Multiple Security Vulnerabilities Advisory ID: DC-2017-01-007 Advisory Title: WordPress Easy Modal Plugin Multiple Vulnerabilities Advisory URL: http://www.defensecode.com/advisories.php Software: WordPress Easy Modal plugin...
  18. badboyhelper

    WordPress Plugin Tribulant Newsletters 4.6.4.2 - File Disclosure / Cross-Site Scripti

    DefenseCode WebScanner DAST Advisory WordPress Tribulant Newsletters Plugin  Multiple Security Vulnerabilities Advisory ID:            DC-2017-01-012 Advisory Title:         WordPress Tribulant Newsletters Plugin Multiple Vulnerabilities Advisory URL:         ...
  19. badboyhelper

    Iperius Backup 5.8.1 Buffer Overflow

    Iperius Backup 5.8.1 Buffer Overflow Topic: Iperius Backup 5.8.1 Buffer Overflow Risk: High Text:# Exploit Title: Iperius Backup 5.8.1 - Buffer Overflow (SEH) # Date: 2018-12-26 # Exploit Author: bzyo # Twitter: @bzyo_ #... https://cxsecurity.com/issue/WLB-2018120225
  20. badboyhelper

    Completed $ 2130 sent to escrow for M33 deal = 7 x MacBook Pro

    Thanks god ! package received today. great job M33 .. i was scarred because my drop wanted to go out of the city tomorrow and i send you his details.. finally the package is received. pelase complete my deal. i will sell all off electronics ad I'll make new order.
Top Bottom