This Metasploit module will exploit a SQL injection in Zabbix 3.0.3 and likely prior in order to save the current usernames and password hashes from the database to a JSON file.
2ebbd2d691dd7508785002385cab0f09585ac3584018b08791e074e76431981a
Jetty version 6.1.6 suffers from a cross site scripting vulnerability.
5a16f6df9887b8370e3580d8d5ebef0042e20e2a03a0475e679f35aa0a28c482
IPSwitch MoveIt versions 8.1 through 9.4 suffer from a persistent cross site scripting vulnerability.
12013f6ce4d0f0ab29797d4705be8ffde2e21245d164e6f3205ddeebdbc5c88a
FreeFloat FTP Server version 1.0 HOST buffer overflow exploit with ASLR bypass.
87bd79a5a3aaf3db3a9c08a2705273f1b0d9a1babc34e142e265648150d6db47
CoolPlayer+ Portable version 2.19.6 stack overflow exploit with ASLR bypass and a bind shell.
2770a7c3c1fa06a4d9f54ade807802dca163b3df6f2cbc67ab49bc588a33dc2a
Zabbix version 3.0.3 suffers from a remote SQL injection vulnerability.
e66499a7042cb8648e12f24179f33ad12b968d3990953a0c243addd146feb69e
Open Web Analytics version 1.5.7 suffers from a cross site scripting vulnerability.
9826ef468507dad63ad72b499b5f63fa30e841d17b63f398c4f0bb78be5d5099
Charts 4 PHP version 1.2.3 suffers from a cross site scripting vulnerability.
9f52771a595d4f701fedd8c6ec11273b06d58e6e9c1035201c77176077d21fdd
BruteX is a bash script that wraps nmap, hydra, and wfuzz to perform scanning with automatic brute forcing.
b602668839864f0994bc9fc07ba540f3e96d6b0f1f15156d8933a1da67db0c65
Findsploit is a simple bash script to quickly and easily search both local and online exploit databases.
7c57fd01df278f1dd04c48e0c1d30069a39d08148c83b12388d162b35688cd5f
Cross Site Tracer is a python script to check remote web servers for cross-site tracing.
dc8726f4ecbe474ad3183b07166b65bf745d3357d8e7b02e746133bc810886fc
WordPress All In One SEO Packet plugin version 2.2.2 suffers from a persistent cross site scripting vulnerability.
fda7f45cc565a3147e5ba92c58662a487ff60f0478cb6e7f55ce73080ff1e02e
Lyris ListManagerWeb version 8.95a suffers from a cross site scripting vulnerability.
e824ac215ca489b54cbb8e68ab45e456ebda1efbabb8167f8f80f7e30fe06d18
MyConnection Server (MCS) version 9.7i suffers from a cross site scripting vulnerability.
5a16d17c8e73a4dfbe43b4d1e8e6c805b4f1e52f5f10b58566b5e4aa143981ce
This script automates scanning for the Supermicro IPMI/BMC cleartext password vulnerability. It can check full subnets or individual hosts and includes an option to scan via proxy and to view vulnerable hosts listed in ShodanHQ.
e368bb65b92ec2b0491d4f9bcbea58351c46f62c857e2b132316a9843b04816d
AlogoSec Fireflow version 6.3 suffers from a cross site scripting vulnerability.
578f9771a6780139081b8976123c0695314af9ef7138996af9a3f7b8ac35530a
This is a shell script that uses unicornscan, the heartbleed proof of concept, nmap, and various other tools in order to do a mass scan for vulnerable SSL instances.
3d5d5d98ca65a01f362846317f934b92ff5da2da31a106a1dbb6210210922bc9