
CVE-2023-08-21-exploit
Axigen < 10.3.3.47, 10.2.3.12 - Reflected XSS

Axigen < 10.3.3.47, 10.2.3.12 - Reflected XSS

PoC (Proof of Concept) de la CVE-2024-4367 - Vulnérabilité RCE dans libwebp. Démonstration complète incluant : création de payloads, scénarios…

Cross Site Scripting vulnerability in mooSocial mooSocial Software v.3.1.6 allows a remote attacker to execute arbitrary code via a crafted script to…

Secure Web Gateway 10.2.11 - Cross-Site Scripting (XSS)

In LetterPress plugin <= 1.2.1 is vulnerable to Html Injection Vulnerability which can futher leads to Open Redirection Vulnerabilty.

xll windows reverse shell

Example on how to injection(currently under work) of keylogger js through Safari Extension(that part done)

WBCE 1.6.1 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will launch…

CVE-2020-13965: Cross-Site Scripting via Malicious XML Attachment in Roundcube Webmail

Microweber version 2.0.4 vulnerable to "Uploading Malicious Files"

Survey XSS combined with CSRF leads to Admin Account Takeover in Concrete5 8.5.4

(DOM-based XSS) HTML Injection vulnerability in TOWeb v.12.05 and before allows an attacker to inject HTML/JS code via the _message.html component.

Read more at Medium

RiteCMS 3.0 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will…

CMSmadesimple 2.2.18 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed…

Cross Site Scripting on sanitization-management-system

ConcreteCMS v.9.2.1 is affected by Arbitrary File Upload vulnerability that allows Cross-Site Scriting (XSS) Stored.

Valid JQuery that profiles the system and returns info to the server in a fake analytics GET request