[go: up one dir, main page]

0% found this document useful (0 votes)
7K views224 pages

Dork Pentakil Team

Uploaded by

aronline2005
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
7K views224 pages

Dork Pentakil Team

Uploaded by

aronline2005
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
You are on page 1/ 224

Poc : Chillipages Technologies - Blind Sql Injection

Dork: intext:Site by | Chillipages Technologies


Date: 16.11.2023

Poc : Plesk Obsidian 18.0.56 command injecrion


Dork: intitle:Plesk Obsidian 18.0.56
Date: 12.11.2023

Poc : Virtual Pages - Sql Injection


Dork: intext:Site by : Virtual Pages
Date: 08.11.2023

Poc : Webnink - sql injection Vulnerability


Dork: intext:Powered by Webnink inurl:.php?Id=
Date: 08.11.2023

Poc : Turning Point - Sql Injection


Dork: intext:Website designed by: Turning Point
Date: 05.11.2023

Poc : Designed by EMH - Blind Sql Injection


Dork: intext:Conception & Réalisation MGSD
Date: 02.11.2023

Poc : Designed by EMH - Cross site scripting


Dork: intext:Designed by EMH
Date: 02.11.2023

Poc : Aadija Technologies - Blind Sql Injection


Dork: intext:Design & Developed by : Aadija Technologies
Date: 02.11.2023

Poc : Aadija Technologies - Xpath Injection Vulnerability


Dork: intext:Design & Developed by : Aadija Technologies
Date: 02.11.2023

Poc : Urvanov Syntax Highlighter <= 2.8.33 - Highlighting Blocks Mgt via CSRF
Dork: site:adroom.ir inurl:/wp-admin/admin-ajax.php
Date: 31.10.2023

Poc : PixelPro Designs - Sql Injection


Dork: intext:Developed By - PixelPro Designs
Date: 31.10.2023

Poc : CMS united - Sql Injection


Dork: intext:Powered by CMS united
Date: 27.10.2023

Poc : Urvanov Syntax Highlighter <= 2.8.33 - Highlighting Blocks Mgt via CSRF
Dork: wp-admin/admin-ajax.php
Date: 27.10.2023

Poc : WordPress Masterstudy LMS 3.0.17 Account Creation


Dork: inurl:/user-public-account
Date: 10.10.2023

Poc : Synotec Holdings - Sql Injection


Dork: intext:Website By: Synotec Holdings (Pvt) Ltd
Date: 01.10.2023

Poc : Edunext Technologies - Sql Injection Vulnerability


Dork: intext:Powered by Edunext Technologies
Date: 01.10.2023

Poc : SFTP/FTP Password Exposure via sftp-config.json


Dork: inurl:/.vscode/sftp-config.json
Date: 20.09.2023

Poc : Super Store Finder 3.7 Remote Command Execution


Dork: intext:designed and built by Joe Iz.
Date: 20.09.2023

Poc : Conception & Réalisation MGSD - Blind Sql Injection Vulnerability


Dork: intext:Conception & Réalisation MGSD
Date: 18.09.2023

Poc : SNDK Technologies - Blind Sql Injection


Dork: intext:Designed by SNDK Technologies Pvt. Ltd.
Date: 18.09.2023

Poc : CMS united - Blind Sql Injection


Dork: intext:Powered by CMS united
Date: 18.09.2023

Poc : Astonished Man Design - Sql Injection Vulnerability


Dork: intext:website by Astonished Man Design
Date: 15.09.2023

Poc : Designed by brandsncodes - Sql Injection Vulnerability


Dork: intext:Designed by brandsncodes
Date: 15.09.2023

Poc : Conception & Réalisation MGSD - Blind Sql Injection Vulnerability


Dork: intext:Conception & Réalisation MGSD
Date: 15.09.2023

Poc : Inforef - Sql Injection Vulnerability


Dork: intext:site web - Inforef
Date: 13.09.2023

Poc : AlgoWid Technologies - Blind Sql Injection Vulnerability


Dork: intext:Powered by AlgoWid Technologies
Date: 13.09.2023

Poc : ITAcumens - Sql Injection Vulnerability


Dork: intext:Powered by ITAcumens
Date: 13.09.2023

Poc : Conception & Réalisation MGSD - Sql Injection


Dork: intext:Conception & Réalisation MGSD
Date: 13.09.2023

Poc : Axigen 10.5.0–4370c946 Cross Site Scripting


Dork: inurl:passwordexpired=yes
Date: 09.09.2023

Poc : Axigen 10.5.0–4370c946 Cross Site Scripting


Dork: inurl:passwordexpired=yes
Date: 09.09.2023

Poc : Soloweb - Sql Injection Vulnerability


Dork: intext:This design is created by Soloweb
Date: 04.09.2023

Poc : design by Diamondwebs - Sql Injection Vulnerability


Dork: intext:Website design by Diamondwebs
Date: 04.09.2023

Poc : AlgoWid Technologies - Sql Injection Vulnerability


Dork: intext:Powered by AlgoWid Technologies
Date: 04.09.2023

Poc : No Sheep Designs - Sql Injection Vulnerability


Dork: intext:Developed by No Sheep Designs
Date: 04.09.2023

Poc : FORMA Design Bureau - Sql Injection Vulnerability


Dork: intext:Design and Development by FORMA Design Bureau
Date: 19.08.2023

Poc : Hilano website design - Cross-Site Scripting (XSS)


Dork: intext:‫طراحی سایت هیالنو‬
Date: 12.08.2023

Poc : Asset Software Solutions - Sql Injection Vulnerability


Dork: intext:Powered by Asset Software Solutions
Date: 12.08.2023

Poc : SNDK Technologies - Sql Injection Vulnerability


Dork: intext:Designed by SNDK Technologies Pvt. Ltd.
Date: 12.08.2023

Poc : Cyberxel - Bypass Admin Panel


Dork: intext:Design n Care :Cyberxel
Date: 12.08.2023

Poc : WordPress Ninja Forms 3.6.25 Cross Site Scripting


Dork: inurl:/wp-content/plugins/ninja-forms/readme.txt
Date: 08.08.2023

Poc : Joomla! com_booking component 2.4.9 Information Leak (Account enumeration)


Dork: inurl:index.php?option=com_booking
Date: 01.08.2023

Poc : Polaris Web 1.21.1 - Reflected XSS


Dork: Siap+Micros S.p.A
Date: 27.07.2023

Poc : mooDating 1.2 - Reflected XSS


Dork: Copyright © 2023 mooDating
Date: 26.07.2023

Poc : Cyberxel - Bypass Admin Panel


Dork: intext:Design n Care :Cyberxel
Date: 23.07.2023
Poc : ErenSoft SQL Injection
Dork: intext:Kodlama: Erensoft
Date: 23.07.2023

Poc : ErenSoft SQL Injection


Dork: intext:Kodlama: Erensoft
Date: 23.07.2023

Poc : Wifi Soft Unibox Administration 3.0 / 3.1 SQL Injection


Dork: intext:Unibox Administration 3.1, intext:Unibox 3.0
Date: 21.07.2023

Poc : Sales of Cashier Goods v1.0 Cross Site Scripting (XSS)


Dork: /print.php?nm_member=
Date: 06.07.2023

Poc : TP-Link TL-WR940N 4 Buffer Overflow


Dork: /userRpm/WanDynamicIpV6CfgRpm
Date: 05.07.2023

Poc : Super Socializer 7.13.52 Reflected XSS


Dork: inurl: https://example.com/wp-admin/admin-ajax.php?
action=the_champ_sharing_count&urls[
3Cimg
20src
3Dx
20onerror
3Dalert
28document
2Edomain
29
3E]=https://www.google.com
Date: 03.07.2023

Poc : ToprakAJans Admin NoRedirect Bypass


Dork: intext:@ToprakAjans
Date: 26.06.2023

Poc : HiSecOS 04.0.01 Privilege Escalation


Dork: HiSecOS Web Server Vulnerability Allows User Role Privilege Escalation
Date: 22.06.2023

Poc : WordPress WP Sticky Social 1.0.1 CSRF / Cross Site Scripting


Dork: inurl:~/admin/views/admin.php
Date: 22.06.2023

Poc : WordPress Theme Medic v1.0.0 Weak Password Recovery Mechanism for Forgotten
Password
Dork: inurl:/wp-includes/class-wp-query.php
Date: 19.06.2023

Poc : BlogMagz 1.0 - Stored XSS


Dork: Copyright © 2023 BlogMagz All Rights Reserved.
Date: 18.06.2023

Poc : Camelon CMS 2.7.4 Stored XSS in Post Title


Dork: intext:Camaleon CMS is a free and open-source tool and a fexible content
management system (CMS) based on Ruby on Rails
Date: 15.06.2023
Poc : WordPress Workreap 2.2.2 Shell Upload
Dork: inurl:/wp-content/themes/workreap/
Date: 13.06.2023

Poc : WordPress Theme Workreap 2.2.2 Unauthenticated Upload Leading to Remote Code
Execution
Dork: inurl:/wp-content/themes/workreap/
Date: 10.06.2023

Poc : JetSınav SQL Injection + Default Password Vulnerability


Dork: allintext:Powered by Jetsınav
Date: 28.05.2023

Poc : SCM Manager 1.60 Cross Site Scripting


Dork: intitle:SCM Manager intext:1.60
Date: 28.05.2023

Poc : Siemens SIMATIC S7-1200 Cross Site Request Forgery


Dork: inurl:/Portal/Portal.mwsl
Date: 21.05.2023

Poc : Sophos Web Appliance 4.3.10.4 Pre-auth command injection


Dork: title:Sophos Web Appliance
Date: 25.04.2023

Poc : Bluesoft Infotech - Sql Injection Vulnerability


Dork: intext:Designed by Bluesoft Infotech
Date: 23.04.2023

Poc : Instagram Brute Force Attack Using Python


Dork: site:instagram.com inurl:login
Date: 15.04.2023

Poc : Altenergy Power Control Software C1.2.5 OS command injection


Dork: intitle:Altenergy Power Control Software
Date: 14.04.2023

Poc : Leaders Group - Sql Injection Vulnerability


Dork: intext:By: Leaders Group
Date: 11.04.2023

Poc : Site by Jundweb - Sql Injection Vulnerability


Dork: intext:Site by Jundweb
Date: 11.04.2023

Poc : pfsenseCE 2.6.0 Protection Bypass


Dork: intitle:pfSense - Login
Date: 10.04.2023

Poc : Goanywhere Encryption Helper 7.1.1 Remote Code Execution


Dork: title:GoAnywhere
Date: 10.04.2023

Poc : Paradox Security Systems IPR512 Denial Of Service


Dork: intitle:ipr512 * - login screen
Date: 10.04.2023

Poc : Bludit 3-14-1 Shell Upload


Dork: intext:'2022 Powered by Bludit'
Date: 02.04.2023

Poc : LISTSERV 17 Reflected Cross Site Scripting (XSS)


Dork: inurl:/scripts/wa.exe
Date: 02.04.2023

Poc : WordPress Real Estate 7 Theme <= 3.3.4 - Abuse of Functionality


Dork: inurl:/wp-content/themes/realestate-7/
Date: 09.03.2023

Poc : WordPress WoodMart Theme <= 7.1.0 - Unauthenticated Arbitrary Shortcodes


Injection
Dork: inurl:/wp-content/themes/woodmart/
Date: 08.03.2023

Poc : WordPress Real Estate 7 Theme <= 3.3.4 - Multiple Cross-Site Request
Forgery (CSRF) Vulnerabilities
Dork: inurl:/wp-content/themes/realestate-7/
Date: 05.03.2023

Poc : WordPress Real Estate 7 Theme <= 3.3.4 - Unauthenticated Reflected Cross-
Site Scripting (XSS)
Dork: inurl:/wp-content/themes/realestate-7/
Date: 05.03.2023

Poc : WordPress WoodMart Theme <= 7.1.1 - Theme License Options Change via CSRF
Dork: inurl:/wp-content/themes/woodmart/
Date: 05.03.2023

Poc : WordPress Real Estate 7 Theme 3.3.4 Cross Site Scripting


Dork: inurl:/wp-content/themes/realestate-7/
Date: 01.03.2023

Poc : WordPress WoodMart Theme 7.1.1 Cross Site Request Forgery


Dork: inurl:/wp-content/themes/woodmart/
Date: 01.03.2023

Poc : Best POS Management System 1.0 Cross Site Scripting


Dork: NA
Date: 17.02.2023

Poc : Developed by Ameya Computers LOGIN SQL INJECTİON


Dork: intext:Developed by : Ameya Computers inurl:login.php
Date: 14.02.2023

Poc : Powered By dokumenary.net Remote Code Execution


Dork: intext:dokumenary.net All rights reserved.
Date: 30.01.2023

Poc : Website by MSBu.de - Sql Injection Vulnerability


Dork: intext:Website by MSBu.de
Date: 23.01.2023

Poc : Stealth Media Ltd - Sql Injection Vulnerability


Dork: intext:Website Designed & Developed By Stealth Media Ltd.
Date: 09.01.2023

Poc : SDM-Downloads 9.3.15 Privilege Escalation Arbritrary File Upload


Dork: inurl:/sdm-downloads/
Date: 06.01.2023

Poc : Wordpress Dsp Dating Csrf FIle Upload


Dork: inurl:wp-content/plugins/dsp_dating
Date: 06.01.2023

Poc : Textpattern 4.8.8 - Remote Code Execution (RCE) (Authenticated)


Dork: intext:Published with Textpattern CMS
Date: 20.12.2022

Poc : Remote Code Execution in SimpleMachinesForum 2.1.1


Dork: SimpleMachinesForum Exploit
Date: 18.11.2022

Poc : Remote Code Execution in MODX Revolution V2.8.3-pl


Dork: MODX Exploit
Date: 15.11.2022

Poc : Remote Code Execution in Abantecart-1.3.2


Dork: Abantecart exploit
Date: 13.11.2022

Poc : Khameneie.ir XSS vulnerabilities


Dork: site:farsi.khamenei.ir/search-result?q=
Date: 23.10.2022

Poc : developway SQL Injection


Dork: intext:Powered By DevelopWay
Date: 23.10.2022

Poc : Wordpress Plugin ImageMagick-Engine 1.7.4 Remote Code Execution (RCE)


(Authenticated)
Dork: inurl:/wp-content/plugins/imagemagick-engine/
Date: 18.10.2022

Poc : blesta 5.4.1 Backdoor Account Vulnerability


Dork: Powered by Blesta, © Phillips Data, Inc.
Date: 13.10.2022

Poc : Authenticated Sql Injection in ImpressCMS v1.4.3


Dork: ImpressCMS Exploit
Date: 12.10.2022

Poc : WordPress WP-UserOnline 2.88.0 Cross Site Scripting


Dork: inurl:/wp-content/plugins/wp-useronline/
Date: 25.09.2022

Poc : VIAVIWEB Wallpaper Admin SQL Injection / Shell Upload


Dork: intext:Wallpaper Admin LOGIN password Username
Date: 22.09.2022

Poc : Genesys PureConnect - Interaction Web Tools XSS


Dork: inurl:/I3Root/chatOrCallback.html
Date: 15.09.2022

Poc : Equitysoft Technologies Pvt Ltd - SQL Injection Vulnerability


Dork: intext:Equitysoft Technologies Pvt Ltd
Date: 13.09.2022
Poc : kansascitynova - Sql Injection Vulnerability
Dork: intext:Designed by kansascitynova
Date: 13.09.2022

Poc : cr-led - Cross Site Scripting Vulnerability (XSS)


Dork: news.php?id=
Date: 31.08.2022

Poc : daihocpccc - Cross Site Scripting Vulnerability (XSS)


Dork: inurl:index.php?id=
Date: 28.08.2022

Poc : Yashwant solutions - Sql Injection Vulnerability


Dork: intext:Designed by Designed by Yashwant solutions
Date: 24.08.2022

Poc : Foodiee 1.0.1 unauthorized administrative access Vulnerability


Dork: intext:restaurants_details.php?id=
Date: 20.08.2022

Poc : Active PHP Bookmarks v1.3 - Sql Injection Vulnerability


Dork: intext:Active PHP Bookmarks v1.3
Date: 06.08.2022

Poc : Picaporte Design - Sql Injection Vulnerability


Dork: intext:Developed By Newgen Technologies
Date: 06.08.2022

Poc : Powered by Compusys e Solutions - Sql Injection Vulnerability


Dork: intext:Powered by Compusys e Solutions
Date: 02.08.2022

Poc : Newgen Technologies - Sql Injection Vulnerability


Dork: intext:Developed By Newgen Technologies
Date: 02.08.2022

Poc : Kaivalya Techno Soft Pvt - Sql Injection Vulnerability


Dork: intext:Developed By - Kaivalya Techno Soft Pvt. Ltd.
Date: 01.08.2022

Poc : Try Catch Technologies - Sql Injection Vulnerability


Dork: intext:Designed By Try Catch Technologies
Date: 01.08.2022

Poc : Web Design By East Technologies - SQL Injection Vulnerability


Dork: intext:Web Design By East Technologies
Date: 29.07.2022

Poc : Active eCommerce Laravel CMS 5.x to 6.1.2 - Cross Site request forgery (CSRF)
to Cross-site Scripting (XSS) (Authenticated)
Dork: intext:|| WHOPPS!!!THIS IS PIRATED COPY OF ACTIVE ECOMMERCE CMS
Date: 20.07.2022

Poc : Designed With by HOME SALON - SQL Injection Vulnerability


Dork: intext:Designed With by HOME SALON
Date: 17.07.2022

Poc : Websyte mit vor webSchmitte.ch - Sql Injection Vulnerability


Dork: intext:Websyte mit vor webSchmitte.ch
Date: 17.07.2022

Poc : dhamdhama anchalik college - Sql Injection Vulnerability


Dork: intext:Designed & Developed By Hirak
Date: 17.07.2022

Poc : Yahweh Touch - Sql Injection Vulnerability


Dork: intext:Developed by Yahweh Touch
Date: 17.07.2022

Poc : Developed by: web3creations.com - Sql Injection Vulnerability


Dork: intext:Developed by: web3creations.com
Date: 16.07.2022

Poc : Designed by VITECH IT Solutions - Sql Injection Vulnerability


Dork: intext:Developed & Designed by VITECH IT Solutions
Date: 15.07.2022

Poc : Developed By : SOFTMAART - Sql Injection Vulnerability


Dork: intext:Developed By : SOFTMAART
Date: 15.07.2022

Poc : Akaal WebSoft Pvt - Sql Injection Vulnerability


Dork: intext:Designed By : Akaal WebSoft Pvt. Ltd
Date: 15.07.2022

Poc : phpAnalyzer v2.0.4 Backdoor Account Vulnerability


Dork: intext:Copyright © phpAnalyzer.com. All rights reserved. Product by AltumCode
Date: 13.07.2022

Poc : MktbaGold 6.4 Arbitrary File Upload


Dork: Powered by: MktbaGold 6.4
Date: 13.07.2022

Poc : Plumcloud Image Browser File Upload


Dork: intext:©2014 PlumCloud. All Rights Reserved.
Date: 12.07.2022

Poc : Exploit mktba 4.2 Arbitrary File Upload


Dork: Powered by: mktba
Date: 10.07.2022

Poc : Openbiz Cubi 3.0.8 Xss/Html inject Upload Vulnerability


Dork: intext: System Login - Cubi Platform
Date: 08.07.2022

Poc : Advanced Testimonials Manager v5.5 Reinstall Add Admin Vulnerability


Dork: Advanced Testimonial Manager
Date: 06.07.2022

Poc : Designed By Sevy INC. - SQL Injection Vulnerability, Unrestricted File Upload
Vulnerability and Default Admin Credentials
Dork: intext:Designed By Sevy INC.
Date: 06.07.2022

Poc : SEO Nethizmet Admin NoRedirect Bypass


Dork: intext:inurl /yonetici/yonetici-giris.php
Date: 05.07.2022
Poc : OPSTECH Thailand Gov Management System Multiple Vulnerabilities
Dork: 1. intext:Copyright © by OPSTECH All Right Reserved site:go.th
Date: 04.07.2022

Poc : SEO Nethizmet Admin NoRedirect Bypass


Dork: intext:intext:Web Tasarım Seo Nethizmet
Date: 28.06.2022

Poc : Mailhog 1.0.1 Stored Cross-Site Scripting (XSS)


Dork: https://www.shodan.io/search?query=mailhog ( > 3500)
Date: 28.06.2022

Poc : BLUEWATER MARIBAGO BEACH RESORT - SQL Injection Vulnerability


Dork: intext:BLUEWATER MARIBAGO BEACH RESORT inurl:/index.php?page=
Date: 22.06.2022

Poc : WEB SITE Yas Arghavani System XSS


Dork: -
Date: 11.06.2022

Poc : H3k / tiny File Manager


Dork: intitle:h3k File Manager
Date: 05.06.2022

Poc : Contao 4.13.2 Cross Site Scripting


Dork: NA
Date: 04.06.2022

Poc : Zyxel USG FLEX 5.21 Command Injection


Dork: title:USG FLEX 100 title:USG FLEX 100W title:USG FLEX 200 title:USG FLEX 500
title:USG FLEX 700 title:USG20-VPN title:USG20W-VPN title:ATP 100 title:ATP 200
title:ATP 500 title:ATP 700 title:ATP 800
Date: 04.06.2022

Poc : qdPM 9.1 Remote Code Execution (RCE) (Authenticated) (v2)


Dork: intitle:qdPM 9.1. Copyright © 2020 qdpm.net
Date: 29.05.2022

Poc : Will VPN App - VPN App With Admin Panel - Phpthumb Command Injection
Dork: - / use your brain
Date: 19.05.2022

Poc : Designed by OG Advertising - Sql Injection Vulnerability


Dork: intext:Designed by OG Advertising
Date: 14.05.2022

Poc : Ruijie Reyee Mesh Router Remote Code Execution


Dork: None
Date: 11.05.2022

Poc : Infreshop - Cross-Site Scripting Vulnerability


Dork: intext:Powered by Infreshop
Date: 10.05.2022

Poc : Zimbra - Request URL Override Vulnerability


Dork: inurl:/public/launchSidebar.jsp
Date: 09.05.2022
Poc : Stisla - Open Redirect Vulnerability
Dork: intitle:Login — Stisla
Date: 09.05.2022

Poc : Strapi 3.6.8 Password Disclosure / Insecure Handling


Dork: intitle:Welcome to your Strapi ap
Date: 03.05.2022

Poc : Infreshop - Sql Injection Vulnerability


Dork: intext:Powered by Infreshop
Date: 01.05.2022

Poc : SayItOnTheWeb - Sql Injection Vulnerability


Dork: intext:Website By: SayItOnTheWeb, Inc.
Date: 01.05.2022

Poc : WordPress Videos Sync PDF 1.7.4 Cross Site Scripting


Dork: inurl:/wp-content/plugins/video-synchro-pdf/
Date: 24.04.2022

Poc : USR IOT 4G LTE Industrial Cellular VPN Router 1.0.36 Remote Root Backdoor
Dork: title:usr-* // 4,648 ed ao 15042022
Date: 22.04.2022

Poc : jsharp Technology - Sql Injection Vulnerability


Dork: intext:Developed by jsharp Technology
Date: 15.04.2022

Poc : Signature Software - Sql Injection Vulnerability


Dork: intext:Website by Signature Software
Date: 15.04.2022

Poc : Miracle Hunt Services - Sql Injection Vulnerability


Dork: intext:Managed By Miracle Hunt Services
Date: 15.04.2022

Poc : WordPress Video-Synchro-PDF 1.7.4 Local File Inclusion


Dork: inurl:/wp-content/plugins/video-synchro-pdf/
Date: 01.04.2022

Poc : Iolite Softwares - Sql Injection Vulnerability


Dork: intext:Designed by Iolite Softwares Pvt. Ltd.
Date: 29.03.2022

Poc : INTERSOFT CMS Login Bypass


Dork: intext:Web & Hosting / INTERSOFT ®
Date: 26.03.2022

Poc : Developed By Yasha Zamanpour - Sql Injection Vulnerability


Dork: intext:Designed & Developed By Yasha Zamanpour
Date: 26.03.2022

Poc : KYB Asian Pacific Corporation - SQL Injection Vulnerability


Dork: intext:KYB Asian Pacific Corporation
Date: 24.03.2022

Poc : WordPress Amministrazione Aperta 3.7.3 Arbitrary File Read


Dork: inurl:/wp-content/plugins/amministrazione-aperta/
Date: 24.03.2022
Poc : iRZ Mobile Router Cross Site Request Forgery / Remote Code Execution
Dork: intitle:iRZ Mobile Router
Date: 22.03.2022

Poc : Copyright 2021 Reobiz. All Rights Reserved. - SQL Injection Vulnerability
Dork: intext:© Copyright 2021 Reobiz. All Rights Reserved.
Date: 21.03.2022

Poc : Design: linkealia.com - Sql Injection Vulnerability


Dork: intext:Design: linkealia.com
Date: 17.03.2022

Poc : Montenegro Shipping Lines, Inc. - SQL Injection Vulnerability


Dork: intext:Designed by Rushtek Enterprise
Date: 14.03.2022

Poc : DEOS AG OPEN 710/810 Cross Site Scripting


Dork: app:DEOS AG OPEN EMS System ics device httpd
Date: 10.03.2022

Poc : Vietnext - Sql Injection Vulnerability


Dork: intext:Designed by Vietnext
Date: 10.03.2022

Poc : Bordaline Web Design - Sql Injection Vulnerability


Dork: intext:Website by Bordaline Web Design
Date: 06.03.2022

Poc : Behkad CMS - Technical And Vocational University Yazd / Iran - Cross-Site
Scripting (XSS)
Dork: -
Date: 06.03.2022

Poc : DCD-ARQAC - Sql Injection Vulnerability


Dork: intext:Designed And Developed by Digital Content Development DCD-ARQAC, JSPM-
TSSM
Date: 05.03.2022

Poc : Z Web Solutions - Sql Injection Vulnerability


Dork: intext:Powered by Z Web Solutions.
Date: 05.03.2022

Poc : Logical Triangle Ltd - Sql Injection Vulnerability


Dork: intext:Development by: Logical Triangle Ltd.
Date: 03.03.2022

Poc : Eticaret Turkey CMS Kcfinder & Roxy File Manager Exploit
Dork: inurl:/nedmin/production/ (dorking on google images)
Date: 01.03.2022

Poc : Support Board 3.4.5 WP and NonWP Arbitrary File Upload / CSRF File Upload
Dork: use your brain brother
Date: 01.03.2022

Poc : Virtual Design - Sql Injection Vulnerability


Dork: intext:Design by Virtual Design
Date: 28.02.2022
Poc : Responsive file manager for russian website
Dork: inurl:/modules/tinymce/source/ site:ru
Date: 28.02.2022

Poc : Futronic Technology Company Limited. - Sql Injection Vulnerability


Dork: intext:Futronic Technology Company Limited.
Date: 26.02.2022

Poc : Tesquito. - Bypass Admin Panel


Dork: intext:© 2022 Copyright tesquito. All Rights reserved.
Date: 26.02.2022

Poc : WordPress dzs-zoomsounds 6.60 Shell Upload


Dork: inurl:wp-content/plugins/dzs-zoomsounds
Date: 23.02.2022

Poc : Themefisher - Sql Injection Vulnerability


Dork: intext:Designed & Developed by Themefisher
Date: 23.02.2022

Poc : Inbounderz - Sql Injection Vulnerability


Dork: intext:Design By Inbounderz
Date: 22.02.2022

Poc : Antik Infotech - Sql Injection Vulnerability


Dork: intext:Created & Cared By Antik Infotech
Date: 22.02.2022

Poc : Agirhnet 1.0 Cross Site Scripting


Dork: inurl:agirhnet
Date: 22.02.2022

Poc : Powered by Kinza Group (Pvt) Ltd. - Sql Injection Vulnerability


Dork: intext:Powered by Kinza Group (Pvt) Ltd.
Date: 20.02.2022

Poc : Fortinet Fortimail 7.0.1 Cross Site Scripting


Dork: inurl:/fmlurlsvc/
Date: 20.02.2022

Poc : Ideation Digital - Sql Injection Vulnerability


Dork: intext:Created by Ideation Digital
Date: 20.02.2022

Poc : BestNetStudio - Sql Injection Vulnerability


Dork: intext:Developed by BestNetStudio
Date: 20.02.2022

Poc : iGrapix Solutions - Sql Injection Vulnerability


Dork: intext:Powered By: iGrapix Solutions
Date: 14.02.2022

Poc : Azhari Infotech - Sql Injection Vulnerability


Dork: intext:Designed by Azhari Infotech
Date: 14.02.2022

Poc : Telford by Vista Design - Sql Injection Vulnerability


Dork: intext:Web Design Telford by Vista Design
Date: 12.02.2022
Poc : Newgen Technologies - Sql Injection Vulnerability
Dork: intext:Site Hosted & Developed By Newgen Technologies
Date: 09.02.2022

Poc : Created By COPPERJAM Admin Bypass To Shell Upload


Dork: intext:created by copperjam
Date: 07.02.2022

Poc : VicitCMS SQL Injection & Admin Panel bypass


Dork: intext:VicitCMS
Date: 31.01.2022

Poc : Quiz Maker 6.2 - Sensitive Data Exposure (Authenticated User Credentials)
Dork: inurl:/wp-content/plugins/quiz-maker
Date: 26.01.2022

Poc : Creative Websoft - Sql Injection Vulnerability


Dork: intext:Website Desined By: Creative Websoft
Date: 26.01.2022

Poc : LDaRosa Xpath Injection Vulnerability


Dork: intext:By LDaRosa
Date: 24.01.2022

Poc : North Wing Limited - Sql Injection Vulnerability


Dork: intext:Developers: North Wing Limited
Date: 20.01.2022

Poc : S.S. Technologies - Sql Injection Vulnerability


Dork: intext:Powered By S.S. Technologies inurl:id=
Date: 20.01.2022

Poc : Archeevo 5.0 Local File Inclusion


Dork: intitle:archeevo
Date: 18.01.2022

Poc : Picaporte Design - Sql Injection Vulnerability


Dork: intext:Picaporte Design
Date: 18.01.2022

Poc : Nyron 1.0 SQL Injection


Dork: inurl:winlib.aspx
Date: 18.01.2022

Poc : Developed by : Muhammad Jamil - SQL Injection


Dork: intext:Developed by : Muhammad Jamil .php?id=
Date: 17.01.2022

Poc : da Grazioli Design - Sql Injection Vulnerability


Dork: intext:Sito web creato da Grazioli Design
Date: 15.01.2022

Poc : Web Canvas - Sql Injection Vulnerability


Dork: intext:Web Design by Web Canvas
Date: 15.01.2022

Poc : MARKS DESIGN - Sql Injection Vulnerability


Dork: intext:Designed by MARKS DESIGN
Date: 13.01.2022

Poc : EDSA Designs - Sql Injection Vulnerability


Dork: intext:website by EDSA Designs
Date: 13.01.2022

Poc : Agile Web Solutions - Sql Injection Vulnerability


Dork: intext:Developed By Agile Web Solutions
Date: 12.01.2022

Poc : Arva Web Developer - Blind Sql Injection Vulnerability


Dork: intext:Designed & Developed by : Arva Web Developer
Date: 11.01.2022

Poc : sixdaysworks - Sql Injection Vulnerability


Dork: intext:Website design and hosting by sixdaysworks
Date: 09.01.2022

Poc : Moor Hunt Services SQL Injection


Dork: intext:Powered by : Moor Hunt Services
Date: 07.01.2022

Poc : NEETAI TECH - Sql Injection Vulnerability


Dork: intext:Designed By NEETAI TECH
Date: 06.01.2022

Poc : PixelPro Designs - Sql Injection Vulnerability


Dork: intext:Designed By - PixelPro Designs
Date: 06.01.2022

Poc : Active PHP BookMarks 1.3 - Sql Injection Vulnerability


Dork: intext:Powered by Active PHP Bookmarks v1.3 inurl:.view_group.php?id=
Date: 05.01.2022

Poc : Dixell XWEB 500 Arbitrary File Write


Dork: inurl:xweb500.cgi
Date: 05.01.2022

Poc : Powered by INSPIROXINDIA - Blind Sql Injection Vulnerability


Dork: intext:Powered by INSPIROXINDIA
Date: 05.01.2022

Poc : RiteCMS 3.1.0 Arbitrary File Overwrite


Dork: intext:Powered by RiteCMS
Date: 05.01.2022

Poc : Media k - Sql Injection Vulnerability


Dork: intext:Designed and Developed by Media k
Date: 04.01.2022

Poc : BeyondTrust Remote Support 6.0 Cross Site Scripting


Dork: intext:BeyondTrust Redistribution Prohibited
Date: 04.01.2022

Poc : Virtual Airlines Manager 2.6.2 - 'plane_location' SQL Injection


Dork: Powered by Virtual Airlines Manager [v2.6.2]
Date: 01.01.2022

Poc : WEBSOFT SOLUTIONS - Sql Injection Vulnerabilit


Dork: intext:Powered by : WEBSOFT SOLUTIONS
Date: 30.12.2021

Poc : HK Global Solutions - Sql Injection Vulnerability


Dork: intext:Powered By: HK Global Solutions
Date: 30.12.2021

Poc : Chahar Technologies - Sql Injection Vulnerability


Dork: intext:Website Designed By Chahar Technologies.
Date: 30.12.2021

Poc : BeeMedia- Sql Injection Vulnerability


Dork: intext:Designed by BeeMedia
Date: 28.12.2021

Poc : BeeMedia - Bypass Admin Panel


Dork: intext:Designed by BeeMedia
Date: 28.12.2021

Poc : HRVAC Consulting Engineering Israel SQL Injection Vulnerability


Dork: page.php?ID=112
Date: 26.12.2021

Poc : WBCE CMS 1.5.1 Admin Password Reset


Dork: intext: Way Better Content Editing
Date: 20.12.2021

Poc : ALFA TEAM SHELL TESLA 4.1 - Remote Code Execution (Unauthenticated)
Dork: inurl:/alfacgiapi intext:alfa
Date: 19.12.2021

Poc : HD-Network Real-Time Monitoring System 2.0 Local File Inclusion


Dork: intitle:HD-Network Real-time Monitoring System V2.0
Date: 13.12.2021

Poc : FiveM & Gmod Loading Screen Maker Free | SQL Injection Vulnerability
Dork: ip:213.202.247.8 .php?id=
Date: 11.12.2021

Poc : LimeSurvey 5.2.4 Remote Code Execution


Dork: inurl:limesurvey/index.php/admin/authentication/sa/login
Date: 10.12.2021

Poc : OpenCATS 0.9.4 Remote Code Execution


Dork: intext:Current Available Openings, Recently Posted Jobs
Date: 10.12.2021

Poc : TestLink 1.19 Arbitrary File Download


Dork: inurl:/testlink/
Date: 09.12.2021

Poc : PageWay Version 1.8 BETA SQL Injection Vulnerability


Dork: intext:PageWay™ Website Administration System, Version 1.8 BETA
Date: 07.12.2021

Poc : WordPress DZS Zoomsounds 6.45 Arbitrary File Read


Dork: inurl:/wp-content/plugins/dzs-zoomsounds/
Date: 05.12.2021
Poc : Openbiz Cubi 3.0.8 Unrestricted File Upload Vulnerability
Dork: intext: System Login - Cubi Platform
Date: 03.12.2021

Poc : WordPress Plugin DZS Zoomsounds 6.45 Arbitrary File Read (Unauthenticated)
Dork: inurl:/wp-content/plugins/dzs-zoomsounds/
Date: 03.12.2021

Poc : Harshainfotech - Sql Injection Vulnerability


Dork: intext:Designed & Maintained by | Harshainfotech
Date: 02.12.2021

Poc : Design By Magic Mayo - Sql Injection Vulnerability


Dork: intext:Design By Magic Mayo
Date: 30.11.2021

Poc : Designed by Desire Web World - Sql Injection Vulnerability


Dork: intext:Designed by Desire Web World
Date: 30.11.2021

Poc : PHPJabbers Simple CMS 5 name Persistent Cross-Site Scripting (XSS)


Dork: subtitle:Copyright © 2021 PHPJabbers.com
Date: 29.11.2021

Poc : NEXIN engine v2.0 Backdoor Account Vulnerability


Dork: NEXIN engine v2.0
Date: 27.11.2021

Poc : itchiangmai SQL Injection Vulnerability


Dork: Power by itchiangmai
Date: 26.11.2021

Poc : Code For Share | SQL Injection Vulnerability


Dork: ip:54.162.128.250 .php?id=
Date: 26.11.2021

Poc : Webrun 3.6.0.42 SQL Injection


Dork: intitle:Webrun 3.6.0.42
Date: 23.11.2021

Poc : Design by ADMINA BULGARIA Ltd Backdoor Account Vulnerability


Dork: ADMINA BULGARIA Ltd.. All Rights Reserved. .
Date: 19.11.2021

Poc : WordPress Smart Product Review 1.0.4 Shell Upload


Dork: inurl: /wp-content/plugins/smart-product-review/
Date: 18.11.2021

Poc : DMIS:C R I 2 SQL Injection Vulnerability


Dork: ระบบฐานข้อมูลสารสนเทศเพื่อการบริหารจัดการศึกษา สำนักงานเขตพื้นที่การศึกษา
ประถมศึกษาเชียงราย เขต 2
Date: 18.11.2021

Poc : GitLab 13.10.2 Remote Code Execution (RCE) (Unauthenticated)


Dork: https://www.shodan.io/search?query=title
3A
22GitLab
22+
2B
22Server
3A+nginx
22
Date: 17.11.2021

Poc : XEL cms© v. 1.1 CSRF Vulnerability


Dork: intext:contact at: +91-98144 06799, z91-161-2408274 email: info@cyberxel.com
Date: 16.11.2021

Poc : Advanced Testimonials Manager v4.1.1 Auth by pass Vulnerability


Dork: Advanced Testimonial Manager
Date: 14.11.2021

Poc : ArenaTurk Admin Panel Bypass


Dork: intext:Designed By Arenatürk
Date: 14.11.2021

Poc : 7Days Creations SQL Injection Vulnerability


Dork: Development and Design by 7Days Creations
Date: 12.11.2021

Poc : FormaLMS 2.4.4 Authentication Bypass


Dork: inurl:index.php?r=adm/
Date: 11.11.2021

Poc : Kmaleon 1.1.0.205 SQL Injection


Dork: intitle: Inicio de Sesión - Kmaleon
Date: 10.11.2021

Poc : Opencart 3 Extension TMD Vendor System SQL Injection


Dork: inurl:index.php?route=vendor/allseller
Date: 05.11.2021

Poc : Open Journal Systems Arbitrary File Upload


Dork: /index.php/journal
Date: 30.10.2021

Poc : Mini-XML 3.2 Heap Overflow


Dork: mxml Mini-xml Mini-XML
Date: 29.10.2021

Poc : Build Smart ERP 21.0817 eidValue SQL Injection (Unauthenticated)


Dork: intitle:buildsmart accounting
Date: 28.10.2021

Poc : CKAN Datastore Search - SQL-I (Brasil POC)


Dork: inurl:/datastore_search_sql?sql=
Date: 28.10.2021

Poc : Optijet School Management System - Blind SQL Injection (Unauthenticated)


Dork: intext:okulsonuc.com
Date: 20.10.2021

Poc : SonicWall SMA 10.2.1.0-17sv Password Reset


Dork: https://www.shodan.io/search?query=title
3A
22Virtual+Office
22+
22Server
3A+SonicWall
22
Date: 20.10.2021

Poc : Plastic SCM 10.0.16.5622 Insecure Direct Object Reference


Dork: title:Plastic SCM
Date: 18.10.2021

Poc : Code For Share | SQL Injection Vulnerability


Dork: ip:54.162.128.250 .php?id=
Date: 17.10.2021

Poc : Logitech Media Server 8.2.0 Cross Site Scripting


Dork: Search Logitech Media Server
Date: 14.10.2021

Poc : Sonicwall SonicOS 7.0 Host Header Injection


Dork: inurl:auth.html intitle:SonicWall
Date: 13.10.2021

Poc : WordPress Pie Register 3.7.1.4 Privilege Escalation


Dork: inurl:/plugins/pie-register/
Date: 11.10.2021

Poc : Developed by VSFB DEVELOPERS ZONE - Sql Injection Vulnerability


Dork: intext:Website Developed by VSFB DEVELOPERS ZONE PVT. LTD.
Date: 11.10.2021

Poc : โดยบริษัท รับทำเว็บไซต์ - Sql Injection Vulnerability


Dork: intext:Web Design โดยบริษัท รับทำเว็บไซต์
Date: 11.10.2021

Poc : Jingle Infosolutions - Sql Injection Vulnerability


Dork: intext:Designed By Jingle Infosolutions Pvt. Ltd.
Date: 09.10.2021

Poc : Worldnet Payments Knowledge Base : Start | SQL Injection Vulnerability


Dork: .php?id= docs.worldnettps.com
Date: 09.10.2021

Poc : Asset Software Solutions - Blind Sql Injection Vulnerability


Dork: intext:Powered by Asset Software Solutions
Date: 06.10.2021

Poc : Asset Software Solutions - Sql Injection Vulnerability


Dork: intext:Powered by Asset Software Solutions
Date: 06.10.2021

Poc : WordPress MStore API 2.0.6 Shell Upload


Dork: inurl:/wp-content/plugins/mstore-api/
Date: 06.10.2021

Poc : Tapatalk Plugins PHP Object Injection


Dork: inurl: mobiquo/mobiquo.php
Date: 06.10.2021

Poc : Open Game Panel Remote Code Execution


Dork: intext:Open Game Panel 2021
Date: 05.10.2021
Poc : krishna Tech - Sql Injection Vulnerability
Dork: intext:Powered by krishna Tech
Date: 03.10.2021

Poc : Shodh Technologies - Sql Injection Vulnerability


Dork: intext:Powered by Shodh Technologies®
Date: 03.10.2021

Poc : WordPress JS Jobs Manager 1.1.7 Authorization Bypass


Dork: inurl:/wp-content/plugins/js-jobs/
Date: 02.10.2021

Poc : Zircon Web Desig - Sql Injection Vulnerability


Dork: intext:Website Design and Hosted by Zircon Web Design
Date: 27.09.2021

Poc : Zircon Web Desig - Blind Sql Injection Vulnerability


Dork: intext:Website Design and Hosted by Zircon Web Design
Date: 27.09.2021

Poc : BitraNet Cms Sql injection


Dork: Designed by BitraNet
Date: 23.09.2021

Poc : WordPress 3DPrint Lite 1.9.1.4 Shell Upload


Dork: inurl:/wp-content/plugins/3dprint-lite/
Date: 23.09.2021

Poc : WP Google Maps Plugin < 8.1.13 - Authenticated Persistent XSS


Dork: inurl:/wp-content/plugins/wp-google-maps/
Date: 20.09.2021

Poc : WP Google Maps PRO Add-on Plugin < 8.1.12 - Authenticated Persistent XSS
Dork: inurl:/wp-content/plugins/wp-google-maps-pro/
Date: 20.09.2021

Poc : Digital Nomad Studi - Sql Injection Vulnerability


Dork: intext:Designed & Powered by Digital Nomad Studio
Date: 20.09.2021

Poc : Developed By Next Come To Us - Sql Injection Vulnerability


Dork: intext:Developed By Next Come To Us
Date: 20.09.2021

Poc : Merit Designs- Sql Injection Vulnerability


Dork: intext:Desarrollado por Merit Designs
Date: 19.09.2021

Poc : Takmeel Global - Blind Sql Injection Vulnerability


Dork: intext:by Takmeel Global
Date: 19.09.2021

Poc : DigiHost Web Services - Sql Injection Vulnerability


Dork: intext:Powered By: DigiHost Web Services
Date: 19.09.2021

Poc : WordPress Download From Files 1.48 Shell Upload


Dork: inurl:/wp-content/plugins/download-from-files
Date: 18.09.2021

Poc : WordPress Themes Haberadam IDOR and Full Path Disclosure via JSON API
( Unathenticated )
Dork: inurl:/wp-content/themes/haberadam
Date: 13.09.2021

Poc : Ficus Global - Sql Injection Vulnerability


Dork: Designed & Maintained by Ficus Global
Date: 11.09.2021

Poc : Web Smile India - Sql Injection Vulnerability


Dork: intext:Maintained By Web Smile India
Date: 11.09.2021

Poc : Craftbox Technology - Sql Injection Vulnerability


Dork: intext:by Craftbox Technology
Date: 10.09.2021

Poc : Five design - Sql Injection Vulnerability


Dork: intext:Website designed and developed by Five design
Date: 10.09.2021

Poc : Powered by Ciws - Sql Injection Vulnerability


Dork: intext:Powered by Ciws
Date: 10.09.2021

Poc : Wordpress Plugin WP Super Edit 2.5.4 - Remote File Upload


Dork: inurl:wp-content/plugins/wp-super-edit/superedit/tinymce_plugins/mse/
fckeditor/editor/filemanager/upload/
Date: 09.09.2021

Poc : Digitalindya - Sql Injection Vulnerability


Dork: intext:Developed by Digitalindya
Date: 05.09.2021

Poc : Creators Touch- Sql Injection Vulnerability


Dork: intext:Designed by Creators Touch
Date: 05.09.2021

Poc : Pricelist Stock Bangladesh Ltd. Center For Financial Analysis | SQL Injection
Vulnerability
Dork: .php?id= stockbangladesh.mobi
Date: 05.09.2021

Poc : Sensitive Data Exposure AWS Access Key & Secret Key
Dork: intext:Copyright © Dennis Publishing Limited 2021. All rights reserved.
Date: 05.09.2021

Poc : Santo Domingo School (CSD) / Web Ratings | SQL Injection Vulnerability
Dork: .php?id= csd.atenas.tech
Date: 05.09.2021

Poc : Athens School / Atenas Familia / Atenas Tech / Bitnami LAMP | SQL Injection
Vulnerability
Dork: .php?id= prod.atenas.tech
Date: 05.09.2021

Poc : Imagino - Sql Injection Vulnerability


Dork: intext:Developed By Imagino
Date: 04.09.2021

Poc : ciclope - Sql Injection Vulnerability


Dork: intext:web by ciclope
Date: 01.09.2021

Poc : Fillip Technologies - Sql Injection Vulnerability


Dork: intext:Design & Maintained by Fillip Technologies
Date: 01.09.2021

Poc : Net Soft Lab - Sql Injection Vulnerability


Dork: intext:Website Designed & Developed By Net Soft Lab
Date: 30.08.2021

Poc : Baker Media - Sql Injection Vulnerability


Dork: intext:Website by Baker Media Ltd.
Date: 29.08.2021

Poc : Webmartindia - Sql Injection Vulnerability


Dork: intext:Powered by Webmartindia
Date: 29.08.2021

Poc : Design by ENTRACOM - Blind Sql Injection Vulnerability


Dork: intext:Design by ENTRACOM
Date: 29.08.2021

Poc : Chillipages - Sql Injection Vulnerability


Dork: intext:Site by Chillipages
Date: 21.08.2021

Poc : Webforio - Sql Injection Vulnerability


Dork: intext:Development Webforio
Date: 21.08.2021

Poc : Online Notice Board System 1.0 - Remote Command Execution (RCE) throw upload
file
Dork: intext:© 2020 ONBS
Date: 19.08.2021

Poc : Developed by Direct2Web Sql Injection Vulnerability


Dork: intext:Developed by Direct2Web
Date: 19.08.2021

Poc : Designed By Algacis Sql Injection Vulnerability


Dork: intext:Designed By Algacis
Date: 18.08.2021

Poc : Hermosoft Sql Injection Vulnerability


Dork: intext:Designed and developed by web design Dubai, Hermosoft.
Date: 17.08.2021

Poc : SAM Softech Sql Injection Vulnerability


Dork: intext:Developed By SAM Softech
Date: 17.08.2021

Poc : MobinNet Router- Remote Code Execution


Dork: In Shodan search engine, the filter is mobinnet country:ir
Date: 11.08.2021
Poc : Washington University College of Engineering SQL Injection Vulnerability
Dork: profile.php?id=
Date: 11.08.2021

Poc : Kurdistan High Elections and Referendum Commission SQL Injection


Vulnerability
Dork: inurl:about.aspx?type=
Date: 09.08.2021

Poc : PGR-Filemanager | Arbitrary File Upload


Dork: inurl:/plugins/pgrfilemanager/
Date: 06.08.2021

Poc : Testa Online Test Management System 3.4.5 - 'q' SQL Injection
Dork: intext:Powered by Testa 3.4.5
Date: 03.08.2021

Poc : Testa CMS 3.4.3 - 'q' SQL Injection


Dork: intext:Powered by Testa 3.4.3
Date: 03.08.2021

Poc : Relieve Marketing y Web Sql Injection Vulnerability


Dork: intext:Created by Obra soft
Date: 01.08.2021

Poc : TripSpark VEO Transportation SQL Injection


Dork: inhtml:Student Busing Information
Date: 28.07.2021

Poc : Better Proposals: Online Proposal Software | SQL Injection


Dork: .php?id= betterproposals.io
Date: 27.07.2021

Poc : Schoolsindia SQL Injection


Dork: intext:Powered by Schoolsindia
Date: 26.07.2021

Poc : hamayeshnegar CMS 10.0.5 - Authentication Bypass


Dork: intext:)10.0.5 ‫ همایش نگار (ویرایش‬: ‫طراحی و پیاده سازی شده توسط‬
Date: 24.07.2021

Poc : Design & Developed By Sial Web - Html Injection


Dork: intext:Design & Developed By Sial Web
Date: 23.07.2021

Poc : Microsoft SharePoint Server 2019 Remote Code Execution (2)


Dork: inurl:quicklinks.aspx
Date: 23.07.2021

Poc : Design & Developed By Nice Techno - Sqli


Dork: intext:Design & Developed By Nice Techno and inurl:?id=
Date: 22.07.2021

Poc : Bluetooth Low Energy (BLE) USB Dongle | SQL Injection


Dork: .php?id= bleuio
Date: 21.07.2021

Poc : Sputnik News Russian government has XSS vulnerabilities


Dork: intext:search/?query=
Date: 19.07.2021

Poc : Design and Development of Saba website - SQL Injection


Dork: intext: ‫طراحی و برنامه نویسی توسط شرکت صبا عصر دانش انجام شده است‬
Date: 17.07.2021

Poc : Testa Online - (V 3.4.6 ) SQL Injection


Dork: intext:Powered by Testa 3.4.6 : Online Test Management System
Date: 17.07.2021

Poc : Dailybread - Sql Injection Vulnerability


Dork: intext:Powered by Dailybread.in
Date: 16.07.2021

Poc : 3KITS - Sql Injection Vulnerability


Dork: intext:Designed & Developed By 3KITS
Date: 14.07.2021

Poc : Shell Technologies CMS - SQL Injection


Dork: intext:Developed by Shell Technologies inurl:.php?id=
Date: 14.07.2021

Poc : ariuswebstudio - Sql Injection Vulnerability


Dork: intext:site by: www.ariuswebstudio.com
Date: 11.07.2021

Poc : Real Estate 7 WordPress Theme < 3.1.1 - Unauthenticated Reflected XSS
Dork: inurl:/wp-content/themes/realestate-7/
Date: 05.07.2021

Poc : scleather - SQL Injection vulnerability


Dork: intext:Powered by scleather
Date: 03.07.2021

Poc : 7Graus - HTML Injection Vulnerability


Dork: intext:- 2021 © 7Graus
Date: 03.07.2021

Poc : Scratch Desktop 3.17 Code Execution / Cross Site Scripting


Dork: 'inurl:/projects/editor/?tutorial=getStarted -mit.edu' (not foolproof on
versioning)
Date: 02.07.2021

Poc : elFinder 2.0.47 - 'PHP connector' Command Injection


Dork: intitle:elFinder 2.0.x
Date: 02.07.2021

Poc : E-Survey Applications - SQL INJECTION


Dork: inurl:/penjelasan.php?id_kategorisend=2
Date: 30.06.2021

Poc : Powered by SDS Sql Injection Vulnerability


Dork: intext:Powered by SDS
Date: 29.06.2021

Poc : Webbdesign: SL-Studio - Local File Inclusion


Dork: intext:Webbdesign: SL-Studio
Date: 27.06.2021
Poc : Adobe ColdFusion 8 Remote Command Execution
Dork: intext:adobe coldfusion 8
Date: 25.06.2021

Poc : Website Design by Site by Tobstar® SQL Injection


Dork: inurl:?.php?id=com
Date: 21.06.2021

Poc : .:: E-CUTI ::. Application - SQL Bypass Authentication


Dork: intitle: .:: E-CUTI ::.
Date: 17.06.2021

Poc : Powered by Explore Bahrain Sql Injection Vulnerability


Dork: intext:Powered by Explore Bahrain
Date: 17.06.2021

Poc : Developed by Calura.com Sql Injection Vulnerability


Dork: intext:Developed by Calura.com
Date: 17.06.2021

Poc : cacpa Sql Injection Vulnerability


Dork: intext:Designed by cacpa
Date: 15.06.2021

Poc : webcreations Sql Injection Vulnerability


Dork: intext:Designed & Hosted by webcreations
Date: 11.06.2021

Poc : Solar-Log 500 2.8.2 Incorrect Access Control


Dork: In Shodan search engine, the filter is Server: IPC@CHIP
Date: 11.06.2021

Poc : Solar-Log 500 2.8.2 Password Disclosure


Dork: In Shodan search engine, the filter is Server: IPC@CHIP
Date: 11.06.2021

Poc : Ekattor Student Assignment php script-Stored XSS


Dork: intext: By Creativeitem
Date: 09.06.2021

Poc : Wordpress Plugin wpDiscuz 7.0.4 - Arbitrary File Upload (Unauthenticated)


Dork: inurl:/wp-content/plugins/wpdiscuz/
Date: 07.06.2021

Poc : Powered By SelongWeb.com - SQL INJECTION


Dork: inurl:/statis- SelongWeb.Com
Date: 06.06.2021

Poc : Synotec Holdings Sql Injection Vulnerability


Dork: intext:Website By : Synotec Holdings (Pvt.) Ltd.
Date: 02.06.2021

Poc : Designed by 360degreeinfo Sql Injection Vulnerability


Dork: intext:Designed by 360degreeinfo
Date: 23.05.2021

Poc : SiteLab Belediye V6 No-Redirect


Dork: inurl:/sayfa/baskanin-ozgecmisi.html
Date: 20.05.2021

Poc : Listeo WordPress Theme <= 1.6.10 - Multiple Authenticated IDOR


Vulnerabilities
Dork: inurl:/wp-content/themes/listeo/
Date: 17.05.2021

Poc : GiveWP WordPress Plugin <= 2.10.3 - Authenticated Persistent XSS


Dork: inurl:/wp-content/plugins/give/
Date: 17.05.2021

Poc : Bello WordPress Theme <= 1.5.9 - Authenticated XFS


Dork: inurl:/wp-content/themes/bello/
Date: 17.05.2021

Poc : Bello WordPress Theme <= 1.5.9 - Unauthenticated Blind SQL Injection
Dork: inurl:/wp-content/themes/bello/
Date: 17.05.2021

Poc : GA Google Analytics WordPress Plugin <= 20210211 - Multiple Authenticated


Persistent XSS
Dork: inurl:/wp-content/plugins/ga-google-analytics/
Date: 17.05.2021

Poc : Goto WordPress Theme 2.0 - Unauthenticated Blind SQL Injection


Dork: inurl:/wp-content/themes/goto/
Date: 17.05.2021

Poc : Mediumish WordPress Theme <= 1.0.47 - Unauthenticated Reflected XSS & XFS
Dork: inurl:/wp-content/themes/mediumish/
Date: 17.05.2021

Poc : Listeo WordPress Theme <= 1.6.10 - Multiple XSS & XFS vulnerabilities
Dork: inurl:/wp-content/themes/listeo/
Date: 17.05.2021

Poc : Bello WordPress Theme <= 1.5.9 - Unauthenticated Reflected XSS & XFS
Dork: inurl:/wp-content/themes/bello/
Date: 17.05.2021

Poc : WP-DB-Backup WordPress Plugin <= 2.3.3 - Authenticated Persistent XSS


Dork: inurl:/wp-content/plugins/wp-db-backup/
Date: 17.05.2021

Poc : Chevereto 3.17.1 Cross Site Scripting


Dork: intext:powered by chevereto
Date: 13.05.2021

Poc : ENERGY CORPORATION Sql Injection Vulnerability


Dork: intext:Powered By ENERGY CORPORATION
Date: 10.05.2021

Poc : OpenNetAdmin 8.5.14 <= 18.1.1 - Remote Command Execution


Dork: inurl:/ona/
Date: 07.05.2021

Poc : Ghostcat Vulnerability Remote Code Execution


Dork: python3 ajpshooter.py IP:ApachePort AjpPort /file/location read/eval
Date: 05.05.2021
Poc : ILDIS v2 Applications Multiple Vulnerabilities
Dork: intitle:Signin | ILDIS JDIHN
Date: 04.05.2021

Poc : Technical Assistance explore IT Sql Injection Vulnerability


Dork: intext:Technical Assistance explore IT
Date: 03.05.2021

Poc : Dulux - Html Injection Vulnerability


Dork: inurl : dulux site:.
Date: 28.04.2021

Poc : Irandesign.ir CMS SQL Injection


Dork: intext:‫طراحی سایت توسط ایران دیزاین‬
Date: 20.04.2021

Poc : SoftNick India - SQL Injection vulnerability


Dork: intext:Developed By SoftNick India
Date: 20.04.2021

Poc : VASYL STEFANYK UNIVERSITY | SQL Injection Vulnerability


Dork: read.php?id=
Date: 18.04.2021

Poc : Greek Shopping Web Site SQL Injection Vulnerability


Dork: productview.php?id=
Date: 16.04.2021

Poc : CITSmart ITSM 9.1.2.27 SQL Injection


Dork: intext:citsmart.local
Date: 15.04.2021

Poc : CITSmart ITSM 9.1.2.22 LDAP Injection


Dork: intext:citsmart.local
Date: 15.04.2021

Poc : USA Cansas City SQL Injection Vulnerability


Dork: news.php?id=
Date: 15.04.2021

Poc : Smtmax SQL Injection Vulnerability


Dork: category.php?id=
Date: 15.04.2021

Poc : Sanah Infosolutions - SQL Injection vulnerability


Dork: intext:Designed by : Sanah Infosolutions
Date: 15.04.2021

Poc : Delhi Jain School SQL Injection Vulnerability


Dork: gallery.php?id=
Date: 13.04.2021

Poc : Brazil Floriano Municipality Blind SQL Injection


Dork: galeria.php?id=
Date: 11.04.2021

Poc : mmcct | SQL injection Vulnerability


Dork: inurl:members.php?lang=en
Date: 10.04.2021

Poc : Custom CMS Okezone - Cross-Site Scripting Vulnerabilities


Dork: site:*.okezone.com/rc.php?id=
Date: 09.04.2021

Poc : Web Design by Island Webservices (SQL) Injection


Dork: intext:/Web design by Island Webservices
Date: 04.04.2021

Poc : indiawebsoft Admin Login ByPass


Dork: intext:/designed and developed by indiawebsoft
Date: 03.04.2021

Poc : Realteo WordPress Plugin <= 1.2.3 - Improper Access Control


Dork: inurl:/wp-content/plugins/realteo/
Date: 02.04.2021

Poc : Realteo WordPress Plugin <= 1.2.3 - Unauthenticated Reflected XSS


Dork: inurl:/wp-content/plugins/realteo/
Date: 02.04.2021

Poc : Web Tasarım - www.bursaproje.com (XSS) Vulnerability


Dork: intext:/Web Tasarım - www.bursaproje.com
Date: 02.04.2021

Poc : Web Tasarım - www.bursaproje.com (SQL) Injection


Dork: intext:/Web Tasarım - www.bursaproje.com
Date: 01.04.2021

Poc : Goto WordPress Theme <= 1.9 - Unauthenticated Reflected XSS


Dork: inurl:/wp-content/themes/goto/
Date: 01.04.2021

Poc : Obra soft Sql Injection Vulnerability


Dork: intext:Created by Obra soft
Date: 27.03.2021

Poc : Moodle Atto Editor Cross Site Scripting


Dork: inurl:/lib/editor/atto/plugins/managefiles/ or calendar/view.php?view=month
Date: 26.03.2021

Poc : Moodle 3.10.3 Calendar Cross Site Scripting


Dork: inurl:/lib/editor/atto/plugins/managefiles/ or calendar/view.php?view=month
Date: 26.03.2021

Poc : Copyrights Samad Elmakchi - Admin Login Bypass


Dork: intext:Copyrights Samad Elmakchi
Date: 23.03.2021

Poc : Controlled Admin Access WordPress Plugin <= 1.4.0 - Improper Access
Control & Privilege Escalation
Dork: inurl:/wp-content/plugins/controlled-admin-access/
Date: 23.03.2021

Poc : Chillipages Technologies - Blind Sql Injection


Dork: intext:Site by | Chillipages Technologies
Date: 16.11.2023
Poc : Plesk Obsidian 18.0.56 command injecrion
Dork: intitle:Plesk Obsidian 18.0.56
Date: 12.11.2023

Poc : Virtual Pages - Sql Injection


Dork: intext:Site by : Virtual Pages
Date: 08.11.2023

Poc : Webnink - sql injection Vulnerability


Dork: intext:Powered by Webnink inurl:.php?Id=
Date: 08.11.2023

Poc : Turning Point - Sql Injection


Dork: intext:Website designed by: Turning Point
Date: 05.11.2023

Poc : Designed by EMH - Blind Sql Injection


Dork: intext:Conception & Réalisation MGSD
Date: 02.11.2023

Poc : Designed by EMH - Cross site scripting


Dork: intext:Designed by EMH
Date: 02.11.2023

Poc : Aadija Technologies - Blind Sql Injection


Dork: intext:Design & Developed by : Aadija Technologies
Date: 02.11.2023

Poc : Aadija Technologies - Xpath Injection Vulnerability


Dork: intext:Design & Developed by : Aadija Technologies
Date: 02.11.2023

Poc : Urvanov Syntax Highlighter <= 2.8.33 - Highlighting Blocks Mgt via CSRF
Dork: site:adroom.ir inurl:/wp-admin/admin-ajax.php
Date: 31.10.2023

Poc : PixelPro Designs - Sql Injection


Dork: intext:Developed By - PixelPro Designs
Date: 31.10.2023

Poc : CMS united - Sql Injection


Dork: intext:Powered by CMS united
Date: 27.10.2023

Poc : Urvanov Syntax Highlighter <= 2.8.33 - Highlighting Blocks Mgt via CSRF
Dork: wp-admin/admin-ajax.php
Date: 27.10.2023

Poc : WordPress Masterstudy LMS 3.0.17 Account Creation


Dork: inurl:/user-public-account
Date: 10.10.2023

Poc : Synotec Holdings - Sql Injection


Dork: intext:Website By: Synotec Holdings (Pvt) Ltd
Date: 01.10.2023

Poc : Edunext Technologies - Sql Injection Vulnerability


Dork: intext:Powered by Edunext Technologies
Date: 01.10.2023
Poc : SFTP/FTP Password Exposure via sftp-config.json
Dork: inurl:/.vscode/sftp-config.json
Date: 20.09.2023

Poc : Super Store Finder 3.7 Remote Command Execution


Dork: intext:designed and built by Joe Iz.
Date: 20.09.2023

Poc : Conception & Réalisation MGSD - Blind Sql Injection Vulnerability


Dork: intext:Conception & Réalisation MGSD
Date: 18.09.2023

Poc : SNDK Technologies - Blind Sql Injection


Dork: intext:Designed by SNDK Technologies Pvt. Ltd.
Date: 18.09.2023

Poc : CMS united - Blind Sql Injection


Dork: intext:Powered by CMS united
Date: 18.09.2023

Poc : Astonished Man Design - Sql Injection Vulnerability


Dork: intext:website by Astonished Man Design
Date: 15.09.2023

Poc : Designed by brandsncodes - Sql Injection Vulnerability


Dork: intext:Designed by brandsncodes
Date: 15.09.2023

Poc : Conception & Réalisation MGSD - Blind Sql Injection Vulnerability


Dork: intext:Conception & Réalisation MGSD
Date: 15.09.2023

Poc : Inforef - Sql Injection Vulnerability


Dork: intext:site web - Inforef
Date: 13.09.2023

Poc : AlgoWid Technologies - Blind Sql Injection Vulnerability


Dork: intext:Powered by AlgoWid Technologies
Date: 13.09.2023

Poc : ITAcumens - Sql Injection Vulnerability


Dork: intext:Powered by ITAcumens
Date: 13.09.2023

Poc : Conception & Réalisation MGSD - Sql Injection


Dork: intext:Conception & Réalisation MGSD
Date: 13.09.2023

Poc : Axigen 10.5.0–4370c946 Cross Site Scripting


Dork: inurl:passwordexpired=yes
Date: 09.09.2023

Poc : Axigen 10.5.0–4370c946 Cross Site Scripting


Dork: inurl:passwordexpired=yes
Date: 09.09.2023

Poc : Soloweb - Sql Injection Vulnerability


Dork: intext:This design is created by Soloweb
Date: 04.09.2023

Poc : design by Diamondwebs - Sql Injection Vulnerability


Dork: intext:Website design by Diamondwebs
Date: 04.09.2023

Poc : AlgoWid Technologies - Sql Injection Vulnerability


Dork: intext:Powered by AlgoWid Technologies
Date: 04.09.2023

Poc : No Sheep Designs - Sql Injection Vulnerability


Dork: intext:Developed by No Sheep Designs
Date: 04.09.2023

Poc : FORMA Design Bureau - Sql Injection Vulnerability


Dork: intext:Design and Development by FORMA Design Bureau
Date: 19.08.2023

Poc : Hilano website design - Cross-Site Scripting (XSS)


Dork: intext:‫طراحی سایت هیالنو‬
Date: 12.08.2023

Poc : Asset Software Solutions - Sql Injection Vulnerability


Dork: intext:Powered by Asset Software Solutions
Date: 12.08.2023

Poc : SNDK Technologies - Sql Injection Vulnerability


Dork: intext:Designed by SNDK Technologies Pvt. Ltd.
Date: 12.08.2023

Poc : Cyberxel - Bypass Admin Panel


Dork: intext:Design n Care :Cyberxel
Date: 12.08.2023

Poc : WordPress Ninja Forms 3.6.25 Cross Site Scripting


Dork: inurl:/wp-content/plugins/ninja-forms/readme.txt
Date: 08.08.2023

Poc : Joomla! com_booking component 2.4.9 Information Leak (Account enumeration)


Dork: inurl:index.php?option=com_booking
Date: 01.08.2023

Poc : Polaris Web 1.21.1 - Reflected XSS


Dork: Siap+Micros S.p.A
Date: 27.07.2023

Poc : mooDating 1.2 - Reflected XSS


Dork: Copyright © 2023 mooDating
Date: 26.07.2023

Poc : Cyberxel - Bypass Admin Panel


Dork: intext:Design n Care :Cyberxel
Date: 23.07.2023

Poc : ErenSoft SQL Injection


Dork: intext:Kodlama: Erensoft
Date: 23.07.2023

Poc : ErenSoft SQL Injection


Dork: intext:Kodlama: Erensoft
Date: 23.07.2023

Poc : Wifi Soft Unibox Administration 3.0 / 3.1 SQL Injection


Dork: intext:Unibox Administration 3.1, intext:Unibox 3.0
Date: 21.07.2023

Poc : Sales of Cashier Goods v1.0 Cross Site Scripting (XSS)


Dork: /print.php?nm_member=
Date: 06.07.2023

Poc : TP-Link TL-WR940N 4 Buffer Overflow


Dork: /userRpm/WanDynamicIpV6CfgRpm
Date: 05.07.2023

Poc : Super Socializer 7.13.52 Reflected XSS


Dork: inurl: https://example.com/wp-admin/admin-ajax.php?
action=the_champ_sharing_count&urls[
3Cimg
20src
3Dx
20onerror
3Dalert
28document
2Edomain
29
3E]=https://www.google.com
Date: 03.07.2023

Poc : ToprakAJans Admin NoRedirect Bypass


Dork: intext:@ToprakAjans
Date: 26.06.2023

Poc : HiSecOS 04.0.01 Privilege Escalation


Dork: HiSecOS Web Server Vulnerability Allows User Role Privilege Escalation
Date: 22.06.2023

Poc : WordPress WP Sticky Social 1.0.1 CSRF / Cross Site Scripting


Dork: inurl:~/admin/views/admin.php
Date: 22.06.2023

Poc : WordPress Theme Medic v1.0.0 Weak Password Recovery Mechanism for Forgotten
Password
Dork: inurl:/wp-includes/class-wp-query.php
Date: 19.06.2023

Poc : BlogMagz 1.0 - Stored XSS


Dork: Copyright © 2023 BlogMagz All Rights Reserved.
Date: 18.06.2023

Poc : Camelon CMS 2.7.4 Stored XSS in Post Title


Dork: intext:Camaleon CMS is a free and open-source tool and a fexible content
management system (CMS) based on Ruby on Rails
Date: 15.06.2023

Poc : WordPress Workreap 2.2.2 Shell Upload


Dork: inurl:/wp-content/themes/workreap/
Date: 13.06.2023
Poc : WordPress Theme Workreap 2.2.2 Unauthenticated Upload Leading to Remote Code
Execution
Dork: inurl:/wp-content/themes/workreap/
Date: 10.06.2023

Poc : JetSınav SQL Injection + Default Password Vulnerability


Dork: allintext:Powered by Jetsınav
Date: 28.05.2023

Poc : SCM Manager 1.60 Cross Site Scripting


Dork: intitle:SCM Manager intext:1.60
Date: 28.05.2023

Poc : Siemens SIMATIC S7-1200 Cross Site Request Forgery


Dork: inurl:/Portal/Portal.mwsl
Date: 21.05.2023

Poc : Sophos Web Appliance 4.3.10.4 Pre-auth command injection


Dork: title:Sophos Web Appliance
Date: 25.04.2023

Poc : Bluesoft Infotech - Sql Injection Vulnerability


Dork: intext:Designed by Bluesoft Infotech
Date: 23.04.2023

Poc : Instagram Brute Force Attack Using Python


Dork: site:instagram.com inurl:login
Date: 15.04.2023

Poc : Altenergy Power Control Software C1.2.5 OS command injection


Dork: intitle:Altenergy Power Control Software
Date: 14.04.2023

Poc : Leaders Group - Sql Injection Vulnerability


Dork: intext:By: Leaders Group
Date: 11.04.2023

Poc : Site by Jundweb - Sql Injection Vulnerability


Dork: intext:Site by Jundweb
Date: 11.04.2023

Poc : pfsenseCE 2.6.0 Protection Bypass


Dork: intitle:pfSense - Login
Date: 10.04.2023

Poc : Goanywhere Encryption Helper 7.1.1 Remote Code Execution


Dork: title:GoAnywhere
Date: 10.04.2023

Poc : Paradox Security Systems IPR512 Denial Of Service


Dork: intitle:ipr512 * - login screen
Date: 10.04.2023

Poc : Bludit 3-14-1 Shell Upload


Dork: intext:'2022 Powered by Bludit'
Date: 02.04.2023

Poc : LISTSERV 17 Reflected Cross Site Scripting (XSS)


Dork: inurl:/scripts/wa.exe
Date: 02.04.2023

Poc : WordPress Real Estate 7 Theme <= 3.3.4 - Abuse of Functionality


Dork: inurl:/wp-content/themes/realestate-7/
Date: 09.03.2023

Poc : WordPress WoodMart Theme <= 7.1.0 - Unauthenticated Arbitrary Shortcodes


Injection
Dork: inurl:/wp-content/themes/woodmart/
Date: 08.03.2023

Poc : WordPress Real Estate 7 Theme <= 3.3.4 - Multiple Cross-Site Request
Forgery (CSRF) Vulnerabilities
Dork: inurl:/wp-content/themes/realestate-7/
Date: 05.03.2023

Poc : WordPress Real Estate 7 Theme <= 3.3.4 - Unauthenticated Reflected Cross-
Site Scripting (XSS)
Dork: inurl:/wp-content/themes/realestate-7/
Date: 05.03.2023

Poc : WordPress WoodMart Theme <= 7.1.1 - Theme License Options Change via CSRF
Dork: inurl:/wp-content/themes/woodmart/
Date: 05.03.2023

Poc : WordPress Real Estate 7 Theme 3.3.4 Cross Site Scripting


Dork: inurl:/wp-content/themes/realestate-7/
Date: 01.03.2023

Poc : WordPress WoodMart Theme 7.1.1 Cross Site Request Forgery


Dork: inurl:/wp-content/themes/woodmart/
Date: 01.03.2023

Poc : Best POS Management System 1.0 Cross Site Scripting


Dork: NA
Date: 17.02.2023

Poc : Developed by Ameya Computers LOGIN SQL INJECTİON


Dork: intext:Developed by : Ameya Computers inurl:login.php
Date: 14.02.2023

Poc : Powered By dokumenary.net Remote Code Execution


Dork: intext:dokumenary.net All rights reserved.
Date: 30.01.2023

Poc : Website by MSBu.de - Sql Injection Vulnerability


Dork: intext:Website by MSBu.de
Date: 23.01.2023

Poc : Stealth Media Ltd - Sql Injection Vulnerability


Dork: intext:Website Designed & Developed By Stealth Media Ltd.
Date: 09.01.2023

Poc : SDM-Downloads 9.3.15 Privilege Escalation Arbritrary File Upload


Dork: inurl:/sdm-downloads/
Date: 06.01.2023

Poc : Wordpress Dsp Dating Csrf FIle Upload


Dork: inurl:wp-content/plugins/dsp_dating
Date: 06.01.2023

Poc : Textpattern 4.8.8 - Remote Code Execution (RCE) (Authenticated)


Dork: intext:Published with Textpattern CMS
Date: 20.12.2022

Poc : Remote Code Execution in SimpleMachinesForum 2.1.1


Dork: SimpleMachinesForum Exploit
Date: 18.11.2022

Poc : Remote Code Execution in MODX Revolution V2.8.3-pl


Dork: MODX Exploit
Date: 15.11.2022

Poc : Remote Code Execution in Abantecart-1.3.2


Dork: Abantecart exploit
Date: 13.11.2022

Poc : Khameneie.ir XSS vulnerabilities


Dork: site:farsi.khamenei.ir/search-result?q=
Date: 23.10.2022

Poc : developway SQL Injection


Dork: intext:Powered By DevelopWay
Date: 23.10.2022

Poc : Wordpress Plugin ImageMagick-Engine 1.7.4 Remote Code Execution (RCE)


(Authenticated)
Dork: inurl:/wp-content/plugins/imagemagick-engine/
Date: 18.10.2022

Poc : blesta 5.4.1 Backdoor Account Vulnerability


Dork: Powered by Blesta, © Phillips Data, Inc.
Date: 13.10.2022

Poc : Authenticated Sql Injection in ImpressCMS v1.4.3


Dork: ImpressCMS Exploit
Date: 12.10.2022

Poc : WordPress WP-UserOnline 2.88.0 Cross Site Scripting


Dork: inurl:/wp-content/plugins/wp-useronline/
Date: 25.09.2022

Poc : VIAVIWEB Wallpaper Admin SQL Injection / Shell Upload


Dork: intext:Wallpaper Admin LOGIN password Username
Date: 22.09.2022

Poc : Genesys PureConnect - Interaction Web Tools XSS


Dork: inurl:/I3Root/chatOrCallback.html
Date: 15.09.2022

Poc : Equitysoft Technologies Pvt Ltd - SQL Injection Vulnerability


Dork: intext:Equitysoft Technologies Pvt Ltd
Date: 13.09.2022

Poc : kansascitynova - Sql Injection Vulnerability


Dork: intext:Designed by kansascitynova
Date: 13.09.2022
Poc : cr-led - Cross Site Scripting Vulnerability (XSS)
Dork: news.php?id=
Date: 31.08.2022

Poc : daihocpccc - Cross Site Scripting Vulnerability (XSS)


Dork: inurl:index.php?id=
Date: 28.08.2022

Poc : Yashwant solutions - Sql Injection Vulnerability


Dork: intext:Designed by Designed by Yashwant solutions
Date: 24.08.2022

Poc : Foodiee 1.0.1 unauthorized administrative access Vulnerability


Dork: intext:restaurants_details.php?id=
Date: 20.08.2022

Poc : Active PHP Bookmarks v1.3 - Sql Injection Vulnerability


Dork: intext:Active PHP Bookmarks v1.3
Date: 06.08.2022

Poc : Picaporte Design - Sql Injection Vulnerability


Dork: intext:Developed By Newgen Technologies
Date: 06.08.2022

Poc : Powered by Compusys e Solutions - Sql Injection Vulnerability


Dork: intext:Powered by Compusys e Solutions
Date: 02.08.2022

Poc : Newgen Technologies - Sql Injection Vulnerability


Dork: intext:Developed By Newgen Technologies
Date: 02.08.2022

Poc : Kaivalya Techno Soft Pvt - Sql Injection Vulnerability


Dork: intext:Developed By - Kaivalya Techno Soft Pvt. Ltd.
Date: 01.08.2022

Poc : Try Catch Technologies - Sql Injection Vulnerability


Dork: intext:Designed By Try Catch Technologies
Date: 01.08.2022

Poc : Web Design By East Technologies - SQL Injection Vulnerability


Dork: intext:Web Design By East Technologies
Date: 29.07.2022

Poc : Active eCommerce Laravel CMS 5.x to 6.1.2 - Cross Site request forgery (CSRF)
to Cross-site Scripting (XSS) (Authenticated)
Dork: intext:|| WHOPPS!!!THIS IS PIRATED COPY OF ACTIVE ECOMMERCE CMS
Date: 20.07.2022

Poc : Designed With by HOME SALON - SQL Injection Vulnerability


Dork: intext:Designed With by HOME SALON
Date: 17.07.2022

Poc : Websyte mit vor webSchmitte.ch - Sql Injection Vulnerability


Dork: intext:Websyte mit vor webSchmitte.ch
Date: 17.07.2022

Poc : dhamdhama anchalik college - Sql Injection Vulnerability


Dork: intext:Designed & Developed By Hirak
Date: 17.07.2022

Poc : Yahweh Touch - Sql Injection Vulnerability


Dork: intext:Developed by Yahweh Touch
Date: 17.07.2022

Poc : Developed by: web3creations.com - Sql Injection Vulnerability


Dork: intext:Developed by: web3creations.com
Date: 16.07.2022

Poc : Designed by VITECH IT Solutions - Sql Injection Vulnerability


Dork: intext:Developed & Designed by VITECH IT Solutions
Date: 15.07.2022

Poc : Developed By : SOFTMAART - Sql Injection Vulnerability


Dork: intext:Developed By : SOFTMAART
Date: 15.07.2022

Poc : Akaal WebSoft Pvt - Sql Injection Vulnerability


Dork: intext:Designed By : Akaal WebSoft Pvt. Ltd
Date: 15.07.2022

Poc : phpAnalyzer v2.0.4 Backdoor Account Vulnerability


Dork: intext:Copyright © phpAnalyzer.com. All rights reserved. Product by AltumCode
Date: 13.07.2022

Poc : MktbaGold 6.4 Arbitrary File Upload


Dork: Powered by: MktbaGold 6.4
Date: 13.07.2022

Poc : Plumcloud Image Browser File Upload


Dork: intext:©2014 PlumCloud. All Rights Reserved.
Date: 12.07.2022

Poc : Exploit mktba 4.2 Arbitrary File Upload


Dork: Powered by: mktba
Date: 10.07.2022

Poc : Openbiz Cubi 3.0.8 Xss/Html inject Upload Vulnerability


Dork: intext: System Login - Cubi Platform
Date: 08.07.2022

Poc : Advanced Testimonials Manager v5.5 Reinstall Add Admin Vulnerability


Dork: Advanced Testimonial Manager
Date: 06.07.2022

Poc : Designed By Sevy INC. - SQL Injection Vulnerability, Unrestricted File Upload
Vulnerability and Default Admin Credentials
Dork: intext:Designed By Sevy INC.
Date: 06.07.2022

Poc : SEO Nethizmet Admin NoRedirect Bypass


Dork: intext:inurl /yonetici/yonetici-giris.php
Date: 05.07.2022

Poc : OPSTECH Thailand Gov Management System Multiple Vulnerabilities


Dork: 1. intext:Copyright © by OPSTECH All Right Reserved site:go.th
Date: 04.07.2022
Poc : SEO Nethizmet Admin NoRedirect Bypass
Dork: intext:intext:Web Tasarım Seo Nethizmet
Date: 28.06.2022

Poc : Mailhog 1.0.1 Stored Cross-Site Scripting (XSS)


Dork: https://www.shodan.io/search?query=mailhog ( > 3500)
Date: 28.06.2022

Poc : BLUEWATER MARIBAGO BEACH RESORT - SQL Injection Vulnerability


Dork: intext:BLUEWATER MARIBAGO BEACH RESORT inurl:/index.php?page=
Date: 22.06.2022

Poc : WEB SITE Yas Arghavani System XSS


Dork: -
Date: 11.06.2022

Poc : H3k / tiny File Manager


Dork: intitle:h3k File Manager
Date: 05.06.2022

Poc : Contao 4.13.2 Cross Site Scripting


Dork: NA
Date: 04.06.2022

Poc : Zyxel USG FLEX 5.21 Command Injection


Dork: title:USG FLEX 100 title:USG FLEX 100W title:USG FLEX 200 title:USG FLEX 500
title:USG FLEX 700 title:USG20-VPN title:USG20W-VPN title:ATP 100 title:ATP 200
title:ATP 500 title:ATP 700 title:ATP 800
Date: 04.06.2022

Poc : qdPM 9.1 Remote Code Execution (RCE) (Authenticated) (v2)


Dork: intitle:qdPM 9.1. Copyright © 2020 qdpm.net
Date: 29.05.2022

Poc : Will VPN App - VPN App With Admin Panel - Phpthumb Command Injection
Dork: - / use your brain
Date: 19.05.2022

Poc : Designed by OG Advertising - Sql Injection Vulnerability


Dork: intext:Designed by OG Advertising
Date: 14.05.2022

Poc : Ruijie Reyee Mesh Router Remote Code Execution


Dork: None
Date: 11.05.2022

Poc : Infreshop - Cross-Site Scripting Vulnerability


Dork: intext:Powered by Infreshop
Date: 10.05.2022

Poc : Zimbra - Request URL Override Vulnerability


Dork: inurl:/public/launchSidebar.jsp
Date: 09.05.2022

Poc : Stisla - Open Redirect Vulnerability


Dork: intitle:Login — Stisla
Date: 09.05.2022

Poc : Strapi 3.6.8 Password Disclosure / Insecure Handling


Dork: intitle:Welcome to your Strapi ap
Date: 03.05.2022

Poc : Infreshop - Sql Injection Vulnerability


Dork: intext:Powered by Infreshop
Date: 01.05.2022

Poc : SayItOnTheWeb - Sql Injection Vulnerability


Dork: intext:Website By: SayItOnTheWeb, Inc.
Date: 01.05.2022

Poc : WordPress Videos Sync PDF 1.7.4 Cross Site Scripting


Dork: inurl:/wp-content/plugins/video-synchro-pdf/
Date: 24.04.2022

Poc : USR IOT 4G LTE Industrial Cellular VPN Router 1.0.36 Remote Root Backdoor
Dork: title:usr-* // 4,648 ed ao 15042022
Date: 22.04.2022

Poc : jsharp Technology - Sql Injection Vulnerability


Dork: intext:Developed by jsharp Technology
Date: 15.04.2022

Poc : Signature Software - Sql Injection Vulnerability


Dork: intext:Website by Signature Software
Date: 15.04.2022

Poc : Miracle Hunt Services - Sql Injection Vulnerability


Dork: intext:Managed By Miracle Hunt Services
Date: 15.04.2022

Poc : WordPress Video-Synchro-PDF 1.7.4 Local File Inclusion


Dork: inurl:/wp-content/plugins/video-synchro-pdf/
Date: 01.04.2022

Poc : Iolite Softwares - Sql Injection Vulnerability


Dork: intext:Designed by Iolite Softwares Pvt. Ltd.
Date: 29.03.2022

Poc : INTERSOFT CMS Login Bypass


Dork: intext:Web & Hosting / INTERSOFT ®
Date: 26.03.2022

Poc : Developed By Yasha Zamanpour - Sql Injection Vulnerability


Dork: intext:Designed & Developed By Yasha Zamanpour
Date: 26.03.2022

Poc : KYB Asian Pacific Corporation - SQL Injection Vulnerability


Dork: intext:KYB Asian Pacific Corporation
Date: 24.03.2022

Poc : WordPress Amministrazione Aperta 3.7.3 Arbitrary File Read


Dork: inurl:/wp-content/plugins/amministrazione-aperta/
Date: 24.03.2022

Poc : iRZ Mobile Router Cross Site Request Forgery / Remote Code Execution
Dork: intitle:iRZ Mobile Router
Date: 22.03.2022
Poc : Copyright 2021 Reobiz. All Rights Reserved. - SQL Injection Vulnerability
Dork: intext:© Copyright 2021 Reobiz. All Rights Reserved.
Date: 21.03.2022

Poc : Design: linkealia.com - Sql Injection Vulnerability


Dork: intext:Design: linkealia.com
Date: 17.03.2022

Poc : Montenegro Shipping Lines, Inc. - SQL Injection Vulnerability


Dork: intext:Designed by Rushtek Enterprise
Date: 14.03.2022

Poc : DEOS AG OPEN 710/810 Cross Site Scripting


Dork: app:DEOS AG OPEN EMS System ics device httpd
Date: 10.03.2022

Poc : Vietnext - Sql Injection Vulnerability


Dork: intext:Designed by Vietnext
Date: 10.03.2022

Poc : Bordaline Web Design - Sql Injection Vulnerability


Dork: intext:Website by Bordaline Web Design
Date: 06.03.2022

Poc : Behkad CMS - Technical And Vocational University Yazd / Iran - Cross-Site
Scripting (XSS)
Dork: -
Date: 06.03.2022

Poc : DCD-ARQAC - Sql Injection Vulnerability


Dork: intext:Designed And Developed by Digital Content Development DCD-ARQAC, JSPM-
TSSM
Date: 05.03.2022

Poc : Z Web Solutions - Sql Injection Vulnerability


Dork: intext:Powered by Z Web Solutions.
Date: 05.03.2022

Poc : Logical Triangle Ltd - Sql Injection Vulnerability


Dork: intext:Development by: Logical Triangle Ltd.
Date: 03.03.2022

Poc : Eticaret Turkey CMS Kcfinder & Roxy File Manager Exploit
Dork: inurl:/nedmin/production/ (dorking on google images)
Date: 01.03.2022

Poc : Support Board 3.4.5 WP and NonWP Arbitrary File Upload / CSRF File Upload
Dork: use your brain brother
Date: 01.03.2022

Poc : Virtual Design - Sql Injection Vulnerability


Dork: intext:Design by Virtual Design
Date: 28.02.2022

Poc : Responsive file manager for russian website


Dork: inurl:/modules/tinymce/source/ site:ru
Date: 28.02.2022

Poc : Futronic Technology Company Limited. - Sql Injection Vulnerability


Dork: intext:Futronic Technology Company Limited.
Date: 26.02.2022

Poc : Tesquito. - Bypass Admin Panel


Dork: intext:© 2022 Copyright tesquito. All Rights reserved.
Date: 26.02.2022

Poc : WordPress dzs-zoomsounds 6.60 Shell Upload


Dork: inurl:wp-content/plugins/dzs-zoomsounds
Date: 23.02.2022

Poc : Themefisher - Sql Injection Vulnerability


Dork: intext:Designed & Developed by Themefisher
Date: 23.02.2022

Poc : Inbounderz - Sql Injection Vulnerability


Dork: intext:Design By Inbounderz
Date: 22.02.2022

Poc : Antik Infotech - Sql Injection Vulnerability


Dork: intext:Created & Cared By Antik Infotech
Date: 22.02.2022

Poc : Agirhnet 1.0 Cross Site Scripting


Dork: inurl:agirhnet
Date: 22.02.2022

Poc : Powered by Kinza Group (Pvt) Ltd. - Sql Injection Vulnerability


Dork: intext:Powered by Kinza Group (Pvt) Ltd.
Date: 20.02.2022

Poc : MARKS DESIGN - Sql Injection Vulnerability


Dork: intext:Designed by MARKS DESIGN
Date: 13.01.2022

Poc : EDSA Designs - Sql Injection Vulnerability


Dork: intext:website by EDSA Designs
Date: 13.01.2022

Poc : Agile Web Solutions - Sql Injection Vulnerability


Dork: intext:Developed By Agile Web Solutions
Date: 12.01.2022

Poc : Arva Web Developer - Blind Sql Injection Vulnerability


Dork: intext:Designed & Developed by : Arva Web Developer
Date: 11.01.2022

Poc : sixdaysworks - Sql Injection Vulnerability


Dork: intext:Website design and hosting by sixdaysworks
Date: 09.01.2022

Poc : Moor Hunt Services SQL Injection


Dork: intext:Powered by : Moor Hunt Services
Date: 07.01.2022

Poc : NEETAI TECH - Sql Injection Vulnerability


Dork: intext:Designed By NEETAI TECH
Date: 06.01.2022
Poc : PixelPro Designs - Sql Injection Vulnerability
Dork: intext:Designed By - PixelPro Designs
Date: 06.01.2022

Poc : Active PHP BookMarks 1.3 - Sql Injection Vulnerability


Dork: intext:Powered by Active PHP Bookmarks v1.3 inurl:.view_group.php?id=
Date: 05.01.2022

Poc : Dixell XWEB 500 Arbitrary File Write


Dork: inurl:xweb500.cgi
Date: 05.01.2022

Poc : Powered by INSPIROXINDIA - Blind Sql Injection Vulnerability


Dork: intext:Powered by INSPIROXINDIA
Date: 05.01.2022

Poc : RiteCMS 3.1.0 Arbitrary File Overwrite


Dork: intext:Powered by RiteCMS
Date: 05.01.2022

Poc : Media k - Sql Injection Vulnerability


Dork: intext:Designed and Developed by Media k
Date: 04.01.2022

Poc : BeyondTrust Remote Support 6.0 Cross Site Scripting


Dork: intext:BeyondTrust Redistribution Prohibited
Date: 04.01.2022

Poc : Virtual Airlines Manager 2.6.2 - 'plane_location' SQL Injection


Dork: Powered by Virtual Airlines Manager [v2.6.2]
Date: 01.01.2022

Poc : WEBSOFT SOLUTIONS - Sql Injection Vulnerabilit


Dork: intext:Powered by : WEBSOFT SOLUTIONS
Date: 30.12.2021

Poc : HK Global Solutions - Sql Injection Vulnerability


Dork: intext:Powered By: HK Global Solutions
Date: 30.12.2021

Poc : Chahar Technologies - Sql Injection Vulnerability


Dork: intext:Website Designed By Chahar Technologies.
Date: 30.12.2021

Poc : BeeMedia- Sql Injection Vulnerability


Dork: intext:Designed by BeeMedia
Date: 28.12.2021

Poc : BeeMedia - Bypass Admin Panel


Dork: intext:Designed by BeeMedia
Date: 28.12.2021

Poc : HRVAC Consulting Engineering Israel SQL Injection Vulnerability


Dork: page.php?ID=112
Date: 26.12.2021

Poc : WBCE CMS 1.5.1 Admin Password Reset


Dork: intext: Way Better Content Editing
Date: 20.12.2021

Poc : ALFA TEAM SHELL TESLA 4.1 - Remote Code Execution (Unauthenticated)
Dork: inurl:/alfacgiapi intext:alfa
Date: 19.12.2021

Poc : HD-Network Real-Time Monitoring System 2.0 Local File Inclusion


Dork: intitle:HD-Network Real-time Monitoring System V2.0
Date: 13.12.2021

Poc : FiveM & Gmod Loading Screen Maker Free | SQL Injection Vulnerability
Dork: ip:213.202.247.8 .php?id=
Date: 11.12.2021

Poc : LimeSurvey 5.2.4 Remote Code Execution


Dork: inurl:limesurvey/index.php/admin/authentication/sa/login
Date: 10.12.2021

Poc : OpenCATS 0.9.4 Remote Code Execution


Dork: intext:Current Available Openings, Recently Posted Jobs
Date: 10.12.2021

Poc : TestLink 1.19 Arbitrary File Download


Dork: inurl:/testlink/
Date: 09.12.2021

Poc : PageWay Version 1.8 BETA SQL Injection Vulnerability


Dork: intext:PageWay™ Website Administration System, Version 1.8 BETA
Date: 07.12.2021

Poc : WordPress DZS Zoomsounds 6.45 Arbitrary File Read


Dork: inurl:/wp-content/plugins/dzs-zoomsounds/
Date: 05.12.2021

Poc : Openbiz Cubi 3.0.8 Unrestricted File Upload Vulnerability


Dork: intext: System Login - Cubi Platform
Date: 03.12.2021

Poc : WordPress Plugin DZS Zoomsounds 6.45 Arbitrary File Read (Unauthenticated)
Dork: inurl:/wp-content/plugins/dzs-zoomsounds/
Date: 03.12.2021

Poc : Harshainfotech - Sql Injection Vulnerability


Dork: intext:Designed & Maintained by | Harshainfotech
Date: 02.12.2021

Poc : Design By Magic Mayo - Sql Injection Vulnerability


Dork: intext:Design By Magic Mayo
Date: 30.11.2021

Poc : Designed by Desire Web World - Sql Injection Vulnerability


Dork: intext:Designed by Desire Web World
Date: 30.11.2021

Poc : PHPJabbers Simple CMS 5 name Persistent Cross-Site Scripting (XSS)


Dork: subtitle:Copyright © 2021 PHPJabbers.com
Date: 29.11.2021

Poc : NEXIN engine v2.0 Backdoor Account Vulnerability


Dork: NEXIN engine v2.0
Date: 27.11.2021

Poc : itchiangmai SQL Injection Vulnerability


Dork: Power by itchiangmai
Date: 26.11.2021

Poc : Code For Share | SQL Injection Vulnerability


Dork: ip:54.162.128.250 .php?id=
Date: 26.11.2021

Poc : Webrun 3.6.0.42 SQL Injection


Dork: intitle:Webrun 3.6.0.42
Date: 23.11.2021

Poc : Design by ADMINA BULGARIA Ltd Backdoor Account Vulnerability


Dork: ADMINA BULGARIA Ltd.. All Rights Reserved. .
Date: 19.11.2021

Poc : WordPress Smart Product Review 1.0.4 Shell Upload


Dork: inurl: /wp-content/plugins/smart-product-review/
Date: 18.11.2021

Poc : DMIS:C R I 2 SQL Injection Vulnerability


Dork: ระบบฐานข้อมูลสารสนเทศเพื่อการบริหารจัดการศึกษา สำนักงานเขตพื้นที่การศึกษา
ประถมศึกษาเชียงราย เขต 2
Date: 18.11.2021

Poc : GitLab 13.10.2 Remote Code Execution (RCE) (Unauthenticated)


Dork: https://www.shodan.io/search?query=title
3A
22GitLab
22+
2B
22Server
3A+nginx
22
Date: 17.11.2021

Poc : XEL cms© v. 1.1 CSRF Vulnerability


Dork: intext:contact at: +91-98144 06799, z91-161-2408274 email: info@cyberxel.com
Date: 16.11.2021

Poc : Advanced Testimonials Manager v4.1.1 Auth by pass Vulnerability


Dork: Advanced Testimonial Manager
Date: 14.11.2021

Poc : ArenaTurk Admin Panel Bypass


Dork: intext:Designed By Arenatürk
Date: 14.11.2021

Poc : 7Days Creations SQL Injection Vulnerability


Dork: Development and Design by 7Days Creations
Date: 12.11.2021

Poc : FormaLMS 2.4.4 Authentication Bypass


Dork: inurl:index.php?r=adm/
Date: 11.11.2021
Poc : Kmaleon 1.1.0.205 SQL Injection
Dork: intitle: Inicio de Sesión - Kmaleon
Date: 10.11.2021

Poc : Opencart 3 Extension TMD Vendor System SQL Injection


Dork: inurl:index.php?route=vendor/allseller
Date: 05.11.2021

Poc : Open Journal Systems Arbitrary File Upload


Dork: /index.php/journal
Date: 30.10.2021

Poc : Mini-XML 3.2 Heap Overflow


Dork: mxml Mini-xml Mini-XML
Date: 29.10.2021

Poc : Build Smart ERP 21.0817 eidValue SQL Injection (Unauthenticated)


Dork: intitle:buildsmart accounting
Date: 28.10.2021

Poc : CKAN Datastore Search - SQL-I (Brasil POC)


Dork: inurl:/datastore_search_sql?sql=
Date: 28.10.2021

Poc : Optijet School Management System - Blind SQL Injection (Unauthenticated)


Dork: intext:okulsonuc.com
Date: 20.10.2021

Poc : SonicWall SMA 10.2.1.0-17sv Password Reset


Dork: https://www.shodan.io/search?query=title
3A
22Virtual+Office
22+
22Server
3A+SonicWall
22
Date: 20.10.2021

Poc : Plastic SCM 10.0.16.5622 Insecure Direct Object Reference


Dork: title:Plastic SCM
Date: 18.10.2021

Poc : Code For Share | SQL Injection Vulnerability


Dork: ip:54.162.128.250 .php?id=
Date: 17.10.2021

Poc : Logitech Media Server 8.2.0 Cross Site Scripting


Dork: Search Logitech Media Server
Date: 14.10.2021

Poc : Sonicwall SonicOS 7.0 Host Header Injection


Dork: inurl:auth.html intitle:SonicWall
Date: 13.10.2021

Poc : WordPress Pie Register 3.7.1.4 Privilege Escalation


Dork: inurl:/plugins/pie-register/
Date: 11.10.2021

Poc : Developed by VSFB DEVELOPERS ZONE - Sql Injection Vulnerability


Dork: intext:Website Developed by VSFB DEVELOPERS ZONE PVT. LTD.
Date: 11.10.2021

Poc : โดยบริษัท รับทำเว็บไซต์ - Sql Injection Vulnerability


Dork: intext:Web Design โดยบริษัท รับทำเว็บไซต์
Date: 11.10.2021

Poc : Jingle Infosolutions - Sql Injection Vulnerability


Dork: intext:Designed By Jingle Infosolutions Pvt. Ltd.
Date: 09.10.2021

Poc : Worldnet Payments Knowledge Base : Start | SQL Injection Vulnerability


Dork: .php?id= docs.worldnettps.com
Date: 09.10.2021

Poc : Asset Software Solutions - Blind Sql Injection Vulnerability


Dork: intext:Powered by Asset Software Solutions
Date: 06.10.2021

Poc : Asset Software Solutions - Sql Injection Vulnerability


Dork: intext:Powered by Asset Software Solutions
Date: 06.10.2021

Poc : WordPress MStore API 2.0.6 Shell Upload


Dork: inurl:/wp-content/plugins/mstore-api/
Date: 06.10.2021

Poc : Tapatalk Plugins PHP Object Injection


Dork: inurl: mobiquo/mobiquo.php
Date: 06.10.2021

Poc : Open Game Panel Remote Code Execution


Dork: intext:Open Game Panel 2021
Date: 05.10.2021

Poc : krishna Tech - Sql Injection Vulnerability


Dork: intext:Powered by krishna Tech
Date: 03.10.2021

Poc : Shodh Technologies - Sql Injection Vulnerability


Dork: intext:Powered by Shodh Technologies®
Date: 03.10.2021

Poc : WordPress JS Jobs Manager 1.1.7 Authorization Bypass


Dork: inurl:/wp-content/plugins/js-jobs/
Date: 02.10.2021

Poc : Zircon Web Desig - Sql Injection Vulnerability


Dork: intext:Website Design and Hosted by Zircon Web Design
Date: 27.09.2021

Poc : Zircon Web Desig - Blind Sql Injection Vulnerability


Dork: intext:Website Design and Hosted by Zircon Web Design
Date: 27.09.2021

Poc : BitraNet Cms Sql injection


Dork: Designed by BitraNet
Date: 23.09.2021
Poc : WordPress 3DPrint Lite 1.9.1.4 Shell Upload
Dork: inurl:/wp-content/plugins/3dprint-lite/
Date: 23.09.2021

Poc : WP Google Maps Plugin < 8.1.13 - Authenticated Persistent XSS


Dork: inurl:/wp-content/plugins/wp-google-maps/
Date: 20.09.2021

Poc : WP Google Maps PRO Add-on Plugin < 8.1.12 - Authenticated Persistent XSS
Dork: inurl:/wp-content/plugins/wp-google-maps-pro/
Date: 20.09.2021

Poc : Digital Nomad Studi - Sql Injection Vulnerability


Dork: intext:Designed & Powered by Digital Nomad Studio
Date: 20.09.2021

Poc : Developed By Next Come To Us - Sql Injection Vulnerability


Dork: intext:Developed By Next Come To Us
Date: 20.09.2021

Poc : Merit Designs- Sql Injection Vulnerability


Dork: intext:Desarrollado por Merit Designs
Date: 19.09.2021

Poc : Takmeel Global - Blind Sql Injection Vulnerability


Dork: intext:by Takmeel Global
Date: 19.09.2021

Poc : DigiHost Web Services - Sql Injection Vulnerability


Dork: intext:Powered By: DigiHost Web Services
Date: 19.09.2021

Poc : WordPress Download From Files 1.48 Shell Upload


Dork: inurl:/wp-content/plugins/download-from-files
Date: 18.09.2021

Poc : WordPress Themes Haberadam IDOR and Full Path Disclosure via JSON API
( Unathenticated )
Dork: inurl:/wp-content/themes/haberadam
Date: 13.09.2021

Poc : Ficus Global - Sql Injection Vulnerability


Dork: Designed & Maintained by Ficus Global
Date: 11.09.2021

Poc : Web Smile India - Sql Injection Vulnerability


Dork: intext:Maintained By Web Smile India
Date: 11.09.2021

Poc : Craftbox Technology - Sql Injection Vulnerability


Dork: intext:by Craftbox Technology
Date: 10.09.2021

Poc : Five design - Sql Injection Vulnerability


Dork: intext:Website designed and developed by Five design
Date: 10.09.2021

Poc : Powered by Ciws - Sql Injection Vulnerability


Dork: intext:Powered by Ciws
Date: 10.09.2021

Poc : Wordpress Plugin WP Super Edit 2.5.4 - Remote File Upload


Dork: inurl:wp-content/plugins/wp-super-edit/superedit/tinymce_plugins/mse/
fckeditor/editor/filemanager/upload/
Date: 09.09.2021

Poc : Digitalindya - Sql Injection Vulnerability


Dork: intext:Developed by Digitalindya
Date: 05.09.2021

Poc : Creators Touch- Sql Injection Vulnerability


Dork: intext:Designed by Creators Touch
Date: 05.09.2021

Poc : Pricelist Stock Bangladesh Ltd. Center For Financial Analysis | SQL Injection
Vulnerability
Dork: .php?id= stockbangladesh.mobi
Date: 05.09.2021

Poc : Sensitive Data Exposure AWS Access Key & Secret Key
Dork: intext:Copyright © Dennis Publishing Limited 2021. All rights reserved.
Date: 05.09.2021

Poc : Santo Domingo School (CSD) / Web Ratings | SQL Injection Vulnerability
Dork: .php?id= csd.atenas.tech
Date: 05.09.2021

Poc : Athens School / Atenas Familia / Atenas Tech / Bitnami LAMP | SQL Injection
Vulnerability
Dork: .php?id= prod.atenas.tech
Date: 05.09.2021

Poc : Imagino - Sql Injection Vulnerability


Dork: intext:Developed By Imagino
Date: 04.09.2021

Poc : ciclope - Sql Injection Vulnerability


Dork: intext:web by ciclope
Date: 01.09.2021

Poc : Fillip Technologies - Sql Injection Vulnerability


Dork: intext:Design & Maintained by Fillip Technologies
Date: 01.09.2021

Poc : Net Soft Lab - Sql Injection Vulnerability


Dork: intext:Website Designed & Developed By Net Soft Lab
Date: 30.08.2021

Poc : Baker Media - Sql Injection Vulnerability


Dork: intext:Website by Baker Media Ltd.
Date: 29.08.2021

Poc : Webmartindia - Sql Injection Vulnerability


Dork: intext:Powered by Webmartindia
Date: 29.08.2021

Poc : Design by ENTRACOM - Blind Sql Injection Vulnerability


Dork: intext:Design by ENTRACOM
Date: 29.08.2021

Poc : Chillipages - Sql Injection Vulnerability


Dork: intext:Site by Chillipages
Date: 21.08.2021

Poc : Webforio - Sql Injection Vulnerability


Dork: intext:Development Webforio
Date: 21.08.2021

Poc : Online Notice Board System 1.0 - Remote Command Execution (RCE) throw upload
file
Dork: intext:© 2020 ONBS
Date: 19.08.2021

Poc : Developed by Direct2Web Sql Injection Vulnerability


Dork: intext:Developed by Direct2Web
Date: 19.08.2021

Poc : Designed By Algacis Sql Injection Vulnerability


Dork: intext:Designed By Algacis
Date: 18.08.2021

Poc : Hermosoft Sql Injection Vulnerability


Dork: intext:Designed and developed by web design Dubai, Hermosoft.
Date: 17.08.2021

Poc : SAM Softech Sql Injection Vulnerability


Dork: intext:Developed By SAM Softech
Date: 17.08.2021

Poc : MobinNet Router- Remote Code Execution


Dork: In Shodan search engine, the filter is mobinnet country:ir
Date: 11.08.2021

Poc : Washington University College of Engineering SQL Injection Vulnerability


Dork: profile.php?id=
Date: 11.08.2021

Poc : Kurdistan High Elections and Referendum Commission SQL Injection


Vulnerability
Dork: inurl:about.aspx?type=
Date: 09.08.2021

Poc : PGR-Filemanager | Arbitrary File Upload


Dork: inurl:/plugins/pgrfilemanager/
Date: 06.08.2021

Poc : Testa Online Test Management System 3.4.5 - 'q' SQL Injection
Dork: intext:Powered by Testa 3.4.5
Date: 03.08.2021

Poc : Testa CMS 3.4.3 - 'q' SQL Injection


Dork: intext:Powered by Testa 3.4.3
Date: 03.08.2021

Poc : Relieve Marketing y Web Sql Injection Vulnerability


Dork: intext:Created by Obra soft
Date: 01.08.2021
Poc : TripSpark VEO Transportation SQL Injection
Dork: inhtml:Student Busing Information
Date: 28.07.2021

Poc : Better Proposals: Online Proposal Software | SQL Injection


Dork: .php?id= betterproposals.io
Date: 27.07.2021

Poc : Schoolsindia SQL Injection


Dork: intext:Powered by Schoolsindia
Date: 26.07.2021

Poc : hamayeshnegar CMS 10.0.5 - Authentication Bypass


Dork: intext:)10.0.5 ‫ همایش نگار (ویرایش‬: ‫طراحی و پیاده سازی شده توسط‬
Date: 24.07.2021

Poc : Design & Developed By Sial Web - Html Injection


Dork: intext:Design & Developed By Sial Web
Date: 23.07.2021

Poc : Microsoft SharePoint Server 2019 Remote Code Execution (2)


Dork: inurl:quicklinks.aspx
Date: 23.07.2021

Poc : Design & Developed By Nice Techno - Sqli


Dork: intext:Design & Developed By Nice Techno and inurl:?id=
Date: 22.07.2021

Poc : Bluetooth Low Energy (BLE) USB Dongle | SQL Injection


Dork: .php?id= bleuio
Date: 21.07.2021

Poc : Sputnik News Russian government has XSS vulnerabilities


Dork: intext:search/?query=
Date: 19.07.2021

Poc : Design and Development of Saba website - SQL Injection


Dork: intext: ‫طراحی و برنامه نویسی توسط شرکت صبا عصر دانش انجام شده است‬
Date: 17.07.2021

Poc : Testa Online - (V 3.4.6 ) SQL Injection


Dork: intext:Powered by Testa 3.4.6 : Online Test Management System
Date: 17.07.2021

Poc : Dailybread - Sql Injection Vulnerability


Dork: intext:Powered by Dailybread.in
Date: 16.07.2021

Poc : 3KITS - Sql Injection Vulnerability


Dork: intext:Designed & Developed By 3KITS
Date: 14.07.2021

Poc : Shell Technologies CMS - SQL Injection


Dork: intext:Developed by Shell Technologies inurl:.php?id=
Date: 14.07.2021

Poc : ariuswebstudio - Sql Injection Vulnerability


Dork: intext:site by: www.ariuswebstudio.com
Date: 11.07.2021

Poc : Real Estate 7 WordPress Theme < 3.1.1 - Unauthenticated Reflected XSS
Dork: inurl:/wp-content/themes/realestate-7/
Date: 05.07.2021

Poc : scleather - SQL Injection vulnerability


Dork: intext:Powered by scleather
Date: 03.07.2021

Poc : 7Graus - HTML Injection Vulnerability


Dork: intext:- 2021 © 7Graus
Date: 03.07.2021

Poc : Scratch Desktop 3.17 Code Execution / Cross Site Scripting


Dork: 'inurl:/projects/editor/?tutorial=getStarted -mit.edu' (not foolproof on
versioning)
Date: 02.07.2021

Poc : elFinder 2.0.47 - 'PHP connector' Command Injection


Dork: intitle:elFinder 2.0.x
Date: 02.07.2021

Poc : E-Survey Applications - SQL INJECTION


Dork: inurl:/penjelasan.php?id_kategorisend=2
Date: 30.06.2021

Poc : Powered by SDS Sql Injection Vulnerability


Dork: intext:Powered by SDS
Date: 29.06.2021

Poc : Webbdesign: SL-Studio - Local File Inclusion


Dork: intext:Webbdesign: SL-Studio
Date: 27.06.2021

Poc : Adobe ColdFusion 8 Remote Command Execution


Dork: intext:adobe coldfusion 8
Date: 25.06.2021

Poc : Website Design by Site by Tobstar® SQL Injection


Dork: inurl:?.php?id=com
Date: 21.06.2021

Poc : .:: E-CUTI ::. Application - SQL Bypass Authentication


Dork: intitle: .:: E-CUTI ::.
Date: 17.06.2021

Poc : Powered by Explore Bahrain Sql Injection Vulnerability


Dork: intext:Powered by Explore Bahrain
Date: 17.06.2021

Poc : Developed by Calura.com Sql Injection Vulnerability


Dork: intext:Developed by Calura.com
Date: 17.06.2021

Poc : cacpa Sql Injection Vulnerability


Dork: intext:Designed by cacpa
Date: 15.06.2021
Poc : webcreations Sql Injection Vulnerability
Dork: intext:Designed & Hosted by webcreations
Date: 11.06.2021

Poc : Solar-Log 500 2.8.2 Incorrect Access Control


Dork: In Shodan search engine, the filter is Server: IPC@CHIP
Date: 11.06.2021

Poc : Solar-Log 500 2.8.2 Password Disclosure


Dork: In Shodan search engine, the filter is Server: IPC@CHIP
Date: 11.06.2021

Poc : Ekattor Student Assignment php script-Stored XSS


Dork: intext: By Creativeitem
Date: 09.06.2021

Poc : Wordpress Plugin wpDiscuz 7.0.4 - Arbitrary File Upload (Unauthenticated)


Dork: inurl:/wp-content/plugins/wpdiscuz/
Date: 07.06.2021

Poc : Powered By SelongWeb.com - SQL INJECTION


Dork: inurl:/statis- SelongWeb.Com
Date: 06.06.2021

Poc : Synotec Holdings Sql Injection Vulnerability


Dork: intext:Website By : Synotec Holdings (Pvt.) Ltd.
Date: 02.06.2021

Poc : Designed by 360degreeinfo Sql Injection Vulnerability


Dork: intext:Designed by 360degreeinfo
Date: 23.05.2021

Poc : SiteLab Belediye V6 No-Redirect


Dork: inurl:/sayfa/baskanin-ozgecmisi.html
Date: 20.05.2021

Poc : Listeo WordPress Theme <= 1.6.10 - Multiple Authenticated IDOR


Vulnerabilities
Dork: inurl:/wp-content/themes/listeo/
Date: 17.05.2021

Poc : GiveWP WordPress Plugin <= 2.10.3 - Authenticated Persistent XSS


Dork: inurl:/wp-content/plugins/give/
Date: 17.05.2021

Poc : Bello WordPress Theme <= 1.5.9 - Authenticated XFS


Dork: inurl:/wp-content/themes/bello/
Date: 17.05.2021

Poc : Bello WordPress Theme <= 1.5.9 - Unauthenticated Blind SQL Injection
Dork: inurl:/wp-content/themes/bello/
Date: 17.05.2021

Poc : GA Google Analytics WordPress Plugin <= 20210211 - Multiple Authenticated


Persistent XSS
Dork: inurl:/wp-content/plugins/ga-google-analytics/
Date: 17.05.2021

Poc : Goto WordPress Theme 2.0 - Unauthenticated Blind SQL Injection


Dork: inurl:/wp-content/themes/goto/
Date: 17.05.2021

Poc : Mediumish WordPress Theme <= 1.0.47 - Unauthenticated Reflected XSS & XFS
Dork: inurl:/wp-content/themes/mediumish/
Date: 17.05.2021

Poc : Listeo WordPress Theme <= 1.6.10 - Multiple XSS & XFS vulnerabilities
Dork: inurl:/wp-content/themes/listeo/
Date: 17.05.2021

Poc : Bello WordPress Theme <= 1.5.9 - Unauthenticated Reflected XSS & XFS
Dork: inurl:/wp-content/themes/bello/
Date: 17.05.2021

Poc : WP-DB-Backup WordPress Plugin <= 2.3.3 - Authenticated Persistent XSS


Dork: inurl:/wp-content/plugins/wp-db-backup/
Date: 17.05.2021

Poc : Chevereto 3.17.1 Cross Site Scripting


Dork: intext:powered by chevereto
Date: 13.05.2021

Poc : ENERGY CORPORATION Sql Injection Vulnerability


Dork: intext:Powered By ENERGY CORPORATION
Date: 10.05.2021

Poc : OpenNetAdmin 8.5.14 <= 18.1.1 - Remote Command Execution


Dork: inurl:/ona/
Date: 07.05.2021

Poc : Ghostcat Vulnerability Remote Code Execution


Dork: python3 ajpshooter.py IP:ApachePort AjpPort /file/location read/eval
Date: 05.05.2021

Poc : ILDIS v2 Applications Multiple Vulnerabilities


Dork: intitle:Signin | ILDIS JDIHN
Date: 04.05.2021

Poc : Technical Assistance explore IT Sql Injection Vulnerability


Dork: intext:Technical Assistance explore IT
Date: 03.05.2021

Poc : Dulux - Html Injection Vulnerability


Dork: inurl : dulux site:.
Date: 28.04.2021

Poc : Irandesign.ir CMS SQL Injection


Dork: intext:‫طراحی سایت توسط ایران دیزاین‬
Date: 20.04.2021

Poc : SoftNick India - SQL Injection vulnerability


Dork: intext:Developed By SoftNick India
Date: 20.04.2021

Poc : VASYL STEFANYK UNIVERSITY | SQL Injection Vulnerability


Dork: read.php?id=
Date: 18.04.2021
Poc : Greek Shopping Web Site SQL Injection Vulnerability
Dork: productview.php?id=
Date: 16.04.2021

Poc : CITSmart ITSM 9.1.2.27 SQL Injection


Dork: intext:citsmart.local
Date: 15.04.2021

Poc : CITSmart ITSM 9.1.2.22 LDAP Injection


Dork: intext:citsmart.local
Date: 15.04.2021

Poc : USA Cansas City SQL Injection Vulnerability


Dork: news.php?id=
Date: 15.04.2021

Poc : Smtmax SQL Injection Vulnerability


Dork: category.php?id=
Date: 15.04.2021

Poc : Sanah Infosolutions - SQL Injection vulnerability


Dork: intext:Designed by : Sanah Infosolutions
Date: 15.04.2021

Poc : Delhi Jain School SQL Injection Vulnerability


Dork: gallery.php?id=
Date: 13.04.2021

Poc : Brazil Floriano Municipality Blind SQL Injection


Dork: galeria.php?id=
Date: 11.04.2021

Poc : mmcct | SQL injection Vulnerability


Dork: inurl:members.php?lang=en
Date: 10.04.2021

Poc : Custom CMS Okezone - Cross-Site Scripting Vulnerabilities


Dork: site:*.okezone.com/rc.php?id=
Date: 09.04.2021

Poc : Web Design by Island Webservices (SQL) Injection


Dork: intext:/Web design by Island Webservices
Date: 04.04.2021

Poc : indiawebsoft Admin Login ByPass


Dork: intext:/designed and developed by indiawebsoft
Date: 03.04.2021

Poc : Realteo WordPress Plugin <= 1.2.3 - Improper Access Control


Dork: inurl:/wp-content/plugins/realteo/
Date: 02.04.2021

Poc : Realteo WordPress Plugin <= 1.2.3 - Unauthenticated Reflected XSS


Dork: inurl:/wp-content/plugins/realteo/
Date: 02.04.2021

Poc : Web Tasarım - www.bursaproje.com (XSS) Vulnerability


Dork: intext:/Web Tasarım - www.bursaproje.com
Date: 02.04.2021
Poc : Web Tasarım - www.bursaproje.com (SQL) Injection
Dork: intext:/Web Tasarım - www.bursaproje.com
Date: 01.04.2021

Poc : Goto WordPress Theme <= 1.9 - Unauthenticated Reflected XSS


Dork: inurl:/wp-content/themes/goto/
Date: 01.04.2021

Poc : Obra soft Sql Injection Vulnerability


Dork: intext:Created by Obra soft
Date: 27.03.2021

Poc : Moodle Atto Editor Cross Site Scripting


Dork: inurl:/lib/editor/atto/plugins/managefiles/ or calendar/view.php?view=month
Date: 26.03.2021

Poc : Moodle 3.10.3 Calendar Cross Site Scripting


Dork: inurl:/lib/editor/atto/plugins/managefiles/ or calendar/view.php?view=month
Date: 26.03.2021

Poc : Copyrights Samad Elmakchi - Admin Login Bypass


Dork: intext:Copyrights Samad Elmakchi
Date: 23.03.2021

Poc : Controlled Admin Access WordPress Plugin <= 1.4.0 - Improper Access
Control & Privilege Escalation
Dork: inurl:/wp-content/plugins/controlled-admin-access/
Date: 23.03.2021

Poc : Team Inertia Technologies Sql Injection Vulnerability


Dork: intext:Designed by Team Inertia Technologies
Date: 22.03.2021

Poc : IT NUCLEUS Sql Injection Vulnerability


Dork: intext:Powered by IT NUCLEUS
Date: 22.03.2021

Poc : Team Inertia Technologies Xpath Injection Vulnerability


Dork: intext:Designed by Team Inertia Technologies
Date: 22.03.2021

Poc : RedJasmin Sql injection vulnerability


Dork: intext:Designed & Developed by Redjasmin.com
Date: 22.03.2021

Poc : Developed by Five design Vulnerability SQL Injection And Admin Default Pass
Dork: intext:developed by Five design
Date: 22.03.2021

Poc : Dynamic Experts script SQL Injection Vulnerability


Dork: intext:Powered By Dynamic Experts
Date: 21.03.2021

Poc : Turning Point script Sql Injection Vulnerability


Dork: intext:Website designed by: Turning Point
Date: 21.03.2021

Poc : Developed By ACME Infosoft Sql Injection Vulnerability


Dork: intext:Developed By ACME Infosoft
Date: 21.03.2021

Poc : GAP Infotech Sql Injection Vulnerability


Dork: intext:Powered By: GAP Infotech
Date: 21.03.2021

Poc : WP Super Cache WordPress Plugin <= 1.7.1 - Authenticated RCE / XSS ->
RCE
Dork: inurl:/wp-content/plugins/wp-super-cache/
Date: 19.03.2021

Poc : Design By Developer Village Sql Injection Vulnerability


Dork: intext:Design By - Developer Village
Date: 18.03.2021

Poc : Multiple Vulnerabilities Default Password - Sql Injection Allhandsmarketing


Designer
Dork: inurl:.php?cid= intext:Design by Allhandsmarketing
Date: 16.03.2021

Poc : Design & Developed By Webcare Technology Vulnerability SQL Injection


Dork: intext:Developed By Webcare Technology
Date: 15.03.2021

Poc : Site Design by Natural Software - Admin Login Bypass


Dork: intext:Site Design by Natural Software
Date: 13.03.2021

Poc : GD Goenka Public School SQL İnjection


Dork: inurl:photo-gallery.php?id= site:gdgoenkaagra.com
Date: 13.03.2021

Poc : Crescent Public School SQL İnjection


Dork: inurl:sub-gallery.php?id= site:www.crescentpublicschool.in
Date: 10.03.2021

Poc : Joomla JCK Editor 6.4.4 SQL Injection


Dork: inurl:/plugins/editors/jckeditor/plugins/jtreelink/
Date: 09.03.2021

Poc : Joomla Matukio Events 7.0.5 Stored XSS


Dork: inurl:option=com_matukio
Date: 08.03.2021

Poc : 2X Ajans SQL Injection Vulnerability


Dork: intext:Designed by 2X Ajans
Date: 08.03.2021

Poc : Joomla Matukio Events 7.0.5 Cross Site Scripting


Dork: inurl:option=com_matukio
Date: 08.03.2021

Poc : ITAcumens Sql Injection Vulnerability


Dork: intext:Powered by ITAcumens
Date: 06.03.2021

Poc : Sitio Web desarrollado por misionessistemas Sql Injection Vulnerability


Dork: intext:Sitio Web desarrollado por misionessistemas
Date: 06.03.2021

Poc : Fr. Evan Gomes SVD Xpath Injection Vulnerability


Dork: intext:Website Maintained by Fr. Evan Gomes SVD
Date: 04.03.2021

Poc : Fr. Evan Gomes SVD Sql Injection Vulnerability


Dork: intext:Website Maintained by Fr. Evan Gomes SVD
Date: 04.03.2021

Poc : Website By ibrandcare Sql Injection Vulnerability


Dork: intext:Website By ibrandcare
Date: 04.03.2021

Poc : Webberz SQL İnjection article.php?id


Dork: inurl:article.php?id= Webberz.com
Date: 01.03.2021

Poc : parameters.yml Config Vulnerable File


Dork: inurl: app / config / intext: parameters.yml intitle: index.of
Date: 28.02.2021

Poc : Triconsole 3.75 Cross Site Scripting


Dork: inurl : /calendar/calendar_form.php
Date: 28.02.2021

Poc : Developed by - Animax Technology. ->Baypas admin


Dork: intext:Developed by - Animax Technology.
Date: 28.02.2021

Poc : Webkrea Cross Site Scripting (XSS)


Dork: intext:Powered by : Webkrea
Date: 26.02.2021

Poc : HFS (HTTP File Server) 2.3.x Remote Code Execution


Dork: intext:httpfileserver 2.3
Date: 24.02.2021

Poc : Myonlieexam Admin Panel Bypass


Dork: inurl:myonlieexam/adminpanel/admin
Date: 24.02.2021

Poc : WordPress Plugin SuperForms 4.9 - Arbitrary File Upload to Remote Code
Dork: inurl:wp-content/plugins/super-forms
Date: 24.02.2021

Poc : Webkrea Cross Site Scripting (XSS)


Dork: intext:Powered by : Webkrea
Date: 17.02.2021

Poc : Developed By : Websoft Creation,Kota Vulnerability Bypass Admin


Dork: intext:Developed By : Websoft Creation,Kota
Date: 17.02.2021

Poc : CHEditor CMS CSRF Vulnerability Leading to Shell Upload ( RCE ) + Bypass
Image Validation
Dork: inurl:/cheditor/imageUpload/ index of intext:upload.php
Date: 14.02.2021
Poc : SW3 Solutions CMS Shell Upload thru weak default admin credentials
Dork: intext: Website Design & Developed by SW3 Solutions
Date: 12.02.2021

Poc : DNNSmart_SuperContent Arbitrary File Upload (csrf)


Dork: inurl:desktopmodules/DNNSmart_SuperContent/AjaxHandler/FileUploadHandler.ashx
Date: 12.02.2021

Poc : AXIS Camera View {CCTV} Exploit version 4.11 4.03 4.05
Dork: intitle:Live View AXIS
Date: 11.02.2021

Poc : gemsbschoolcms - Admin Panel Bypass


Dork: inurl: gemsbschoolcms
Date: 09.02.2021

Poc : Designed & Developed by SNT Infotech Pvt Ltd - Sql Injection
Dork: intext:Designed & Developed by SNT Infotech Pvt Ltd
Date: 09.02.2021

Poc : Designed by sirigroup Vulnerability Bypass Admin Login


Dork: intext:Designed by sirigroup
Date: 07.02.2021

Poc : MANAGE BY TLJ TECHNOLAB - Admin Panel Bypass


Dork: Google Dork:intext:Designed By : TLJ Technolab
Date: 07.02.2021

Poc : Designed & Developed by ENS Sql Injection Vulnerability


Dork: intext:Designed & Developed by ENS
Date: 07.02.2021

Poc : CMS E-Belajar Default Password


Dork: intext:Copyright 2020 © e-belajar, All Rights Reserved.
Date: 07.02.2021

Poc : Powered By iWebsoul - SQL Injection


Dork: intext:Powered By: iWebsoul
Date: 06.02.2021

Poc : Custom CMS Jogjasite - SQL-Injection Vulnerability


Dork: intext:By jogjasite.com
Date: 06.02.2021

Poc : powered by iPOT Technologies sql Injection


Dork: intext:powered by iPOT Technologies & inurl:/.php?id=
Date: 04.02.2021

Poc : ADDEALINDIA Vulnerabelity Bypass Login Admin


Dork: intext:Developed by ADDEALINDIA site:
Date: 04.02.2021

Poc : Ruang Edukasi - Admin Weak Password


Dork: Intext:Ruang Edukasi site:
Date: 03.02.2021

Poc : ZEN SERVICES Cross Site Scripting (XSS)


Dork: intext:Powered By: ZEN SERVICES
Date: 31.01.2021
Poc : headlight Cross Site Scripting (XSS)
Dork: intext:Powered by Headlight
Date: 31.01.2021

Poc : CANDOUR SOFTWARE Cross Site Scripting (XSS)


Dork: intext:Powered By : CANDOUR SOFTWARE
Date: 31.01.2021

Poc : MIProject Cross Site Scripting (XSS)


Dork: intext:Powered by MIProject.
Date: 31.01.2021

Poc : Aplikasi PPDB Online - SQL-Injection Vulnerability


Dork: intitle:Halaman Login inurl:/panel_admin/log_in
Date: 30.01.2021

Poc : Aplikasi PPDB Online - Default Admin Login Credentials


Dork: intitle:Halaman Login inurl:/panel_admin/log_in
Date: 30.01.2021

Poc : Aplikasi PPDB Online - Cross-site-scripting (POST) Vulnerabilities


Dork: intitle:Halaman Login inurl:/panel_admin/log_in
Date: 30.01.2021

Poc : Wordpress [SuperForms] Plugin Unsecured File Upload leads to remote code
execution
Dork: inurl:/wp-content/plugins/super-forms/
Date: 29.01.2021

Poc : Horizon Softnet Solutions Cross Site Scripting (XSS)


Dork: intext:Powered by Horizon Softnet Solutions.
Date: 26.01.2021

Poc : Ainpex Solutions Sql Injection Vulnerability


Dork: intext:Powered by: Ainpex Solutions
Date: 22.01.2021

Poc : Designed by GN DIGITAL - Admin Login Bypass


Dork: intext:Designed by GN DIGITAL
Date: 22.01.2021

Poc : Qboxus - Server Requirements Default Admin Password


Dork: intext:Login in. To see it in action.
Date: 20.01.2021

Poc : wordpress superstorefinder plugins Security misconfigurations bug


Dork:
inurl:wp-content/plugins/superstorefinder-wp/ssf-wp-admin/pages/exportAjax.php
Date: 20.01.2021

Poc : Aplikasi Kartu Pelajar Vulnerability arbitrary file upload with


CSRF(indonesian school)
Dork: intext:Responsive image aplikasi kartu pelajar sch.id
Date: 17.01.2021

Poc : wordpress-newsletter * wordpress plugin * SQL Injection


Dork: inurl:plugins/wordpress-newsletter-master
Date: 17.01.2021
Poc : wp-ticket - wordpress plugin - Cross-Site-Scripting
Dork: inurl:wp-content/plugins/wp-ticket-master/
Date: 13.01.2021

Poc : unisender-integration * wordpress plugin * Code-Execution


Dork: inurl:wp-content/plugins/unisender-integration-master/class/
Date: 13.01.2021

Poc : Socialtitli - Bypass Admin Panel


Dork: intext: All Rights Reserved, Developed by Socialtitli.
Date: 11.01.2021

Poc : wordpress hashtagger plugin - 3.2 -Cross-Site-Scripting


Dork: inurl: /plugins/hashtagger-master/
Date: 11.01.2021

Poc : Aplikasi E - S A K I P v1.1 Indonesian Goverment File Manager File Upload


Dork: inurl:/portal/home/kontak_view
Date: 10.01.2021

Poc : Aplikasi Sistem E-Voting Vulnerability Weak Password.


Dork: intext:Aplikasi e-voting site:.id
Date: 06.01.2021

Poc : Responsive FileManager 9.13.4 Path Traversal


Dork: intitle:Responsive FileManager 9.x.x
Date: 05.01.2021

Poc : Simogeo Filemanager - Arbitrary File Upload


Dork: intext:Powered by CORNERSTONE CONTENT MANAGEMENT SYSTEM
Date: 04.01.2021

Poc : SIKADES 2020 Admin Login Default Password


Dork: intext:Developed by PT Gimmed
Date: 03.01.2021

Poc : LWMC - SQL Injection vulnerability


Dork: intext:Powered by Lwmc
Date: 31.12.2020

Poc : AQUACITY - SQL Injection vulnerability


Dork: intext:Powered by Aquacity
Date: 29.12.2020

Poc : Designed & Developed By Sync Co. Sql Injection Vulnerability


Dork: intext:Designed & Developed By Sync Co.
Date: 29.12.2020

Poc : MEANMENTOR - SQL Injection vulnerability


Dork: intext:Powered by Meanmentor
Date: 28.12.2020

Poc : ATHOLBOOKS - SQL Injection vulnerability


Dork: intext:Powered by Atholbooks
Date: 28.12.2020

Poc : WordPress Plugin Adning Advertising 1.5.5 - Arbitrary File Upload


Dork: inurl:/wp-content/plugins/angwp
Date: 28.12.2020

Poc : Shinja Xpath Injection Vulnerability


Dork: intext:Made with ♥ by Shinja
Date: 28.12.2020

Poc : IBOOKAVENUE - SQL Injection vulnerability


Dork: intext:Powered by Ibookavenue
Date: 26.12.2020

Poc : Developed by SoftwareInfoline.com Sql Injection Vulnerability


Dork: intext:Developed by SoftwareInfoline.com
Date: 26.12.2020

Poc : WordPress Adning Advertising 1.5.5 Shell Upload


Dork: inurl:/wp-content/plugins/angwp
Date: 25.12.2020

Poc : Powered by webnink Sql Injection Vulnerability


Dork: intext:Powered by webnink
Date: 24.12.2020

Poc : SCO Openserver 5.0.7 Command Injection


Dork: inurl:/cgi-bin/manlist?section
Date: 22.12.2020

Poc : SCO Openserver 5.0.7 Cross Site Scripting


Dork: inurl:/cgi-bin/manlist?section
Date: 22.12.2020

Poc : Developed By Fluent Technology Auth by pass Vulnerability


Dork: intext:Developed By - Fluent Technology
Date: 20.12.2020

Poc : Designed by JLC Web Sql Injection Vulnerability


Dork: intext:Designed by JLC Web
Date: 20.12.2020

Poc : OAM Techno Media Auth by pass Vulnerability


Dork: OAM Techno Media
Date: 18.12.2020

Poc : LibreNMS 1.46 MAC Accounting Graph Authenticated SQL Injection


Dork: Unknown
Date: 18.12.2020

Poc : WordPress Total Upkeep 1.14.9 Backup Disclosure


Dork: intitle:(Index of AND wp-content/plugins/boldgrid-backup/=)
Date: 15.12.2020

Poc : Designed & Developed By Yasha Zamanpour - SQL Injection vulnerability


Dork: intext:Designed & Developed By Yasha Zamanpour
Date: 14.12.2020

Poc : bbse_board_pro plugin XSS


Dork: inurl:/wp-content/plugins/BBSe_Board_Pro
Date: 11.12.2020

Poc : IdeKode Local File Inclusion Exploiter


Dork: inurl:link=page/berita.php
Date: 10.12.2020

Poc : Google Groups - Public File Disclosure (Sensitive Info)


Dork: site:googlegroups.com ext:txt password:
Date: 09.12.2020

Poc : infopi.io Playsms RCE


Dork: inurl:index.php?app=main
Date: 07.12.2020

Poc : Группа компаний "Сумотори" sql injection


Dork: intext: © 2020 Группа компаний Сумотори inurl:id=
Date: 05.12.2020

Poc : Mailman Information Disclosure


Dork: Inurl:mailman/listinfo mailman
Date: 04.12.2020

Poc : Web Design by Mio Creative Sql Injection Vulnerability


Dork: intext:Web Design by Mio Creative Co.,Ltd
Date: 04.12.2020

Poc : ООО "СУ-3" - компания sql injection


Dork: intext:ООО СУ-3 - компания
Date: 03.12.2020

Poc : Rejetto HttpFileServer 2.3.x Remote Command Execution


Dork: intext:httpfileserver 2.3
Date: 01.12.2020

Poc : YATinyWinFTP Denial of Service (PoC)


Dork: None
Date: 30.11.2020

Poc : Star Web Maker Sql Injection Vulnerability


Dork: intext:Designed by Star Web Maker
Date: 28.11.2020

Poc : Stealth Media Ltd Sql Injection Vulnerability


Dork: intext:Website Designed & Developed By Stealth Media Ltd.
Date: 28.11.2020

Poc : MASTER TECNOLOGIA - Sql Injection Vulnerability


Dork: intext:Powered By Trynet Solutions
Date: 26.11.2020

Poc : Powered By Trynet Solutions Sql Injection Vulnerability


Dork: intext:Powered By Trynet Solutions
Date: 24.11.2020

Poc : CyberDairy Solutions Sql Injection Vulnerability


Dork: intext:Designed by Star Web Maker
Date: 24.11.2020

Poc : Waters Computer Consultants Sql Injection Vulnerability


Dork: intext:Website by Waters Computer Consultants
Date: 23.11.2020
Poc : Developed By Click Informatics - Sql Injection Vulnerability
Dork: intext:Developed By Click Informatics
Date: 23.11.2020

Poc : Made by Capitalwebapps - Sql Injection Vulnerability


Dork: intext:Made by Capitalwebapps
Date: 23.11.2020

Poc : Fortinet FortiOS 6.0.4 Password Modification


Dork: intitle:Please Login Use FTM Push
Date: 22.11.2020

Poc : E-ticaretim v1.1 Sql İnjection Vulnerability


Dork: inurl:/blog/haberinizolsunhaberiniz.html
Date: 22.11.2020

Poc : LIT Creations Sql Injection Vulnerability


Dork: intext:Website designed and hosted by LIT Creations.
Date: 19.11.2020

Poc : Water Billing System 1.0 - username and password parameters SQL Injection
Dork: Water Billing System Exploit
Date: 18.11.2020

Poc : PMB 5.6 Local File Disclosure / Directory Traversal


Dork: inurl:opac_css
Date: 16.11.2020

Poc : Designe by E.LINK - Blind Sql Injection Vulnerability


Dork: intext:Designe by E.LINK
Date: 15.11.2020

Poc : SIGE (Joomla) 3.4.1 & 3.5.3 Pro - Multiple Vulnerabilities


Dork: intext:Powered by Simple Image Gallery Extended
Date: 13.11.2020

Poc : WPJobBoard plugin v5.6.4 - Unauthenticated SQL Injection


Dork: inurl:/wp-content/plugins/wpjobboard/
Date: 13.11.2020

Poc : Powered by Maria Softwares - SQL Injection vulnerability


Dork: intext:Powered by Maria Softwares Pvt Ltd
Date: 13.11.2020

Poc : SW Ajax WooCommerce Search plugin v1.2.6 - Unauthenticated Reflected XSS &
XFS
Dork: inurl:/wp-content/plugins/sw_ajax_woocommerce_search/
Date: 12.11.2020

Poc : Best Support System v3.0.5 - Authenticated Persistent XSS


Dork: intext:Powered By Best Support System
Date: 12.11.2020

Poc : Quick Chat plugin v4.14 - Unauthenticated Persistent XSS


Dork: inurl:/wp-content/plugins/quick-chat/
Date: 12.11.2020

Poc : BA Book Everything WordPress plugin v1.3.24 - Unauthenticated Reflected XSS &
XFS
Dork: inurl:/wp-content/plugins/ba-book-everything/
Date: 11.11.2020

Poc : Development by Progous - SQL Injection vulnerability


Dork: intext:Design by Design Wise, Development by Progous
Date: 11.11.2020

Poc : Altair WordPress theme v4.8 - Unauthenticated Reflected XSS


Dork: inurl:/wp-content/themes/altair/
Date: 10.11.2020

Poc : benisi Cross Site Scripting (XSS)


Dork: intext:‫‌گستر ِبنیسی است‬
‫ ویژه شرکت رسانه‬،‫تمام حقوق اين وبگاه‬
Date: 10.11.2020

Poc : Web Mingo I.T. Solutions - SQL Injection vulnerability


Dork: intext:Design & Developed By Web Mingo I.T. Solutions
Date: 10.11.2020

Poc : Love Travel WordPress theme v3.8 - Unauthenticated Reflected XSS


Dork: inurl:/wp-content/themes/lovetravel/
Date: 10.11.2020

Poc : Love Travel WordPress theme v1.9 - Unauthenticated Reflected XSS


Dork: inurl:/wp-content/themes/lovetravel/
Date: 10.11.2020

Poc : SciOne SQL Injection Vulnerability


Dork: intext:Hosted by SciOne
Date: 09.11.2020

Poc : demositeportal SQL Injection Vulnerability


Dork: intext:Powered by demositeportal.com
Date: 09.11.2020

Poc : Copyright © 2019 Bangkok Hospital Udon All rights reserved SQL Injection
Dork: intext:Copyright © 2019 Bangkok Hospital Udon All rights reserved Or
intext:Copyright © 2019 Bangkok Hospital Udon All rights reserved inurl:.php?id=
Date: 09.11.2020

Poc : Globosoft Technology Solutions - SQL Injection vulnerability


Dork: intext:Powered by Globosoft Technology Solutions
Date: 08.11.2020

Poc : Parasight Solutons SQL Injection


Dork: intext:Powered By Parasight Solutons
Date: 08.11.2020

Poc : imaginae SQL Injection


Dork: intext:CREDITS: IMAGINAE.IT
Date: 08.11.2020

Poc : Designed by Launch Web Dreams - SQL Injection vulnerability


Dork: intext:Designed by Launch Web Dreams
Date: 07.11.2020

Poc : Design & Develop by shopweb - SQL Injection vulnerability


Dork: intext:Design & Develop by shopweb
Date: 07.11.2020
Poc : ‫‌گستر ِبنیسی است‬
‫ ویژه شرکت رسانه‬،‫ تمام حقوق اين وبگاه‬SQL injection
Dork: intext:‫‌گستر ِبنیسی است‬
‫ ویژه شرکت رسانه‬،‫تمام حقوق اين وبگاه‬
Date: 07.11.2020

Poc : Joomla JVTwitter - SQL Injection & XSS Vulnerabilities


Dork: inurl:mod_jvtwitter/jvtwitter.php?id=
Date: 07.11.2020

Poc : Unicus SQL Injection


Dork: intext:Powered by Unicus
Date: 07.11.2020

Poc : Aries e-Solutions SQL Injection


Dork: intext:Powered by Aries e-Solutions
Date: 07.11.2020

Poc : Design By Web Design Mumbai Yaaaro - SQL Injection vulnerability


Dork: intext:Design By Web Design Mumbai Yaaaro | Powered By Blue Sun Info
Date: 07.11.2020

Poc : Fairness Web ID - Cross Site Scripting


Dork: site:fairness.web.id
Date: 06.11.2020

Poc : Powered by : HindSoft Technology - SQL Injection vulnerability


Dork: intext:Powered by : HindSoft Technology
Date: 05.11.2020

Poc : XUpload Remote File Upload Vulnerability


Dork: intext:Powered by XUpload
Date: 04.11.2020

Poc : Joomla JomSocial 4.7.6 Stored XSS


Dork: inurl:templates/jomsocial/
Date: 04.11.2020

Poc : Joomla JomSocial 4.7.6 Stored XSS


Dork: inurl:templates/jomsocial/
Date: 03.11.2020

Poc : Apache Flink 1.9.x Shell Upload


Dork: None
Date: 02.11.2020

Poc : windowfrance - SQL Injection


Dork: inurl: / windowfrance php id
Date: 31.10.2020

Poc : Powered by Sinaps Iletisim - SQL Injection vulnerability


Dork: intext:Powered by Sinaps Iletisim
Date: 30.10.2020

Poc : OneMall WordPress theme v1.7.7 - Unauthenticated Reflected XSS & XFS
Dork: inurl:/wp-content/themes/onemall/
Date: 28.10.2020

Poc : Real Estate 7 WordPress theme v3.0.4 - Unauthenticated Reflected XSS


Dork: inurl:/wp-content/themes/realestate-7/
Date: 28.10.2020

Poc : Sphider Search Engine 1.3.6 Remote Code Execution


Dork: intitle:Sphider Admin Login
Date: 27.10.2020

Poc : Sphider Search Engine 1.3.6 word_upper_bound RCE (Authenticated)


Dork: intitle:Sphider Admin Login
Date: 27.10.2020

Poc : WordPress Plugin Rest Google Maps < 7.11.18 SQL Injection
Dork: inurl:index.php?rest_route=3D/wpgmza/
Date: 26.10.2020

Poc : MEGGIESCHNEIDER - SQL Injection vulnerability


Dork: intext:Powered by Meggieschneider
Date: 26.10.2020

Poc : icewarp webmail 11.4.5.0 exploit


Dork: inurl:/webmail/ intext:Powered by IceWarp Server
Date: 25.10.2020

Poc : Powered by Shambhala.Travel - SQL Injection vulnerability


Dork: intext:Powered by Shambhala.Travel
Date: 25.10.2020

Poc : webinnovation - SQL Injection vulnerability


Dork: intext:site designed by webinnovation.net
Date: 25.10.2020

Poc : INLISLite v3.1 - Cross Site Scripting


Dork: intext:INLISLite v3.1 /browse
Date: 24.10.2020

Poc : ENG - SQL Injection vulnerability


Dork: intext:Powered by Eng
Date: 23.10.2020

Poc : HUMOR - SQL Injection vulnerability


Dork: intext:Powered by Humor
Date: 23.10.2020

Poc : BOWTIEOVERDRIVES - SQL Injection vulnerability


Dork: intext:Powered by Bowtieoverdrives
Date: 22.10.2020

Poc : TESTPHP - SQL Injection vulnerability


Dork: intext:Powered by Testphp
Date: 22.10.2020

Poc : Powered by Shambhala.Travel - SQL Injection vulnerability


Dork: intext:Powered by Shambhala.Travel
Date: 22.10.2020

Poc : DEBOUGAINVILLEA - SQL Injection vulnerability


Dork: intext:Powered by Debougainvillea
Date: 22.10.2020

Poc : Apache Struts 2 Remote Code Execution


Dork: ext:action | filetype:action
Date: 21.10.2020

Poc : WordPress Rest Google Maps SQL Injection


Dork: inurl:index.php?rest_route=3D/wpgmza/
Date: 21.10.2020

Poc : WONDERGRAPHY - SQL Injection vulnerability


Dork: intext:Powered by Wondergraphy
Date: 21.10.2020

Poc : Textpattern CMS 4.6.2 Cross-site Request Forgery


Dork: intext:Published with Textpattern CMS
Date: 19.10.2020

Poc : Cloudflare bypass XSS payloads


Dork: ≋ ><!/**/*/*--></Script><Image SrcSet=K */;
OnError=confirm(document.domain) //># ≋
Date: 18.10.2020

Poc : Sensitive Directories & Usernames and Passwords and all other tables
Dork: intext:-- table `users` | `category` | `structure` ext:sql | ext:txt
Date: 18.10.2020

Poc : PARTNER - Cross Site Scripting Vulnerability (XSS)


Dork: intext:Powered by Web Partner
Date: 18.10.2020

Poc : Sensitive Juicy Dorks, Data Exposure


Dork: inurl:index.php/user/password/ intext:Password Reset
Date: 17.10.2020

Poc : Wecom SQL Injection vulnerability


Dork: intext:web site by WeC.O.M.
Date: 16.10.2020

Poc : Zboya Design– SQL Injection vulnerability


Dork: intext:designed by Zboya Design
Date: 13.10.2020

Poc : vBulletin 5.6.3 Cross Site Scripting


Dork: intext:Powered by vBulletin® Version 5.6.3
Date: 12.10.2020

Poc : Designed By : WEBSYS - SQL Injection vulnerability


Dork: intext:Designed By : WEBSYS
Date: 12.10.2020

Poc : Zavoly Online Shopping - Cross Site Scripting (Stored)


Dork: intext:© blueferns technologies
Date: 12.10.2020

Poc : SIDEXOVERSEAS - SQL Injection vulnerability


Dork: products.php?sub=
Date: 12.10.2020

Poc : Webworx Technologies - SQL Injection vulnerability


Dork: intext:Website Developed By: Webworx Technologies
Date: 11.10.2020
Poc : RTK - SQL Injection vulnerability
Dork: intext:Powered by Rtk
Date: 10.10.2020

Poc : GLAZERRANTIQUES - SQL Injection vulnerability


Dork: display_page.php?id=339
Date: 10.10.2020

Poc : Designed by : Shinja - SQL Injection vulnerability


Dork: intext:Designed by : Shinja Pvt. Ltd.
Date: 10.10.2020

Poc : GetSimple CMS 3.3.16 Persistent Cross-Site Scripting


Dork: -
Date: 09.10.2020

Poc : Jaringan Dokumentasi dan Informasi Hukum - Cross Site Scripting


Dork: site:jdih.*.go.id inurl:/result?q=
Date: 09.10.2020

Poc : Kabupaten Kulonprogo - Cross Site Scripting


Dork: site:*kulonprogokab.go.id
Date: 08.10.2020

Poc : LAGOCCIA - SQL Injection vulnerability


Dork: photogallery.php?id=545
Date: 08.10.2020

Poc : Textpattern CMS 4.6.2 body Persistent Cross-Site Scripting


Dork: intext:Published with Textpattern CMS
Date: 08.10.2020

Poc : SCHLOSSWUELFLINGEN - SQL Injection vulnerability


Dork: promo.php?ID=54
Date: 07.10.2020

Poc : Sony IPELA Network Camera 1.82.01 ftpclient.cgi Remote Stack Buffer Overflow
Dork: Server: Mida eFramework
Date: 07.10.2020

Poc : bawaslu subdomain | SQL Injection


Dork: inurl:/blog/..html/ site:*.bawaslu.go.id
Date: 06.10.2020

Poc : Krpano Panorama Viewer 1.20.8 Cross Site Scripting


Dork: inurl:krpano.html
Date: 06.10.2020

Poc : BELBANA - SQL Injection vulnerability


Dork: intext:Powered by Belbana
Date: 06.10.2020

Poc : Aplikasi Pengumuman Kelulusan – SQL-I, XSS, and Database Information


Disclosure Vulnerability
Dork: intitle:Pengumuman.Kelulusan site:sch.id intext:Masukkan
Date: 05.10.2020

Poc : Chris Anderson CMS SQL Injection Vulnerability


Dork: intext: Design by Chris Anderson
Date: 05.10.2020

Poc : CBS CMS SQL Injection Vulnerability


Dork: intext: Developed By CBS
Date: 04.10.2020

Poc : PHUKET SOLUTIONCMS SQL Injection and XSS Vulnerability


Dork: intext: Powered by Phuket Solution
Date: 04.10.2020

Poc : CMS Swarakalibata default password


Dork: intext:album-44-festival-seni-terbesar-di-duniaaa.html
Date: 04.10.2020

Poc : Expert Soft CMS - SQL Injection and XSS Vulnerability


Dork: intext: Designed by - Expert Soft
Date: 04.10.2020

Poc : PENTESTCORE - Cross Site Scripting Vulnerability (XSS)


Dork: intext:Powered by Pentestcore
Date: 02.10.2020

Poc : DIGIKALA - Cross Site Scripting Vulnerability (XSS)


Dork: intext:Powered by Digikala
Date: 01.10.2020

Poc : Typesetter CMS 5.1 Cross Site Scripting


Dork: intext:Powered by Typesetter
Date: 01.10.2020

Poc : APIWHATSAPP - Cross Site Scripting Vulnerability (XSS)


Dork: intext:Powered by Whatsapp
Date: 01.10.2020

Poc : Powered by Noviindus - SQL Injection vulnerability


Dork: intext:Powered by Noviindus
Date: 30.09.2020

Poc : EP Web Solutions CMS – SQL Injection and XSS Vulnerability


Dork: intext:EPweb or Evergreen Park Web
Date: 29.09.2020

Poc : Design by Chichen-Tech - SQL Injection vulnerability


Dork: intext:Design by Chichen-Tech
Date: 29.09.2020

Poc : Alibaba Group - URL Poisoning


Dork: site:m.*.alibaba.com inurl:/stream.html?
Date: 29.09.2020

Poc : My Office SQL Injection Authentication Bypass


Dork: intext:My Office 2563
Date: 29.09.2020

Poc : WEB SITE BY Synotec Holdings Xpath Injection Vulnerability


Dork: intext:WEB SITE BY: Synotec Holdings (Pvt) Ltd.
Date: 26.09.2020
Poc : Webbuild - Blind Sql Injection Vulnerability
Dork: intext:Design by Webbuild
Date: 25.09.2020

Poc : BigTree CMS 4.4.10 Remote Code Execution


Dork: intext: BigTree CMS
Date: 25.09.2020

Poc : Designed by : Shinja - SQL Injection vulnerability


Dork: intext:Designed by : Shinja Pvt. Ltd.
Date: 24.09.2020

Poc : Google Adservice - Arbitrary Text Reflected


Dork: site:adservice.google.com
Date: 24.09.2020

Poc : MATH4ALL - SQL Injection vulnerability


Dork: news.php?id=6
Date: 23.09.2020

Poc : E-Learning Madrasah - SQL Injection Vulnerabilities


Dork: intitle:E-Learning.Madrasah site:sch.id
Date: 23.09.2020

Poc : ckeditor-elfinder Remote File Upload Vulnerability


Dork: inurl:/vendor/elFinder/elfinder.html
Date: 21.09.2020

Poc : Website Developed by Irsyadi Siradjuddin Indonesian Riau SQL Injection


Dork: intext:Developed by Irsyadi Siradjuddin
Date: 21.09.2020

Poc : MIQPM - SQL Injection vulnerability


Dork: News.php?ID=1
Date: 20.09.2020

Poc : CHELSEALIGHTINGDESIGN - SQL Injection vulnerability


Dork: news.php?id=24
Date: 20.09.2020

Poc : BTACIA - SQL Injection vulnerability


Dork: news.php?id=3
Date: 19.09.2020

Poc : GBACORONA - SQL Injection vulnerability


Dork: news.php?id=6
Date: 19.09.2020

Poc : Microsoft SQL Server Reporting Services 2016 Remote Code Execution
Dork: inurl:ReportViewer.aspx
Date: 18.09.2020

Poc : RWMC - SQL Injection vulnerability


Dork: news.php?id=11
Date: 18.09.2020

Poc : Kelurahan Komet Banjarbaru Kota - SQL Injection


Dork: site:go.id inurl:/berita_detail.php?id=1
Date: 17.09.2020
Poc : Piwigo 2.10.1 Cross Site Scripting
Dork: intext: Powered by Piwigo
Date: 17.09.2020

Poc : Synotec Holdings Sql Injection Vulnerability


Dork: intext:WEB SITE BY: Synotec Holdings (Pvt) Ltd.
Date: 14.09.2020

Poc : FORGERIESONLINE - SQL Injection vulnerability


Dork: products.php?prodID=14
Date: 14.09.2020

Poc : WHISTLERGIFTBASKET - SQL Injection vulnerability


Dork: baskets.php?id=2
Date: 14.09.2020

Poc : SHOWGLADS - SQL Injection vulnerability


Dork: basket.php?action=add&id=84
Date: 14.09.2020

Poc : DYSAUTONOMIAINTERNATIONAL - SQL Injection vulnerability


Dork: page.php?ID=30
Date: 13.09.2020

Poc : FORBROPACK - SQL Injection vulnerability


Dork: product.php?id=10
Date: 13.09.2020

Poc : KYANC - SQL Injection vulnerability


Dork: page.php?id=10
Date: 13.09.2020

Poc : Powered by Media NX - SQL Injection vulnerability


Dork: intext:Powered by Media NX
Date: 13.09.2020

Poc : Amazon Web Services - Database Disclosure (Sensitive Information)


Dork: password site:amazonaws.com filetype:xls
Date: 13.09.2020

Poc : Scopia XT Desktop 8.3.915.4 Cross-Site Request Forgery (change admin


password)
Dork: inurl:scopia+index.jsp
Date: 10.09.2020

Poc : SAMARITERMUENSIGEN - SQL Injection vulnerability


Dork: index.php?id=2
Date: 10.09.2020

Poc : FREESCIENCE - SQL Injection vulnerability


Dork: books.php?id=2
Date: 10.09.2020

Poc : DESIGNINGITALY - SQL Injection vulnerability


Dork: form.php?id=2
Date: 10.09.2020

Poc : Lokomedia CMS - SQL Injection & Bypass SQL Login Vulnerabilities
Dork: inurl:media.php?module= | &id=
Date: 10.09.2020

Poc : Joomla GMapFP J3.5 / J3.5F Arbitrary File Upload


Dork: inurl:com_gmapfp
Date: 08.09.2020

Poc : E-Learning Madrasah (CKEditor) - Injecting Arbitrary Sentences


Dork: intitle:E-Learning.Madrasah site:sch.id
Date: 08.09.2020

Poc : Pengumuman Kelulusan - Bypass SQL Vulnerabilities


Dork: intext:Pengumuman.Kelulusan intext:Masukkan.NISN
Date: 07.09.2020

Poc : Aplikasi Sistem Informasi Kelulusan - Bypass SQL Vulnerabilities


Dork: inurl:/index.html intitle:Admin Tokol DistroIT
Date: 06.09.2020

Poc : SymphonyCMS 3.0.0 Persistent Cross-Site Scripting


Dork: intext:lepton cms
Date: 05.09.2020

Poc : Best Support System v3.0.4 - Authenticated Persistent XSS


Dork: intext:Powered By Best Support System
Date: 05.09.2020

Poc : CANSNASHIK - SQL Injection vulnerability


Dork: photo gallery.php?id=
Date: 04.09.2020

Poc : SKYSTARTRAVELS - SQL Injection vulnerability


Dork: photo gallery.php?id=
Date: 04.09.2020

Poc : ebbuild - SQL Injection vulnerability


Dork: intext:Design by Webbuild
Date: 02.09.2020

Poc : Codegrap - SQL Injection vulnerability


Dork: intext:by Codegrap
Date: 02.09.2020

Poc : Asfaa - SQL Injection vulnerability


Dork: site:asfaa.org inurl:.php?id=
Date: 02.09.2020

Poc : MANIA - SQL Injection vulnerability


Dork: intext:Made by MANIA
Date: 01.09.2020

Poc : Mida eFramework 2.9.0 Remote Code Execution


Dork: Server: Mida eFramework
Date: 31.08.2020

Poc : CRWETECH - SQL Injection vulnerability


Dork: Services.php?ID=
Date: 31.08.2020
Poc : TEJASVANI - SQL Injection vulnerability
Dork: item.php?id=
Date: 31.08.2020

Poc : DEBUG - SQL Injection vulnerability


Dork: item.php?id=
Date: 31.08.2020

Poc : Symphony CMS 3.0.0 Cross Site Scripting


Dork: intext:lepton cms
Date: 30.08.2020

Poc : Buck Softech Pvt. Ltd. Password SQL Injection


Dork: intext:Buck Softech Pvt. Ltd.
Date: 30.08.2020

Poc : Accesstek (Pvt.) Ltd.Password SQL Injection vulnerability


Dork: intext:Copyright © Accesstek (Pvt.) Ltd. All Rights Reserved.
Date: 30.08.2020

Poc : Viper Online – SQL Injection vulnerability


Dork: intext:Website by: Viper Online
Date: 27.08.2020

Poc : QPlusHost - SQL Injection vulnerability


Dork: intext:Powered by QPlusHost.com or Powered by QPC.co.th
Date: 27.08.2020

Poc : HIMALAYA - SQL Injection vulnerability


Dork: content.php?id=
Date: 27.08.2020

Poc : NESTLABORATORY - SQL Injection vulnerability


Dork: content.php?id=
Date: 27.08.2020

Poc : MotionsMedia – Cross Site Scripting


Dork: intext:Site Created by MotionsMedia
Date: 25.08.2020

Poc : Colour Moon – Blind Sql Injection Vulnerability


Dork: intext:Powered by: The Colour Moon
Date: 25.08.2020

Poc : E-Learning Madrasah 2.0 - Arbitary File Upload


Dork: intitle:E-Learning Madrasah - Halaman Login
Date: 23.08.2020

Poc : PNPSCADA 2.200816204020 SQL Injection


Dork: -
Date: 22.08.2020

Poc : Kuicms Php EE 2.0 - Persistent Cross-Site Scripting


Dork: https://kuicms.com/kuicms.zip
Date: 21.08.2020

Poc : PNPSCADA 2.200816204020 interf SQL Injection (Authenticated)


Dork: -
Date: 21.08.2020
Poc : Cisco Adaptive Security Appliance Software 9.7 Unauthenticated Arbitrary File
Deletion
Dork: inurl:/+CSCOE+/
Date: 20.08.2020

Poc : Oleotech Solutions CMS – SQL Injection vulnerability


Dork: intext: Developed by Oleotech Solutions”
Date: 18.08.2020

Poc : Microsoft SharePoint Server 2019 Remote Code Execution


Dork: inurl:quicklinks.aspx
Date: 17.08.2020

Poc : VEDIO - Cross Site Scripting Vulnerability (XSS)


Dork: inurl:search.php?q=
Date: 17.08.2020

Poc : Nscript web studios – SQL Injection and XSS Vulnerability


Dork: intext:Powered by : Nscript web studios
Date: 17.08.2020

Poc : NASLOVI - Cross Site Scripting Vulnerability (XSS)


Dork: inurl:search.php?q=
Date: 17.08.2020

Poc : Home Page Pro CMS Pro Designz Bypass Admin No Redirect
Dork: Powered By : Pro Designz
Date: 17.08.2020

Poc : SHOOWBIZ - Cross Site Scripting Vulnerability (XSS)


Dork: inurl:search.php?q=
Date: 17.08.2020

Poc : Media Network – Blind Sql Injection Vulnerability


Dork: intext:Powered by Media Network
Date: 17.08.2020

Poc : Oleotech Solutions– SQL Injection vulnerability


Dork: intext: Developed by Oleotech Solutions”
Date: 16.08.2020

Poc : Alchemist Digital – SQL Injection vulnerability


Dork: intext:Designed by Alchemist Digital LLC
Date: 16.08.2020

Poc : VETERINER - SQL Injection vulnerability


Dork: home.php?id=
Date: 16.08.2020

Poc : MONITORINGRIS - Cross Site Scripting Vulnerability (XSS)


Dork: inurl:index.php?id=
Date: 16.08.2020

Poc : DIMLE - SQL Injection vulnerability


Dork: home.php?id=
Date: 15.08.2020

Poc : ARDCOLLEGE - SQL Injection vulnerability


Dork: more_details.php?id=
Date: 15.08.2020

Poc : "Web Design Company Nextwebi.com" Password SQL Injection


Dork: intext:Web Design Company Nextwebi.com
Date: 15.08.2020

Poc : "Design by Perfect Software" Password SQL Injection vulnerability


Dork: intext:Design by Perfect Software
Date: 15.08.2020

Poc : Sialweb – SQL Injection vulnerability


Dork: intext:Design And Developed By Sialweb
Date: 15.08.2020

Poc : vabase– Cross Site Scripting vulnerability (xss)


Dork: intext:Powered & Designed by vaBase.com
Date: 14.08.2020

Poc : TRMH - SQL Injection vulnerability


Dork: more_details.php?id=
Date: 12.08.2020

Poc : Astronim Belarus gov CMS SQLi XSS


Dork: intext:Дизайн и программирование” astronim
Date: 11.08.2020

Poc : IDS – SQL Injection vulnerability


Dork: intext:Designed and Developed By IDS
Date: 10.08.2020

Poc : IRIran – SQL Injection vulnerability


Dork: intext:Powered By: IRIran.net
Date: 09.08.2020

Poc : Impression Technologies – SQL Injection vulnerability


Dork: intext:Website | Impression Technologies
Date: 09.08.2020

Poc : AEM Solutions – SQL Injection vulnerability


Dork: intext:Design & Devloped By:AEM Solutions
Date: 09.08.2020

Poc : IBSmng 1.24 - id SQL Injection (Authenticated)


Dork: inurl:index.php inurl:group= inurl:mode=auto
Date: 07.08.2020

Poc : WordPress Plugin Email Subscribers & Newsletters 4.2.2 Unauthenticated File
Download
Dork: intext:Stable tag inurl:wp-content/plugins/email-subscribers/readme.txt
Date: 07.08.2020

Poc : IdeKode Local File Inclusion


Dork: inurl:link=page/berita.php
Date: 06.08.2020

Poc : Seabreeze Consulting – SQL Injection vulnerability


Dork: intext:Seabreeze Consulting
Date: 04.08.2020
Poc : Tycoon Pacific – SQL Injection vulnerability
Dork: intext:Designed by Tycoon Pacific
Date: 03.08.2020

Poc : Design by fajri.com – SQL Injection vulnerability


Dork: intext:Design by fajri.com
Date: 03.08.2020

Poc : Opulent Solutions Design Default Admin Password


Dork: intext:Website Designed & Developed By Opulent Solutions.
Date: 03.08.2020

Poc : Softalgo – SQL Injection vulnerability


Dork: intext:Designed and Developed By Softalgo
Date: 02.08.2020

Poc : ECMD – SQL Injection vulnerability


Dork: intext:Design / ECMD
Date: 02.08.2020

Poc : CMS Sekolahku - Indonesian School HTML Injection


Dork: intext:Powered by sekolahku.web.id
Date: 02.08.2020

Poc : indowebhub Cms Sql Injection


Dork: intext:Powered By www.indowebhub.com & Created by Indowebhub
Date: 30.07.2020

Poc : Konzept - Fullscreen Portfolio WordPress Theme v2.3 - Unauthenticated


Reflected XSS
Dork: inurl:/wp-content/themes/konzept/
Date: 30.07.2020

Poc : Testa 3.4.7 - Online Test Management System - q SQL Injection


Dork: intext:Powered by Testa
Date: 30.07.2020

Poc : Testa OTMS 2.0 - Online Test Management System - uname,pass Time Based SQL
Injection
Dork: intitle:Testa - Online Test Management System
Date: 30.07.2020

Poc : Cisco Adaptive Security Appliance Software 9.7 Arbitrary File Deletion
Dork: inurl:/+CSCOE+/
Date: 30.07.2020

Poc : Virtual Airlines Manager 2.6.2 Persistent Cross-Site Scripting


Dork: inurl:/vam/index_vam_op.php
Date: 27.07.2020

Poc : WordPress Plugin Email Subscribers & Newsletters 4.2.2 hash SQL Injection
(Unauthenticated)
Dork: inurl:wp-content/plugins/email-subscribers/readme.txt
Date: 27.07.2020

Poc : System IT Remote File Upload Vulnerability


Dork: intext:Powered by System IT
Date: 27.07.2020
Poc : FoodBakery | Food Delivery Restaurant Directory WordPress Theme v1.9 -
Unauthenticated Reflected XSS
Dork: inurl:/wp-content/themes/foodbakery/
Date: 27.07.2020

Poc : Geo Magazine | Modern Responsive Newspaper | News Portal WordPress Theme v2.0
- Unauthenticated Reflected XSS
Dork: inurl:/wp-content/themes/geomagazine/
Date: 27.07.2020

Poc : Home Villas | Real Estate WordPress Theme v2.2 - Multiple Vulnerabilities
Dork: inurl:/wp-content/themes/homevillas-real-estate/
Date: 27.07.2020

Poc : JobCareer | Job Board Responsive WordPress Theme v3.4 - Multiple


Vulnerabilities
Dork: inurl:/wp-content/themes/jobcareer/
Date: 27.07.2020

Poc : JobSearch WP Job Board WordPress Plugin v1.5.4 - Unauthenticated Reflected


XSS
Dork: inurl:/wp-content/plugins/wp-jobsearch/
Date: 25.07.2020

Poc : Balitbang Open Redirect Indonesian School Site


Dork: inurl:html/index.php
Date: 25.07.2020

Poc : Careerfy - Job Board WordPress Theme v4.3.0 - Unauthenticated Reflected XSS
Dork: inurl:/wp-content/themes/careerfy/
Date: 25.07.2020

Poc : surena CMS Travel SQL injection


Dork: inurl:php?id= intext:‫تمام حقوق مادی و معنوی این سایت متعلق به سورنا میباشد‬
Date: 23.07.2020

Poc : Real Estate 7 WordPress v3.0.3 - Unauthenticated Reflected XSS


Dork: inurl:/wp-content/themes/realestate-7/
Date: 23.07.2020

Poc : upRedSun Port Forwarding Wizard 4.8.0 and earlier version- SEH based Buffer
Overflow in Register
Dork: Port Forwarding Wizard buffer overflow
Date: 23.07.2020

Poc : Workup – Job Board WordPress Theme v2.1.5 - Unauthenticated Reflected XSS
Dork: inurl:/wp-content/themes/workup/
Date: 21.07.2020

Poc : Workio – Job Board WordPress Theme v1.0.1 - Unauthenticated Reflected XSS
Dork: inurl:/wp-content/themes/workio/
Date: 21.07.2020

Poc : Careerfy - Job Board WordPress Theme v4.2.0 - Unauthenticated Reflected XSS
Dork: inurl:/wp-content/themes/careerfy/
Date: 21.07.2020

Poc : JobSearch WP Job Board WordPress Plugin v1.5.2 - Multiple Vulnerabilities


Dork: inurl:/wp-content/plugins/wp-jobsearch/
Date: 21.07.2020

Poc : CarePlus - Health & Medical Responsive WordPress Theme v1.2 - Unauthenticated
Reflected XSS
Dork: inurl:/wp-content/themes/careplus/
Date: 21.07.2020

Poc : InJob | Multi features for recruitment WordPress Theme v3.4.0 - Authenticated
Reflected XSS
Dork: inurl:/wp-content/themes/injob/
Date: 21.07.2020

Poc : Powered By Hepta Infotech Services LLP SQL injection


Dork: intext:Powered By Hepta Infotech Services LLP inurl:gallery-details.php?
cat_id=
Date: 21.07.2020

Poc : Powered by BOOMER SQL injection


Dork: inurl:php?id= intext:Powered by BOOMER
Date: 20.07.2020

Poc : Powered By AlamWahdIT SQL injection


Dork: inurl:php?id= intext:Powered By : AlamWahdIT
Date: 19.07.2020

Poc : Reality | Estate Multipurpose WordPress Theme v2.5.5 - Unauthenticated


Reflected XSS
Dork: inurl:/wp-content/themes/reality/
Date: 18.07.2020

Poc : JobSearch WP Job Board WordPress Plugin v1.5.1 - Multiple Vulnerabilities


Dork: inurl:/wp-content/plugins/wp-jobsearch/
Date: 18.07.2020

Poc : PMB 5.6 Cross Site Scripting


Dork: inurl:opac_css
Date: 18.07.2020

Poc : Careerfy - Job Board WordPress Theme v4.0.0 - Multiple Vulnerabilities


Dork: inurl:/wp-content/themes/careerfy/
Date: 18.07.2020

Poc : Travel Booking WordPress Theme v2.8.3 - Multiple Vulnerabilities


Dork: inurl:/wp-content/themes/traveler/
Date: 17.07.2020

Poc : Reality | Estate Multipurpose WordPress Theme v2.5.3 - Multiple Reflected XSS
Dork: inurl:/wp-content/themes/reality/
Date: 17.07.2020

Poc : Careerfy - Job Board WordPress Theme v3.9.0 - Multiple Vulnerabilities


Dork: inurl:/wp-content/themes/careerfy/
Date: 17.07.2020

Poc : Infor Storefront B2B 1.0 usr_name SQL Injection


Dork: inurl:storefrontb2bweb
Date: 16.07.2020
Poc : ‫ االحالم ديزاين‬sql injection
Dork: intext:‫برمجة وتصميم مجموعة االحالم ديزاين‬
Date: 14.07.2020

Poc : Information Village Sql Injection


Dork: intext:Powered by Information Village
Date: 14.07.2020

Poc : Unicus – SQL Injection vulnerability


Dork: intext:Powered by Unicus
Date: 14.07.2020

Poc : Wordpess Jannah Theme |Stored XSS


Dork: Index of /wp-content/themes/jannah/
Date: 13.07.2020

Poc : PennDev – SQL Injection vulnerability


Dork: intext:Site Development: PennDev, LLC or PennDev, LLC
Date: 13.07.2020

Poc : Golo - City Travel Guide WordPress Theme v1.3.2 - Unauthenticated Reflected
XSS
Dork: inurl:/wp-content/themes/golo/
Date: 13.07.2020

Poc : CareerUp - Job Board WordPress Theme v2.3.0 - Unauthenticated Reflected XSS
Dork: inurl:/wp-content/themes/careerup/
Date: 13.07.2020

Poc : Prolisting - Directory Listing WordPress Theme v1.2 - Unauthenticated


Reflected XSS
Dork: inurl:/wp-content/themes/prolist/
Date: 13.07.2020

Poc : HomeSweet - Real Estate WordPress Theme v1.4 - IDOR leading to arbitrary
deletion of ads
Dork: inurl:/wp-content/themes/homesweet/
Date: 13.07.2020

Poc : Jetapo | Jobboard WordPress Theme v1.0.0 - Unauthenticated Reflected XSS


Dork: inurl:/wp-content/themes/jetapo/
Date: 13.07.2020

Poc : Monalisa | Hotel & Resort WordPress Theme v2.1.2 - Unauthenticated Reflected
XSS
Dork: inurl:/wp-content/themes/monalisa/
Date: 13.07.2020

Poc : Kormosala – Job Board WordPress Theme v1.0.22 - Unauthenticated Reflected XSS
Dork: inurl:/wp-content/themes/kormosala/
Date: 13.07.2020

Poc : Vista Panel - XSS Vulnerability


Dork: intitle:VP Login
Date: 13.07.2020

Poc : CSoftNet – Blind SQL Injection vulnerability


Dork: intext:Web Solution by CSoftNet
Date: 12.07.2020
Poc : ATOM STUDIO – Cross Site Scripting & SQL Injection vulnerability
Dork: intext:Designed by ATOM STUDIO
Date: 12.07.2020

Poc : Antarees Technologies – SQL Injection vulnerability


Dork: intext:Website Developed By : Antarees Technologies
Date: 11.07.2020

Poc : HelloWeb 2.0 Arbitrary File Download


Dork: inurl:exec/file/download.asp
Date: 11.07.2020

Poc : Geotrent – SQL Injection vulnerability


Dork: intext:Developed & hosted by Geotrent
Date: 09.07.2020

Poc : gsonline – SQL Injection vulnerability


Dork: intext:Powered by: gsonline WebNDesign
Date: 09.07.2020

Poc : Ciber Web Design – SQL Injection vulnerability


Dork: intext:Created By: Ciber Web Design
Date: 07.07.2020

Poc : REPLICA WATCHES – SQL Injection vulnerability


Dork: intext:DESENVOLVIDO POR REPLICA WATCHES
Date: 07.07.2020

Poc : IT InfoTech Solution – SQL Injection vulnerability


Dork: intext:Designed by IT InfoTech Solution
Date: 07.07.2020

Poc : MINMAX – SQL Injection vulnerability


Dork: intext:Designed by MINMAX
Date: 07.07.2020

Poc : Brandbugle – SQL Injection vulnerability


Dork: intext:Powered by: Brandbugle
Date: 05.07.2020

Poc : EATAN – SQL Injection vulnerability


Dork: intext:Designed by 易透網
Date: 04.07.2020

Poc : MOBOTIX Live camera Vulnerability


Dork: inurl:/control/userimage.html
Date: 04.07.2020

Poc : ZenTao Pro 8.8.2 - Command Injection Dork


Dork: inurl:/zentao/user-login.html
Date: 04.07.2020

Poc : DataSoft Forum TR SQL Injection


Dork: inurl:forumdisplay.php?fid= DataSoft
Date: 02.07.2020

Poc : Everywhere – SQL Injection vulnerability


Dork: intext:Design by Everywhere
Date: 02.07.2020

Poc : Health Insurance Organization of the Islamic Republic of Iran SQL INJECTION
Vulnerabilities
Dork: site:gov.ir index.php?id=1
Date: 02.07.2020

Poc : TYPO3 CMS SQL Injection


Dork: inurl:index.php?id= TYPO3 CMS
Date: 01.07.2020

Poc : Open eClass SQL Injection


Dork: inurl:/modules/auth/opencourses.php?fc= Open eClass
Date: 30.06.2020

Poc : Developed by Desh Universal Limited SQL Injection


Dork: inurl:/messages?message?id= site:edu.bd Desh Universal Limited
Date: 30.06.2020

Poc : Reside Property Management 3.0 profile SQL Injection


Dork: intext:Copyright 2020 Reside Property Management
Date: 30.06.2020

Poc : Nexos - Real Estate WordPress Theme v1.7 - Multiple Vulnerabilities


Dork: inurl:/wp-content/themes/nexos/
Date: 29.06.2020

Poc : Design by AlamWahdIT SQL Injection


Dork: intext:Powered by: AlamWahdIT
Date: 29.06.2020

Poc : Design by WAN IT Ltd. SQL Injection Vulnerability


Dork: intext:Design & Developed by WAN IT Ltd.
Date: 29.06.2020

Poc : TechSparkIT Design SQL Injection


Dork: inurl:/site/dynamic-content?id= TechSparkIT
Date: 29.06.2020

Poc : Dynamic Experts Solution Design Default Admin Password


Dork: intext:Designed & Developed By : Dynamic Experts Solution
Date: 29.06.2020

Poc : Atrium SQL Injection Vulnerability


Dork: inurl:/image_info.php?img=
Date: 27.06.2020

Poc : Bangladesh EDU CMS SQL Injection => Recovery Login Info
Dork: inurl:/admission/recovery/ site:edu.bd
Date: 27.06.2020

Poc : Judiciary affiliated site SQL INJECT Vulnerabilitie


Dork: inurl:ghanoonban.ir/blog/7?obligationId=
Date: 26.06.2020

Poc : Mihalism Multi Host v 5.0 XSS Vulnerabilities


Dork: intext:powered by Mihalism Multi Host
Date: 26.06.2020
Poc : Travel Booking WordPress Theme v2.8.1 - Unauthenticated Reflected XSS
Dork: inurl:/wp-content/themes/traveler/
Date: 22.06.2020

Poc : TownHub - Directory & Listing WordPress Theme v1.2.9 - Unauthenticated


Reflected XSS
Dork: inurl:/wp-content/themes/townhub/
Date: 22.06.2020

Poc : Neetai Tech – SQL Injection vulnerability


Dork: intext:Designed by Neetai Tech
Date: 22.06.2020

Poc : Neetai Tech – SQL Injection vulnerability


Dork: intext:Designed by Neetai Tech
Date: 22.06.2020

Poc : CityBook - Directory & Listing WordPress Theme v2.4.3 - Unauthenticated


Reflected XSS
Dork: inurl:/wp-content/themes/citybook/
Date: 22.06.2020

Poc : : Lógico y Creativo CMS - SQL Injection vulnerability


Dork: intext:Desarrollo: Lógico y Creativo
Date: 21.06.2020

Poc : detail_popup Cross Site Scripting (XSS)


Dork: inurl:/detail_popup.php?img=
Date: 20.06.2020

Poc : Iran-Tech CMS Travel SQL Injection


Dork: [intext:‫ ایران تکنولوژی‬:‫ && ]طراحی سایت‬find portfolio from here :
http://www.iran-tech.com/portfolio/
Date: 20.06.2020

Poc : TABS MailCarrier 2.51 - EHLO SEH Based Remote Buffer Overflow
Dork: MailCarrier exploit
Date: 20.06.2020

Poc : SmarterMail 16 Arbitrary File Upload


Dork: inurl:/interface/root
Date: 17.06.2020

Poc : Chichen-Tech – SQL Injection vulnerability


Dork: intext:Design by Chichen-Tech
Date: 14.06.2020

Poc : Powered by © 2019 All Rights Reserved by MTech Default U/P admin
Dork: Powered by © 2019 All Rights Res[+]erved by MTech
Date: 13.06.2020

Poc : Qualcomm WorldMail 3.0 - IMAPd Remote Buffer Overflow in LOGIN command
Dork: https://github.com/sartlabs/OSCE-Prep/blob/master/Qualcomm_IMAP_Login_BOF.py
Date: 13.06.2020

Poc : Oriol Espinal CMS 1.0 id SQL Injection


Dork: inurl:/eotools_share/
Date: 12.06.2020
Poc : Powered By iByte Solutions - SQL Injection
Dork: intext:Powered By iByte Solutions inurl:id=
Date: 08.06.2020

Poc : Virtual Airlines Manager 2.6.2 SQL Injection


Dork: inurl:notam_id=
Date: 08.06.2020

Poc : News website CMS SQL injection & Bypass Admin Panel & XSS Vulnerability &
Remote code Execution By Aryan Chehreghani
Dork: inurl:php?id= intext:Design By Dassinfotech.com
Date: 05.06.2020

Poc : MiniShare 1.4.1 - PUT Remote Buffer Overflow, allows remote attackers to
execute arbitrary code via a long HTTP PUT request.
Dork:
https://github.com/sartlabs/OSCE-Prep/blob/9a9d2471a9de09457f970be4ea1b57a74d26705a
/My
20CVEs/Minishare_BOF_PUT.py
Date: 05.06.2020

Poc : Dtell Cross Site Scripting


Dork: intext:Designed by Dtell
Date: 03.06.2020

Poc : Infomedia Web Solutions Cross Site Scripting


Dork: intext:Developed by: Infomedia Web Solutions
Date: 02.06.2020

Poc : Advertroindia Cross Site Scripting


Dork: intext:Copyrights Advertroindia
Date: 01.06.2020

Poc : Zoom Web Media - Admin Login bypass


Dork: intext:Powered By Zoom Web Media
Date: 01.06.2020

Poc : Taiwanese Travel Websites Local File Inclusion


Dork: intext:COPYRIGHT inurl:?page=regulation.php
Date: 28.05.2020

Poc : Novaworks Local File Inclusion


Dork: intext:Novaworks inurl:.php?
Date: 27.05.2020

Poc : Chamilo © 2020 Campus v1 ElFinder Backdoor Access Shell Upload Vulnerability
Dork: Powered by Chamilo © 2020 site:com
Date: 27.05.2020

Poc : Websites of Iranian travel agencies By Aryan chehreghani


Dork: [inurl:php?id= intext:‫ ایران تکنولوژی‬: ‫]طراحی وب سایت‬
Date: 26.05.2020

Poc : Dassinfotech CMS SQL Injection Bypass Admin Vulnerability


Dork: intext:Design by Dassinfotech.com
Date: 25.05.2020

Poc : Default U/P admin on Powered by © 2019 All Rights Reserved by MTech
Websolution
Dork: Powered by © 2019 All Rights Reserved by MTech
Date: 22.05.2020

Poc : Powered by IZYWEBSTORE - Indonesian Academy XSS Vulnerability


Dork: intext:powered by izywebstore.com
Date: 22.05.2020

Poc : DGinteractive Internet Automobile XSS SQL Injection


Dork: DGinteractive : création de site internet automobile
Date: 21.05.2020

Poc : Zone-Xsec Stored XSS PoC


Dork: intext:Zone-Xsec
Date: 19.05.2020

Poc : Powered By Magical Cloud - SQL Injection


Dork: intext:Powered By Magical Cloud
Date: 17.05.2020

Poc : Powered By iByte Solutions - SQL Injection


Dork: intext:Powered By iByte Solutions
Date: 17.05.2020

Poc : 2018 © ‫ جميع الحقوق محفوظة لمعهد صناعة الحياة للتدريب واالستشارات‬SQL
Injection Vulnerability
Dork: intext:2018 © ‫جميع الحقوق محفوظة لمعهد صناعة الحياة للتدريب واالستشارات‬
Date: 17.05.2020

Poc : Powered By AryaNet - SQL Injection


Dork: intext:by AryaNet inurl:.php?id=
Date: 17.05.2020

Poc : Netlink XPON 1GE WiFi V2801RGW Remote Command Execution


Dork: Not applicable
Date: 17.05.2020

Poc : Power-eCommerce SQL Injection Vulnerability


Dork: intext:Powered by Power-eCommerce
Date: 12.05.2020

Poc : Joomla Component prayercenter id SQL Injection Vulnerability


Dork: inurl:index.php?option=com_prayercenter
Date: 12.05.2020

Poc : cpCommerce 1.2.8 id_document Blind SQL Injection


Dork: intext:Powered by cpcommerce
Date: 11.05.2020

Poc : ICTECH Blind SQL Injection


Dork: intext:Powered by ICTECH php?id=
Date: 09.05.2020

Poc : TipTopLand CMS - Local File Inclusion Vulnerability


Dork: intext:TipTopLand Design Studio
Date: 09.05.2020

Poc : Joomla Component com_hotel Xss


Dork: inurl:index.php?option=com_hotel
Date: 06.05.2020
Poc : SimplePHPGal 0.7 Remote File Inclusion
Dork: intext:Created with Simple PHP Photo Gallery
Date: 06.05.2020

Poc : DESIGNED & DEVELOPED BY : CREATIVE-ZONE SQL Injection


Dork: inurl:/about.php?id=
Date: 05.05.2020

Poc : Transinfo Solutions SQL Injection


Dork: intext:Powered By: Transinfo Solutions
Date: 05.05.2020

Poc : johncaruso PHP Photo Gallery Remote File Inculsion Vulnerability [ RFI ]
Dork: intext:Created with Simple PHP Photo Gallery
Date: 05.05.2020

Poc : WordPress Themes begin-its-1 Remote File Inclusion


Dork: inurl:/wp-content/themes/begin-lts-1/inc/go.php?url=
Date: 05.05.2020

Poc : Joomla com_content 1.5 - Blind SQL Vulnerability


Dork: inurl:index.php?option=com_content
Date: 04.05.2020

Poc : Propellogic SQL Injection


Dork: intext:Powered By : - Propellogic It Solutions Pvt Ltd
Date: 04.05.2020

Poc : Transinfo Solutions Cross Site Scripting (XSS)


Dork: intext:Powered By: Transinfo Solutions
Date: 04.05.2020

Poc : dreams SQL Injection


Dork: intext:‫برمجة وتصميم مجموعة االحالم ديزاين‬
Date: 04.05.2020

Poc : Web Designed by studio03 sql Injection


Dork: inurl: asp?id= intext:Nu.Me.D. Nuclear Medicine Discovery © 2020 - Webmaster
Date: 03.05.2020

Poc : saudi softech SQL Injection


Dork: intext:Designed By: SAUDI SOFTECH (MST)
Date: 03.05.2020

Poc : filemanager File Upload vulnerability


Dork: inurl:/ckeditor/filemanager/
Date: 03.05.2020

Poc : jardcs - sql injection


Dork: intext:© JARDCS 2020 All right reserved
Date: 02.05.2020

Poc : Web Designed by Valiant SQL Injection


Dork: inurl: php?id= Website Design by Valiant Media
Date: 02.05.2020

Poc : PlaySMS Unauthenticated Remote Code Execution Shell Upload


Dork: inurl:?app=main intitle:sms
Date: 28.04.2020

Poc : Interphoto Remote file upload


Dork: intext:interphoto register
Date: 27.04.2020

Poc : CMS Sangihe Bypass Sql Login Vulnerable


Dork: intext:Made with by CV. Karya Anak Sangihe.
Date: 26.04.2020

Poc : Catch Breadcrumb v1.5.4 WordPress plugin - Unauthenticated Reflected XSS


Dork: inurl:/wp-content/plugins/catch-breadcrumb/
Date: 22.04.2020

Poc : Car Dealer 5 SQL Injection


Dork: intext:Website powered by Car Dealer 5 inurl:/sold.php
Date: 21.04.2020

Poc : PMB 5.6 SQL Injection


Dork: inurl:opac_css
Date: 21.04.2020

Poc : jizhi CMS 1.6.7 Arbitrary File Download


Dork: jizhicms
Date: 21.04.2020

Poc : ImageUploader Vulnerable


Dork: index of /plugins/ckeditor/plugins/imageuploader/
Date: 21.04.2020

Poc : Web Designed by MaxPower SQL Injection


Dork: inurl: php?id= powered by max
Date: 20.04.2020

Poc : LifeRay File Upload (CKEditor Vulnerable)


Dork: inurl:/ckeditor/editor/filemanager/
Date: 20.04.2020

Poc : Windu 3.1 => SQL Inj & RCE


Dork: intextt:Na silniku: windu.org
Date: 19.04.2020

Poc : Designed and Developed by Vibhuti Infotech - Bypass Admin


Dork: intext:Designed and Developed by Vibhuti Infotech
Date: 15.04.2020

Poc : MOVEit Transfer 11.1.1 token Unauthenticated SQL Injection


Dork: inurl:human.aspx intext:moveit
Date: 15.04.2020

Poc : Vorood Admin Login Bypass


Dork: inurl:vorood.php
Date: 12.04.2020

Poc : adak-co.ir CMS Sql Injection


Dork: intext:‫ شرکت آداک‬:‫ طراحی و اجرا‬inurl:/NewsDetails.aspx?NewsId=
Date: 12.04.2020

Poc : f1softech sql injection


Dork: intext:Designed & Developed By : F1Softech Servies
Date: 12.04.2020

Poc : Xeroneit Library Management System 3.0 SQL Injection


Dork: intext:LMS v3.0 - Xerone IT
Date: 11.04.2020

Poc : eform 3solutions Arbitrary File Upload


Dork: inurl:/modules/eform/globals/upload/
Date: 10.04.2020

Poc : LifeRay CMS (Fckeditor) Arbitrary File Upload Vulnerability


Dork: inurl:/web/guest/
Date: 10.04.2020

Poc : SitesPlus England SQL Injection


Dork: intext:Build your own website with SitesPlus inurl:/catalogue.php
Date: 09.04.2020

Poc : Developed by INOVINDO WEB - SQL Injection Vulnerabellity


Dork: intext:Developed by INOVINDO WEB
Date: 06.04.2020

Poc : SAUDI SOFTECH (MST) search.php Sql injection


Dork: intext: Designed by SAUDI SOFTECH (MST)
Date: 04.04.2020

Poc : balajicms Auth by pass Vulnerability


Dork: Copyright © KAAHGO INFOTECH | GRIEVANCES REDRESSAL CELL
Date: 04.04.2020

Poc : Biddokkes Polda SQL Injection


Dork: inurl:?act=berita
Date: 04.04.2020

Poc : 2020 © ClasesIT - SIREA. Derechos reservados Admin Panel Bypass Exploit
Dork: intext:2020 © ClasesIT - SIREA. Derechos reservados (edu.ve)
Date: 04.04.2020

Poc : Hacker Factor Local File Inclusion Vulnerability


Dork: intext:Copyright 2012-2020 Hacker Factor inurl:faq.php?
Date: 03.04.2020

Poc : Website Iranian .EDU admin Bypassing


Dork: site:.ir admin login.php
Date: 31.03.2020

Poc : WordPress Eatery Restaurant Themes 2.2 Open Redirection


Dork: inurl:/wp-content/themes/eatery/
Date: 30.03.2020

Poc : Design by DheerSoftwareSolutions - Bypass Admin


Dork: intext:intext:Design by DheerSoftwareSolutions site:.in
Date: 30.03.2020

Poc : Zen Load Balancer 3.10.1 Remote Code Execution


Dork: no
Date: 30.03.2020
Poc : DesignMasterEvents CMS 1.0 SQL Injection / Cross Site Scripting
Dork: intext:by :Design Master Events
Date: 30.03.2020

Poc : Joomla Fabrik 3.9.11 Directory Traversal


Dork: inurl:index.php?option=com_fabrik
Date: 30.03.2020

Poc : Webexcels Ecommerce CMS 2.x SQL Injection / Cross Site Scripting
Dork: intext:intext: By WEB EXCELS +inurl:?Id=
Date: 29.03.2020

Poc : WordPress Randy Peterman Murph StatTraq 1.1 SQL Injection


Dork: StatTraq 1.1 Maintained by Murph.
Date: 29.03.2020

Poc : LeptonCMS 4.5.0 Cross Site Scripting


Dork: intext:lepton cms
Date: 29.03.2020

Poc : Brand Group International Oy Finland SQL Injection


Dork: inurl:/product-list.php?pageNum_recP= site:fi
Date: 29.03.2020

Poc : Taylor Morrison Evergreen-LM Vertilinc Neighborhood SQL Injection


Dork: inurl:/std.php?lID=
Date: 29.03.2020

Poc : Developed by :: SysPro Computers, Nandgaon 8421025839 Admin Panel Bypass


Vulnerability
Dork: intext:Developed by :: SysPro Computers, Nandgaon 8421025839
Date: 28.03.2020

Poc : SAIN tags Cross Site Scripting (XSS)


Dork: inurl:p_r_p_564233524_tag= intext:‫تهیه شده در سپهر افزار ایرانیان‬
Date: 28.03.2020

Poc : CMS dagenDin Norway XSS SQL Injection


Dork: CMS dagenDin inurl:/index.php?f= site:no
Date: 27.03.2020

Poc : Soluzione Globale Ecommerce CMS 1 SQL Injection


Dork: intext: Soluzione Globale s.r.l.s. +inurl:/.php?id=
Date: 27.03.2020

Poc : SharePoint Workflows XOML Injection


Dork: intext: By Sial Web +inurl:/.php?id=
Date: 25.03.2020

Poc : SharePoint Workflows XOML Injection


Dork: intext:lepton cms
Date: 25.03.2020

Poc : SharePoint Workflows XOML Injection


Dork: intext:lepton cms
Date: 25.03.2020

Poc : SharePoint Workflows XOML Injection


Dork: inurl:/wp-content/themes/eatery/
Date: 25.03.2020

Poc : SharePoint Workflows XOML Injection


Dork: intext: Soluzione Globale s.r.l.s. +inurl:/.php?id=
Date: 25.03.2020

Poc : SharePoint Workflows XOML Injection


Dork: intext: Soluzione Globale s.r.l.s. +inurl:/.php?id=
Date: 25.03.2020

Poc : SialWeb CMS eCommerce 1.0 / 1.1 Cross Site Scripting / SQL Injection
Dork: intext: By Sial Web +inurl:/.php?id=
Date: 25.03.2020

Poc : Joomla GMapFP 3.30 Arbitrary File Upload


Dork: inurl:com_gmapfp
Date: 25.03.2020

Poc : Dinamik İşler Tasarım ve Tanıtım Hizmetleri - Bypass Admin Panel with
Noredirect
Dork: /sayfa/form/01/iletisimformu
Date: 24.03.2020

Poc : Strassen24 Panomizer XSS SQL Injection


Dork: Wohltorf Immobilien - Ludolfingerplatz
Date: 24.03.2020

Poc : Joomla! com_hdwplayer 4.2 search.php SQL Injection


Dork: inurl:index.php?option=com_hdwplayer
Date: 24.03.2020

Poc : WordPress Grimag Themes 1.2.5 Open Redirection


Dork: inurl:/wp-content/themes/Grimag/
Date: 24.03.2020

Poc : WordPress FxInfinityTheme Themes 2.2.1 Open Redirection Remote File Inclusion
Dork: inurl:/wp-content/themes/fxinfinitytheme/
Date: 24.03.2020

Poc : WordPress Upward Themes 1.5 Open Redirection


Dork: inurl:/wp-content/themes/Upward/
Date: 24.03.2020

Poc : dyephotographic sql injection


Dork: intext:Design, implementation, and photography by dyePhotographic
Date: 23.03.2020

Poc : EnovaNet Chateau-Thierry FormaLog WebService02 eChampagne 7.0 XSS SQL


Injection
Dork: intext:Création enovanet - Moteur eChampagne 7.0
Date: 23.03.2020

Poc : Worldviewer Admin Panel Bypass


Dork: intext:Created by: Worldviewer.in.
Date: 22.03.2020

Poc : RedGreenBD ITS SQL Injection


Dork: intext:Powered by RedGreenBD IT Solutions. inurl:.php?id=
Date: 22.03.2020
Poc : WEBONLYWEB IT SOLUTION - SQL Injection
Dork: intext:Theme Developed By WebOnlyWeb
Date: 22.03.2020

Poc : Intouch group - SQL Injection


Dork: intext:Design & Developed by: Intouch Group inurl:.php?id=
Date: 22.03.2020

Poc : Maptek Softwares LLP - SQL Injection


Dork: intext:Powered by Maptek inurl:.php?id=
Date: 22.03.2020

Poc : Koha GreenStone Library 3.x Open Redirection


Dork: inurl:/greenstone/cgi-bin/
Date: 22.03.2020

Poc : Daktilo News Software 1.9 Open Redirection


Dork: intext:daktilo haber yazılımı v1.9
Date: 22.03.2020

Poc : Created by SR Edu Solutions - Bypass Admin


Dork: intext:Created By SR Edu
Date: 22.03.2020

Poc : ENS Consultants SQL Injection


Dork: intext:Designed & Developed by ENS
Date: 22.03.2020

Poc : Oracle E-Business Suite Default credentials vulnerability


Dork: inurl:/OA_HTML/RF.jsp
Date: 21.03.2020

Poc : Azerbaijan Proqres IPX SQL Injection


Dork: intext:Designed by: Proqres IPX
Date: 21.03.2020

Poc : Chrisans Web Solutions - Bypass Adminpanel with Noredirect


Dork: intext:Powered by Chrisans Web Solutions
Date: 21.03.2020

Poc : Websco-Innovations SQL Injection


Dork: inurl:/index.php?id_menu= site:fr
Date: 19.03.2020

Poc : PixeHub SQL Injection


Dork: intext:Designed By PixeHub.com
Date: 19.03.2020

Poc : WordPress Custom-BackGround Plugins 3.0 CSRF Shell Upload Vulnerability


Dork: inurl:/wp-content/plugins/custom-background/
Date: 19.03.2020

Poc : Fujtech SQL Injection


Dork: intext:Designed & Developed By Fujtech
Date: 18.03.2020

Poc : Global Dream Apna School Software Admin Login bypass


Dork: intext:Global Dream Apna School Software
Date: 18.03.2020

Poc : Joomla Component com_newsfeeds SQL injection vulnerability


Dork: inurl:index.php?option=com_newsfeeds
Date: 16.03.2020

Poc : MiladWorkShop VIP System 1.0 SQL Injection


Dork: Powered By MiladWorkShop VIP System
Date: 16.03.2020

Poc : EVO-CRM Script Multi Vulnerability


Dork: intext:Sito web realizzato da OperaGrafica
Date: 14.03.2020

Poc : ГБОУ ПОО ztte sql injection


Dork: intext:ГБОУ ПОО Златоустовский техникум технологий и экономики
Date: 14.03.2020

Poc : New IMCE Dir Exploit for Hacking Drupal Websites


Dork: inurl:/imce?dir=
Date: 12.03.2020

Poc : AtMail Webmail Open Redirect


Dork: inurl:/atmail/parse.pl or /mail/parse.pl
Date: 11.03.2020

Poc : IRISgraphic sql injection


Dork: intext:Powered by www.IRISgraphic.com
Date: 08.03.2020

Poc : UniSharp Laravel File Manager 2.0.0 Arbitrary File Read


Dork: inurl:laravel-filemanager?type=Files -site:github.com -site:github.io
Date: 04.03.2020

Poc : ‫حمار‬SHELL UPLOAD


Dork: intitle:‫الحمير‬
Date: 04.03.2020

Poc : GUnet OpenEclass 1.7.3 SQL Injection


Dork: intext:© GUnet 2003-2007
Date: 04.03.2020

Poc : Wing FTP Server 6.2.5 Privilege Escalation


Dork: intitle:Wing FTP Server - Web
Date: 03.03.2020

Poc : İstanbul Teknik University XSS vul


Dork: allintext: www.ehb.itu.edu.tr/
Date: 03.03.2020

Poc : Horizon gov Blind Sql


Dork: intext:Created by Horizon s.r.l.s. inurl:sec=
Date: 03.03.2020

Poc : Rosependar IRANIAN CMS SQL injection


Dork: intext:Powered By RoseCms inurl:sec=
Date: 27.02.2020

Poc : Powered by COCSSYS Infotech - Bypass Admin


Dork: intext:All rights reserved | Powered by COCSSYS Infotech Pvt. Ltd.
Date: 22.02.2020

Poc : Indonesian School - SQL Lokomedia Vulnerability


Dork: inurl:/hal-visi-misi.html site:.sch.id
Date: 22.02.2020

Poc : Element Ajans Scripts Local File Inclusion Vulnerability


Dork: intext:Copyrigt © 2019 Element Ajans ®
Date: 22.02.2020

Poc : colorcode - Bypass admin


Dork: intext:Designed & Developed By colorcode
Date: 22.02.2020

Poc : Tom Cowan - Bypass admin with Noredirect


Dork: intext:Website by Tom Cowan
Date: 22.02.2020

Poc : Pengadilan Negeri Sidrap - SQL Injection


Dork: intext:Pengadilan Negeri Sidrap
Date: 21.02.2020

Poc : Techoriginator - Bypass admin


Dork: intext:Designed by Techoriginator
Date: 20.02.2020

Poc : Rainhopes - Bypass admin with Noredirect


Dork: intext:Powered by Rainhopes
Date: 20.02.2020

Poc : Komquest Solutions - SQL Injection & Bypass admin Noredirect


Dork: intext:Powered by Komquest Solutions
===================================================================================
Date: 19.02.2020

Poc : WordPress Fruitful 3.8 Cross Site Scripting


Dork: intext:Fruitful theme by fruitfulcode Powered by: WordPress intext:Comment
intext:Leave a Reply
Date: 19.02.2020

Poc : Indian Travel - SQL Injection Vulnerability


Dork: intext:© 2018 - Travel Of India Powered By Channel Softech inurl:php?id=
Date: 18.02.2020

Poc : Indonesian Shop - SQL Injection Vulnerability


Dork: inurl:/produk.php?id= site:.id
Date: 17.02.2020

Poc : Innovinc International Script Local File Download Vulnerability


Dork: inurl:/importantdates intext:Innovinc International
Date: 14.02.2020

Poc : CHIYU BF430 TCP IP Converter Cross Site Scripting


Dork: In Shodan search engine, the filter is CHIYU
Date: 12.02.2020

Poc : PackWeb Formap E-learning 1.0 SQL Injection


Dork: intitle: PackWeb Formap E-learning
Date: 11.02.2020

Poc : Des-Click 1.0.0 - Error Based SQL Injection Vulnerability


Dork: inurl:mobile/produit.php?id_famille=
Date: 10.02.2020

Poc : Des-click 1.0.0 - Reflective cross site scripting


Dork: inurl:mobile/produit.php?titlefamille=
Date: 09.02.2020

Poc : AdSerfvices Inc. - SQL Injection vulnerability


Dork: intext:Web design & development by AdServices Inc. inurl:.php?id=
Date: 03.02.2020

Poc : Created by Paperless - SQL Injection


Dork: intext:© Created by Paperless inurl:php?id=
Date: 03.02.2020

Poc : EDJE Technologies - SQL Injection vulnerability


Dork: intext:Website Design by Fee Creative inurl:.php?id
Date: 01.02.2020

Poc : EDJE Technologies - SQL Injection vulnerability


Dork: intext:Website Design by Fee Creative inurl:.php?id
Date: 01.02.2020

Poc : Citrix XenMobile Server 10.8 XML External Entity Injection


Dork: inurl:zdm logon
Date: 31.01.2020

Poc : Powered By baanwesite SQL injection


Dork: intext:Powered By baanwebsite inurl:.php?id=
Date: 30.01.2020

Poc : Kibana 6.6.1 CSV Injection


Dork: inurl:/app/kibana intitle:Kibana
Date: 30.01.2020

Poc : Powered By Schoolsindia.Com SQl injection / El Behram


Dork: intext:Powered By Schoolsindia.Com inurl:.php?id=
Date: 30.01.2020

Poc : IceWarp WebMail Cross-Site Scripting Vulnerability


Dork: inurl:/webmail/ intext:Powered by IceWarp Server
Date: 29.01.2020

Poc : Newsite CMS Sql Injection Vulnerability


Dork: site:uz inurl:/content.php?q=
Date: 29.01.2020

Poc : ATC India - Express Delivery, Courier & Shipping Services Admin Login bypass
Dork: intext:Designed By Afireweb
Date: 28.01.2020

Poc : IceWarp WebMail 11.4.4.1 Cross Site Scripting


Dork: inurl:/webmail/ intext:Powered by IceWarp Server
Date: 28.01.2020

Poc : OLK Web Store 2020 Cross Site Request Forgery


Dork: intext:TopManage ® 2002 - 2020
Date: 25.01.2020

Poc : Devloped by MONIKA ARYA SQLi


Dork: intext: Devloped by MONIKA ARYA
Date: 24.01.2020

Poc : qdPM 9.1 Remote Code Execution


Dork: intitle:qdPM 9.1. Copyright © 2020 qdpm.net
Date: 23.01.2020

Poc : Shopsystem WebanOS SQL Injection


Dork: inurl:/index.php?mode=versand_uebersicht site:de
Date: 23.01.2020

Poc : ECTouch ECShop v2.7.3 SQL Injection


Dork: inurl:/mobile/index.php?m=default site:cn
Date: 22.01.2020

Poc : WordPress WP Fanzone 3.1 SQL Injection


Dork: Built with WordPress and WP FanZone site:ca
Date: 22.01.2020

Poc : Balikesir Üniversitesi SQL İnjection


Dork: allintext: nef.balikesir.edu.tr
Date: 22.01.2020

Poc : Sistem Informasi Akademik SQL Injection


Dork: inurl:/detailNews.php?id= inurl:/detailnews.php?no=
Date: 22.01.2020

Poc : Built with WordPress and WP FanZone Themes 3.1 SQL Injection
Dork: Built with WordPress and WP FanZone site:ca
Date: 21.01.2020

Poc : Dokuz Eylül Üniversitesi Bilgisayar Bölümü reflected xss


Dork: intext:csc.deu.edu.tr
Date: 21.01.2020

Poc : İstanbul Technical University Ottoman Architecture Texts Archives SQL


Injection
Dork: Osmanlı Mimarlık Metinleri Arşivi site:itu.edu.tr
Date: 20.01.2020

Poc : Powered by myIT-School Education System HongKong XSS SQL Injection


Dork: inurl:/it-school/php/webcms/public/ site:edu.hk
Date: 20.01.2020

Poc : izmir ekonomi üniversitesi XSS


Dork: site:ieu.edu.tr -www
Date: 20.01.2020

Poc : ATS4 Internetowy System Planowia Zajec SQL Injection


Dork: inurl:/plan.php?type= site:pl
Date: 19.01.2020

Poc : Powered by Platinum Inc (Syrian gov) script SQLi


Dork: allintext:Powered by Platinum Inc
Date: 17.01.2020
Poc : CarSpot – Dealership Wordpress Classified Theme v2.2.0 Multiple
Vulnerabilities
Dork: /wp-content/themes/carspot/
Date: 17.01.2020

Poc : Reality | Estate Multipurpose WordPress Theme v2.5.1 Reflected XSS


Dork: /wp-content/themes/reality/
Date: 16.01.2020

Poc : Cankırı Belediyesi SQL İnjection


Dork: allintext: cankiri.bel.tr
Date: 14.01.2020

Poc : ThePortalSystem Admin Login Bypass


Dork: intext:Bejelentkezés Portal inurl:/admin
Date: 14.01.2020

Poc : Real Estate 7 WordPress v2.9.4 Multiple Vulnerabilities


Dork: /wp-content/themes/realestate-7/
Date: 13.01.2020

Poc : ListingPro - WordPress Directory Theme v2.5.3 Reflected XSS


Dork: /wp-content/themes/listingpro/
Date: 13.01.2020

Poc : Batflat CMS - Default U/P Admin


Dork: Dork : Copyright 2020 © by Company Name. All rights reserved. Powered by
Batflat.
Date: 13.01.2020

Poc : ogretmenlerodasi Reflected XSS + SQL injection


Dork: allintext: ogretmenlerodasi
Date: 13.01.2020

Poc : MD-WEBMARKETING - SQL Injection vulnerability


Dork: intext:Desenvolvido por: MD-WEBMARKETING inurl:.php?id=
Date: 12.01.2020

Poc : Bogazici University CRLF injection/HTTP response splitting


Dork: allintext: ikincibahar.test.boun.edu.tr
Date: 12.01.2020

Poc : Conception e-partenaire XSS Vulnerability


Dork: intext:Conception : e-partenaire inurl:.php?id=
Date: 12.01.2020

Poc : Houzez - Real Estate WordPress Theme v1.8.3.1 Reflected XSS


Dork: /wp-content/themes/houzez/
Date: 11.01.2020

Poc : Design by CREATIVESWEB XSS


Dork: intext:Design by CREATIVESWEB
Date: 11.01.2020

Poc : Bogazici University CRLF injection/HTTP response splitting


Dork: allintext: ikincibahar.test.boun.edu.tr
Date: 11.01.2020
Poc : Hostel Management System 2.0 id SQL Injection
Dork: intitle: Hostel management system
Date: 11.01.2020

Poc : Codoforum 4.8.3 input_txt Persistent Cross-Site Scripting


Dork: intext:Powered by Codoforum
Date: 11.01.2020

Poc : Travel Booking WordPress Theme v2.7.8.5 Persistent XSS


Dork: /wp-content/themes/traveler/
Date: 11.01.2020

Poc : Campus De La Rivera Argentina SQL Injection


Dork: Campus De La Rivera site:edu.ar
Date: 10.01.2020

Poc : La Universidad Nacional Tecnológica de Lima Sur Untels Peru XSS SQL Injection
Dork: Catálogo en línea Red de Biblioteca UTM. site:untels.edu.pe
Date: 10.01.2020

Poc : Mariano Moreno Instituto Superior Córdoba SQL Injection


Dork: Mariano Moreno Instituto Superior - Córdoba
Date: 10.01.2020

Poc : Centro Universitario de Idiomas Cui Argentina SQL Injection


Dork: CUI - Centro Universitario de Idiomas
Date: 10.01.2020

Poc : afyon kocatepe üniversitesi SQL injection


Dork: allintext: afyon kocatepe üniversitesi
Date: 09.01.2020

Poc : Powered by Lokomedia new sqli injection


Dork: inurl:/visi-misi.html
Date: 08.01.2020

Poc : Interactive Media Cross-site Scripting (XSS)


Dork: intext: Design & Developed By Interactive Media.
Date: 07.01.2020

Poc : lidya hacettepe Cross Site Scripting


Dork: allintext:lidya.hacettepe.edu.tr
Date: 07.01.2020

Poc : Codoforum 4.8.3 Cross Site Scripting


Dork: intext:Powered by Codoforum
Date: 07.01.2020

Poc : ParsCMS - Arbitrary File Upload


Dork: intext:modules/eform/upload/
Date: 06.01.2020

Poc : Glide Wordpress Themes Timthumb RCE


Dork: /wp-content/themes/glide/image/
Date: 31.12.2019

Poc : CityBook - Directory & Listing WordPress Theme v2.2.2 Multiple


Vulnerabilities
Dork: /wp-content/themes/citybook/
Date: 27.12.2019

Poc : TownHub - Directory & Listing WordPress Theme v1.0.2 Multiple Vulnerabilities
Dork: /wp-content/themes/townhub/
Date: 27.12.2019

Poc : EasyBook – Directory & Listing WordPress Theme v1.2.1 Multiple


Vulnerabilities
Dork: /wp-content/themes/easybook/
Date: 27.12.2019

Poc : LNSEL Admin Login Bypass


Dork: intext:Designed by LNSEL
Date: 26.12.2019

Poc : Antiprizuv Form-Data Log Emails Information Disclosure


Dork: inurl:/form-data/php_wrappers/
Date: 26.12.2019

Poc : seabreezeconsulting sql injection vulnerability


Dork: intext:Seabreeze Consulting
Date: 25.12.2019

Poc : Lagenz Cms STEMera Admin Login ByPass


Dork: intext: 2018 STEMera. All Rights Reserved. Developed by Lagenz.
Date: 24.12.2019

Poc : 82webmaster sql injection vulnerability


Dork: Design & Developed By: 82webmaster
Date: 24.12.2019

Poc : cms lagenz admin login bypass / admin no session


Dork: intext:by lagenz site:my
Date: 22.12.2019

Poc : Rumpus FTP Web File Manager 8.2.9.1 Reflected Cross-Site Scripting
Dork: site:*.*.com Web File Manager inurl:?login=
Date: 18.12.2019

Poc : Alcatel-Lucent Omnivista 8770 Remote Code Execution


Dork: inurl:php-bin/webclient.php
Date: 17.12.2019

Poc : Powered BY applezeed.com Vlunrability sqli injection


Dork: intext:Power BY applezeed.com php?id=
Date: 12.12.2019

Poc : Made By Thinkbox312 Vulnrability SQL Injection


Dork: intext: Made By Thinkbox312 php?id=
========================================================================
Date: 12.12.2019

Poc : Creative-Zone SQL Injection


Dork: inurl:about.php?id= intext:designed & developed by Creative-Zone
Date: 11.12.2019

Poc : Design By RABS Net Solutions Vulnrability Bypass Page Admin Login
Dork: intext:Design By RABS Net Solutions (Use Your brain :v)
=======================================
Date: 11.12.2019

Poc : Revive Adserver 4.2 Remote Code Execution


Dork: intext:inurl:www/delivery filetype:php
Date: 10.12.2019

Poc : disdukcapil kab. Lampung SQL Injection


Dork: inurl:pengumuman.php?url= site:go.id
Date: 08.12.2019

Poc : portalinfo.me site Sql injection


Dork: inurl:index.php?page=kategori
Date: 08.12.2019

Poc : turtep SQL İnjection


Dork: allintext: turtep.edu.tr
Date: 06.12.2019

Poc : Superlist - Directory WordPress Theme v2.9.2 Persistent XSS


Dork: /wp-content/themes/superlist/
Date: 02.12.2019

Poc : Avanthi Group Admin Page Bypass


Dork: inurl: /login.php Avanthi Group
Date: 01.12.2019

Poc : Italian Hotels Blind SQL Injection vulnerability


Dork: inurl:camere-dettaglio.php?id= site:.it
Date: 30.11.2019

Poc : ListingPro - WordPress Directory Theme v2.0.14.2 Reflected & Persistent XSS
Dork: /wp-content/themes/listingpro/
Date: 29.11.2019

Poc : alfacommunication.it SQL Injection vulnerability


Dork: inurl:detail.php?id= site:.it
Date: 29.11.2019

Poc : InduSoft Web Studio 8.1 SP1 Denial Of Service


Dork: chuyrojas1997@gmail.com: chuyreds
Date: 28.11.2019

Poc : DEVELOPED BY SUPER GEEKS Vulnrability sqli injection


Dork: DEVELOPED BY SUPER GEEKS php?id=
Date: 26.11.2019

Poc : Xfilesharing 2.5.1 Arbitrary File Upload


Dork: inurl:/?op=registration
Date: 25.11.2019

Poc : Yoncu Domain Take Over Method ( NameServer Take Over )


Dork: intext:Bu Alan Adı Yöncü Bilişim Çözümleri Tarafından Sağlanmıştır
Date: 18.11.2019

Poc : R&D Visions CMS - SQL Injection Vulnerability


Dork: intext:Website by R&D Visions inurl:.php?id=
Date: 17.11.2019

Poc : Maintained By Web Smile India - SQL Injection Vulnerability


Dork: intext:Maintained By Web Smile India inurl:.php?id=
Date: 17.11.2019

Poc : IceHrm Admin Weak Password


Dork: intitle:Ice Hrm Login intext:Forgot Password
Date: 16.11.2019

Poc : Xfilesharing 2.5.1 Local File Inclusion / Shell Upload


Dork: inurl:/?op=registration
Date: 15.11.2019

Poc : Powered By Komquest Solutions Vulnerability Bypass Admin Default & Register
User
Dork: intext:Powered By Komquest Solutions
Date: 12.11.2019

Poc : Powered by ARE InfoTech Vulnerability SQL Injection


Dork: Powered by ARE InfoTech inurl:.php?id= or inurl:php?id= intext:Powered by
ARE InfoTech
Date: 12.11.2019

Poc : Developed by: Sanskar TechnoLab Vulnrability Bypass admin Login


Dork: intext:Developed by: Sanskar TechnoLab
Date: 12.11.2019

Poc : Kemenristek Dikti @Pelatihan UMKM Bypass Admin Panel


Dork: intext:Kemenristek Dikti @Pelatihan UMKM Dengan Innovative Digital Learning
2019
Date: 11.11.2019

Poc : Powered by Reaksicms vulnerablity SQLI INJECTION


Dork: inurl:/agenda.html
Date: 08.11.2019

Poc : KPKComputer - Multiple Vulnerabilities


Dork: intext:Powered by KPKComputer
Date: 08.11.2019

Poc : Zaliyo Technologies Cms Admin Page Bypass


Dork: intext:Powered By Zaliyo Technologies Pvt Ltd
Date: 08.11.2019

Poc : Responsive File Manager to Path Leaked


Dork: inurl:/filemanager/css/
Date: 06.11.2019

Poc : DevelopWay " - DW CMS v1.0.1 " SQLi


Dork: intext:DW CMS v1.0.1
Date: 05.11.2019

Poc : Soloweb Kcfinder arbitary file upload


Dork: intext:This design is created by Soloweb
Date: 04.11.2019

Poc : OzzzyWeb CMS Multiple Vulnerabilities


Dork: Copyright 2015 @ Ozzzy Akıllı Web Panelleri
Date: 03.11.2019

Poc : WordPress Google Review Slider 6.1 SQL Injection


Dork: inurl:/wp-content/plugins/wp-google-places-review-slider/
Date: 01.11.2019

Poc : SQL-i Cms Webtema


Dork: intext:Designed by webtema.id
Date: 30.10.2019

Poc : ham3d Information Processing Script Local File Download & Default Password
Vulnerability
Dork: inurl:fa/forgotpass.html
Date: 29.10.2019

Poc : Wordpress FooGallery 1.8.12 Persistent Cross-Site Scripting


Dork: inurl:wp-contentpluginsfoogallery
Date: 28.10.2019

Poc : Pejvakco CMS Sql Injection Vulnerability


Dork: site:pnuba.ac.ir inurl:news.php?id=
Date: 28.10.2019

Poc : Responsive File Manager with Path Traversal


Dork: inurl:/filemanager/ dialog.php
Date: 26.10.2019

Poc : Miracle Hunt Services SQL Injection


Dork: intext:Powered by : Miracle Hunt Services
Date: 25.10.2019

Poc : Royalcommerce Laravel Sql Injection


Dork: intext:All Rights Reserved By GeniusOcean.com
Date: 25.10.2019

Poc : Noted - Temporary Notes System Sql Injection


Dork: intext:1- Create a note and get a link
Date: 22.10.2019

Poc : Rlight Ventes Bypass Sql Login


Dork: intext:developed by Rlight Ventes
Date: 20.10.2019

Poc : WordPress Soliloquy Lite 2.5.6 Cross Site Scripting


Dork: inurl:wp-contentpluginssoliloquy-lite
Date: 18.10.2019

Poc : WordPress FooGallery 1.8.12 Cross Site Scripting


Dork: inurl:wp-contentpluginsfoogallery
Date: 18.10.2019

Poc : WordPress Popup Builder 3.49 Cross Site Scripting


Dork: inurl:wp-contentpluginspopupbuilder
Date: 18.10.2019

Poc : 3kits CMS Sql Injection Vulnerability


Dork: intext:Designed & Developed By 3KITS inurl:.php?id=
Date: 17.10.2019

Poc : Made in Globopex Bypass Sql Login


Dork: intext:Made in Globopex
Date: 16.10.2019
Poc : iPOT Technologies Bypass Admin
Dork: intext:Powered by iPOT Technologies.
Date: 13.10.2019

Poc : Neha Web Solutions Multiple vulnerabilities


Dork: intext:Powered by Neha Web Solutions
Date: 13.10.2019

Poc : Siteni Hazırla CMS - Local File Inclusion


Dork: Index of /sh-cdn/
Date: 12.10.2019

Poc : Moduliti Creation De Site İnternet Professionnel XSS SQL Injection


Dork: /catalogueproduit.php? intext:Location de sites Web avec la solution Moduliti
Date: 11.10.2019

Poc : Webofisi CMS - LFI


Dork: Index of /tema/firmarehberi
Date: 10.10.2019

Poc : Realizzato da CityNetGroup SQL Injection


Dork: ?idArticolo= intext:Realizzato da. Logo Citynet Srl. site:it
Date: 09.10.2019

Poc : Realisation Pascale Moise XSS SQL Injection


Dork: intext:réalisation pascale moise
Date: 09.10.2019

Poc : HTML5-Jquery-filedrop csrf file upload


Dork: intext:post_file.php
Date: 08.10.2019

Poc : powered Abednego sqli injection indonesia


Dork: inurl:/profil-visi-dan-misi.html
Date: 08.10.2019

Poc : SolmetraUploader csrf File upload


Dork: index of intext:SolmetraUploader.php
Date: 08.10.2019

Poc : Realizzato da MDAWeb MDA Informatica ItalyGov XSS SQL Injection


Dork: intext:Realizzato da MDAWEB - Mda Informatica site:it
Date: 07.10.2019

Poc : Thailand Union Library Management 6.2 XSS SQL Injection


Dork: inurl:/ULIB/about.php site:ac.th
Date: 07.10.2019

Poc : TharrosNet Italy Web Agency SQL Injection


Dork: inurl:/modules.php?modulo=mkNews site:it
Date: 07.10.2019

Poc : ParantezTeknoloji Library Software 16.0519000 Open Redirection


Dork: Parantez Teknoloji inurl:/cgi-bin/koha/ site:tr
Date: 05.10.2019

Poc : InoERP 0.7.2 Persistent Cross-Site Scripting


Dork: None
Date: 04.10.2019

Poc : Desarollo por Ezink Gds-Web Open Redirection Vulnerability


Dork: inurl:/home/cont_click.php?url=
Date: 04.10.2019

Poc : Devinim Library Software 19.0504000 Open Redirection Vulnerability


Dork: intext:Bu yazılım Devinim Yazılım Eğitim Danışmanlık tarafından geliştirilip
kurulmuştur.
Date: 04.10.2019

Poc : ParantezTeknoloji Library Software 16.0519000 Open Redirection Vulnerability


Dork: Parantez Teknoloji inurl:/cgi-bin/koha/ site:tr
Date: 04.10.2019

Poc : Zoner - Real Estate WordPress Theme v4.1.1 Persistent XSS & IDOR
Dork: inurl:/wp-content/themes/zoner/
Date: 27.09.2019

Poc : all-in-one-seo-pack 3.2.7 Cross Site Scripting


Dork: inurl:wp-contentpluginsall-in-one-seo-pack
Date: 27.09.2019

Poc : Chamilo LMS 1.11.8 Shell Upload


Dork: intext:powered by chamilo
Date: 26.09.2019

Poc : Created By: Haarty Hanks SQL Injection Vulnerability


Dork: site:uk +inurl:php?id
Date: 24.09.2019

Poc : jommla component ccnewsletter 2.2.4 - sbid Parameter SQL Injection


Dork: inurl:index.php?option=com_ccnewsletter inurl:sbid
Date: 23.09.2019

Poc : Dokeos 1.8.6.1 / 1.8.6.3 Arbitrary File Upload


Dork: intext:Plateforme Dokeos 1.8.6.3 or 1.8.6.1
Date: 22.09.2019

Poc : StartPoligraf SQLInjection


Dork: Inurl:post.php?id= site:ua
Date: 20.09.2019

Poc : Western Digital My Book World II NAS 1.02.12 Hardcoded Credential


Dork: intitle:My Book World Edition - MyBookWorld
Date: 19.09.2019

Poc : InJob | Multi-purpose for recruitment WordPress Theme v3.3.6 Reflected &
Persistent XSS
Dork: inurl:/wp-content/themes/injob/
Date: 16.09.2019

Poc : Zoner | Real Estate Joomla Theme Persistent XSS


Dork: /templates/bt_zoner/html/
Date: 16.09.2019

Poc : Cabrera Propiedades (Blind SQL Injection)


Dork: intext:inurl:php?id= site:ar intext:propiedades
Date: 15.09.2019
Poc : La Paz Shopping (SQL Injection / XSS Reflected)
Dork: intext:inurl:.php?id= site:.ar intext:shopping
Date: 14.09.2019

Poc : Laprida Gobierno Municipal (SQL Injection)


Dork: intext:inurl:.php?id= site:.gov.ar
Date: 13.09.2019

Poc : by Logic Indo Solution Bypass Admin Login


Dork: intext:Supported by Logic Indo Solution © 2019
Date: 12.09.2019

Poc : Turkish Real Estate Sites Sql İnjection


Dork: inurl:template/default/print.php?id=
Date: 12.09.2019

Poc : Reality | Estate Multipurpose WordPress Theme Persistent XSS


Dork: intext:/wp-content/themes/reality/framework/
Date: 09.09.2019

Poc : Design by Yuvantra pvt ltd bypass admin panel and upload shell
Dork: intext:Design by Yuvantra pvt ltd
Date: 08.09.2019

Poc : Pulse Secure Post-Auth Remote Code Execution


Dork: inurl:/dana-na/ filetype:cgi
Date: 08.09.2019

Poc : WordPress Plugin UserPro 4.9.32 Cross-Site Scripting


Dork: intitle:Index of intitle:UserPro -uploads
Date: 08.09.2019

Poc : Wordpress Plugin Event Tickets 4.10.7.1 CSV Injection


Dork: inurl:wp-contentpluginsevent-tickets
Date: 06.09.2019

Poc : WordPress Event Tickets 4.10.7.1 CSV Injection


Dork: inurl:wp-contentpluginsevent-tickets
Date: 03.09.2019

Poc : YouPHPTube 7.4 Remote Code Execution


Dork: intext:Powered by YouPHPTube
Date: 02.09.2019

Poc : Wordpress Gallery Objects Version 0.4 SQL Injection vulnerability


Dork: inurl:/admin-ajax.php?action=go_view_object
Date: 30.08.2019

Poc : Joomla 2.5.28 Com_JomEstate Real Estate Components 4.1 SQL Injection
Dork: inurl:/index.php?option=com_jomestate
Date: 30.08.2019

Poc : Joomla 1.0.15 Easy GuestBook Com_EasyGB Components 1.0 SQL Injection
Dork: inurl:/index.php?option=com_easygb
Date: 29.08.2019

Poc : LSoft ListServ Cross Site Scripting


Dork: intitle:LISTSERV 16.5
Date: 27.08.2019

Poc : © All Rights Are Reserved | Designed By Keywe Solution Bypass Authentication
Dork: /kadmin/login.php
Date: 26.08.2019

Poc : Plexo Torresoft Alex Torres Software 2.0 XSS SQL Injection
Dork: intext:Powered By Plexo Torresoft Alex Torres Software site:gov.co
Date: 26.08.2019

Poc : vBulletin Reflected XSS via "Click here"


Dork: intext : Powered by vBulletin® Version 5.5.3 Copyright © 2019 MH Sub I, LLC
dba vBulletin
Date: 25.08.2019

Poc : Joomla 1.5.26 Com_OrgChart Components 1.0.0 XSS SQL Injection


Dork: intext:Realizzato con CMS-PAL 1.0 - Altropiano.com inurl:/index.php?
option=com_orgchart
Date: 25.08.2019

Poc : OneSource Consultoria Informatica Coimbra Portugal XSS SQL Injection


Dork: inurl:/index.php?target=showContent site:pt
Date: 22.08.2019

Poc : Produzione Izdelava MMvisual SQL Injection


Dork: intext:Izdelava: MMstudio site:si
Date: 22.08.2019

Poc : DomusMondo AgestaNet BeniaStudio Domini e Web Hosting XSS SQL Injection
Dork: inurl:/ricerca-immobile.php?prov_imm=
Date: 22.08.2019

Poc : Fragolan Linking People D-Gen CMS SQL Injection


Dork: intext:fragolan inurl:/index.php?lengua= site:com
Date: 21.08.2019

Poc : Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Arbitrary File Disclosure


(metasploit)
Dork: inurl:/dana-na/ filetype:cgi
Date: 21.08.2019

Poc : Designed by RaphSoft Sql Injection Vulnerability


Dork: intext:intext:Designed by RaphSoft
Date: 21.08.2019

Poc : FortiOS 5.6.7 / 6.0.4 Credential Disclosure


Dork: intext:Please Login inurl:/remote/login
Date: 20.08.2019

Poc : MajorDoMo 1.2 Backup Disclosure Vulnerability


Dork: intext:admin.php?pd=&md=panel&inst=&action=users
Date: 20.08.2019

Poc : WordPress Add Mime Types Plugin 2.2.1 Cross-Site Request Forgery
Dork: inurl:”/wp-content/plugins/wp-add-mime-types”
Date: 20.08.2019

Poc : Zaheb.ir | SQL Injection


Dork: intext:)‫ آسان همایش (نرم افزار مدیریت همایش و کنفرانس‬: ‫طراح و پشتیبان‬
Date: 17.08.2019

Poc : Asanhamayesh CMS | SQL Injection


Dork: intext:)‫ آسان همایش (نرم افزار مدیریت همایش و کنفرانس‬: ‫طراح و پشتیبان‬
Date: 15.08.2019

Poc : BSI Advance Hotel Booking System 2.0 Cross Site Scripting
Dork: intext:Hotel Booking System v2.0 © 2008 - 2012 Copyright Best Soft Inc
Date: 13.08.2019

Poc : Joomla JS Jobs 1.2.5 SQL Injection


Dork: inurl:index.php?option=com_jsjobs
Date: 12.08.2019

Poc : Joomla JS Support Ticket 1.1.5 Arbitrary File Download


Dork: inurl:index.php?option=com_jssupportticket
Date: 09.08.2019

Poc : Joomla JS Support Ticket 1.1.5 SQL Injection


Dork: inurl:index.php?option=com_jssupportticket
Date: 09.08.2019

Poc : Joomla! Component JS Support Ticket (component com_jssupportticket) 1.1.5 SQL


Injection
Dork: inurl:index.php?option=com_jssupportticket
Date: 08.08.2019

Poc : WordPress JoomSport 3.3 SQL Injection


Dork: intext:powered by JoomSport - sport WordPress plugin
Date: 08.08.2019

Poc : ibrowser phpthumb Command Injection


Dork: intext:/ibrowser/scripts/
Date: 05.08.2019

Poc : Powered by mediatoonz. Admin Panel Bypass


Dork: intext:Powered by mediatoonz.
Date: 02.08.2019

Poc : ct web design by brown bear creative XSS Vulnerability


Dork: intext:ct web design by brown bear creative inurl:.php?id=
Date: 01.08.2019

Poc : Amcrest Cameras 2.520.AC00.18.R Unauthenticated Audio Streaming


Dork: html:@WebVersion@
Date: 30.07.2019

Poc : yazılımı jettweb Haber V3 Auth By Pass Vulnerability


Dork: intext:yazılımı jettweb
Date: 30.07.2019

Poc : Smart campus bypass login admin


Dork: smart campus login site:ac.id
Date: 28.07.2019

Poc : Alsovalue CMS Sql Injection Vulnerability


Dork: intext:Powered by Alsovalue inurl:/.php?id=
Date: 26.07.2019
Poc : BookingWizz v5.5 sensitive information disclosure Vulnerability
Dork: intext:BookingWizz v5.5
Date: 26.07.2019

Poc : Création site internet Adveris XSS Vulnerability


Dork: intext:Création site internet : Adveris inurl:.php?id=
Date: 26.07.2019

Poc : GigToDo - Freelance Marketplace Script v1.3 Persistent XSS Injection &
WebShell Upload
Dork: -
Date: 24.07.2019

Poc : Real Estate 7 - Real Estate WordPress Theme v2.8.9 Persistent XSS Injection
Dork: inurl:/wp-content/themes/realestate-7/
Date: 24.07.2019

Poc : Coming Soon Page & Maintenance Mode v1.8.0 Unauthenticated Persistent XSS
Injection
Dork: inurl:wp-content/plugins/responsive-coming-soon
Date: 23.07.2019

Poc : Axway SecureTransport 5 Unauthenticated XML Injection


Dork: intitle:Axway SecureTransport Login
Date: 23.07.2019

Poc : DREAM TECHNOLOGY Upload Shell


Dork: intext:POWERED BY - DREAM TECHNOLOGY.
Date: 22.07.2019

Poc : Advanced Testimonials Manager v5.7 Unauthorized administrative access


Vulnerability
Dork: Advanced Testimonial Manager
Date: 21.07.2019

Poc : Web Design By East Technologies


Dork: inurl:.php?id= intext:Web Design By East Technologies
Date: 20.07.2019

Poc : Cont Web CMS Sql Injection Vulnerability


Dork: site:pi.gov.br inurl:/galeria.php?id=
Date: 20.07.2019

Poc : Smokybyte CMS Sql Injection Vulnerability


Dork: intext:site by Smokybyte inurl:/.php?id=
Date: 20.07.2019

Poc : Microsoft Windows Remote Desktop BlueKeep Denial of Service (Metasploit)


Dork: port:3389
Date: 18.07.2019

Poc : phpFK 8.0 version Reinstall Add Admin Vulnerability


Dork: Powered by: phpFK
Date: 17.07.2019

Poc : pixaal sql injection


Dork: inurl:.php?id= intext:Developed by pixaal
Date: 15.07.2019
Poc : Oracle Support Platform Service XSS Vulnerability
Dork: inurl:/app/answers/list
Date: 11.07.2019

Poc : Fédération Francaise de Voile SQL Injection Vulnerability


Dork: site:www.ffvoile.fr id=
Date: 07.07.2019

Poc : Cédia.fr SQL Injection Vulnerability


Dork: intext:Cedia- Éditions Maradi - Copyright Cedia© 1999-2018 - 758.
Date: 07.07.2019

Poc : Website designed & developed by designrz. SQL Injection vulnerability


Dork: inurl:.php?id= intext:website designed & developed by designrz.
Date: 07.07.2019

Poc : PULSONİX SQL Injection Vulnerability


Dork: intext:WestDev Ltd 1998-2019 id=
Date: 06.07.2019

Poc : PowerPanel Business Edition Cross-Site Scripting


Dork: None
Date: 05.07.2019

Poc : Elif Safak SQL Injection Vulnerability


Dork: intext:www.elifsafak.us id=
Date: 05.07.2019

Poc : WDD CHINESE CMS SQL injection


Dork: intext:DESIGNED BY WDD inurl:ID=
Date: 03.07.2019

Poc : Carpool Web App 1.0 Cross Site Scripting / SQL Injection
Dork: intext:Powered by Prosentient Systems
Date: 01.07.2019

Poc : YELM ‫ ישיבת אלון מורה‬Sql İnjection Vulnerability


Dork: intile:‫ ישיבת אלון מורה‬id=
Date: 01.07.2019

Poc : Humor ‫סיפורים מצחיקים ועוד‬ Sql İnjection Vulnerability


Dork: intext‫ קטעי ווידאו‬id=
Date: 01.07.2019

Poc : Designed by ORGINSTUDIOS.COM Sql İnjection Vulnerability


Dork: intext:Designed by ORGINSTUDIOS.COM inurl:catid
Date: 01.07.2019

Poc : Sangwan Technology Admin panel bypass & upload shell


Dork: intext:Powered by : Sangwan Technology
Date: 27.06.2019

Poc : Live Chat Unlimited v2.8.3 Stored XSS Injection


Dork: inurl:wp-content/plugins/screets-chat
Date: 25.06.2019

Poc : AZADMIN CMS Of HIDEA 1.0 SQL Injection


Dork: inurl:news_det.php?cod= HIDEA
Date: 25.06.2019
Poc : BookingWizz v5.5 Sql Injection Vulnerability
Dork: intext:BookingWizz v5.5
Date: 24.06.2019

Poc : Sistem Informasi Kesehatan Daerah v1.4 (SIKDA) Xpath Injection Vulnerability
Dork: intext:SIKDA Generik - All Rights Reserved
Date: 24.06.2019

Poc : Koha Library Software 18.1106000 Tracklinks Open Redirection


Dork: inurl:/cgi-bin/koha/opac-user.pl site:edu
Date: 20.06.2019

Poc : Ajax File Manager Login Form Weak Password


Dork: inurl:/ajaxfilemanager/
Date: 20.06.2019

Poc : Cloud Base Multiple school Generate & Management System Backdoor Account
Vulnerability
Dork: intext:/website_upzilla/noticeUno/
Date: 20.06.2019

Poc : Ajans Otuz9 Cross Site Scripting


Dork: intext:Ajans Otuz9 inurl:/?Syf=
Date: 19.06.2019

Poc : Lacivert Ajans Cross Site Scripting


Dork: intext:2018 Designed by Lacivert Ajans inurl:/?pnum=
Date: 19.06.2019

Poc : Saynet Bilgisayar Cross Site Scripting


Dork: intext:Saynet Bilgisayar site:tr
Date: 19.06.2019

Poc : WordPress - ChurcHope Responsive Themes 4.7.x Directory Traversal


Vulnerability
Dork: intext:/wp-content/themes/churchope/lib/
Date: 17.06.2019

Poc : AutoLore VillMotor CrisciCars idveicoli SQL Injection


Dork: inurl:/index.php?pagina=parcoclienti site:it
Date: 17.06.2019

Poc : EmpNeusis Web Design XSS SQL Injection


Dork: intext:EmpNeusis Web Design and Hosting Services site:gr
Date: 17.06.2019

Poc : Yurdum Software Reflected XSS Privilege Escalation


Dork: inurl:/?pnum= site:tr
Date: 17.06.2019

Poc : Wordpress Plugins Simple-e-commerce-shopping-cart DatabaseSQL Backup


Disclosure Vulnerability
Dork: inurl:/wp-content/plugins/simple-e-commerce-shopping-cart/
Date: 16.06.2019

Poc : Demo Illustrations by Justin Mezzell reflected XSS


Dork: allintext:Demo Illustrations by Justin Mezzell
Date: 16.06.2019
Poc : Designed & Developed by Rlight NoRedirect Bypass
Dork: intext:Designed & Developed by Rlight
Date: 15.06.2019

Poc : Cwcontrol Default Admin


Dork: inurl:/cwcontrol/
Date: 15.06.2019

Poc : Wordpress Plugins Cart66-Lite DatabaseSQL Backup Disclosure Vulnerability


Dork: intext:Index of /wp-content/plugins/cart66-lite/sql
Date: 15.06.2019

Poc : Filegator DatabaseSQL Backup Disclosure


Dork: intext:filegator ?cd=
Date: 15.06.2019

Poc : DigaSell - Digital store PHP Script V1.0.0 XSS Vulnerability


Dork: intext:Copyright © DigaSell All Rights Reserved.
Date: 15.06.2019

Poc : LightMax eCommerce GroupBandejas XSS SQL Injection


Dork: eCommerce GroupBandejas
Date: 14.06.2019

Poc : Bluesteel Design and Technology hidden Uploader/ bypass admin


Dork: intext:Bluesteel Design and Technology
Date: 14.06.2019

Poc : WebLord WL-Nuke Coppermine for PHP-Nuke v1.3.1c SQL Injection


Dork: intext:Engine PHP-Nuke - Powered by WL-Nuke site:it
Date: 14.06.2019

Poc : Credits Agora Web Italy XSS SQL Injection


Dork: intext:Credits Agora Web site:it
Date: 14.06.2019

Poc : Websmart Inc Moose Jaw Area Canada XSS SQL Injection
Dork: intext:Web Site by Websmart Inc site:ca
Date: 14.06.2019

Poc : AlumniMagnet auth by pass Vulnerability


Dork: intext:Powered by AlumniMagnet site:edu inurl:/images.html?view_album=
site:edu
Date: 13.06.2019

Poc : Designed by EMH XSS Vulnerability


Dork: Designed by EMH TheEmhGlobal
Date: 13.06.2019

Poc : Design By : Web India Solution.Net Basic SQLI || SQLi Authentication bypass
|| XSS || Html injection
Dork: allintext:Design By : Web India Solution.Net Basic SQLI || SQLi
Authentication bypass || XSS || Html injection
Date: 12.06.2019

Poc : Conception Web ViGlob XSS SQL Injection


Dork: intext:Conception Web : ViGlob site:ca
Date: 12.06.2019
Poc : MINMAX Web Design - SQL Injection Vulnerability
Dork: intext:Design by MINMAX
Date: 12.06.2019

Poc : LIT Creations African CMS SQL injection


Dork: intext:Website designed and hosted by LIT Creations inurl:id=
Date: 10.06.2019

Poc : LIT Creations African CMS SQL injection


Dork: intext:Website designed and hosted by LIT Creations inurl:id=
Date: 10.06.2019

Poc : CHUENG SHINE CO SQl Injection Vulnerability


Dork: inurl:product.php?id=
Date: 10.06.2019

Poc : Pendaftaran Kontributor Indonesian sites BUG File Upload Vulnerability + Add
Berita
Dork: inurl:kontributor Allowed File : gif, jpg, png, jpeg
Date: 10.06.2019

Poc : WordPress 5.2.1 Antena_Ri Institute Themes 2.0 Open Redirection


Dork: inurl:/wp-content/themes/antena_ri/ss/
Date: 10.06.2019

Poc : kocaeli univercity SQL injection Vul


Dork: none
Date: 08.06.2019

Poc : Yasha Zamanpour SQL Injection Vulnerability And XSS


Dork: intext:Designed & Developed By Yasha Zamanpour or ‫ ياشا زمانپور‬:‫طراحي و اجرا‬
Date: 07.06.2019

Poc : Desarrollado por Objetivo Virtual SQL Injection


Dork: intext:Desarrollado por Objetivo Virtual inurl:/producto-detalle.php?id=
Date: 06.06.2019

Poc : Terabim Bilgi Teknolojileri SQL Injection


Dork: inurl:hizmetlerimiz.php?id=
Date: 06.06.2019

Poc : WordPress Satoshi 2.0 Cross Site Request Forgery / File Upload
Dork: intext:Design By Voosh Themes
Date: 06.06.2019

Poc : Terabim Bilgi Teknolojileri SQL Injection


Dork: inurl:hizmetlerimiz.php?id= Terabim Bilgi Teknolojileri
Date: 06.06.2019

Poc : Humhub 1.3.13 Directory traversal Vulnerability


Dork: intext:Propulsé par HumHub
Date: 04.06.2019

Poc : RedGreenBD IT Solutions XSS Reflected Cross Site Scripting


Dork: intext:Design & Developed by : RedGreenBD IT Solutions site:edu.bd
Date: 04.06.2019

Poc : CMSMadeSimple Software Babel Modules 1.9.4.2 Open Redirection


Dork: /modules/babel/ intext:Site is powered by CMS Made Simple 1.9.4.2
Date: 03.06.2019

Poc : CitraWeb Local File Inclusion to Remote Code Execution and get Cpanel
Dork: inurl:/cni-system/
Date: 03.06.2019

Poc : ProRank v2.3.0 – Analyzer stats website Sql Injection Vulnerability


Dork: intext:Copyright 2017 - ProRank.co | All Right Reserved
Date: 03.06.2019

Poc : Designed and Developed by Web Experts SQL Injection (Greece script)
Dork: intext:Designed and Developed by Web Experts inurl:english/article.php?id=
Date: 02.06.2019

Poc : Sitenizolsun CMS - Defce Exploit


Dork: intext : Site içerik Yönetim Paneli
Date: 02.06.2019

Poc : Masch CMStudio Banners Modules 8.6.1 XSS Vulnerability


Dork: intext:bannergo.php inurl:/modules/banners/
Date: 31.05.2019

Poc : QUICKAD CMS 7.3 Unauthorized administrative access Vulnerability


Dork: intext:Bylancer, All right reserved
Date: 31.05.2019

Poc : Haddads Fine SQL Injection


Dork: intitle:Haddads Fine Arts - Search
Date: 30.05.2019

Poc : WordPress WPAds Plugins 1.0 Open Redirection


Dork: intext:Ansvarlige redaktører: Karsten Meinich og Lars Ole Kristiansen
Date: 29.05.2019

Poc : WordPress 4.8 Nya-Comment-DoFollow Plugins 1.0 Open Redirection


Dork: inurl:/wp-content/plugins/nya-comment-dofollow/
Date: 29.05.2019

Poc : iGears Technology Limited 網頁設計及維護 科擎科技有限公司 XSS SQL Injection


Dork: pkey= intext:網頁設計及維護 科擎科技有限公司
Date: 29.05.2019

Poc : Humhub 1.3.13 Unrestricted File Upload Vulnerability


Dork: intext:Propulsé par HumHub
Date: 28.05.2019

Poc : WordPress 5.1.1 jilijilibegin Themes LTS 4.6 Open Redirection


Dork: inurl:/wp-content/themes/jilijilibegin/
Date: 28.05.2019

Poc : WordPress 4.9.10 Xunjin Themes 4.6 Open Redirection


Dork: inurl:/wp-content/themes/xunjin/
Date: 28.05.2019

Poc : WordPress 4.8.9 Tigin Themes 1.0.5 Open Redirection


Dork: inurl:/wp-content/themes/tigin/
Date: 28.05.2019
Poc : WordPress 5.2.1 Divi-Child Themes 1.0 Open Redirection
Dork: intext:Réalisé par Atlantis multimédia site:com
Date: 28.05.2019

Poc : East Technologies XSS Reflected Cross Site Scripting


Dork: intext:Web Design By East Technologies site:edu.hk
Date: 28.05.2019

Poc : Joomla 3.9.6 Com_Attachments Components 3.x Unauthorized File Insertion


Dork: inurl:/index.php?option=com_attachments&task=upload
Date: 27.05.2019

Poc : Desenvolvido por EngePlus Brazil XSS Vulnerability


Dork: intext:Desenvolvido por EngePlus site:br
Date: 27.05.2019

Poc : RussianSpares.com SQL Injection


Dork: /products.php?cat=54
Date: 27.05.2019

Poc : WordPress 4.9.10 4DMayi Themes 4.6 Open Redirection


Dork: inurl:/wp-content/themes/4dmayi/
Date: 25.05.2019

Poc : WordPress 5.2.1 DingTalk Themes LTS 4.6 Open Redirection


Dork: inurl:/wp-content/themes/dingtalk/
Date: 25.05.2019

Poc : STS development SQLi


Dork: allintext:Designed and Developed by STS
Date: 25.05.2019

Poc : WordPress 4.9.8 LaneMotorSport Responsive Themes 1.8.4 Open Redirection


Dork: inurl:/wp-content/themes/lanemotorsport/
Date: 25.05.2019

Poc : WordPress 4.6.14 lqcPlugin-regiePublicites Plugins 1.0 Open Redirection


Dork: inurl:/wp-content/plugins/lqcPlugin-regiePublicites/
Date: 25.05.2019

Poc : Hawkeye Community College SQL Injection


Dork: intext:Hawkeye Community College hccit id=
Date: 25.05.2019

Poc : Spilf stanford university SQL Injection


Dork: intitle:Stanford Public Interest Law Foundation
Date: 25.05.2019

Poc : Разработка сайта Artonica Russia Unauthorized File Insertion


Dork: intext:Разработка сайта: Artonica site:ru
Date: 23.05.2019

Poc : Web80.ir SQL INJECTION


Dork: site:web80.ir inurl:/File/post/index.php?id=
Date: 23.05.2019

Poc : WordPress 4.6.12 PHPL Plugins 1.0 Open Redirection


Dork: inurl:/wp-content/plugins/phpl/
Date: 23.05.2019
Poc : WordPress 5.2.1 Dankov Planer Themes 1.1.2 Open Redirection
Dork: inurl:/wp-content/themes/planer/
Date: 23.05.2019

Poc : WordPress 4.9.10 Aliyun Themes 5.2 Open Redirection


Dork: inurl:/wp-content/themes/aliyun/inc/
Date: 23.05.2019

Poc : WordPress 4.4.18 Ad-Manager Plugins 1.1.2 Open Redirection


Dork: inurl:/wp-content/plugins/ad-manager/
Date: 23.05.2019

Poc : WordPress 4.9.10 Chrome-Extensions Themes 1.0 Open Redirection


Dork: inurl:/wp-content/themes/chrome-extensions/
Date: 23.05.2019

Poc : Outsystems Platform CSRF


Dork: site:outsystemsenterprise.com -www
Date: 22.05.2019

Poc : WordPress Inkblot Themes 4.9.10 Cross Site Request Forgery


Dork: intext:Powered by WordPress with Inkblot
Date: 22.05.2019

Poc : WordPress 4.6.1 Roberto Antonacci Cross Site Request Forgery


Dork: intext:Sviluppato da Roberto Antonacci, siti web bari
Date: 22.05.2019

Poc : WordPress Versett Cross Site Request Forgery


Dork: intext:Site by Versett site:com
Date: 22.05.2019

Poc : WordPress TPG Business Services Cross Site Request Forgery


Dork: Copyright 2015 Geoff Zahn LLC | Powered by TPG Business Services
Date: 22.05.2019

Poc : WordPress Retreat Guru Cross Site Request Forgery


Dork: intext:Site by Retreat Guru site:com
Date: 22.05.2019

Poc : Schwabe Slovakia WebDesign Studio Nandu Unauthorized File Insertion


Dork: intext:Copyright © 2012 Schwabe Slovakia s.r.o., webdesign studio nandu
Date: 21.05.2019

Poc : ImgHosting 1.3 Sql Injection Vulnerability


Dork: intext:ImgHosting Programming by FoxSash
Date: 21.05.2019

Poc : Irantechnologhy IRANIAN CMS SQL injection


Dork: [intext:By Irantechnologhy inurl:*id=] & [intext:‫ ایران تکنولوژی‬inurl:*id=]
Date: 21.05.2019

Poc : Netvidade Portugal Unauthorized File Insertion


Dork: intext:Desenvolvido por netvidade.com site:pt
Date: 21.05.2019

Poc : phpKF 1.10 XSS / CSRF / SQL Injection


Dork: Yazılım: phpKF © 2007-2019
Date: 20.05.2019

Poc : Irantechnologhy IRANIAN CMS SQL injection


Dork: [intext:By Irantechnologhy inurl:*id=] & [intext:‫ ایران تکنولوژی‬inurl:*id=]
Date: 20.05.2019

Poc : baqai.edu.pk sql injection


Dork: site:baqai.edu.pk inurl:/NewsDetail.php?id=
Date: 20.05.2019

Poc : College of Architecture SQL Injection


Dork: intitle:College of Architecture and Center for Design Nashik photo-
gallery.php?id=3
Date: 20.05.2019

Poc : Architecture SQL Injection


Dork: site:www.atelierdsync.com id=
Date: 20.05.2019

Poc : Xoops Wordpress Modules WP-Ktai 0.5.0 Japan Open Redirection


Dork: intext:WP-Ktai ver 0.5.0
Date: 20.05.2019

Poc : AlumniMagnet OmniMagnet Improper Access Control Vulnerability


Dork: intext:Powered By AlumniMagnet + inurl:/article.html?aid= site:org
Date: 20.05.2019

Poc : Manav Vikas Seva Sangh SQL Injection


Dork: intext:Manav Vikas Seva Sangh gallery.php?id=
Date: 20.05.2019

Poc : skystartravels SQL Injection


Dork: intext:All Rights Reserved to www.skystartravels.com gallery.php?id=1
Date: 20.05.2019

Poc : KATUN SQL Injection


Dork: intext:2015 KATUN. All rights reserved.
Date: 20.05.2019

Poc : Indonesia Toko CMS unauthorized administrative access Vulnerability


Dork: inurl:index.php?mnu=login
Date: 20.05.2019

Poc : Masch CMStudio Banners Modules 8.6.1 Sql Injection Vulnerability


Dork: bannergo.php inurl:/modules/banners/
Date: 20.05.2019

Poc : Création du Site Internet Agence Digitale NetSkiss France SQL Injection
Dork: intext:Création du site Internet : Agence digitale Netskiss site:fr
Date: 19.05.2019

Poc : Delhi Jain Public School or Jinvani Bharati School SQL Injection
Dork: intext:Powered by Schoolsindia download.php?id=5
Date: 19.05.2019

Poc : Rohana Laing SQL Injection


Dork: intext: 2019 Rohana Laing id=
Date: 19.05.2019
Poc : Real Instruments SQL Injection
Dork: intitle:Real Instruments gallery.php?id=
Date: 19.05.2019

Poc : Nippon Instruments SQL Injection


Dork: intext:© Copyright 2011 Silentium Designs id=
Date: 19.05.2019

Poc : Big Daddys Sauces SQL Injection


Dork: intext:Graphics by Kinkaid id=
Date: 19.05.2019

Poc : Stumbler SQL Injection


Dork: intext:Marius Milner 2002-2004. id=
Date: 19.05.2019

Poc : Jucepi Governo de Estado Piaui Brasil XSS SQL Injection


Dork: Junta Comercial do Estado do Piauí Jucepi site:gov.br
Date: 19.05.2019

Poc : Slims CMS Akasia 8.3.1 Improper Authorization Vulnerability


Dork: intext:Template By Erwan Setyo Budi. Powered By SLiMS and ShapeBootstrap.
site:ac.id
Date: 19.05.2019

Poc : Ministryfocusets SQL Injection


Dork: intitle:Ministry Focus ETS id=
Date: 18.05.2019

Poc : Powered by Adox Solutions SQL INJECTION


Dork: intext:Powered by Adox Solutions
Date: 18.05.2019

Poc : BabyLYK SQL Injection


Dork: intext:Website design A & H Design 2 Print & Web id=
Date: 17.05.2019

Poc : Abstract of New Technology SQL Injection


Dork: intitle:Abstract of New Technology id=
Date: 17.05.2019

Poc : ‫פלדות אלגר בנגב‬ SQL Injection


Dork: intitle:‫ פלדות אלגר בנגב‬cat=8&id_category=15
Date: 17.05.2019

Poc : Yeshiva Tiferet İsrael SQL Injection


Dork: intext: by Yeshiva Tiferet id=
Date: 17.05.2019

Poc : Katoomba Group SQL Injection


Dork: intitle:Welcome to the Katoomba Group id=
Date: 17.05.2019

Poc : AlumniMagnet XSS Vulnerability


Dork: intext:Powered by AlumniMagnet site:edu inurl:/images.html?view_album=
site:edu
Date: 17.05.2019

Poc : WordPress Share Buttons Plugin – AddThis Path Disclosure 6.2.3 Vulnerability
Dork: intext:/wp-content/plugins/addthis/backend/AddThisPlugin.php
Date: 17.05.2019

Poc : rimitrading Boolean SQL Injection


Dork: intext: Powered by erigoitsolutions
Date: 16.05.2019

Poc : Teaminertia CMS Sql Injection Vulnerability


Dork: dork : intext:Design by Team Inertia Technologies & inurl:/.php?id=
Date: 16.05.2019

Poc : Geneseo Schools Directory Traversal


Dork: inurl:index.php?page= .php
Date: 16.05.2019

Poc : SAMANET ARABIC CMS SQL injection


Dork: intext:By SAMANET inurl:*id=
Date: 16.05.2019

Poc : İyiwebsitesi.com SQL Login bypass


Dork: intext:Powered by iyiWebSitesi
Date: 16.05.2019

Poc : fusionsecond ARABIC CMS SQL injection


Dork: intext:‫ تطوير وتصميم فيوجن سكند‬inurl:*id=
Date: 16.05.2019

Poc : МБОУДО СДЮСШОР № 7 «Акробат» SQL İnjection


Dork: intitle:МБОУДО СДЮСШОР № 7 «Акробат» trainers.php?id=3
Date: 15.05.2019

Poc : C3iM * HiperwebBrasil * HumbertoCaldas * Vale Mais Comunicação * Webproj Web


Designs XSS Vulnerability
Dork: intext:Hiperweb Brasil site:br
Date: 15.05.2019

Poc : mrhavakuk Authentication Bypass SQL Injection


Dork: site:www.mrhavakuk.co.il forum/adminlogin.asp
Date: 15.05.2019

Poc : Techno Traders Pakistan admin bypass


Dork: powered by Techno Traders Pakistan or inurl site/admin/login.php
Date: 15.05.2019

Poc : XOOPS CMS 2.5.9 SQL Injection


Dork: inurl:gerar_pdf.php inurl:modules // use your brain ;)
Date: 13.05.2019

Poc : SHOOUB ADV ARABIC CMS SQL injection


Dork: intext:SHOOUB ADV inurl:*id=
Date: 13.05.2019

Poc : Mohammad Ali Abassi(Web designers) IRANIAN CMS SQL injection


Dork: intext:Design and developed by : Mohammad Ali Abassi
Date: 13.05.2019

Poc : 2 Plan Team 1.3.0 - Application error message Vulnerability


Dork: intext:Login @ 2-plan
Date: 13.05.2019
Poc : AlumniMagnet Unrestricted File Upload Vulnerability
Dork: intext:Powered by AlumniMagnet site:edu inurl:/images.html?view_album=
site:edu
Date: 13.05.2019

Poc : Turkish Radio Web Page SQL İnjection


Dork: inurl:haberoku.php?id= intext:radyo
Date: 12.05.2019

Poc : East of Western(Web designers) SQL injection


Dork: intext:Site powered by East of Western inurl:*id=
Date: 11.05.2019

Poc : Turkish Radio Web Page SQL İnjection haberoku.php?id="


intext:"radyo"
Dork: inurl:haberoku.php?id= intext:radyo
Date: 11.05.2019

Poc : WordPress Diarise 1.5.9 Local File Disclosure


Dork: inurl:wp-content/themes/diarise/
Date: 11.05.2019

Poc : Extreme Sistemas CMS SQL Injection


Dork: inurl:pagina.aspx?cat= // use your brain ;)
Date: 11.05.2019

Poc : PHPads 2.0 click.php3?bannerID SQL Injection


Dork: inurl:click.php3?bannerID= // use your brain ;)
Date: 11.05.2019

Poc : "Incrementer Technology Solutions" Upload Shell


Dork: intext:Design by Incrementer Technology Solutions Pvt. Ltd.
Date: 10.05.2019

Poc : fire Shop IRANIAN CMS SQL injection & Remote File Upload
Dork: intext:‫قدرت گرفته از فروشگاه ساز فايرشاپ‬
Date: 10.05.2019

Poc : Justboil.ME Plugins Image Upload Vulnerability New Method


Dork: inurl:/plugins/justboil.me/ site:
Date: 10.05.2019

Poc : Royalways WebDesign Authentication Bypass SQL Injection


Dork: intext:Website Design By Royalways
Date: 10.05.2019

Poc : Symphony Project sfDoctrinesfPropel 1.x Database Password Disclosure


Dork: class: sfDoctrineDatabase inurl:/config/databases.yml
Date: 10.05.2019

Poc : EastTechnology Hong Kong 此網站由東科技設計 XSS SQL Injection


Dork: 此網站由東科技設計
Date: 09.05.2019

Poc : Biznetvigator Accessibility HongKong SQL Injection


Dork: Mary Rose School Hong Kong
Date: 09.05.2019
Poc : Mairie de Toreilles French Municipality XSS SQL Injection
Dork: Mairie de Torreilles
Date: 09.05.2019

Poc : SACtr Website SQL Injection


Dork: inurl:/page.php?id=
Date: 09.05.2019

Poc : EGYGRAFX Website SQL Injection


Dork: inurl:articles.php?id=
Date: 09.05.2019

Poc : MiniFtp parseconf_load_setting Buffer Overflow


Dork: None
Date: 09.05.2019

Poc : Meggie Schneider SQL Injection


Dork: inurl:category.php?id=
Date: 08.05.2019

Poc : SMTMax SQL Injection


Dork: inurl:category.php?id=
Date: 08.05.2019

Poc : Rena Metro Germany SQL Injection


Dork: inurl:detail.php?id=
Date: 08.05.2019

Poc : Wordpress - W3 Total Cache - SSRF / RCE


Dork: inurl:/wp-content/plugins/w3-total-cache/readme.txt
Date: 08.05.2019

Poc : Moradabad Institue of Technology SQL Injection


Dork: inurl:articlesdetails.php?id=
Date: 08.05.2019

Poc : Belbana NV SQL Injection


Dork: inurl:view_items.php?id=
Date: 08.05.2019

Poc : MegaSoftTransparencia SQL Injection


Dork: Desenvolvido por Megasoft Informática LTDA. site:go.gov.br
Date: 07.05.2019

Poc : SO-AT Solution CMS Bypass SQL Login


Dork: inurl:/coop/re_register.php
Date: 07.05.2019

Poc : Kendriya Vidyalaya Sourabh Kumar Mishra PHP-Fusion SQL Injection


Dork: Alumni detail view intext:Kendriya Vidyalaya - site:edu.in
Date: 07.05.2019

Poc : Studio2ABrasil SQL Injection


Dork: inurl:/revenda_ver.php?id= noticias site:br
Date: 07.05.2019

Poc : BoutikOne XSS


Dork: allintext:Distributed by BoutikOne
Date: 07.05.2019
Poc : OpusPromocoes SQL Injection
Dork: opuspromocoes inurl:/programacao.php?id=
Date: 07.05.2019

Poc : Aspire Designs Indiamart SQL Injection


Dork: intext:Developed by : Aspire Designs site:in
Date: 07.05.2019

Poc : Fluent Technology Pvt. Ltd. India XSS SQL Injection


Dork: intext:Developed By - Fluent Technology Pvt. Ltd. site:in
Date: 07.05.2019

Poc : Rajeb Chowdhury XSS SQL Injection


Dork: intext:Design & Developed By Rajeb Chowdhury site:bd
Date: 07.05.2019

Poc : Tarka Web Design SQLi


Dork: intext:php?ID= Developed by Tarka Web Design
Date: 07.05.2019

Poc : microASP (Portal+) CMS SQL Injection


Dork: inurl:/pagina.phtml?explode_tree // use your brain ;)
Date: 07.05.2019

Poc : Design by WebDevelopersPune Arbitrary File Upload Vulnerability


Dork: intext:Design by WebDevelopersPune
Date: 06.05.2019

Poc : G Digital Media Solutions India Admin Panel Bypass


Dork: intext:” Designed & Developed By G Digital Media Solutions India Pvt. Ltd.”
Date: 06.05.2019

Poc : TraveloWeb Login Bypass


Dork: allintext:Powered by : TraveloWeb
Date: 06.05.2019

Poc : Si Restu Admin Page Login Baypass


Dork: Dork :inurl:/admin/login.php Intext:Sistem Informasi Masa Berlaku
Rekomendasi SITU
Date: 06.05.2019

Poc : CMS Profile Application NSI SQL-Injection Vulnerability


Dork: inurl:/semua-tokoh.html site:id
Date: 05.05.2019

Poc : © Opera Nationala 2010 - Prezent Admin Panel Bypass Vulnerabilities


Dork: intext:© Opera Nationala 2010 - Prezent site:.ro
Date: 05.05.2019

Poc : Thailand Majesty PhraCharoen Provincial Police Region P1 XSS SQL Injection
Dork: ทรงพระเจริญ | ตำรวจภูธรภาคที่ 1
Date: 04.05.2019

Poc : Kementerian Agama Indonesia Voting System SQL Injection


Dork: Aplikasi Pemilihan Agen Perubahan Kementerian Agama Online site:go.id
Date: 04.05.2019

Poc : Pemerintah Kota Cimahi Pelayanan Terpadu Indonesia SQL Injection


Dork: © 2017 - Dinas Penanaman Modal dan Pelayanan Terpadu Satu Pintu Kota Cimahi.
site:go.id
Date: 04.05.2019

Poc : Web Dinas Pariwisata dan Kebudayaan Provinsi Jawa Barat Indonesia XSS SQL
Injection
Dork: Beranda - Web Dinas Pariwisata dan Kebudayaan Provinsi Jawa Barat site:go.id
Date: 04.05.2019

Poc : Assesi Serviço de Informação Cidadão e-Sic Brazil SQL Injection


Dork: inurl:/materias.php?id= site:gov.br intext:Erro ao executar a query:
Date: 04.05.2019

Poc : CompletaWeb Comunicação Virtual Brazil SQL Injection


Dork: intext:Desenvolvido por CompletaWeb Soluções Virtuais
Date: 04.05.2019

Poc : ThailandGov Agricultural Commodity and Food Standards XSS SQL Injection
Dork: National Bureau of Agricultural Commodity and Food Standards - ACFS
site:go.th
Date: 04.05.2019

Poc : Sorubak Login Panel SQL BYPASS


Dork: allintext: sorubak.com
Date: 03.05.2019

Poc : [PEEL.FR] SQL INJECTION


Dork: intext:Technologie : [PEEL.FR]
Date: 03.05.2019

Poc : Indonesian Government & University Admin weak password


Dork: inurl:/web/strukturorganisasi/ site:
Date: 03.05.2019

Poc : Kementerian Perindustrian Balai Besar Pulp dan Kertas Indonesia SQL Injection
Dork: Kementerian Perindustrian Balai Besar Pulp dan Kertas site:go.id
Date: 03.05.2019

Poc : Kementerian Pekerjaan Umum dan Perumahan Rakyat Indonesia XSS SQL Injection
Dork: Biro Hukum PU - Kementerian Pekerjaan Umum dan Perumahan Rakyat site:go.id
Date: 03.05.2019

Poc : Badan Pengawas Obat dan Makanan Republik Indonesia XSS SQL Injection
Dork: Notifkos Badan Pengawas Obat dan Makanan Republik Indonesia site:go.id
Date: 02.05.2019

Poc : Momtaj Trading Pvt Ltd Bangladesh Database Configuration Disclosure


Dork: intext:Design & Developed By Momtaj Trading(Pvt) Ltd. site:edu.bd
Date: 02.05.2019

Poc : WANCOM BY PASS LOGIN AND UPLOAD SHELL


Dork: intitle:WANCOM
Date: 01.05.2019

Poc : Yettishare / MFScripts.com - Server Side Request Forgery


Dork: intext:File Sharing Script Created By MFScripts.com
Date: 30.04.2019

Poc : Joomla! Component JiFile 2.3.1 - Arbitrary File Download


Dork: inurl:index.php?option=com_jifile
Date: 28.04.2019

Poc : EMH BY PASS ADMIN PANEL


Dork: intitle:ICOM : Admin Panel
Date: 28.04.2019

Poc : ifluid Techology Admin Login Bypass | UpShell


Dork: DEVELOPED BY IFLUID TECHNOLOGY
Date: 28.04.2019

Poc : BrokenGlass Designs SQL INJECTION


Dork: intext:Designed and Developed by BrokenGlass Designs
Date: 27.04.2019

Poc : RH Digisoft SQL INJECTION


Dork: intext:Designed and developed by RH Digisoft Technical Services
Date: 27.04.2019

Poc : Joomla! Component com_cwreserveer - SQL Injection


Dork: inurl:index.php?option=com_cwreserveer
Date: 27.04.2019

Poc : Câmara Metropolitana do Rio de Janeiro / Metropolitan Chamber - SQL Injection


Dork: Câmara Metropolitana site:rj.gov.br
Date: 26.04.2019

Poc : T-Series Solutions Bangladeshi Design reflected XSS


Dork: allintext:T-Series Solutions All Rights Reserved
Date: 26.04.2019

Poc : SethComunicacao FreshDesk Brazil SQL Injection


Dork: Faculdade Jesuíta Portal FAJE site:edu.br
Date: 25.04.2019

Poc : "Powered By Ecshop" Sql Injection Vulnerbility


Dork: intext:Powered By Ecshop php?id=
Date: 24.04.2019

Poc : SAUDI SOFTECH (MST) SQLi


Dork: intext:php?id= Designed By: SAUDI SOFTECH (MST)
Date: 24.04.2019

Poc : UliCMS 2019.2 / 2019.1 Multiple Cross-Site Scripting


Dork: intext:by UliCMS
Date: 23.04.2019

Poc : Red Wire Computers Login Panel SQL BYPASS


Dork: allintext: Powerd by Red Wire Computers
Date: 23.04.2019

Poc : peter bourne communications UK design SQLi


Dork: intext:php?id= website design by peter bourne communications
Date: 22.04.2019

Poc : Thailand Government CityVariety Corporation Error Based SQL Injection -


Arbitrary File Download
Dork: intext:Powered By CityVariety Corporation site:go.th
Date: 21.04.2019
Poc : LivroreClamacoes Grupo Ajulio Portugal SQL Injection
Dork: intext:Desenvolvido por AJTEC © 2018 Grupo AJúlio
Date: 20.04.2019

Poc : CyberDairy Solutions SQLi


Dork: intext:.php?id= Powered by CyberDairy Solutions
Date: 20.04.2019

Poc : lai_nassim Design - Admin Panel Bypass & SQLi


Dork: allintext:: lai_nassim@hotmail.fr
Date: 20.04.2019

Poc : Netcodes Technologies login bypass


Dork: allintext:Design & Developed by Netcodes Technologies
Date: 19.04.2019

Poc : Thailand Ministry of Public and Mental Health Union Library Management SQL
Injection - Reflected Cross Site Scripting
Dork: Library dmh.go.th ULibM (Union Library Management)
Date: 18.04.2019

Poc : Desenvolvido por EngePlus Brazil SQL Injection


Dork: intext:Desenvolvido por EngePlus site:br
Date: 17.04.2019

Poc : Site Desenvolvido Por Buscazip Guiaking Empresas Brazil SQL Injection
Dork: intext:Site desenvolvido por Buscazip, Guiaking Empresas
Date: 17.04.2019

Poc : Desenvolvido Por Network Evolution Brazil SQL Injection


Dork: intext:Desenvolvido Por, Network Evo
Date: 17.04.2019

Poc : Desenvolvido Com Por Oficina5 Brazil SQL Injection


Dork: intext:Desenvolvido com por Oficina5
Date: 17.04.2019

Poc : Cloud Base Multiple school Generate & Management System Sql injection
Vulnerability
Dork: intext:/website_upzilla/noticeUno/
Date: 17.04.2019

Poc : DevSoft * BTMArgeBilişim * Algoritma İzmir * M.Ceylan MPlusNet * Webİcerik *


Verisay * Web Designs XSS Vulnerability
Dork: intext:Web Yazılım: Devsoft
Date: 17.04.2019

Poc : DigaSell - Digital store PHP Script V1.0.0 Blind Sql Injection Vulnerability
Dork: intext:Copyright © DigaSell All Rights Reserved.
Date: 17.04.2019

Poc : Dinesh Kodithuwakku ADDprint XSS Vulnerability


Dork: intext:Design by - Dinesh Kodithuwakku | ADDprint site:lk
Date: 17.04.2019

Poc : Ekushey Project Manager CRM 3.1 Backdoor Account Vulnerability


Dork: intext:Login | Ekushey Project Manager CRM
Date: 17.04.2019
Poc : Emaar – Real Estate Agency Directory System 5.7 Unrestricted File Upload
Vulnerability
Dork: intext:© 2019 Emaar. All Rights Reserved.
Date: 17.04.2019

Poc : Responsive FIlemanager - Target Soft BD


Dork: intext:Develope By Target Soft BD
Date: 16.04.2019

Poc : BackUpWordPress 3.8 Plugins Backup Path Disclosure Vulnerability


Dork: intext:/wp-content/backupwordpress-
Date: 14.04.2019

Poc : CyberArk EPM 10.2.1.603 Security Restrictions Bypass


Dork: -
Date: 14.04.2019

Poc : Design & Developed by : SOFTBD Ltd. SQL Injection Vul


Dork: intext:Design & Developed by : SOFTBD Ltd. inurl:/about.php?id=
Date: 11.04.2019

Poc : Wordpress Markant theme Arbitrary file Download


Dork: inurl:/wp-content/themes/markant/
Date: 11.04.2019

Poc : Powered by 7Concepts Informatics Remote File Inculsion Vulnerability [ RFI ]


Dork: intext:Powered by 7Concepts Informatics
Date: 11.04.2019

Poc : PostgreSQL- Attack on default password


Dork: port:5432 PostgreSQL country:##ANY COUNTRY## FATAL: database
Date: 11.04.2019

Poc : Rest - Cafe and Restaurant Website CMS XSS Vulnerability


Dork: intext:chef.php?slug=
Date: 09.04.2019

Poc : ShoreTel Connect ONSITE Cross Site Scripting / Session Fixation


Dork: inurl:/signin.php?ret=
Date: 09.04.2019

Poc : Desenvolvido por Agencia CDG Design Brasil Improper Authentication


Dork: intext:Desenvolvimento por Agencia CDG Design site:br
Date: 09.04.2019

Poc : Joomla omponent iPhone homepage icon 2.0.0 Parameter SQL Injection
Dork: : inurl:index.php?option=com_iPhone homepage
Date: 08.04.2019

Poc : Engineered by Enigmaa Technologies group BASE64 Sql injection Vulnerability


Dork: Engineered by : Enigmaa Tech Group | Powered by Enigmaa Technologies |
Designed by Sphinx Technology
Date: 08.04.2019

Poc : The Company Business Website CMS Authentication Bypass Vulnerability


Dork: intext:© | Morkocbilisim
Date: 07.04.2019
Poc : Subrion cms v 4.1.2 Arbitrary File Download Vulnerability
Dork: intext: © 2019 Powered by Subrion CMS
Date: 07.04.2019

Poc : WordPress Menu Plugin - Mega Main Menu unauthorized backup


Dork: inurl:/wp-content/plugins/mega_main_menu/
Date: 07.04.2019

Poc : FreeSMS 2.1.2 SQL Injection


Dork: pass) RLIKE (SELECT (CASE WHEN (4404=4404) THEN 0x61646d696e74 ELSE 0x28
END)) AND (WpaN=WpaN
Date: 05.04.2019

Poc : Design by Soft Solutionz Admin Panel Authentication Bypass Vulnerability


Dork: intext:Design by Soft Solutionz
Date: 04.04.2019

Poc : Sayfa Simple SQL Injection


Dork: inurl:sayfa.php
Date: 04.04.2019

Poc : aktifcms Shell upload


Dork: inurl:/aktifcms/ , inurl:/aktifcms/upload/ site:tr ,
inurl:/aktifcms/upload/tmp/
Date: 04.04.2019

Poc : Seroch Server Admin Page Bypass


Dork: intext:Powered and preserved by:Seroch Server Solution
Date: 04.04.2019

Poc : Created by Fujishka sql injection Vulnerability


Dork: intext:Created by Fujishka
Date: 03.04.2019

Poc : The Company Business Website CMS Authentication Bypass Vulnerability


Dork: intext:© | Morkocbilisim
Date: 02.04.2019

Poc : Conception et réalisation MGSD Sql injection Vulnerability


Dork: intext:.php?id intext:Conception et réalisation MGSD
Date: 02.04.2019

Poc : WordPress - Nishizawa_Tmp Themes Directory Traversal Vulnerability


Dork: inurl:/wp-content/themes/nishizawa_tmp/
Date: 31.03.2019

Poc : Ordius IT Solutions Bypass Admin


Dork: intext:Designed By . Ordius IT Solutions Pvt. Ltd.
Date: 30.03.2019

Poc : Wehelp Ticket Support System v1.6 HTML Inject Vulnerability


Dork: Powered BY by Marwa El-Manawy
Date: 29.03.2019

Poc : Masch CMStudio Banners 8.6.1 Open Redirection


Dork: bannergo.php inurl:/modules/banners/
Date: 29.03.2019

Poc : WordPress 4.9.10 ButterKekse Plugins Open Redirection


Dork: inurl:/wp-content/plugins/butterkekse/
Date: 29.03.2019

Poc : WordPress 4.9.2 WordPress-Feed-Statistics Plugins 4.1 Open Redirection


Dork: inurl:/wp-content/plugins/wordpress-feed-statistics/
Date: 29.03.2019

Poc : WordPress 4.8 Ait-ThemesClub TemplatePreview 1.8.1 RFI Open Redirection


Dork: inurl:/template-preview.php?url=
Date: 28.03.2019

Poc : WordPress Ultimate Form Builder Plugins 1.0 Database Disclosure


Dork: filetype:sql inurl:/wp-content/plugins/ultimate-form-builder/
Date: 28.03.2019

Poc : HollandPlaza TexelseMedia AdvertisementsCounter Plugins Open Redirection


Dork: inurl:/plugins/advertisementscounter/ site:nl
Date: 28.03.2019

Poc : Masch CMStudio Banners Modules 8.6.1 Open Redirection


Dork: bannergo.php inurl:/modules/banners/
Date: 28.03.2019

Poc : Institut VerpackungsMarktForschung GMBH Modules Arbitrary File Upload


Dork: [PDF] inurl:/modules/fck/usr/
Date: 28.03.2019

Poc : WordPress 4.6.1 WireFunnel Plugins Open Redirection


Dork: inurl:/wp-content/plugins/wirefunnel/
Date: 28.03.2019

Poc : WordPress 5.1.1 WPBounce AND-AntiBounce Plugins 1.0.3 Open Redirection


Dork: inurl:/wp-content/plugins/AND-AntiBounce/
Date: 27.03.2019

Poc : WordPress 2.0.2 WP-Forum Plugins 1.7.8 Database Disclosure


Dork: forum_db.txt inurl:/wp-content/plugins/wp-forum/
Date: 27.03.2019

Poc : Jayam Web Solutions SQLi


Dork: intext:php?id= intext:Design by Jayam Web Solutions
Date: 27.03.2019

Poc : openSIS Student Information System SQLi


Dork: intitle:openSIS Student Information System
Date: 26.03.2019

Poc : Logicpro Solutions admin bypass


Dork: allintext:2018 Website Maintained & Designed By Logicpro Solutions
Date: 26.03.2019

Poc : AlumniMagnet Open Redirection


Dork: intext:Powered by AlumniMagnet site:edu
Date: 26.03.2019

Poc : Progetti di Impresa SRL ItalyGov Open Redirection


Dork: intext:Portale internet realizzato da Progetti di Impresa Srl - Copyright
site:it
Date: 26.03.2019
Poc : Spip CMS 2.x/3.x Add Administrator Account & Insert File Vulnerability
Dork: inurl:/spip.php?rubrique site:fr
Date: 26.03.2019

Poc : Sanskar Technolab Admin Login Bypass | UpShell


Dork: Designed by: Sanskar Technolab Pvt. Ltd.
Date: 25.03.2019

Poc : C T & T SQL Injection Vulnerability And Bypass Admin page Login
Dork: intext:Design & Developed By C T & T
Date: 25.03.2019

Poc : Wehelp ticket support system v1.5 XSS Vulnerability


Dork: Powered BY by Marwa El-Manawy
Date: 23.03.2019

Poc : WordPress 3.4.2 The-CL-Amazon-Thingy Plugins 1.0 Open Redirection


Dork: inurl:/wp-content/plugins/the-cl-amazon-thingy/
Date: 23.03.2019

Poc : Database compilation by Marco Castellani XSS Vulnerability


Dork: intext:Database compilation by Marco Castellani( INAF - Astronomical
Observatory of Rome)
Date: 22.03.2019

Poc : University of Barcelona Librarianship Center Spain RFI Open Redirection


Dork: BiD: textos universitaris de biblioteconomia i documentació Universitat de
Barcelona
Date: 22.03.2019

Poc : Independent University of Bangladesh IUB Database Disclosure


Dork: Slass Independent University Bangladesh
Date: 22.03.2019

Poc : WordPress Easy WP SMTP plugin 0-day


Dork: inurl:/wp-content/plugins/easy-wp-smtp/
Date: 22.03.2019

Poc : WordPress 5.0.4 Age-Verification Plugins 0.5 Open Redirection


Dork: inurl:/wp-content/plugins/age-verification/
Date: 21.03.2019

Poc : WordPress 4.9.8 KingAbdullahPort KAP Themes Database Configuration File


Download
Dork: inurl:/wp-content/themes/kap/
Date: 21.03.2019

Poc : WordPress 4.9.x U_Parts Themes Database Configuration File Download


Dork: inurl:/wp-content/themes/u_parts/
Date: 21.03.2019

Poc : WordPress 4.7.13 ChurcHope Responsive Themes 4.7.x Database Configuration


File Download
Dork: inurl:/wp-content/themes/churchope/
Date: 21.03.2019

Poc : WordPress 4.2.2 Oxygen-Theme Themes Database Configuration File Download


Dork: inurl:/wp-content/themes/oxygen-theme/
Date: 21.03.2019

Poc : WordPress 4.x CafeSalivation Themes Database Configuration File Download


Dork: inurl:/wp-content/themes/cafesalivation/
Date: 21.03.2019

Poc : WordPress 4.x Nishizawa_Tmp Themes Database Configuration File Download


Dork: inurl:/wp-content/themes/nishizawa_tmp/
Date: 20.03.2019

Poc : Negar CMS SQL INJECTION


Dork: intext:Powered by NegarCMS
Date: 20.03.2019

Poc : Gila CMS 1.9.1 Cross Site Scripting


Dork: intext:Powered By Gila CMS
Date: 20.03.2019

Poc : Shopping Portal Vlunrability bypass admin page login


Dork: inurl:/admin/insert-product.php
Date: 19.03.2019

Poc : WordPress Menu Plugin - Mega Main Menu v2.1.2 unauthorized backup download
Vulnerability
Dork: intext:/wp-content/plugins/mega_main_menu/
Date: 19.03.2019

Poc : Web Wiz Forums 12.01 Sql Injection Vulnerability


Dork: Forum Software by Web Wiz Forums® version 12.01 Copyright ©2001-2018 Web Wiz
Ltd.
Date: 19.03.2019

Poc : WordPress 5.0.4 Zangai Themes Open Redirection


Dork: inurl:/wp-content/themes/zangai/
Date: 18.03.2019

Poc : WordPress 5.0.4 FormCraft Plugins 2.0 CSRF Backdoor Access Vulnerability
Dork: inurl:/wp-content/plugins/formcraft/
Date: 18.03.2019

Poc : WordPress 5.1.1 Liberator Themes Arbitrary File Download


Dork: inurl:/wp-content/themes/liberator/inc/
Date: 18.03.2019

Poc : WordPress 5.1.1 Green_Farming_New Themes Arbitrary File Download


Dork: inurl:/wp-content/themes/green_farming_new/
Date: 18.03.2019

Poc : WordPress 4.8.9 Rowe Themes Arbitrary File Download


Dork: inurl:/wp-content/themes/rowe/
Date: 18.03.2019

Poc : Moodle 3.4.1 Remote Code Execution


Dork: inurl:/course/jumpto.php?jump=
Date: 17.03.2019

Poc : Studio G&G Corporate Communication Italy SQL Injection


Dork: intext:Powered by Studio G&G Corporate Communication site:it
Date: 16.03.2019
Poc : Dinesh Kodithuwakku ADDprint SQL Injection
Dork: intext:Design by - Dinesh Kodithuwakku | ADDprint site:lk
Date: 16.03.2019

Poc : aup.edu.ph SQL Injection


Dork: inurl: /features.php?id
Date: 15.03.2019

Poc : Site designer company & sql injection


Dork: intext:‫ طراحی و برنامه نویسی شرکت داده پرداز طراحان ماندگار‬inurl:?id=
Date: 15.03.2019

Poc : ISPROJEK Bypass SQL Login Admin Indonesia School PMB Sites Upload Shell
Vulnerability
Dork: intext:ISPROJEK
Date: 14.03.2019

Poc : Разработка сайта: Студия Взгляд SQL Injection


Dork: intext:Разработка сайта: Студия Взгляд inurl:.php?id=
Date: 14.03.2019

Poc : Database compilation by Marco Castellani unauthorized administrative access


Vulnerability
Dork: intext:Database compilation by Marco Castellani( INAF - Astronomical
Observatory of Rome)
Date: 13.03.2019

Poc : 2 Plan Team 1.0.4 - From XSS to Unauthorized administrative access


Vulnerability
Dork: intext:Login @ 2-plan
Date: 13.03.2019

Poc : SIMPONIE v2.3 Indonesia Government Responsive File Manager File Upload
Dork: intext:SIMPONIE v2.3
Date: 12.03.2019

Poc : Globalmedia Inti Semesta 2018 Sql injection


Dork: intext:copyright @ Globalmedia Inti Semesta 2018. All right reserved.
Date: 12.03.2019

Poc : Globalmedia Inti Semesta 2018 Sql injection


Dork: intext:copyright @ Globalmedia Inti Semesta 2018. All right reserved.
Date: 12.03.2019

Poc : WordPress Azzxx Themes Open Redirection


Dork: inurl:/wp-content/themes/azzxx/
Date: 12.03.2019

Poc : State University of Shahid Beheshti Iran SQL injection


Dork: site:sbu.ac.ir inurl:php?id=
Date: 10.03.2019

Poc : Goalline Sports Administration | SQLInjection


Dork: inurl:.php?id= Powered by Goalline Sports Administration
Date: 09.03.2019

Poc : penerimaan.polri.go.id Bypass Sql Login


Dork: -
Date: 09.03.2019

Poc : vw-tour-lite Comment Box Xss Vuln


Dork: inurl:/wp-content/themes/vw-tour-lite
Date: 07.03.2019

Poc : MeteoTemplate 17.1 Nectarine Diary Plugins 4.0 Open Redirection


Dork: redirectDiary.php inurl:/plugins/diary/
Date: 07.03.2019

Poc : MeteoTemplate 17.1 Nectarine globalSnow Plugins 1.1 Open Redirection


Dork: inurl:/plugins/globalSnow/
Date: 07.03.2019

Poc : Meteotemplate 17.1 Nectarine indoorData Plugins 4.0 Open Redirection


Dork: inurl:/plugins/indoorData/
Date: 07.03.2019

Poc : WordPress WP-DreamworkGallery Plugins 2.3 CSRF Backdoor Access Vulnerability


Dork: filetype:xml inurl:/wp-content/plugins/wp-dreamworkgallery
Date: 05.03.2019

Poc : elFinder 2.1.47 Command Injection


Dork: intitle:elFinder 2.1.x
Date: 05.03.2019

Poc : zzzphp CMS 1.6.1 Cross Site Request Forgery


Dork: intext:2015-2019 zzcms.com
Date: 05.03.2019

Poc : PHPMiniAdmin 1.9 Database Open No-Secure Exploit


Dork: inurl:phpminiadmin
Date: 04.03.2019

Poc : vBulletin 4.2.5 Ajax Threads 1.1.3 Lite Open Redirection


Dork: intext:Live Threads provided by AJAX Threads v1.1.3 (Lite)
Date: 04.03.2019

Poc : vBulletin 4.2.5 Thread Post Bookmarking 1.2.0 Open Redirection


Dork: intext:Thread / Post Bookmarks provided by Thread / Post Bookmarking v1.2.0
(Free)
Date: 04.03.2019

Poc : vBulletin 4.2.5 vBSuper_PM 1.2.3 Lite Open Redirection


Dork: intext:Super PM System provided by vBSuper_PM v1.2.3 (Lite)
Date: 04.03.2019

Poc : vBulletin 4.2.5 Member Map 1.1.2 Lite Open Redirection


Dork: intext:Live Map provided by Member Map v1.1.2 (Lite)
Date: 04.03.2019

Poc : DongDuongCMS Vietnext Unauthorized File Insertation Vulnerability


Dork: intext:Design by Vietnext ® site:vn
Date: 04.03.2019

Poc : MeteoTemplate 17.1 Nectarine Deviations Plugins 2.0 Open Redirection


Dork: inurl:/plugins/deviations/redirect.php
Date: 03.03.2019
Poc : Engr Rashedul Islam StitBD Software Improper Authentication Backdoor Access
Vulnerability
Dork: intext:Develop By: Engr. Rashedul Islam Technical Support: STITBD site:edu.bd
Date: 03.03.2019

Poc : Web Wiz Forums 12.01 Database Disclosure Exploit


Dork: Forum Software by Web Wiz Forums® version 12.01 Copyright ©2001-2018 Web Wiz
Ltd.
Date: 03.03.2019

Poc : Indonesia Toko CMS Bypass SQL Admin Login


Dork: inurl:index.php?mnu=login
Date: 02.03.2019

Poc : SMF 2.0.15 SMF4Mobile 1.1.5/1.2 SMF-Media Open Redirection


Dork: redirect intext:SMF4Mobile 1.1.5 © SMF-Media.com
Date: 02.03.2019

Poc : XenForo 1.5.x Advanced Application Forms 1.2.2 Open Redirection


Dork: intext:Advanced Application Forms 1.2.2 © 2011 by Snog
Date: 02.03.2019

Poc : XenForo 1.5.x XF-Russia Open Redirection


Dork: intext:Forum software by XenForo™ ©2010-2016 XenForo Ltd. XF-Russia.ru
Date: 02.03.2019

Poc : vBulletin 3.8.x vBadvanced CMPS v3.2.3 Open Redirection


Dork: intext:Powered by vBadvanced CMPS v3.2.3
Date: 01.03.2019

Poc : vBulletin 3.8.4 Zoints SEO 2.3.2 Computer-Logic Open Redirection


Dork: intext:Zoints SEO v2.3.0 by Zoints & Computer-Logic.org
Date: 01.03.2019

Poc : vBulletin 4.2.5 vBSEO 3.6.1 Open Redirection


Dork: Search Engine Optimization by vBSEO 3.6.1 inurl:/?redirect=
Date: 28.02.2019

Poc : vBulletin 4.x.x DragonByte SEO v2.0.31 Pro Open Redirection


Dork: intext:Search Engine Optimisation provided by DragonByte SEO v2.0.31 (Pro)
Date: 28.02.2019

Poc : Joomla Content Components 3.x SQL Injection


Dork: inurl:/index.php?option=com_content
Date: 28.02.2019

Poc : DassInfotech Bypass Panel


Dork: intext:Design By DassInfotech.com
Date: 28.02.2019

Poc : MeteoTemplate 17.1 Nectarine windDirection Plugins 2.2 Open Redirection


Dork: inurl:/meteo/plugins/windDirection/
Date: 27.02.2019

Poc : WordPress NativeChurch Multi-Purpose Themes 5.0.x Arbitrary File Download


Dork: [PDF]Sample PDF File inurl:/wp-content/themes/NativeChurch/
Date: 27.02.2019

Poc : ARTX Softtech | Sql injection


Dork: intext:Copyright © 2018 | All rights reserved | Whitex Design Limited |
Develop By @ ARTX Sore
Date: 27.02.2019

Poc : MeteoTemplate 17.1 Nectarine Deviations Open Redirection


Dork: inurl:/plugins/deviations/redirect.php
Date: 26.02.2019

Poc : AsureSoftware AsureForce Time Version 12.0 Open Redirection


Dork: intext:AsureForce Time Version 12.0
Date: 26.02.2019

Poc : MeteoTemplate 17.1 Nectarine stationExtremes Plugins 2.0 Open Redirection


Dork: inurl:/meteo/plugins/stationExtremes/
Date: 26.02.2019

Poc : 1up! Software Going1up The Newspaper CMS 1998-2019 1.x Open Redirection
Dork: intext:Software © 1998-2019 1up! Software, All Rights Reserved
Date: 26.02.2019

Poc : Subrion cms v 4.0.5.10 Arbitrary File Download Vulnerability


Dork: intext: © 2019 Powered by Subrion CMS
Date: 25.02.2019

Poc : Joomla FlexiContent Components 3.2.1.15 SQL Injection


Dork: inurl:/index.php?option=com_flexicontent
Date: 25.02.2019

Poc : Joomla Contact Enhanced Components 3.9.2 SQL Injection


Dork: inurl:/index.php?option=com_contact_enhanced
Date: 25.02.2019

Poc : Joomla JM Car Classifieds CarAgent Templates 3.8.12 SQL Injection


Dork: inurl:/index.php?option=com_djclassifieds
Date: 25.02.2019

Poc : Fajri Web Solutions SQL-Injection Vulnerability


Dork: intext:inurl:/php?id= intext:by Fajri.com
Date: 20.02.2019

Poc : HAM3D Shop CMS Security Hole XSS & SQlinjection [Nullix TM]
Dork: intext:ham3d.net inurl:id=
Date: 20.02.2019

Poc : sananet cms sql injection


Dork: intext :‫طراحي و راه اندازي از طراحان سنا نت‬
Date: 19.02.2019

Poc : Joomla JWallPapers Components 2.0.1 CSRF Backdoor Access Vulnerability


Dork: inurl:/index.php?option=com_jwallpapers
Date: 19.02.2019

Poc : Joomla JoomGallery 3.2.2 PonyGallery 2.5.1 SQL Injection


Dork: inurl:/index.php?option=com_ponygallery
Date: 18.02.2019

Poc : LayerBB 1.1.1 XSS Vulnerability


Dork: intext:Powered by LayerBB 1.1.1
Date: 18.02.2019
Poc : BytecoinPool 7.0 Sensitive information disclosure Vulnerability
Dork: intext:Powered with doorGets ™
Date: 18.02.2019

Poc : AMSS++ v 2.0 Backdoor account Vulnerability


Dork: แนะนำให้ใช้บราวเซอร์ Google Chrome AMSS++
Date: 18.02.2019

Poc : Openbiz Cubi 3.0.8 Arbitrary File Download Vulnerability


Dork: intext: System Login - Cubi Platform
Date: 18.02.2019

Poc : eBrigade ERP 4.5 Backdoor Account Vulnerability


Dork: intext:eBrigade
Date: 18.02.2019

Poc : Subrion cms 4.2.0 Arbitrary File Download Vulnerability


Dork: intext: © 2019 Powered by Subrion CMS
Date: 18.02.2019

Poc : WordPress WP-JS-External-Link-Info Plugins 2.2.0 Open Redirection


Dork: inurl:/wp-content/plugins/wp-js-external-link-info/
Date: 18.02.2019

Poc : Listing Hub CMS 1.0 SQL Injection


Dork: inurl:pages.php?title=privacy-policy
Date: 17.02.2019

Poc : JobFinder Cross Site Scripting


Dork: inurl:jobs?j=Accounting
Date: 17.02.2019

Poc : Find A Place CMS Directory 1.5 SQL Injection


Dork: inurl:assets/external/data.php
Date: 17.02.2019

Poc : BLack Media Group Admin Default User and pass


Dork: intext: Design By Black Media Group
Date: 16.02.2019

Poc : Kurumsal Script v4 Admin Page Bypass


Dork: Powered By Psoft
Date: 16.02.2019

Poc : UniSharp Laravel File Manager 2.0.0-alpha7 Arbitrary File Upload


Dork: inurl:laravel-filemanager?type=Files -site:github.com -site:github.io
Date: 16.02.2019

Poc : phpMyVisites CNTNT Templates 2.4 SQL Injection


Dork: inurl:/index.php?mact=
Date: 15.02.2019

Poc : Joomla DatsoGallery Components 3.4.4 SQL Injection


Dork: inurl:/index.php?option=com_datsogallery
Date: 15.02.2019

Poc : Joomla DT Register Components 4.0.3 SQL Injection


Dork: inurl:/index.php?option=com_dtregister
Date: 15.02.2019

Poc : Joomla EasyBookReloaded Components 3.3.2 SQL Injection


Dork: inurl:/index.php?option=com_easybookreloaded
Date: 15.02.2019

Poc : Joomla LightGallery Components 1.2.1 SQL Injection


Dork: inurl:/index.php?option=com_lightgallery
Date: 15.02.2019

Poc : Joomla OSMap Components 4.2.19 SQL Injection / Database Disclosure


Dork: inurl:/index.php?option=com_osmap
Date: 15.02.2019

Poc : Joomla PhocaMaps 3.0.5 SQL Injection / Database Disclosure


Dork: inurl:/index.php?option=com_phocamaps
Date: 15.02.2019

Poc : Joomla PrayerCenter 3.0.4 SQL Injection / Database Disclosure


Dork: inurl:/index.php?option=com_prayercenter
Date: 15.02.2019

Poc : Joomla VirtueMart Components 3.4.1 SQL Injection


Dork: inurl:/index.php?option=com_virtuemart
Date: 15.02.2019

Poc : ImgHosting 1.2 html injection Vulnerability


Dork: intext:ImgHosting Programming by FoxSash
Date: 14.02.2019

Poc : Joomla ZCalendar Zap Calendar 4.4.0 SQL Injection


Dork: inurl:/index.php?option=com_zcalendar
Date: 14.02.2019

Poc : Joomla ExtCalendar 2.0 SQL Injection


Dork: inurl:/index.php?option=com_extcalendar
Date: 13.02.2019

Poc : Desined by Anaxco Admin Panel Bypass


Dork: Powered by Anaxco
Date: 13.02.2019

Poc : XLAgenda 4.4 CSRF Vulnerability


Dork: intext:Propulsé par XLAgenda 4.4
Date: 13.02.2019

Poc : ResourceSpace 8.6 watched_searches.php SQL Injection


Dork: intext:Powered by ResourceSpace
Date: 12.02.2019

Poc : Joomla JoomGallery 3.2.2 PonyGallery 2.5.1 SQL Injection / Database


Disclosure
Dork: inurl:/index.php?option=com_ponygallery
Date: 12.02.2019

Poc : Joomla WordPress Blog 4.8.0 SQL Injection


Dork: inurl:/index.php?option=com_wordpress
Date: 12.02.2019
Poc : Joomla PhocaGuestBook 3.0.8 SQL Injection / Database Disclosure
Dork: inurl:/index.php?option=com_phocaguestbook
Date: 12.02.2019

Poc : Joomla AcePolls 3.x SQL Injection


Dork: inurl:/index.php?option=com_acepolls
Date: 11.02.2019

Poc : Joomla DocMan 3.3.4 SQL Injection


Dork: inurl:/index.php?option=com_docman
Date: 11.02.2019

Poc : Rukovoditel Project Management CRM 1.9.1 - XSS Vulnerability


Dork: intext:Powered by Rukovoditel
Date: 11.02.2019

Poc : Sistem Informasi Akademik - XSS Vulnerability


Dork: inurl:?mnux=login or Powered by Sisfo Kampus UNISMA
Date: 11.02.2019

Poc : Elearning Vlunrability sqli injection


Dork: Inurl:/?idberita= or Inurl:/hal=daftra page=berita
Date: 10.02.2019

Poc : Register Member Vlunrability Upload With .txt,.csv


Dork: inurl:upload.php .txt,csv
Date: 10.02.2019

Poc : Joomla jDownloads 3.2.63 SQL Injection / Database Disclosure


Dork: inurl:/index.php?option=com_jdownloads
Date: 10.02.2019

Poc : Joomla WebLinks 3.6.0 SQL Injection / Database Disclosure


Dork: inurl:/index.php?option=com_weblinks
Date: 10.02.2019

Poc : Joomla BreezingForms 1.9.0 SQL Injection / Database Disclosure


Dork: inurl:/index.php?option=com_breezingforms
Date: 10.02.2019

Poc : Joomla JVLE JV-LinkExchanger 3.2 SQL Injection


Dork: inurl:/index.php?option=com_jvle
Date: 10.02.2019

Poc : Joomla RedShop 2.0.0.3 SQL Injection / Database Disclosure


Dork: inurl:/index.php?option=com_redshop
Date: 08.02.2019

Poc : doorGets CMS 7.0 Unrestricted File Upload Vulnerability


Dork: intext:Powered with doorGets ™
Date: 08.02.2019

Poc : Stock Manager Advance with Point of Sale Module v3.4.11 - nulled Backdoor
Account Vulnerability
Dork: intext:© SMA Shop. All rights reserved. or product/minion-crazy
Date: 08.02.2019

Poc : Rukovoditel Project Management CRM 2.4.1 - LFI Vulnerability


Dork: intext:Powered by Rukovoditel
Date: 08.02.2019

Poc : Joomla ComProfiler Community Builder 2.4.0 SQL Injection / Database


Disclosure
Dork: inurl:/index.php?option=com_comprofiler
Date: 07.02.2019

Poc : Joomla FacileForms 1.4.7 SQL Injection


Dork: inurl:/index.php?option=com_facileforms
Date: 07.02.2019

Poc : Joomla PhotoMapGallery 1.0 SQL Injection


Dork: inurl:/index.php?option=com_photomapgallery
Date: 07.02.2019

Poc : Joomla RSForm 1.5 Multiple Vulnerabilities


Dork: inurl:/index.php?option=com_rsform
Date: 07.02.2019

Poc : Joomla WebMapPlus 1.0 SQL Injection


Dork: inurl:/index.php?option=com_webmapplus
Date: 07.02.2019

Poc : Joomla Mailto 1.2.2.2 SQL Injection


Dork: inurl:/index.php?option=com_mailto
Date: 06.02.2019

Poc : Joomla Jumi 3.0.5 Database Disclosure / SQL Injection


Dork: inurl:/index.php?option=com_jumi
Date: 04.02.2019

Poc : WordPress Ultimate-Member Plugins 2.0.38 CSRF Backdoor Access


Dork: inurl:/wp-content/plugins/ultimate-member/
Date: 04.02.2019

Poc : Joomla PhocaDownload Components 3.1.7 SQL Injection / Database Disclosure


Dork: inurl:/index.php?option=com_phocadownload
Date: 03.02.2019

Poc : Joomla ActivityManager Components 5.3 SQL Injection


Dork: inurl:/index.php?option=com_activitymanager
Date: 03.02.2019

Poc : Joomla Mailto Components 1.2.2.2 SQL Injection


Dork: inurl:/index.php?option=com_mailto
Date: 03.02.2019

Poc : Joomla Ninja RSS Syndicator Components 2.0.5 SQL Injection


Dork: inurl:/index.php?option=com_ninjarsssyndicator
Date: 03.02.2019

Poc : Design & Developed By Seawind Solution Pvt Ltd. Sql injection
Dork: inurl:.php?id= intext:Design & Developed By Seawind Solution Pvt Ltd.
Date: 03.02.2019

Poc : DoorGets CMS 7.0 Sensitive information disclosure Vulnerability


Dork: intext:Powered with doorGets ™
Date: 03.02.2019
Poc : AMSS++ v 4.2 Sql Injection Vulnerability
Dork: แนะนำให้ใช้บราวเซอร์ Google Chrome AMSS++
Date: 02.02.2019

Poc : SureMDM Local / Remote File Inclusion


Dork: inurl:/api/DownloadUrlResponse.ashx
Date: 02.02.2019

Poc : Joomla JamBook Components 1.5 SQL Injection


Dork: inurl:/index.php?option=com_jambook
Date: 01.02.2019

Poc : Joomla ChronoConnectivity2 Components 6.0.7 SQL Injection


Dork: inurl:/index.php?option=com_chronoconnectivity2
Date: 01.02.2019

Poc : Joomla Sobi2 SobiPro Components 1.4.9 SQL Injection


Dork: inurl:/index.php?option=com_sobi2
Date: 01.02.2019

Poc : Joomla GMapFP Google Map Components 3.52 SQL Injection


Dork: inurl:/index.php?option=com_gmapfp
Date: 01.02.2019

Poc : Event Locations 1.0.1 - unrestricted files upload Vulnerability


Dork: intext:/events_edit.php?id=
Date: 01.02.2019

Poc : Active super shop v1 5.1 HTML inject Vulnerability


Dork: intext:Home || Active Super Shop
Date: 01.02.2019

Poc : Joomla AtomiconGallery Components 1.5.x SQL Injection


Dork: inurl:/index.php?option=com_atomicongallery
Date: 01.02.2019

Poc : Joomla wgPicasa Components 3x SQL Injection


Dork: inurl:/index.php?option=com_wgpicasa
Date: 01.02.2019

Poc : Active Matrimonial CMS v 1.5 HTML inject Vulnerability


Dork: intext:Active Matrimonial CMS - All Rights Reserved
Date: 01.02.2019

Poc : Joomla HotelGuide Components 1.0 - XSS Vulnerability


Dork: inurl:/index.php?option=com_hotelguide
Date: 01.02.2019

Poc : KALIMATAN GOVERNMENT Grafik.php - XSS Vulnerability


Dork: inurl:/front/grafik.php?tahun=
Date: 01.02.2019

Poc : 2 Plan Team 1.0.4 - XSS Vulnerability


Dork: intext:Login @ 2-plan
Date: 01.02.2019

Poc : Sistem Informasi Akademik SQL Injection


Dork: inurl:?mnux=login
Date: 31.01.2019
Poc : sijariEMAS v2.1 Login Xpath Injection Vulnerability
Dork: intext:Intext:Sistem Informasi dan Komunikasi Jejaring Rujukan Pelayanan
Kesehatan
Date: 31.01.2019

Poc : Joomla HotelGuide Components 1.0 SQL Injection


Dork: inurl:/index.php?option=com_hotelguide
Date: 31.01.2019

Poc : Joomla JUserTube Components 8.3.1 SQL Injection


Dork: inurl:/index.php?option=com_jusertube
Date: 31.01.2019

Poc : Joomla JEvents Components 3.4.47 SQL Injection


Dork: inurl:/index.php?option=com_jevents
Date: 31.01.2019

Poc : Joomla JComments Components 3.0.5 SQL Injection


Dork: inurl:/index.php?option=com_jcomments
Date: 31.01.2019

Poc : Joomla Formularz Components 1.0.2 SQL Injection


Dork: inurl:/index.php?option=com_formularz
Date: 31.01.2019

Poc : Joomla JooMap Components 2.0.6 SQL Injection


Dork: inurl:/index.php?option=com_joomap
Date: 31.01.2019

Poc : Active Matrimonial CMS v 1.4 HTML inject Vulnerability


Dork: intext:Copyright © 2019 Active Matrimonial CMS - All Rights Reserved
Date: 31.01.2019

Poc : Joomla MorfeoShow Components 1.2.0 SQL Injection


Dork: inurl:/index.php?option=com_morfeoshow
Date: 31.01.2019

Poc : Joomla Rokin RokGallery Components 3.2.6 SQL Injection


Dork: inurl:/index.php?option=com_rokin
Date: 31.01.2019

Poc : Joomla SimplestForum Components 1.5 SQL Injection


Dork: inurl:/index.php?option=com_simplestforum
Date: 30.01.2019

Poc : Mahkamah Agung CMS ( SIPP ) Versi 3.2.0-5 SQL INJECTION


Dork: inurl:/statistik_perkara
Date: 30.01.2019

Poc : Psoft Admin Panel Bypass


Dork: Powered By Psoft
Date: 30.01.2019

Poc : Fusioncms 2.1 Admin Panel Bypass


Dork: /cmsadmin/login.php intext: ::Administration Login::
Date: 30.01.2019

Poc : Joomla HWDVideoShare Components 1.5 SQL Injection / Database Disclosure /


Incorrect Authorization
Dork: inurl:/index.php?option=com_hwdvideoshare
Date: 30.01.2019

Poc : Joomla XMap Components 2.3.0 SQL Injection / Database Disclosure


Dork: inurl:/index.php?option=com_xmap
Date: 30.01.2019

Poc : Joomla Remository Components 3.58 SQL Injection / Database Disclosure /


Backdoor Access
Dork: inurl:/index.php?option=com_remository
Date: 30.01.2019

Poc : Joomla Zoo by YooTheme Components 3.3.10 SQL Injection / Database Disclosure
Dork: inurl:/index.php?option=com_zoo
Date: 29.01.2019

Poc : Goozmo™ Systems v.1.0 Improper Privilege Management


Dork: intext:Goozmo™ Systems - v.1.0
Date: 29.01.2019

Poc : LongBox Limited Access Manager Insecure Direct Object Reference


Dork: /runJob.html?jobId=<#>
Date: 29.01.2019

Poc : WordPress PT-Content-Views-Pro Plugins 2.1.2 SQL Injection


Dork: inurl:/wp-content/plugins/pt-content-views-pro/
Date: 28.01.2019

Poc : WordPress Add Code To Head upsite_analytics_plugin Plugins 1.13 SQL Injection
Dork: inurl:/wp-content/plugins/upsite_analytics_plugin/
Date: 28.01.2019

Poc : WordPress Snax Plugins 4.9.x SQL Injection


Dork: inurl:/wp-content/plugins/snax/templates/
Date: 28.01.2019

Poc : WordPress Advanced Custom Fields Pro Plugins 5.7.10 SQL Injection
Dork: inurl:/wp-content/plugins/advanced-custom-fields-pro/
Date: 28.01.2019

Poc : WordPress WP-Smushit Plugins 3.0.2 SQL Injection


Dork: inurl:/wp-content/plugins/wp-smushit/
Date: 28.01.2019

Poc : WordPress All-in-One WP Migration Plugins 6.83 SQL Injection


Dork: inurl:/wp-content/plugins/all-in-one-wp-migration/
Date: 28.01.2019

Poc : WordPress Yeloni Free Exit Popup Plugins 8.1.9 SQL Injection
Dork: inurl:/wp-content/plugins/yeloni-free-exit-popup/wordpress/
Date: 28.01.2019

Poc : WordPress Popup Builder Gold Plugins 3.1.5.2 SQL Injection


Dork: inurl:/wp-content/plugins/popup-builder-gold/
Date: 28.01.2019

Poc : WordPress Diamond MultiSite Widgets Plugins 1.8.2 SQL Injection


Dork: inurl:/wp-content/plugins/diamond-multisite-widgets/
Date: 28.01.2019

Poc : Papoo CMS PKalender Plugins 3.5 Database Disclosure


Dork: inurl:/plugins/pkalender/sql/
Date: 28.01.2019

Poc : Impression Technologies LLC - SQL Injection & XSS


Dork: intext:Website | Impression Technologies LLC inurl:store.php?id=
Date: 27.01.2019

Poc : WordPress MM-Forms-Community Plugins 2.2.7 Backdoor Access and SQL Injection
Vulnerability
Dork: inurl:/wp-content/plugins/mm-forms-community/
Date: 27.01.2019

Poc : WordPress pitajte-strucnjaka Plugins 4.9.6 Backdoor Access Vulnerability


Dork: inurl:/wp-content/plugins/pitajte-strucnjaka/
Date: 27.01.2019

Poc : Joomla RSFirewall Components 2.11.25 Database and Password Disclosure


Dork: inurl:/index.php?option=com_rsfirewall
Date: 25.01.2019

Poc : SirsiDynix e-Library 3.5.x Cross Site Scripting


Dork: inurl:/x/x/0/49
Date: 25.01.2019

Poc : DevSoft * BTMArgeBilişim * Algoritma İzmir * M.Ceylan MPlusNet * Webİcerik *


Verisay * Web Designs SQL Injection
Dork: intext:Web Yazılım: Devsoft - intext:Tüm hakları saklıdır. BTM ARGE. -
intext:www.algoritma.com.tr - intext:Powered By M.Ceylan site:tr - intext:Webİcerik
Kurumsal - intext:Verisay Web Tasarım
Date: 24.01.2019

Poc : Active Matrimonial CMS v 1.6 HTML inject Vulnerability


Dork: intext:Active Matrimonial CMS - All Rights Reserved
Date: 23.01.2019

Poc : Active super shop v1 5.2 HTML inject Vulnerability


Dork: intext:Home || Active Super Shop
Date: 23.01.2019

Poc : Desenvolvido C3iM Portugal XSS Vulnerability


Dork: intext:Desenvolvido C3iM site:pt
Date: 23.01.2019

Poc : HumbertoCaldas XSS Vulnerability


Dork: intext:Site by Humberto Caldas
Date: 22.01.2019

Poc : Powered by: Websites & More SQL Injection


Dork: inurl:php?id= intext:Powered by: Websites & More
Date: 22.01.2019

Poc : WebCzech CMS Sql Injection Vulnerability


Dork: intext:e-shop system WebCzech inurl:/.php?id=
Date: 22.01.2019

Poc : EKinerja Indonesia Goverment Bypass Admin Vulnerability


Dork: intext:EKinerja (Remunerasi Kinerja)
Date: 21.01.2019

Poc : Joomla JVFramework Components 1.6.4.0 Database Disclosure


Dork: inurl:/administrator/components/com_jvframework/
Date: 21.01.2019

Poc : Perfex v2.2.1 - Powerful Open Source CRM Backdoor Account Vulnerability
Dork: intext: Copyright Perfex INC
Date: 21.01.2019

Poc : Nomoweb CMS 2.2.2 SQL Injection Authentication Bypass


Dork: intext:Nomoweb 2.2.2
Date: 19.01.2019

Poc : Joomla Akeeba Backup Components 6.3.3 Database Disclosure


Dork: inurl:/administrator/components/com_akeeba/
Date: 19.01.2019

Poc : Joomla FPSS Art Frontpage Slideshow Components 1.6.0 Database Disclosure /
Open Redirection / SQL Injection
Dork: inurl:/index.php?option=com_fpss
Date: 19.01.2019

Poc : DNNSoftware EventsCalendar Modules 1.x Arbitrary File Download


Dork: intext:Copyright 2019 by Associated Builders and Contractors
Date: 18.01.2019

Poc : C3iM * HiperwebBrasil * HumbertoCaldas * Vale Mais Comunicação * Webproj Web


Designs SQL Injection
Dork: intext:Desenvolvido C3iM site:pt - intext:Hiperweb Brasil site:br -
intext:Site by Humberto Caldas - intext:Desenvolvido por Vale Mais Comunicação -
intext:Desenvolvido por Webproj site:br
Date: 18.01.2019

Poc : Joomla YoutubeGallery Components 4.5.8 Database Disclosure and SQL Injection
Dork: inurl:/index.php?option=com_youtubegallery
Date: 18.01.2019

Poc : Joomla ZHYandexMap Components 8.0.0.2 Database Disclosure


Dork: inurl:/administrator/components/com_zhyandexmap/ site:ru
Date: 18.01.2019

Poc : WordPress category-page-icons Plugins 3.6.1 CSRF Backdoor Access


Vulnerability
Dork: inurl:/wp-content/plugins/category-page-icons/
Date: 18.01.2019

Poc : ShoreTel / Mitel Connect ONSITE ST14.2 Remote Code Execution


Dork: +Public +My Conferences +Personal Library +My Profile +19.49.5200.0
Date: 17.01.2019

Poc : Blueimps jQuery file upload <=v9.22.0 Exploit for file upload
vulnerability
Dork: inurl: /jquery-file-upload/server/php
Date: 16.01.2019

Poc : Desarrollado por Rodrigo Guidetti RG21 Argentina SQL Injection


Dork: intext:Desarrollado por Rodrigo Guidetti
Date: 16.01.2019

Poc : Criação sitesrapidos.com.br Web Design Brazil SQL Injection


Dork: intext:criação: sitesrapidos.com.br
Date: 16.01.2019

Poc : Horizon Websolutions Administration Page Bypass


Dork: intext:Powered by: Horizon Websolutions
Date: 16.01.2019

Poc : Ariadna3 Web Design Spain - XSS Vulnerability


Dork: intext:Powered by ariadna3.com
Date: 16.01.2019

Poc : Sedinet SQL Injection


Dork: intext:Diseño, desarrollo y mantenimiento: Sedinet
Date: 16.01.2019

Poc : WordPress topcsstools Plugins 1.0 Remote File Inclusion and Open Redirect
Dork: inurl:/wp-content/plugins/topcsstools/
Date: 15.01.2019

Poc : ModX Open Source CMS Babel Modules 3.0.0 Open Redirect
Dork: inurl:/modules/babel/
Date: 15.01.2019

Poc : Ariadna3 Web Design Spain SQL Injection


Dork: intext:Powered by ariadna3.com
Date: 15.01.2019

Poc : Joomla Simple RSS Feed Reader mod_jw_srfr 3.6.0 Modules Open Redirect
Dork: inurl:/modules/mod_jw_srfr/
Date: 15.01.2019

Poc : Desarrollado por C-Diseño Web Design Spain SQL Injection


Dork: intext:Desarrollado por C-Diseño
Date: 15.01.2019

Poc : Desarrollado por OxiGenic Web Design Spain SQL Injection


Dork: intext:Desarrollado por OXIGENIC
Date: 15.01.2019

Poc : Desenvolvido por Fidelizarte Web Design Portugal SQL Injection


Dork: intext:Desenvolvido por Fidelizarte site:pt
Date: 15.01.2019

Poc : WordPress lbg_zoominoutslider Plugins 5.0.3 File Information Exposure


Dork: inurl:/wp-content/plugins/lbg_zoominoutslider/
Date: 14.01.2019

Poc : WordPress lbg-audio5-html5-shoutcast_sticky 4.9.x File Information Exposure


Dork: inurl:/wp-content/plugins/lbg-audio5-html5-shoutcast_sticky/
Date: 14.01.2019

Poc : WordPress all_in_one_bannerWithPlaylist Plugins 5.0.3 File Information


Exposure
Dork: inurl:/wp-content/plugins/all_in_one_bannerWithPlaylist/
Date: 14.01.2019
Poc : wehelp ticket support system v1.5 HTML Inject Vulnerability
Dork: Powered BY by Marwa El-Manawy
Date: 14.01.2019

Poc : WordPress all_in_one_bannerRotator Plugins 4.9.9 File Information Exposure


Dork: inurl:/wp-content/plugins/all_in_one_bannerRotator/
Date: 14.01.2019

Poc : WordPress lbg-audio8-html5-radio_ads Plugins 4.9.x File Information Exposure


Dork: inurl:/wp-content/plugins/lbg-audio8-html5-radio_ads/
Date: 14.01.2019

Poc : VideoPRO - Ultimate Video Sharing Platform Backdoor Account Vulnerability


Dork: Powered By GeniousOcean
Date: 13.01.2019

Poc : Design by david fox SQL Injection Vulnerability


Dork: intext:Design by david fox
Date: 12.01.2019

Poc : FoccusWeb Brasil Sao Paulo Web Design SQL Injection


Dork: intext:foccusweb site:br
Date: 11.01.2019

Poc : Desenvolvimento MSoftX Brasil Web Design SQL Injection and Open Redirection
Dork: intext:Desenvolvimento MSoftX
Date: 11.01.2019

Poc : Desenvolvido por Gilbert Sampaio SQL Injection


Dork: intext:Desenvolvido por Gilbert Sampaio.
Date: 11.01.2019

Poc : Diseño y Desarrollo Creadores Agencia Paraguay SQL Injection


Dork: intext:Diseño y Desarrollo: Creadores site:py
Date: 11.01.2019

Poc : Divabercom Almeria Spain Web Design SQL Injection


Dork: intext:Diseñado y desarrollado por Divabercom
Date: 11.01.2019

Poc : Desenvolvido por NSIBrasil Web Design SQL Injection


Dork: intext:Desenvolvido por nsibrasil
Date: 11.01.2019

Poc : Development Netgócio.pt ® Portugal Web Design SQL Injection


Dork: inurl:Development Netgócio ® site:pt
Date: 11.01.2019

Poc : Desenvolvimento Agência IndustriaWeb Webi.Com.Br SQL Injection


Dork: intext:Desenvolvido por WEBI site:br
Date: 11.01.2019

Poc : Heatmiser Wifi Thermostat 1.7 Cross Site Request Forgery


Dork: intitle:Heatmiser Wifi Thermostat & you can use shodan
Date: 10.01.2019

Poc : Netical24 Web Design SQL Injection Vulnerability


Dork: Diseño y Desarrollo Web:Netical24
Date: 10.01.2019
Poc : EstudioNeoFilms Web Design Argentina SQL Injection Vulnerability
Dork: intext:www.estudioneofilms.com.ar
Date: 10.01.2019

Poc : Anmoul Infomatics Pvt. Ltd India SQL Injection Vulnerability


Dork: intext:Powered By Anmoul Infomatics Pvt. Ltd site:edu.in
Date: 10.01.2019

Poc : İdeaSeven Web Design Cyprus SQL Injection Vulnerability


Dork: intext:web design by ideaseven.com site:cy
Date: 10.01.2019

Poc : Grupo LosGrobo Web Design Argentina SQL Injection Vulnerability


Dork: intext:Grupo LosGrobo site:ar
Date: 10.01.2019

Poc : Informatica Icarus Diteh Web Design Spain SQL Injection Vulnerability
Dork: intext:diseno web informatica icarus diteh
Date: 10.01.2019

Poc : Wordpress Plugin UserPro < 4.9.21 User Registration Privilege Escalation
Dork: inurl:/wp-content/plugins/userpro/
Date: 09.01.2019

Poc : Heatmiser Wifi Thermostat 1.7 - Cross-Site Request Forgery


Dork: intitle:Heatmiser Wifi Thermostat & you can use shodan
Date: 09.01.2019

Poc : Educational Websites Developper - Chris Deotte - Cross Site Scripting (XSS)
Dork: dork : intext: Website developed by Chris Deotte
Date: 09.01.2019

Poc : Joomla Codextrous Com_B2jcontact Components 2.1.17 Shell Upload Vulnerability


Dork: inurl:/index.php?option=com_b2jcontact
Date: 09.01.2019

Poc : ShopUp V 2016 - DOM-based cross site scripting


Dork: intext:Engine by Shopup.com
Date: 08.01.2019

Poc : ChenDesign CDA - Cross site Scripting / Sql injection


Dork: ntext:site design by chendesign.com || intext:site design by CDA
Date: 08.01.2019

Poc : Power By W3 IT Solution Web Company Nepal SQL Injection


Dork: intext:Power by W3 IT SOLUTION site:edu.np
Date: 08.01.2019

Poc : WordPress UserPro Privilege Escalation


Dork: inurl:/wp-content/plugins/userpro/
Date: 08.01.2019

Poc : By Prodigy PixiTale Games Bangladesh Education SQL Injection Vulnerability


Dork: intext:Designed by PIXITALE GAMES. site:edu.bd
Date: 08.01.2019

Poc : Iceberg Technology Software Nepal SQL Injection Vulnerability


Dork: inurl:Developed by:Iceberg Technology site:edu.np
Date: 08.01.2019

Poc : Trinity Solutions India SQL Injection Vulnerability


Dork: intext:Powered by Trinity Solutions site:edu.in
Date: 08.01.2019

Poc : Trendsoft Technologies India SQL Injection Vulnerability


Dork: intext:Designed & Maintained by Trendsoft Technologies
Date: 08.01.2019

Poc : Website Design by Haas IT Solutions XSS Vulnerability


Dork: Website Design by Haas IT Solutions, Inc.
Date: 08.01.2019

Poc : Kaadesign CMS Sql Injection Vulnerability


Dork: intext:‫ & تصميم وتطوير شركة الموسوعة العراقية‬inurl:CMS.php?CMS_P=
Date: 07.01.2019

Poc : Tariqul Computer & Internet Point TcipBD SQL Injection Vulnerability
Dork: intext:Developed By: Tariqul Computer & Internet Point site:edu.bd
Date: 07.01.2019

Poc : Sikder Computer Center Mathbaria Bangladesh SQL Injection Vulnerability


Dork: intext:Design & Developed by Sikder Computer, Mathbaria site:edu.bd
Date: 07.01.2019

Poc : Soft IT Security Hululu IT Bangladesh SQL Injection Vulnerability


Dork: intext:© Copyright 2019. Designed and
Date: 07.01.2019

Poc : Powered By ITNext Bangladesh Solutions Limited SQL Injection Vulnerability


Dork: intext:This is Web-App Not Only A Website!!!
Date: 07.01.2019

Poc : Zombi Bot V7 || 850+ Exploit,2000+ Shells, Hack Smtp,Cpanel,Root Server


2018||
Dork: intext:inurl:/wp-content/plugins/revslider/ inurl:sites/default/files
inurl:/index.php?option= inurl:inurloption=com in inurl:intext.php?
options=com_hello
inurl:/wp-content/plugins/framework/plugins/revslider/temp/update_extract/revslider
inurl:wp-content/themes/hospital
Date: 06.01.2019

Poc : Improved File Manager Arbitrary File Upload


Dork: intext:IFM - improved file manager
Date: 05.01.2019

Poc : RedGreenBD IT Solutions SQL Injection - Backup and File Disclosure


Dork: intext:Design & Developed by : RedGreenBD IT Solutions
Date: 05.01.2019

Poc : Template Web Portal Kampus Swarakalibata SQL-Injection Vulnerability


Dork: inurl:/page/detail/kata-sambutan site:id
Date: 05.01.2019

Poc : zStore 1.10 – an amazon Affiliate Store XSS Vulnerability


Dork: © homac e.U. 2018 powered by zStore
Date: 04.01.2019
Poc : Typo3 CMS twwc_pages Extension 8.7.x Database Disclosure
Dork: inurl:/typo3conf/ext/twwc_pages/
Date: 04.01.2019

Poc : Typo3 CMS Site Crawler Extension 6.1.2 Database Disclosure


Dork: inurl:/typo3conf/ext/crawler/
Date: 04.01.2019

Poc : Typo3 CMS YAG Themepack jQuery Extension 1.3.2 Database Disclosure
Dork: inurl:/typo3conf/ext/yag_themepack_jquery/
Date: 04.01.2019

Poc : Typo3 CMS Static Info Tables Extension 6.7.3 Database Disclosure
Dork: inurl:/typo3conf/ext/static_info_tables/
Date: 04.01.2019

Poc : Typo3 CMS pw_highslide_gallery Extension 0.3.1 Database Disclosure


Dork: inurl:/typo3conf/ext/pw_highslide_gallery/
Date: 04.01.2019

Poc : ModelAgency - Complete Model Agency and Directory System Backdoor Account
Vulnerability
Dork: Powered By GeniousOcean
Date: 03.01.2019

Poc : ProDoctor - Doctor Appointment System with Portfolio Management Backdoor


Account Vulnerability
Dork: Powered By GeniousOcean
Date: 03.01.2019

Poc : Powered by Quaid Technologie XSS Vulnerability


Dork: Powered by PakCyber
Date: 03.01.2019

Poc : Gusto - Recipes Management v1.5.1 System SQL Injection Vulnerability


Dork: /profile/1-gusto
Date: 02.01.2019

Poc : Gusto - Recipes Management v1.5.1 System Backdoor Account Vulnerability


Dork: /profile/1-gusto
Date: 02.01.2019

Poc : JustBoil.me Images Upload Vulnerability


Dork: /assets/tiny_mce/plugins/jbimages/dialog-v4.htm /
Date: 02.01.2019

Poc : Logo & Web Design by LogoBee XSS Vulnerability


Dork: intext:Logo & Web Design by LogoBee
Date: 02.01.2019

Poc : WordPress WP-Ajax-Form-Pro Plugins 5.0.2 Remote Shell Upload Vulnerability


Dork: inurl:/wp-content/plugins/wp-ajax-form-pro ,intext:AJAX Form Pro - All Rights
Reserved
Date: 01.01.2019

Poc : KALIMATAN GOVERNMENT XSS Grafik.php Vulnerability


Dork: inurl:/front/grafik.php?tahun=
Date: 01.01.2019
Poc : Designed & Developed By TAS TasPK Pakistan Education XSS Vulnerability
Dork: intext:Designed & Developed By TAS site:edu.pk
Date: 01.01.2019

Poc : Gusto - Recipes Management v1.5.1 System XSS Vulnerability


Dork: /profile/1-gusto
Date: 01.01.2019

Poc : PrestaShop PM_ModalCart Modules 1.6.1.4 Database Disclosure


Dork: inurl:/modules/pm_modalcart/
Date: 01.01.2019

Poc : PrestaShop PM_AdvancedSearch4 Modules 1.6.1.18 Database Disclosure


Dork: inurl:/modules/pm_advancedsearch4/
Date: 01.01.2019

Poc : PrestaShop yllyaidechantier Modules 1.4.9.0 Database Disclosure


Dork: inurl:/modules/yllyaidechantier/db/
Date: 01.01.2019

Poc : PrestaShop Google GSnippetsReviews Modules 1.6.1.4 Database Backup Disclosure


Dork: inurl:/modules/gsnippetsreviews/sql/
Date: 01.01.2019

Poc : PrestaShop PM_AdvancedTopMenu Modules 1.4.6.2 Database Disclosure and SQL


Injection
Dork: inurl:/modules/pm_advancedtopmenu/
Date: 01.01.2019

Poc : PrestaShop FacebookPsConnect Modules 1.6.1.4 Database Disclosure


Dork: inurl:/modules/facebookpsconnect/sql/
Date: 01.01.2019

Poc : Drupal 7 CivicRM Modules 5.8.2 Database Disclosure


Dork: inurl:/sites/all/modules/civicrm/sql/
Date: 01.01.2019

Poc : Summernote Arbitrary File Upload


Dork: intext:Summernote Image manager by futre
Date: 01.01.2019

Poc : Dreams Ultimate Solutions DreamSus India Improper XSS Vulnerability


Dork: intext:Designed and Developed by Dreams Ultimate Solutions site:edu.in
Date: 31.12.2018

Poc : Designed & Developed By TAS TasPK Pakistan Education XSS Vulnerability
Dork: intext:Designed & Developed By TAS site:edu.pk
Date: 31.12.2018

Poc : WordPress Plugin Audio Record 1.0 - Arbitrary File Upload


Dork: none
Date: 31.12.2018

Poc : WordPress Plugin Baggage Freight Shipping Australia 0.1.0 - Arbitrary File
Upload
Dork: none
Date: 29.12.2018

Poc : Simple Upload dan Download File Cross Site Scripting


Dork: inurl:/download.php Tgl. Upload
Date: 26.12.2018

Poc : Delta Sql 1.8.2 - Arbitrary File Upload


Dork: none
Date: 24.12.2018

Poc : Adobe ColdFusion 2018 Arbitrary File Upload


Dork: ext:cfm
Date: 22.12.2018

Poc : Powered By Ricaricaweb Cross Site Scripting Vulnerabiliry (Form Search)


Dork: intextPowered By Ricaricaweb | inurl:/login
Date: 22.12.2018

Poc : Designed & Developed by Brigadasoft Auth Bypass Vulnerability


Dork: intext:Designed & Developed by Brigadasoft
Date: 21.12.2018

Poc : WordPress St_Newsletter Swift Mailer Plugins 2.7 Remote Shell Upload
Vulnerability
Dork: inurl:/wp-content/plugins/st_newsletter/
Date: 20.12.2018

Poc : WordPress FCKEditor-For-Wordpress-Plugin 3.3.1 Remote Shell Upload


Vulnerability
Dork: inurl:/wp-content/plugins/fckeditor-for-wordpress-plugin/
Date: 20.12.2018

Poc : WordPress Monsters-Editor-10-For-WP-Super-Edit Plugins 2.3.1 Remote Shell


Upload Vulnerability
Dork: inurl:/wp-content/plugins/monsters-editor-10-for-wp-super-edit/mse/
Date: 20.12.2018

Poc : WordPress Sem-Wysiwyg Plugins 1.0 Remote Shell Upload Vulnerability


Dork: inurl:/wp-content/plugins/sem-wysiwyg/fckeditor/
Date: 20.12.2018

Poc : Surge Domain/Subdomain Takeover


Dork: intext:powered by surge.sh
Date: 20.12.2018

Poc : WordPress Lumise 4.9 Database Disclosure


Dork: inurl:/wp-content/plugins/lumise/woo/
Date: 18.12.2018

Poc : Simple CMS PHPJabbers Stivasoft 4.0 Database Backup Disclosure


Dork: intext:PHP Scripts Copyright © 2018 StivaSoft Ltd
Date: 18.12.2018

Poc : Desarrollado por Kodfee Constultores IT. Mexico XSS Vulnerability


Dork: intext:Desarrollado por Kodfee - Constultores IT.
Date: 17.12.2018

Poc : Design By iQ Digital İQ-Medya Web Hosting XSS Vulnerability


Dork: intext:Tasarım iQ Digital
Date: 17.12.2018

Poc : Acon - Architecture and Construction Website CMS v1.2 Backdoor Account
Vulnerability
Dork: Acon - Building and Architecture Website CMS
Date: 17.12.2018

Poc : Developed By NaiveScripters Noakhali Science and Technology University


Bangladesh XSS Vulnerability
Dork: intext:Developed By NaiveScripters site:edu.bd
Date: 17.12.2018

Poc : CMS Lokomedia -Local File Download


Dork: inurl: /downlot.php site: go.id
Date: 17.12.2018

Poc : Joomla! Com_regionalm SQL Injection


Dork: inurl:index.php?option=com_regionalm
Date: 17.12.2018

Poc : WordPress Ithemes-BackupBuddy Amazon WP-S3 Plugins 2.9 Database Backup


Disclosure
Dork: inurl:/wp-content/uploads/wp-s3-database-backup.sql
Date: 17.12.2018

Poc : WordPress Mirrorwp-Backups 4.8 Database Backup Disclosure


Dork: inurl:/wp-content/uploads/mirrorwp-backups/
Date: 17.12.2018

Poc : WordPress Dev-Custom-Management Plugins VerzDesign 1.0 Database Backup


Disclosure and Arbitrary File Upload
Dork: inurl:/wp-content/plugins/dev-custom-management/
Date: 17.12.2018

Poc : WordPress Lumise Plugins 4.9 Woo Database Backup Disclosure


Dork: inurl:/wp-content/plugins/lumise/woo/
Date: 17.12.2018

Poc : ITAdvisorsNepal 9Qube Testimonials Modules 1.0 Database Backup Disclosure


Dork: intext:Designed & developed by IT Advisors Nepal
Date: 17.12.2018

Poc : designed and developed by : japno IT department " SQL Injection "
Dork: intext:designed and developed by : japno IT department
Date: 15.12.2018

Poc : WordPress JoeBooking Plugins 6.6.5 Database Backup Disclosure


Dork: inurl:/wp-content/plugins/joebooking/
Date: 13.12.2018

Poc : WordPress MagicMembers Plugins 1.0 Database Backup Disclosure


Dork: inurl:/wp-content/plugins/magicmembers/core/libs/
Date: 13.12.2018

Poc : WordPress TimeTable Responsive Schedule Plugins 5.4 Database Backup


Disclosure
Dork: inurl:/wp-content/plugins/timetable/dummy-content-files/
Date: 13.12.2018

Poc : Bangladesh Educational School & College Admin Panels


Dork: admin/login
Date: 12.12.2018
Poc : WordPress Wysija-Newsletters 2.10.2 Database Backup Disclosure
Dork: inurl:/wp-content/plugins/wysija-newsletters/sql/
Date: 12.12.2018

Poc : Joomla Com_Acymailing Components 2.0.0 Database Backup Disclosure


Dork: inurl:/administrator/components/com_acymailing/
Date: 12.12.2018

Poc : Digitkart Multivendor Digital Products Marketplace V3.0 Backdoor Account


Vulnerability
Dork: All Rights Reserved. Designed by Avigher login
Date: 12.12.2018

Poc : Wordpress theme cameleon arbitrary file upload


Dork: inurl:/wp-content/themes/cameleon
Date: 12.12.2018

Poc : WordPress WP-Syntax Download Extension Plugins 1.1.1 Database Backup


Disclosure
Dork: inurl:/wp-content/plugins/wp-syntax-download-extension/
Date: 12.12.2018

Poc : WordPress Simple-E-Commerce-Shopping-Cart Plugins 2.2.5 Database Backup


Disclosure
Dork: inurl:/wp-content/plugins/simple-e-commerce-shopping-cart/
Date: 12.12.2018

Poc : WordPress WP EasyCart Plugins 3.1.11 Database Backup Disclosure


Dork: inurl:/wp-content/plugins/wp-easycart/inc/admin/sql/
Date: 12.12.2018

Poc : WordPress WP-Business-Directory Plugins 5.3.4 Multiple Vulnerabilities


Dork: inurl:/wp-content/plugins/wp-business-directory/
Date: 12.12.2018

Poc : WordPress Total-Child-Theme-Master Themes 1.0 Arbitrary File Download


Disclosure
Dork: inurl:/wp-content/themes/total-child-theme-master/
Date: 12.12.2018

Poc : WordPress WPide ACE-0.2.0 Plugins 2.4.0 Database Backup Disclosure


Dork: inurl:/wp-content/plugins/wpide/
Date: 12.12.2018

Poc : WordPress Simple-Forum Plugins 4.0 Database Backup Disclosure


Dork: inurl:/wp-content/plugins/simple-forum/admin/
Date: 12.12.2018

Poc : WordPress Shopp Plugins 1.4 Database Backup Disclosure


Dork: inurl:/wp-content/plugins/shopp/
Date: 12.12.2018

Poc : WordPress WP_Quiz Plugins 1.1.9 Database Backup Disclosure


Dork: inurl:/wp-content/plugins/wp_quiz/
Date: 12.12.2018

Poc : WordPress WP-Bannerize Plugins 4.0.2 Database Backup Disclosure


Dork: inurl:/wp-content/plugins/wp-bannerize/Classes/
Date: 12.12.2018

Poc : Dreams Ultimate Solutions DreamSus India Improper XSS Vulnerability


Dork: intext:Designed and Developed by Dreams Ultimate Solutions site:edu.in
Date: 11.12.2018

Poc : WordPress Events Made Easy Plugins 2.0.68 Database Backup Disclosure
Dork: inurl:/wp-content/plugins/events-made-easy/
Date: 11.12.2018

Poc : WordPress HighStand Themes 4.6.1 Database Backup Disclosure


Dork: inurl:/wp-content/themes/highstand/core/sample/
Date: 11.12.2018

Poc : WordPress Caldera Forms Plugins 1.7.4 Database Backup Disclosure


Dork: inurl:/wp-content/plugins/caldera-forms/
Date: 11.12.2018

Poc : WordPress Orbis Plugins 1.3.3 Pronamic Database Backup Disclosure


Dork: inurl:/wp-content/plugins/orbis/
Date: 11.12.2018

Poc : WordPress CodeCanyon-5293356-Ajax-Store-Locator-Wordpress Plugins 1.2.0


Multiple Vulnerabilities
Dork: inurl:/wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/
Date: 11.12.2018

Poc : WordPress Ad Buttons Plugins 3.1 Database Backup Disclosure


Dork: inurl:/wp-content/plugins/ad-buttons/
Date: 11.12.2018

Poc : WordPress WpEasyCart LevelFourStoreFront Plugins 8.1.16 Database Backup


Disclosure
Dork: inurl:/wp-content/plugins/levelfourstorefront/
Date: 11.12.2018

Poc : WordPress Ari Adminer Plugins 1.1.12 Database Backup Disclosure


Dork: inurl:/wp-content/plugins/ari-adminer/
Date: 11.12.2018

Poc : WordPress Exports-and-Reports Plugins 0.8.1 Database Backup Disclosure


Dork: inurl:/wp-content/plugins/exports-and-reports/
Date: 11.12.2018

Poc : WordPress newwpml Plugins 3.0 Database Backup Disclosure


Dork: inurl:/wp-content/plugins/newwpml/
Date: 11.12.2018

Poc : WordPress NikolayDyankovDesign Themes 2.0 Arbitrary File Download Disclosure


Dork: inurl:/wp-content/themes/nikolaydyankovdesign/
Date: 11.12.2018

Poc : WordPress Real-Estate-Listing-Realtyna-Wpl Plugins 4.3.2 Database Backup


Disclosure
Dork: inurl:/wp-content/plugins/real-estate-listing-realtyna-wpl/
Date: 11.12.2018

Poc : Digitkart Multivendor Digital Products Marketplace V4.0 Backdoor Account


Vulnerability
Dork: All Rights Reserved. Designed by Avigher login
Date: 11.12.2018

Poc : WordPress CSS & JavaScript Toolbox Plugins 8.4.1 Database Backup Disclosure
Dork: inurl:/wp-content/plugins/css-javascript-toolbox/models/
Date: 10.12.2018

Poc : WordPress BatchMove Plugins 1.5 Database Backup Disclosure


Dork: inurl:/wp-content/plugins/batchmove/
Date: 10.12.2018

Poc : WordPress Custom-Blocks SypexGeo Plugins 1.0 Database Backup Disclosure


Dork: inurl:/wp-content/plugins/custom-blocks/sypexgeo/
Date: 10.12.2018

Poc : WordPress Disqus Comment System Plugins 2.87 Database Backup Disclosure
Dork: inurl:/wp-content/plugins/disqus-comment-system/tests/
Date: 10.12.2018

Poc : 3CX Open Standards Software IP PBX Thailand XSS Vulnerability


Dork: intext:3CX: Open Standards Software IP PBX
Date: 10.12.2018

Poc : ApepBlack Premium Checker XSS Vulnerability


Dork: A tool made with by ApepBlack
Date: 10.12.2018

Poc : India Admin Panel Bypass


Dork: intext:2017 The Indian Institute of Welding
Date: 10.12.2018

Poc : Lider - The Best Social Network v 1.0.1 Blind Sql injection Vulnerability
Dork: intext:© 2018 SocialNetwork
Date: 10.12.2018

Poc : Copyright © 2008 by OPSTECH All Right Reserved Xss Vulnerability


Dork: intext:Copyright © 2008 by OPSTECH All Right Reserved. site:th
Date: 10.12.2018

Poc : Dashboard Dinkes Kab.Tangerang CSRF Vulnerability


Dork: inurl:/dashboard/index.php/login/
Date: 10.12.2018

Poc : Created by Vanavi.com Digital Agency Web Design xss Vulnerability


Dork: intext:Created by Vanavi.com site:cz
Date: 10.12.2018

Poc : Symfony 1.4.17 sfDoctrinePlugin sfPropelPlugin Database Backup Disclosure


Dork: inurl:/symfony/lib/plugins/sfPropelPlugin/
Date: 10.12.2018

Poc : Kurumsalx News Template Cross Site Scripting


Dork: intext:Kurumsalx Haber sistemi
Date: 10.12.2018

Poc : MTPReklam Kornea Web Design XSS Vulnerability


Dork: intext:mtpreklam
Date: 09.12.2018
Poc : Termit.Am Armenia Hosting Պատրաստեց TermIT ընկերությունը RFI Vulnerability
Dork: intext:Պատրաստեց TermIT ընկերությունը site:am
Date: 09.12.2018

Poc : SMSITE‫ נבנה ע״י‬SmSite.Co.il Hosting Israel XSS Vulnerability


Dork: intext:SMSITE‫נבנה ע״י‬
Date: 09.12.2018

Poc : Web Development Invasor Diagonal XSS Vulnerability


Dork: intext:web development // invasor diagonal
Date: 09.12.2018

Poc : OVOO v2.5.5 - Movie & Video Streaming CMS with Unlimited TV-Series backup
disclosure Vulnerability
Dork: intext:Ovoo movie & Tv Show streaming cms - Login
Date: 09.12.2018

Poc : MNW Digital Agency Mnw.Pt Hosting Portugal XSS Vulnerability


Dork: intext:MNW Digital Agency
Date: 09.12.2018

Poc : myIgniter v4.0.2 - Admin CRUD and Page Generator Backdoor Account
Vulnerability
Dork: Version 4.0.3 Copyright © 2018 kotaxdev. All rights reserved.
Date: 09.12.2018

Poc : myIgniter v4.0.2 - Admin CRUD and Page Generator export users list
Vulnerability
Dork: Version 4.0.3 Copyright © 2018 kotaxdev. All rights reserved.
Date: 09.12.2018

Poc : Web Portal People LLC 2018 OurClassOnline USA URL redirection Vulnerability
Dork: intext:To obtain a site like this for your class visit
www.ourclassonline.com.
Date: 07.12.2018

Poc : StNetwork 20.11 Auth By Pass Vulnerability Vulnerability


Dork: intext:Diseño y Desarrollo CORPORACIÓN M&M
Date: 07.12.2018

Poc : Sistem Informasi SiRestu Bypass Admin Vulnerability


Dork: intext:Sistem Informasi Masa Berlaku Rekomendasi SITU
Date: 07.12.2018

Poc : Web Portal People LLC 2018 OurClassOnline USA XSS Vulnerability
Dork: intext:To obtain a site like this for your class visit
www.ourclassonline.com.
Date: 07.12.2018

Poc : Termit.Am Armenia Hosting Պատրաստեց TermIT ընկերությունը RFI Vulnerability


Dork: intext:Պատրաստեց TermIT ընկերությունը site:am
Date: 07.12.2018

Poc : StNetwork 20.11 Sql injection Vulnerability


Dork: intext:Diseño y Desarrollo CORPORACIÓN M&M
Date: 07.12.2018

Poc : StNetwoork 3.0 Sql injection Vulnerability


Dork: intext:Diseño y Desarrollo CORPORACIÓN M&M
Date: 07.12.2018

Poc : Cms Criderweb Shell Upload Vulnerability


Dork: intext:Copyright © Criderweb
Date: 06.12.2018

Poc : Cms Criderweb Shell Upload Vulnerability


Dork: intext:Copyright © Criderweb
Date: 06.12.2018

Poc : Chipsa Hosting Дизайн: «Чипса» Разработка сайта: weltgroup Hosting Russia XSS
Vulnerability
Dork: intext:Дизайн: «Чипса» Разработка сайта: weltgroup site:ru
Date: 06.12.2018

Poc : Design by Christian Bernal Development by Monoattack XSS Vulnerability


Dork: intext:Design by Christian Bernal - Development by Monoattack site:ec
Date: 06.12.2018

Poc : ZAMAN Graphic Web Design Iran XSS Vulnerability


Dork: intext:Designed and Powered by ZAMAN
Date: 06.12.2018

Poc : Designed By Catpops Technobiz Graphic Design Company in Raipur XSS


Vulnerability
Dork: intext:Designed By Catpops Technobiz
Date: 06.12.2018

Poc : Developed by Aathesh Soft Infotech Pvt Ltd XSS Vulnerability


Dork: intext:Developed by Aathesh Soft Infotech Pvt Ltd
Date: 06.12.2018

Poc : ProTeam.Co.iL ‫&נבנה ע‬quot;‫ י‬Hosting Israel xss Vulnerability


Dork: intext:PROTEAM ‫ נבנה עי‬site:il
Date: 06.12.2018

Poc : Website Design by Haas IT Solutions (SQL Injection)


Dork: /printobit.php?id=
Date: 05.12.2018

Poc : PHOENIX WEB WORLD sql injection Vulnerability


Dork: Design and Developed by PHOENIX WEB WORLD
Date: 05.12.2018

Poc : Website Design Powered by baanwebsite SQLi


Dork: detail_ab.php?id_ab=
Date: 05.12.2018

Poc : Trademart Admin Panel Bypass


Dork: intext:Powered by Trademart.
Date: 04.12.2018

Poc : KeyBase Botnet v1.5 - SQL Injection Vulnerability


Dork: intitle:KeyBase: Login + intext:( Login to get access to your logs )
Date: 04.12.2018

Poc : Joomla Kunena Components 5.1.7 Database Backup Disclosure


Dork: inurl:/index.php?option=com_kunena&view=topic&catid=
Date: 03.12.2018
Poc : Advanced HRM v1.6 Reset admin login Vulnerability
Dork: intext:Copyright © CoderPixel 2016 All Rights Reserved
Date: 02.12.2018

Poc : Joomla Content Editor Com_JCE Components 2.5.24 Database Backup Disclosure
Dork: inurl:/index.php?option=com_jce
Date: 01.12.2018

Poc : WordPress jazzy-forms Plugins 1.1.1 Database Backup Disclosure


Dork: inurl:/wp-content/plugins/jazzy-forms/
Date: 30.11.2018

Poc : B & W S.R.L. www.bywgroup.com SQL Injection


Dork: intext:B & W S.R.L. www.bywgroup.cominurl:id=
Date: 30.11.2018

Poc : WordPress pm_market Plugins 1.0 Database Backup Disclosure


Dork: inurl:/wp-content/plugins/pm_market/backup/
Date: 30.11.2018

Poc : WordPress events-calendar-premium Plugins 1.0 Database Backup Disclosure


Dork: inurl:/wp-content/plugins/events-calendar-premium/zipcodes/
Date: 30.11.2018

Poc : WordPress wp-complete-backup Plugins 3.0.5 Database Backup Disclosure


Dork: inurl:/wp-content/plugins/wp-complete-backup/storage/
Date: 30.11.2018

Poc : WordPress wawp_framework Plugins 1.0 Database Backup Disclosure


Dork: inurl:/wp-content/plugins/wawp_framework/
Date: 30.11.2018

Poc : WordPress uploadingdownloading-non-latin-filename Plugins 1.1.5 Arbitrary


File Download Vulnerability
Dork: inurl:/wp-content/plugins/uploadingdownloading-non-latin-filename/
Date: 29.11.2018

Poc : Joomla Com_Fabrik 3.9 Multiple Vulnerabilities


Dork: inurl:/index.php?option=com_fabrik
Date: 29.11.2018

Poc : Joomla Com_Fabrik pluginAjax importcsv _advancedsearch getprodimg controller


LFI with htaccess CSRF Shell Access Vulnerability
Dork: inurl:/index.php?option=com_fabrik
Date: 29.11.2018

Poc : Joomla com_eventbooking Components Database Backup Arbitrary File Download


Vulnerability
Dork: inurl:/index.php?option=com_eventbooking - EB_INVALID_EVENT
Date: 29.11.2018

Poc : WordPress hwm_board Plugins Korea Arbitrary File Download Vulnerability


Dork: inurl:/wp-content/plugins/hwm_board/ site:kr
Date: 28.11.2018

Poc : WordPress user-spam-remover Plugins Database Backup Information Disclosure


Vulnerability
Dork: inurl:/wp-content/plugins/user-spam-remover/
Date: 28.11.2018

Poc : WordPress Delme Themes 3.0 Database Backup Information Disclosure


Vulnerability
Dork: inurl:/wp-content/plugins/delme/admin/
Date: 28.11.2018

Poc : WordPress Delme Plugins 3.0 Database Backup Information Disclosure


Vulnerability
Dork: inurl:/wp-content/plugins/delme/admin/
Date: 28.11.2018

Poc : SQLiteManager Sql Injection


Dork: intitle:SQLiteManager intext:Welcome to SQLiteManager version
Date: 27.11.2018

Poc : MariaDB Client 10.1.26 Denial Of Service


Dork: None
Date: 27.11.2018

Poc : WordPress wp-contactpage-designer Plugins Database Backup Information


Disclosure Vulnerability
Dork: inurl:/wp-content/plugins/wp-contactpage-designer/
Date: 26.11.2018

Poc : WordPress zerotolaunch Plugins Database Backup Arbitrary File Download


Vulnerability
Dork: inurl:/wp-content/plugins/zerotolaunch/
Date: 26.11.2018

Poc : WordPress wp-contactpage-designer Plugins Database Backup Information


Disclosure Vulnerability
Dork: inurl:/wp-content/plugins/wp-contactpage-designer/
Date: 26.11.2018

Poc : WordPress Universal Post Manager 1.5.0 Database Disclosure


Dork: inurl:/wp-content/plugins/universal-post-manager/
Date: 26.11.2018

Poc : WordPress rss-feed-post-generator-echo Plugins Database Backup Information


Disclosure Vulnerability
Dork: inurl:/wp-content/plugins/rss-feed-post-generator-echo/
Date: 26.11.2018

Poc : WordPress backwpup Plugins 2.1.17 Database Backup Information Disclosure


Vulnerability
Dork: inurl:/wp-content/plugins/backwpup/libs/
Date: 24.11.2018

Poc : Designed & Powered by : BlackburnGraphics.com SQL Injection


Dork: intext:Designed & Powered by : BlackburnGraphics.com inurl:id=
Date: 23.11.2018

Poc : Designed & Powered by Digital Nomad Studio SQL Injection


Dork: intext:Designed & Powered by Digital Nomad Studio inurl:id=
Date: 23.11.2018

Poc : Powered by Quaid Technologie (SQL Injection)


Dork: contents.php?content_id=
Date: 23.11.2018

Poc : Joomla com_kunena Components Database Backup Arbitrary File Download


Vulnerability
Dork: inurl:/index.php?option=com_kunena
Date: 23.11.2018

Poc : WordPress paid-memberships-pro Plugins 1.5.2 Database Backup Information


Disclosure Vulnerability
Dork: inurl:/wp-content/plugins/paid-memberships-pro/
Date: 23.11.2018

Poc : WordPress Pods Plugins 2.7.9 Database Backup Arbitrary File Download
Vulnerability
Dork: inurl:/wp-content/plugins/pods/
Date: 22.11.2018

Poc : ebsite By PHP Development India SQL Injection


Dork: intext:Website By PHP Development India
Date: 22.11.2018

Poc : Joomla com_finder Components Database Backup Arbitrary File Download


Vulnerability
Dork: inurl:/administrator/components/com_finder/
Date: 22.11.2018

Poc : ebsite By PHP Development India SQL Injection


Dork: intext:Website By PHP Development India
Date: 22.11.2018

Poc : Webbdesign: SL-Studio. Directory Traversal


Dork: inurl:index.php?page= intext:Webbdesign: SL-Studio.
Date: 22.11.2018

Poc : WordPress CherryFramework Themes 3.1.4 Backup File Download


Dork: inurl:/wp-content/themes/CherryFramework
Date: 22.11.2018

Poc : WordPress universal-post-manager 1.5.0 Plugins Database Backup Information


Disclosure Vulnerability
Dork: inurl:/wp-content/plugins/universal-post-manager/
Date: 21.11.2018

Poc : Created by Obra soft SQL Injection


Dork: intext:Created by Obra soft inurl:id=
Date: 20.11.2018

Poc : Powered by www.IRISgraphic.com SQL Injection


Dork: intext:Powered by www.IRISgraphic.com inurl:id=
Date: 20.11.2018

Poc : Joomla com_admin Components from V2.5.4 to V3.7.4 Database Backup Arbitrary
File Download Vulnerability
Dork: inurl:/administrator/components/com_admin/sql/
Date: 20.11.2018

Poc : WordPress wp-editor Plugins Database Backup Information Disclosure


Vulnerability
Dork: inurl:/wp-content/plugins/wp-editor/
Date: 20.11.2018

Poc : Wordpress Database Backup Information Disclosure Vulnerability


Dork: Index of /wp-content/uploads/database-backups/
Date: 20.11.2018

Poc : Ricoh myPrint Hardcoded Credentials / Information Disclosure


Dork: intitle:ricoh myprint Copyright Ricoh. All Rights Reserved
Date: 20.11.2018

Poc : WordPress TemplateOne Themes Dubicars Database Backup Information Disclosure


Vulnerability
Dork: intext:© Copyright 2018 | Powered by Dubicars -
inurl:/wp-content/themes/templateone/
Date: 19.11.2018

Poc : Develpoed by SKYMAX Blind SQL Injection


Dork: intext:Develpoed by SKYMAX
Date: 19.11.2018

Poc : Powered by Tayburn Kurumsal SQL İnjection


Dork: intext:”Powered by Tayburn Kurumsal” inurl:php?id=
Date: 19.11.2018

Poc : Developed by PBCS Technology XSS Vulnerability


Dork: intext: Developed by PBCS Technology
Date: 19.11.2018

Poc : Design studio "RayStudio" SQL Injection


Dork: Design studio RayStudio
Date: 18.11.2018

Poc : CEPCO Management SqlInjection Vulnerability


Dork: CEPCO Management inurl:id=
Date: 18.11.2018

Poc : Powered By SDS Co SQL Injection


Dork: intext:Powered By SDS Co
Date: 18.11.2018

Poc : WordPress wp-backup-plus Plugins Database Backup Information Disclosure


Vulnerability
Dork: inurl:/wp-content/uploads/wp-backup-plus/
Date: 18.11.2018

Poc : WordPress Absolutely Glamorous Custom Admin ag-custom-admin Plugin Database


Backup Arbitrary File Download Vulnerability
Dork: inurl:/wp-content/plugins/ag-custom-admin/
Date: 18.11.2018

Poc : WordPress Education Theme on Genesis Framework 2018 Database Backup


Information Disclosure Vulnerability
Dork: intext:Copyright © 2018 ·Education Theme on Genesis Framework · WordPress
Date: 18.11.2018

Poc : Designed & Maintained By Amrithaa.com Xpath Injection base64


Dork: intext:Designed & Maintained By Amrithaa.com inurl:php?id=
Date: 17.11.2018
Poc : Web Portal People LLC 2018 OurClassOnline USA Unauthorized Arbitrary File
Insert Vulnerability
Dork: intext:To obtain a site like this for your class visit
www.ourclassonline.com.
Date: 13.11.2018

Poc : WEBSITE DEVELOPED BY: A R INFOTECH SQL injection


Dork: inurl:product-detail.php?id= intext:WEBSITE DEVELOPED BY: A R INFOTECH
Date: 13.11.2018

Poc : WEBSITE DEVELOPED BY: A R INFOTECH SQL injection


Dork: inurl:product-detail.php?id= intext:WEBSITE DEVELOPED BY: A R INFOTECH
Date: 13.11.2018

Poc : Developed By NaiveScripters Noakhali Science and Technology University


Bangladesh SQL Injection Vulnerability
Dork: intext:Developed By NaiveScripters site:edu.bd
Date: 13.11.2018

Poc : Powered By Dimofinf CMS Version 4.0.0 Saudi-Arabia Government Unauthorized


Arbitrary Insert File Vulnerability
Dork: intext:Powered by Dimofinf cms Version 4.0.0 site:gov.sa
Date: 12.11.2018

Poc : Design and Developed by TechSparkIT Limited Bangladesh Education Unauthorized


Insert File Vulnerability
Dork: intext:Design and Developed by : TechSparkIT Ltd. site:edu.bd
Date: 12.11.2018

Poc : Design & Develop by Mahamud Bangladesh Education Unauthorized Arbitrary


Insert File Vulnerability
Dork: intext:Design & Develop by Mahamud. site:edu.bd
Date: 12.11.2018

Poc : WB4Host Saudi Arabia Hosting Company ‫ النطاق الواسع لالستضافة‬SQL Injection
Vulnerability
Dork: intext:‫ النطاق الواسع لالستضافة‬site:sa
Date: 10.11.2018

Poc : Sadv.Com.Sa Hosting ‫ شعوب المتقدمة‬Shooub Adv CMS V.1 SQL Injection
Vulnerability
Dork: intext:© ‫ جميع الحقوق محفوظة لشركة شعوب المتقدمة‬site:sa
Date: 10.11.2018

Poc : Dreams Ultimate Solutions DreamSus India Improper Authorization and SQL
Injection Vulnerability
Dork: intext:Designed and Developed by Dreams Ultimate Solutions site:edu.in
Date: 09.11.2018

Poc : Vibrant Hardware and Software Solutions E-sampradaay India Improper


Authorization Vulnerability
Dork: intext:Designed by Vibrant Hardware and Software Solutions site:edu.in
Date: 09.11.2018

Poc : Designed & Developed By TAS TasPK Pakistan Education SQL Injection
Vulnerability
Dork: intext:Designed & Developed By TAS site:edu.pk
Date: 08.11.2018
Poc : Design By Orica Technology OricaWorld India Education SQL Injection
Vulnerability
Dork: intext:Design By Orica Technology site:edu.in
Date: 08.11.2018

Poc : OPSTECH (Open Source Technology) CMS - MULTI SQL INJECTION


Dork: inurl:id_sub= & site:go.th, intext:Copyright © 2008 by OPSTECH All Right
Reserved. site:go.th
Date: 06.11.2018

Poc : Designed & Developed By Mars Software International Ltd Marssil Bangladesh
Education SQL Injection Vulnerability
Dork: intext:Designed & Developed By : Mars Software International Ltd. site:edu.bd
Date: 06.11.2018

Poc : পাঠশালা inventusltd Software Development Bangladesh Education SQL Injection


Vulnerability
Dork: intext:© All rights reserved, A product of পাঠশালা site:edu.bd
Date: 05.11.2018

Poc : Designed By RONY IT CorporateSolutionBD Backup File Disclosure Vulnerability


Dork: intext:Desgined by RONY IT site:bd
Date: 05.11.2018

Poc : Powered by ODHYYON A product of ADDIE Soft Ltd Bangladesh Education SQL
Injection Vulnerability
Dork: intext:Powered by ODHYYON, A product of ADDIE Soft Ltd. site:edu.bd
Date: 05.11.2018

Poc : Bangladesh Web site:bd SQL Injection


Dork: inurl:page.php?id= site:bd
Date: 04.11.2018

Poc : WordPress Begin Themes Start-up Business ThemeForest Open Redirection


Vulnerability
Dork: inurl:/wp-content/themes/begin/inc/
Date: 04.11.2018

Poc : WordPress Developed By Pigeon Soft Bangladesh Education Management Improper


Authentication Vulnerability
Dork: intext:Developed By Pigeon Soft site:bd - intext:Powered By Pigeon Soft
site:bd
Date: 03.11.2018

Poc : Fhapl Technologies SQL Injection Vulnerability


Dork: intext:Website Designed & Maintained by GRAPHIC PARK TECHNOLOGIES
Date: 03.11.2018

Poc : Danilo Pegoraro-Marketing Admin Panel Bypass


Dork: intext:Desenvolvedor: estudiofdi.com.br
Date: 03.11.2018

Poc : Technical Support Corporate System Solutions Limited SIB Web Portal
Bangladesh Education SQL Injection Vulnerability
Dork: intext:কারিগরি সহায়তায়: কর্পোরেট সিস্টেম সলিউশনস লিমিটেড site:edu.bd
site:gov.bd
Date: 02.11.2018

Poc : WordPress © 2015 Neon Admin Theme by Laborator.co Improper Authorization


Vulnerability
Dork: intext:© 2015 Neon Admin Theme by Laborator
Date: 31.10.2018

Poc : © Vincent Gabriel 2013 Bootstrap Templates WordPress at BrainTemplate


Improper Authorization Vulnerability
Dork: intext:© Vincent Gabriel 2013 : Bootstrap templates, Bootstrap wordpress
download at Braintemplate.com
Date: 31.10.2018

Poc : Anaxco Admin Panel Bypass


Dork: Powered by Anaxco
Date: 29.10.2018

Poc : Viet Solution backdoor account


Dork: intext:Thiết kế web bởi Viet Solution.
Date: 29.10.2018

Poc : M1 Logix Technologies Admin Panel Bypass


Dork: intext:Design by M1 Logix Technologies.
Date: 27.10.2018

Poc : Technaq Systems Admin Panel Bypass


Dork: Developed by Technaq Systems
Date: 27.10.2018

Poc : NTCREATIC Admin Panel Bypass


Dork: Powered by NTCREATIC
Date: 27.10.2018

Poc : WordPress aio-shortcodes Plugin - Remote Code Execution


Dork: Index of /wp-content/plugins/aio-shortcodes
Date: 26.10.2018

Poc : Joomla Com_Ajax Component Jsnextfw Plugin Jform_Article Incorrect Default


Permission Vulnerability
Dork: inurl:/index.php?option=com_ajax
Date: 24.10.2018

Poc : Powered By iByte Solutions - SQL Injection


Dork: intext:Powered By iByte Solutions
Date: 22.10.2018

Poc : Powered By Magical Cloud - SQL Injection


Dork: intext:Powered By Magical Cloud
Date: 22.10.2018

Poc : Powered By AryaNet - SQL Injection


Dork: intext:by AryaNet inurl:.php?id=
Date: 22.10.2018

Poc : 2018 © ‫ جميع الحقوق محفوظة لمعهد صناعة الحياة للتدريب واالستشارات‬SQL
Injection Vulnerability
Dork: intext:2018 © ‫جميع الحقوق محفوظة لمعهد صناعة الحياة للتدريب واالستشارات‬
inurl:abroad/page.php?cid=
Date: 20.10.2018

Poc : Heatmiser Wifi Thermostat 1.7 Credential Disclosure


Dork: intitle:Heatmiser Wifi Thermostat
Date: 17.10.2018

Poc : Webmaster Atom Computer Software Counselling Improper Access Control


Vulnerability
Dork: intext:Webmaster Atom Bilgisayar Yazılım Danışmanllık site:meb.gov.tr
Date: 16.10.2018

Poc : PROGRAMERS SQL Injection Vulnerability


Dork: intext:Developed by PROGRAMERS
Date: 16.10.2018

Poc : Summernote Cross Site Scripting ( XSS ) Vulnerability


Dork: inurl:/summernote.php editor
Date: 15.10.2018

Poc : Seawind Solution SQL Injection


Dork: intext:Website Design & Developed By Seawind Solution Pvt. Ltd. inurl:.php?
id=
Date: 15.10.2018

Poc : Design by Koncepts SQL Injection Vulnerability


Dork: intext:Design by Koncepts
Date: 13.10.2018

Poc : Đăng nhập Arbitrary File Upload


Dork: intext:Đăng nhập. Xác nhận. inurl:/xadmin
Date: 13.10.2018

Poc : CustomPublish CMS - Login Admin panel Page Bypass


Dork: inurl:/admin/login.php and intitle:CustomPublish CMS
Date: 10.10.2018

Poc : jQuery-File-Upload <= v9.22.0 unauthenticated arbitrary file upload


vulnerability
Dork: inurl:/server/php/index.php
Date: 10.10.2018

Poc : Designed by TopDesign SQL injection Vulnerability


Dork: intext:Designed by Top-Design ?id= site:tw
Date: 09.10.2018

Poc : Bongomedia Cms Admin Page Bypass Vulnerability


Dork: Powered by bongomedia
Date: 09.10.2018

Poc : Copyright © 2008 by OPSTECH All Right Reserved Multi SQL


Dork: intext:Copyright © 2008 by OPSTECH All Right Reserved. site:th &
inurl:index.php?id_news=
Date: 08.10.2018

Poc : Copyright © 2007 jmcwebpublications England SQL Injection Vulnerability


Dork: intext:Copyright © 2007 jmcwebpublications site:uk
Date: 08.10.2018

Poc : Dev by bunia.net Web Development SQL Injection Vulnerability


Dork: intext:Dev by bunia.net
Date: 08.10.2018

Poc : *.ozgunwebtasarim.com & yardim.php SQL Injection / Login Bypass


Dork: inurl:yardim.php?id= & site:*.ozgunwebtasarim.com
Date: 08.10.2018

Poc : Termit.Am Armenia Hosting Պատրաստեց TermIT ընկերությունը SQL Injection


Vulnerability
Dork: intext:Պատրաստեց TermIT ընկերությունը site:am - intext: © 2011 Developed by
TermIT site:am
Date: 07.10.2018

Poc : Web Design by Mark Nakamura Web Development by Ben Greeley SQL Injection
Vulnerability
Dork: intext:Web Design by Mark Nakamura / Web Development by Ben Greeley
Date: 06.10.2018

Poc : OPSTECH Multi SQL Injection


Dork: intext:Copyright © 2008 by OPSTECH All Right Reserved. site:th & use your
brain
Date: 06.10.2018

Poc : Copyright © 2008 by OPSTECH Multi SQL Injection


Dork: intext:Copyright © 2008 by OPSTECH All Right Reserved. site:go.th
Date: 06.10.2018

Poc : ProTeam.Co.iL ‫&נבנה ע‬quot;‫ י‬Hosting Israel SQL Injection Vulnerability


Dork: intext:PROTEAM ‫ נבנה עי‬site:il
Date: 05.10.2018

Poc : RaphSoft Control Panel Bypass Admin Page Vulnerability


Dork: intext:intext:Designed by RaphSoft
Date: 05.10.2018

Poc : Created by Vanavi.com Digital Agency Web Design SQL Injection Vulnerability
Dork: intext:Created by Vanavi.com site:cz
Date: 05.10.2018

Poc : Star Design BD Bypass Admin No Redirect


Dork: intext:Design & Developed by: Star Design BD
Date: 05.10.2018

Poc : Priza.Co.iL Hosting Israel SQL Injection Vulnerability


Dork: intext:2002-2016 © ‫כל הזכויות שמורות לחברת פריזה מערכות מידע וטכנולוגיות בעמ‬
Date: 04.10.2018

Poc : EkDesign.Co.il Web Design Hosting SQL Injection Vulnerability


Dork: intext: ‫ תחזוקת אתר‬: EKD site:il ~ intext:‫כל הזכויות שמורות ל‬EKDESIGN
site:il
Date: 04.10.2018

Poc : Chipsa Hosting Дизайн: «Чипса» Разработка сайта: weltgroup Hosting Russia SQL
Injection Vulnerability
Dork: intext:Дизайн: «Чипса» Разработка сайта: weltgroup site:ru -
intext:Разработка сайта Weltgroup site:ru
Date: 04.10.2018

Poc : Designed By Catpops Technobiz Graphic Design Company in Raipur SQL Injection
Vulnerability
Dork: intext:Desgined By Catpops Technobiz - intext:Designed By Catpops Technobiz
Date: 04.10.2018
Poc : OPAC EasyWeb Five 5.7 biblio SQL Injection
Dork: inurl:index.php?scelta=campi
Date: 04.10.2018

Poc : Dipnot Yönetim Paneli Arbitrary File Upload


Dork: inurl:/dipnotpanel/js/tinymce/plugins/fileman
Date: 03.10.2018

Poc : Seawind Solution SQL Injection Vulnerability


Dork: intext:Design & Developed By Seawind Solution Pvt. Ltd.
Date: 03.10.2018

Poc : Design by Christian Bernal Development by Monoattack SQL Injection


Vulnerability
Dork: intext:Design by Christian Bernal - Development by Monoattack site:ec
Date: 03.10.2018

Poc : Wikindx 5.3.2 Multiple Cross-Site Scripting


Dork: inurl:/wikindx/ , inurl:index.php?action=noMenu&method=
Date: 03.10.2018

Poc : infografia web SQL Injection Vulnerability


Dork: intext:Diseño y desarrollo web por Infografia Web or Sitio desarrollado por
Infografia Web
Date: 01.10.2018

Poc : Site Specken.NL + Starque.Com Groningen Web Design Netherlands SQL Injection
Vulnerability
Dork: intext:SITE: SPECKEN.NL + STARQUE.COM
Date: 01.10.2018

Poc : Powered by Giga Soft Systems Pvt. Ltd. India SQL Injection Vulnerability
Dork: intext:Powered by : Giga Soft Systems Pvt. Ltd.
Date: 01.10.2018

Poc : Media-Art.ir HaaYahoo Web Design Studio Iran ‫ هنر رسانه‬:‫ طراحی و اجرا‬SQL
Injection Vulnerability
Dork: intext:‫ هنر رسانه‬:‫ طراحی و اجرا‬- intext:‫ هنررسانه‬:‫ مجری سایت‬- intext:‫طراحی و‬
‫توسعه هیاهـو‬
Date: 01.10.2018

Poc : Powered by AZSys Romania SQL Injection Vulnerability


Dork: intext:Powered by AZSys
Date: 01.10.2018

Poc : Web Development Invasor Diagonal SQL Injection and Open Redirection
Vulnerability
Dork: intext:web development // invasor diagonal
Date: 01.10.2018

Poc : Copyright © 2018 九江市文化旅游发展集团有限公司官方网站 版权所 Admin Panel Bypass Vulnerability


Dork: intext:Copyright © 2018 九江市文化旅游发展集团有限公司官方网站 版权所
Date: 30.09.2018

Poc : BidSun.ir Web Design ‫ بیدسان‬:‫ طراحی و پیاده سازی توسط‬SQL Injection
Vulnerability
Dork: intext:‫ بیدسان‬:‫طراحی و پیاده سازی توسط‬
Date: 29.09.2018
Poc : ZAMAN Graphic Web Design Iran SQL Injection Vulnerability
Dork: intext:Designed and Powered by ZAMAN
Date: 29.09.2018

Poc : IT Developers Network Iran Web Design SQL Injection Vulnerability


Dork: intext:C o p y r i g h t © 2 0 0 7 , D e s i g n e d & D e v e l o p e d B y
IT Developers network.
Date: 29.09.2018

Poc : BDWebDev SQL Injection Vulnerability


Dork: intext:Developed by BDWebDev.Com
Date: 29.09.2018

Poc : Developed By Gohar Ali SQL Injection Vulnerability


Dork: intext:Developed By Gohar Ali inurl:.php?id=
Date: 29.09.2018

Poc : Chirag Lad SQL Injection Vulnerability


Dork: intext:Design by Dr. Hardik Desai | Developed by Chirag Lad
Date: 29.09.2018

Poc : Powered By XEDteam ‫ گروه زد‬:‫ راحی و توسعه‬Iran SQL Injection Vulnerability
Dork: intext:Powered By: XEDteam. - intext:‫ گروه زد‬:‫طراحی و توسعه‬.
Date: 29.09.2018

Poc : Gwebbook Yash Computers Company Hosting India SQL Injection Vulnerability
Dork: intext:Powered by Gwebbook.com - intext:Panel Develope By YASH COMPUTERS
COMPANY
Date: 29.09.2018

Poc : Developed by Aathesh Soft Infotech Pvt Ltd SQL Injection Vulnerability
Dork: intext:Developed by Aathesh Soft Infotech Pvt Ltd
Date: 29.09.2018

Poc : Rausoft ID.prove 2.95 SQL Injection


Dork: inurl:IdproveWebclient
Date: 29.09.2018

Poc : Designed & Hosted By MWC Design England Authentication Bypass Vulnerability
Dork: intext:Designe & Hosted By. MWC - intext:Design By: MWC
Date: 29.09.2018

Poc : Azeemi-Tech Technology Company A2zcreatorz Authentication Bypass


Vulnerability
Dork: intext:Designed & Developed by: Azeemi
Date: 28.09.2018

Poc : Developed By PC TECH 1996 - 2014 Pakistan Hosting Authentication Bypass


Vulnerability
Dork: intext:All Rights Reserved by PC TECH 1996 - 2014. Developed by PC TECH -
intext:Developed By: PC TECH
Date: 28.09.2018

Poc : Joomla Com_BibleStudy Proclaim MediaFileForm Remote File Upload Vulnerability


Dork: inurl:/index.php?option=com_biblestudy
Date: 28.09.2018

Poc : matri4web v 9.04 CSRF Vulnerability


Dork: intext:simplesearch_results.php?p=
Date: 28.09.2018

Poc : matri4web v 9.04 Sql injection Vulnerability


Dork: intext:simplesearch_results.php?p=
Date: 28.09.2018

Poc : Copyright @ 2018 九江市道路运输管理局 Admin Panel Bypass Vulnerability


Dork: intext:Copyright @ 2018 九江市道路运输管理局
Date: 27.09.2018

Poc : Sitio desarrollado por Infografia Web - Low Security


Dork: intext:Sitio desarrollado por Infografia Web
Date: 27.09.2018

Poc : WordPress WP Insert 2.4.2 Arbitrary File Upload


Dork: /wp-content/plugins/wp-insert
Date: 27.09.2018

Poc : CMS ISWEB 3.5.3 - Local file download


Dork: moduli/downloadFile.php?file=oggetto_documenti/../.././inc/config.php
Date: 26.09.2018

Poc : reserved by : City District Government, Multan. SQL Injection Vulnerability


Dork: intext:reserved by : City District Government, Multan.
Date: 26.09.2018

Poc : Powered by CORPORATE IT LIMITED - SQL Injection Vulnerability


Dork: intext:Powered by CORPORATE IT LIMITED
Date: 26.09.2018

Poc : Designed & Developed by Brigadasoft Authentication Bypass Vulnerability


Dork: intext:Designed & Developed by Brigadasoft
Date: 23.09.2018

Poc : StNetwoork 3.0 Backdoor Account Vulnerability


Dork: intext:Diseño y Desarrollo CORPORACIÓN M&M
Date: 23.09.2018

Poc : Developed By RKV IT Solutions Pvt. Ltd India Authentication Bypass


Vulnerability
Dork: intext:Developed By : RKV IT Solutions Pvt. Ltd
Date: 23.09.2018

Poc : izeneth SQL Injection Vulnerability


Dork: intext:Powered by iZeneth Innovative Technologies
Date: 23.09.2018

Poc : StNetwoork 3.0 XsS Vulnerability


Dork: intext:Diseño y Desarrollo CORPORACIÓN M&M
Date: 22.09.2018

Poc : Pixel2URL Web Design Company Sialkot Pakistan Authentication Bypass


Vulnerability
Dork: intext:Powered By PIXEL2URL - intext:Proudly Powered By:Pixel2URL
Date: 22.09.2018

Poc : Design and Developed By UNASJEE Authentication Bypass Vulnerability


Dork: intext:Designed & Developed by: UNASJEE - intext:Developed by: UNASJEE
Date: 22.09.2018
Poc : Designed by Longtail E-Media Improper Access Control and RFU Vulnerability
Dork: intext:Designed by Longtail E-media site:com
Date: 22.09.2018

Poc : MyBB Visual Editor Stored XSS <= v1.8.18


Dork: intext:Powered By MyBB
Date: 22.09.2018

Poc : Acelle Email Marketing Web Application v3.0.15 file uploads Vulnerability
Dork: intext:. Acelle Email Marketing Application by acellemail.com
Date: 22.09.2018

Poc : Credits Mediastudio.it Web Hosting SQL Injection Vulnerability


Dork: intext:Credits: Mediastudio
Date: 22.09.2018

Poc : Site Created by Frontline Multimedia Design Hosting SQL Injection


Vulnerability
Dork: intext:Site Created by FRONTLINE MULTIMEDIA DESIGN
Date: 22.09.2018

Poc : Design By iQ Digital İQ-Medya Web Hosting SQL Injection Vulnerability


Dork: intext:Tasarım iQ Digital
Date: 22.09.2018

Poc : Sito Creato Da Amaka Web Agency e Posizionamento Siti SQL Injection
Vulnerability
Dork: intext:sito creato da Amaka web agency e posizionamento siti
Date: 22.09.2018

Poc : Logo & Web Design by LogoBee SQL Injection Vulnerability


Dork: intext:Logo & Web Design by LogoBee
Date: 22.09.2018

Poc : Acelle Email Marketing Web Application v3.0.18 file uploads Vulnerability
Dork: intext:© 2018. Acelle Email Marketing Application by acellemail.com
Date: 22.09.2018

Poc : Orange Solutions sql injection Vulnerability


Dork: Desenvolvido por: Orange Solutions.
Date: 22.09.2018

Poc : 3CX Open Standards Software IP PBX Thailand SQL Injection Vulnerability
Dork: intext:3CX: Open Standards Software IP PBX
Date: 21.09.2018

Poc : FabrikaMedya 2018 SQL Injection Vulnerability


Dork: intext:© FabrikaMedya 2018. All rights reserved
Date: 21.09.2018

Poc : MTPReklam Kornea Web Design SQL Injection Vulnerability


Dork: intext:mtpreklam
Date: 21.09.2018

Poc : RemainArt Software Development SQL Injection Vulnerability


Dork: intext:Sitenin tasarımı ve yazılımı Remainart tarafından yapılmıştır.
Date: 21.09.2018
Poc : ZirveNetwork SQL Injection Vulnerability
Dork: intext:zirvenetwork.com
Date: 21.09.2018

Poc : ACTReklam Web Design SQL Injection Vulnerability


Dork: intext:www.actreklam.com
Date: 21.09.2018

Poc : Dove Ticket System v2.0.0 Reinstall add admin Vulnerability


Dork: Dove Ticket System v2.0.0 Reinstall add admin Vulnerability
Date: 21.09.2018

Poc : Surat Web Solution Admin Panel Bypass


Dork: intext:Design By / Surat Web Solution.
Date: 20.09.2018

Poc : Reanod Default Admin Password Vulnerability


Dork: intext:Powered by reanod
Date: 20.09.2018

Poc : Reanod Default Admin Password Vulnerability


Dork: intext:Powered by reanod
Date: 20.09.2018

Poc : UK Schools SQL Injection Vulnerability


Dork: site:uk filetype:php inurl:newsid= intitle:school
Date: 18.09.2018

Poc : Copyright © 2011 - 2018 Webutation Belgium Multiple Vulnerabilities


Dork: intext:Copyright © 2011 - 2018 Webutation site:be
Date: 18.09.2018

Poc : SocioQuiz v1.1.2 unauthorized administrative access Vulnerability


Dork: © Super Quiz - All rights reserved. Privacy policy Terms of service
Date: 18.09.2018

Poc : StNetwork 20.11 XSS Vulnerability


Dork: intext:Diseño y Desarrollo CORPORACIÓN M&M
Date: 18.09.2018

Poc : pouya-tech SQL Injection Vulnerability


Dork: intext:‫طراحی و اجرا پویا تک‬
Date: 17.09.2018

Poc : Designed by Logiprint Estratégica Mexico SQL Injection Vulnerability


Dork: intext:Designed by Logiprint Estratégica
Date: 16.09.2018

Poc : Powered by: SYSCOM Technologies S.A.R.L SqlInjection


Dork: intext:Powered by: SYSCOM Technologies S.A.R.L
Date: 15.09.2018

Poc : WebEmpire.co.il ‫&נבנה ע‬quot;‫ י‬Hosting Web Design Israel SQL Injection
Vulnerability
Dork: intext:WebEmpire ‫נבנה עי‬
Date: 15.09.2018

Poc : Desarrollado por Kodfee Constultores IT. Mexico SQL Injection Vulnerability
Dork: intext:Desarrollado por Kodfee - Constultores IT.
Date: 15.09.2018

Poc : Another Site By Simply-Smart.Com Hosting Israel SQL Injection Vulnerability


Dork: intext:Another Site By Simply-Smart.com site:il
Date: 15.09.2018

Poc : Design G. Wolfgang Build Y. Neuman 1234 Up.Co.il Hosting Israel SQL Injection
Vulnerability
Dork: intext:Design G. Wolfgang | Build Y. Neuman site:il
Date: 15.09.2018

Poc : SMSITE‫ נבנה ע״י‬SmSite.Co.il Hosting Israel SQL Injection Vulnerability


Dork: intext:© ‫ כל הזכויות שמורות‬SMSITE - intext:SMSITE‫נבנה ע״י‬
Date: 15.09.2018

Poc : MNW Digital Agency Mnw.Pt Hosting Portugal SQL Injection Vulnerability
Dork: intext:MNW Digital Agency
Date: 15.09.2018

Poc : v1technologies admin page bypass vulnerability


Dork: intext:Mobile Friendly Web Design By: V1 Technologies Ltd
Date: 15.09.2018

Poc : CirCarLife SCADA 4.3.0 Credential Disclosure


Dork: Server: CirCarLife Server: PsiOcppApp
Date: 12.09.2018

Poc : Rubedo CMS 3.4.0 Directory Traversal


Dork: intext:rubedo.current.page.description
Date: 12.09.2018

Poc : WiseGroup ‫ בניית אתרים‬Israel SQL Injection Vulnerability


Dork: intext:WiseGroup ‫בניית אתרים‬
Date: 12.09.2018

Poc : Web Design ‫ בניית אתרים‬SSD.co.il Israel SQL Injection Vulnerability


Dork: intext:‫ בניית אתרים‬ssd site:il - inurl:/ShowProduct.php?ProductID= site:il
Date: 12.09.2018

Poc : brsis XSS Vulnerability


Dork: intext:Produzido por Brsis
Date: 12.09.2018

Poc : OVOO v2.5.1 - Movie & Video Streaming CMS with Unlimited TV-Series backup
disclosure Vulnerability
Dork: intext:Ovoo movie & Tv Show streaming cms - Login
Date: 12.09.2018

Poc : Hertfordshire FluidStudiosLtd Web Design England SQL Injection Vulnerability


Dork: intext:Web design by Fluid Studios
Date: 12.09.2018

Poc : Powered By Exnet Exclusive Solution Network Nepal SQL Injection Vulnerability
Dork: intext:Powered by Exnet Exclusive Solution Network site:np
Date: 12.09.2018

Poc : Website Designed By 21st Century Ireland SQL Injection Vulnerability


Dork: intext:website designed by 21st Century site:ie
Date: 12.09.2018
Poc : Website Designed and Developed By integralinfosystems England SQL Injection
Vulnerability
Dork: intext:Website Designed and Developed By integralinfosystems
Date: 12.09.2018

Poc : ND Design AS Norway SQL Injection Vulnerability


Dork: intext:ND Design AS site:no
Date: 12.09.2018

Poc : Scandesign Media AS Denmark SQL Inj Auth Bypass Vulnerability


Dork: intext:Scandesign Media A/S site:dk
Date: 12.09.2018

Poc : Developed by Softech Pakistan SQL Injection Vulnerability


Dork: intext:Developed by SOFTECH site:pk
Date: 12.09.2018

Poc : Cod4 status - Cross-site scripting (XSS)


Dork: inurl:banned.php?server_id=
Date: 11.09.2018

Poc : Powered By invitroestudio Argentina SQL Injection Vulnerability


Dork: intext:Powered By invitroestudio site:ar
Date: 10.09.2018

Poc : Diseño y Desarrollo LastClick Argentina SQL Injection Vulnerability


Dork: intext:Desarrollo: www.lastclick.com.ar | Corrientes - Argentina
Date: 10.09.2018

Poc : Powered By PAS World Communitcation Ltd and Nakhonkorat ThailandGov SQL
Injection
Dork: intext:Powered By :: PAS World Communitcation,.ltd. AND nakhonkorat.com
Date: 10.09.2018

Poc : BizPotential EasyWebTime 8.6.2 Thailand Government SQL Injection


Vulnerability
Dork: inurl:/ewtadmin/ site:go.th - inurl:/main.php?filename= site:go.th - intext:©
Copyright 2007 - BizPotential.com - All Rights Reserved.
Date: 10.09.2018

Poc : MMI Softwares admin page bypass vulnerability / upload shell


Dork: intext:Design by MMI Softwares inurl:admin.php
Date: 09.09.2018

Poc : Sitio oficial de Jeep® Argentina Powered By Turnos SQL Injection


Vulnerability
Dork: intext:©2017 FCA US LLC. Todos los derechos reservados.Chrysler, Dodge, Jeep,
Ram, Mopar y SRT son marcas registradas de FCA US LLC.
Date: 09.09.2018

Poc : Diseño y Desarrollo D&H Soluciones Argentina SQL Injection Vulnerability


Dork: intext:Diseño y Desarrollo: D&H Soluciones
Date: 09.09.2018

Poc : brsis sql injection Vulnerability


Dork: intext:Produzido por Brsis
Date: 09.09.2018
Poc : Multecart eCommerce Digital Multivendor marketplace shopping Cart - CMS v3.0
backdoor account Vulnerability
Dork: intext:Mult-e-Cart 2018
Date: 09.09.2018

Poc : Softneta MedDream PACS Server Premium 6.7.1.1 SQL Injection


Dork: inurl:Pacs/login.php, inurl:pacsone filetype:php home, inurl:pacsone
filetype:php login
Date: 08.09.2018

Poc : Softneta MedDream PACS Server Premium 6.7.1.1 Directory Traversal


Dork: inurl:pacs/login.php, inurl:pacsone/login.php, inurl:pacsone filetype:php
home, inurl:pacsone filetype:php login
Date: 08.09.2018

Poc : Hoteliraqua Todos los Derechos Reservados © 2013 SQL Injection Vulnerability
Dork: intext:www.hoteliraqua.com - Todos los Derechos Reservados © 2013
Date: 07.09.2018

Poc : ReturnDates is under the care of (c) ThePopeRope SQL Injection Vulnerability
Dork: intext:Returndates.com is under the care of (c) Thepoperope.
Date: 07.09.2018

Poc : India Ministry of Earth Sciences Meteorological Department SQL Injection


Vulnerability
Dork: intext:Copyright © India Meteorological Department 2015 This Website belongs
to India Meteorological Department, Ministry of Earth Sciences,Government of India
Date: 07.09.2018

Poc : © Inter Alia 2013 InterAliaProject Web Design SQL Injection Vulnerability
Dork: intext:© Inter Alia 2013
Date: 07.09.2018

Poc : © Copyright: Indianz NewsCenter Open Redirection Vulnerability


Dork: intext:© Copyright: Indianz.com
Date: 07.09.2018

Poc : Powered by StudioNET Mexico SQL Injection Vulnerability


Dork: intext:Powered by StudioNET
Date: 07.09.2018

Poc : Apache Roller 5.0.3 XML External Entity Injection (File Disclosure)
Dork: intext:apache roller weblogger version {vulnerable_version_number}
Date: 06.09.2018

Poc : Apache Roller 5.0.3 XML Injection / File Disclosure


Dork: intext:apache roller weblogger version {vulnerable_version_number}
Date: 06.09.2018

Poc : Designed by Tristar Software Solutions India SQL Injection Vulnerability


Dork: intext:Designed by Tristar Software Solutions
Date: 06.09.2018

Poc : Brihaspathi Skoolcom India Software Development Authentication Bypass


Vulnerability
Dork: intext:Designed and Developed by Brihaspathi
Date: 06.09.2018

Poc : Developed By Jay4web Web Design Company Kochi Kerala India SQL Injection
Vulnerability
Dork: intext:Developed By Jay4web site:in
Date: 06.09.2018

Poc : Indian Society of Tele Dermatology Insted SQL Injection Vulnerability


Dork: intext:Copyright © 2011 insted.in. All rights reserved.
Date: 06.09.2018

Poc : Website designed & developed by Radical Reflex India SQL Injection
Vulnerability
Dork: intext:Website designed & developed by Radical Reflex
Date: 06.09.2018

Poc : Copyright © 2017 Kannur University India SQL Injection Vulnerability


Dork: intext:Copyright © 2017 Kannur University
Date: 06.09.2018

Poc : Copyrights @ Agarwal Siksha Samiti 1971-2017 Authentication Bypass


Vulnerability
Dork: intext:Copyrights @ Agarwal Siksha Samiti 1971-2017
Date: 06.09.2018

Poc : Designed and Hosted By WebGen Internet Technologies Pvt Ltd India SQL
Injection Vulnerability
Dork: intext:Designed and Hosted By : WebGen
Date: 06.09.2018

Poc : Powered by - Tech Campus India Application Development SQL Injection


Vulnerability
Dork: intext:Powered by - Tech Campus site:in
Date: 06.09.2018

Poc : © 2015 Math4All India All Rights Reserved SQL Injection Vulnerability
Dork: intext:© 2015 Math4All. All Rights Reserved
Date: 06.09.2018

Poc : Website Maintained By Ankur Biswas SASLAB Technologies Pvt Ltd SQL Injection
Vulnerability
Dork: intext:Website Maintained By : Ankur Biswas ( SASLAB Technologies Pvt Ltd )
Date: 06.09.2018

Poc : BRIGHTBRIX® Web Producer - Extending the Internet Add Admin Vulnerability
Dork: Dashboard for BRIGHTBRIX® Web Producer - Extending the Internet
Date: 06.09.2018

Poc : Design & Developed By Target Soft BD Bangladesh SQL Injection Vulnerability
Dork: intext:Design & Develope By : Target Soft site:edu.bd
Date: 05.09.2018

Poc : eVorticity xss vulnerability


Dork: intext:Design by eVorticity inurl:php?id=
Date: 05.09.2018

Poc : aramehr admin login bypass vulnerability


Dork: intext:‫ تیم برنامه نویسی آرامهر‬: ‫طراحی و برنامه نویسی‬
Date: 05.09.2018

Poc : WordPress Developed by Netsoft Limited Software Development Bangladesh


Improper Authentication Vulnerability
Dork: intext:Datacenter :: A Product of Netsoft Ltd - intext:Developed by : Netsoft
Limited.
Date: 05.09.2018

Poc : Sphider 1.3.6 Auth By pass Vulnerability


Dork: Sphider Admin Login
Date: 05.09.2018

Poc : Glenn Loney xss vulnerability


Dork: intext:intext:Copyright - 2018 - All rights reserved Glenn Loney inurl:php?
id=
Date: 04.09.2018

Poc : irisgraphic sql injection vulnerability


Dork: intext:Powered by www.IRISgraphic.com inurl:php?id=
Date: 04.09.2018

Poc : Design & Developed by SoftBd Ltd. Bangladesh Education Portals Multiple
Vulnerabilities
Dork: intext:DEVELOPED BY : SOFTBD Ltd. site:edu.bd
Date: 04.09.2018

Poc : Technical Assistance explore IT Bangladesh Education Portals SQL Injection


Vulnerability
Dork: intext:Technical Assistance explore IT
Date: 04.09.2018

Poc : Design by Dream EntraCom DreamTemplate Bangladesh SQL Injection Vulnerability


Dork: intext:Design by Dream EntraCom intext:Design by EntraCom
Date: 04.09.2018

Poc : Powered By Nobo IT Software Company Bangladesh SQL Injection Vulnerability


Dork: intext:Powered by : Nobo IT. site:edu.bd
Date: 04.09.2018

Poc : BdHostSoft WebHosting Company Bangladesh SQL Injection Vulnerability


Dork: intext:All Rights Reserved BDHOST
Date: 04.09.2018

Poc : Site Design & Developed by G4 Tech Solutions Bangladesh SQL Injection
Vulnerability
Dork: intext:Powered by : G4 Tech Solutions
Date: 04.09.2018

Poc : Developed by OneTech Web Design Bangladesh Multiple Vulnerabilities


Dork: intext:Developed by: OneTech
Date: 04.09.2018

Poc : Powered by NN Softech Web Design Bangladesh SQL Injection Vulnerability


Dork: intext:Powered by : NN SOFTECH
Date: 04.09.2018

Poc : BulkSMSSystem Bangladesh Education Improper Authentication Backdoor Account


Vulnerability
Dork: inurl:/admin/myfile/index.php site:bd
Date: 04.09.2018

Poc : Developed by Desh Universal (Pvt.) Limited SQL Injection Vulnerability


Dork: intext:Developed by Desh Universal (Pvt.) Limited.
Date: 04.09.2018

Poc : AdultJoy Reflected XSS


Dork: inurl:/adultjoy intext:porn inurl:search.php
Date: 03.09.2018

Poc : PornZebra Search Engine Ref. XSS


Dork: inurl:pornzebra q=
Date: 03.09.2018

Poc : MenorahMarket Multi Vendor Digital Goods Market Place Script V 2.0 Backdoor
Account Vulnerability
Dork: intext:COPYRIGHTS 2017 ALL RIGHTS RESERVED BY - EDD MARKET PLACE
Date: 03.09.2018

Poc : JPC2 Group Web Sql injection Vulnerability


Dork: intext:Web design and development JPC2 Group Web
Date: 03.09.2018

Poc : The Next Gen School Management Software - Menorah Academy 7.0 Backdoor
Account Vulnerability
Dork: intext:Menorah Academy System
Date: 02.09.2018

Poc : WordPress Jibu Pro 1.7 Cross Site Scripting


Dork: inurl:/wp-content/plugins/jibu-pro
Date: 31.08.2018

Poc : WordPress Plugin Jibu Pro 1.7 Cross-Site Scripting


Dork: inurl:/wp-content/plugins/jibu-pro
Date: 30.08.2018

Poc : MenorahOES - Online Learning and Examination System v 5.5Backdoor Account


Vulnerability
Dork: intext:Login Educate Enlight Enforce
Date: 30.08.2018

Poc : MR Technology Multi Vulnerability


Dork: Index of /apanel/admin
Date: 30.08.2018

Poc : Sitenizolsun thema XSS Cross site request forgery


Dork: inurl:Yer sağlayıcı: SitenizOlsun
Date: 28.08.2018

Poc : Impression Technologies LLC Sql injection Vulnerability


Dork: intext:Website | Impression Technologies LLC .php?id=
Date: 28.08.2018

Poc : WikiGrosir SQL Injection


Dork: intext:WikiGrosir | PT MensaMCo .php?ID=
Date: 27.08.2018

Poc : WordPress Plugin Gift Voucher 1.0.5 template_id SQL Injection


Dork: intext:/wp-content/plugins/gift-voucher/
Date: 27.08.2018

Poc : Creasotol Admin Panel Bypass


Dork: intext:Diseño Web : www.creasotol.com
Date: 23.08.2018

Poc : Web Developer : Mr. Chheng Udom SQL Injection


Dork: intext:Web Developer : Mr. Chheng Udom
Date: 23.08.2018

Poc : SiteQuarters PHP Code Injection


Dork: intext:Powered by SiteQuarters
Date: 22.08.2018

Poc : Cline Communications Blind SQL Injection


Dork: intext:This site powered by Cline Communications
Date: 22.08.2018

Poc : Powered by GenetchSolutions, Inc. SQL Injection


Dork: intext:Powered by GenetchSolutions, Inc.
Date: 21.08.2018

Poc : CMFI 2010 Unauthorised Administrative Access Vulnerability


Dork: Install CryptoTab and mine Bitcoin! https://getcryptotab.com/2231098 Get Free
Bitcoin Earn more than 1 BTC per week!
Date: 21.08.2018

Poc : SystemSolutions Admin Panel Bypass


Dork: intext:Designed & Developed By :systemsolutions.biz.
Date: 20.08.2018

Poc : Powered by : Ads-comm SQL Injection


Dork: intext:Powered by : Ads-comm
Date: 20.08.2018

Poc : SocioQuiz v1.1.2 unauthorized administrative access Vulnerability


Dork: © Super Quiz - All rights reserved. Privacy policy Terms of service
Date: 20.08.2018

Poc : WordPress Dreamsmiths Themes 0.0.1 Arbitrary File Download


Dork: inurl:/wp-content/themes/fiestaresidences/
Date: 18.08.2018

Poc : News365 v4 disconnect database connection Vulnerability


Dork: intext:bdtask Theme | All right Reserved 2016 Login |
Date: 18.08.2018

Poc : phpMeteo v1.6 sensitive information disclosure Vulnerability


Dork: Powered by phpMeteo.
Date: 17.08.2018

Poc : Designed & Developed by: Progressive NoRedirect Bypass


Dork: intext:Welcome to Control PanelUse a valid Loginid and password to gain
access to the administration console
Date: 17.08.2018

Poc : TheNextBigWriter.com Insecure Direct Object References Leading To Possibly


Defacement
Dork: intext:Built by Proxima B
Date: 16.08.2018

Poc : IceWarp WebMail Cross Site Scripting (XSS) & Execution Code
Dork: intext:Sign in to WebClient
Date: 14.08.2018

Poc : IceWarp WebMail 12.0.3.1 Cross Site Scripting


Dork: intext:Sign in to WebClient
Date: 14.08.2018

Poc : Developed By Fluent Technology - SQL Injection


Dork: intext:Developed By - Fluent Technology inurl:php?id=
Date: 12.08.2018

Poc : Powered by Go For Solution - SQL Injection


Dork: intext:Powered by : Go For Solution inurl:php?id=
Date: 12.08.2018

Poc : JET Database isral SQL Injection


Dork: intext:JET Database +site:il
Date: 12.08.2018

Poc : LG-Ericsson iPECS NMS 30M Directory Traversal


Dork: iPECS CM
Date: 09.08.2018

Poc : Création by jaune-cerise.ch - SQL Injection


Dork: intext:Created by www.jaune-cerise.ch
Date: 08.08.2018

Poc : Powered By Integral Info Systems - SQL Injection


Dork: intext:Powered By integralinfosystems
Date: 08.08.2018

Poc : Designed by Creative Web Designers SQL Injection


Dork: intext:Designed by Creative Web Designers
Date: 08.08.2018

Poc : Website designed by Agape Designs SQL Injection


Dork: intext:Website designed by Agape Designs
Date: 07.08.2018

Poc : onArcade 2.4.2 Cross Site Request Forgery


Dork: Powered by onArcade v2.4.2
Date: 07.08.2018

Poc : Carbiz - Buy Sell Car Marketplace Script V 1.2.0 Backdoor Account
Vulnerability
Dork: intext:© Copyright 2018 Webhelios . All rights reserved
Date: 07.08.2018

Poc : SocioQuiz v2.0.0 unauthorized administrative access Vulnerability


Dork: © Super Quiz - All rights reserved. Privacy policy Terms of service
Date: 07.08.2018

Poc : Premium URL Shortener (c) KBRmedia Version 5.0.2 Add Admin Vulnerability
Dork: 2012-2018 © KBRmedia - All Rights Reserved
Date: 07.08.2018

Poc : Laravel 4.2 sensitive information disclosure Vulnerability


Dork: intext:Whoops! There was an error.
Date: 06.08.2018
Poc : SocioQuiz v2.0.3 unauthorized administrative access Vulnerability
Dork: © Super Quiz - All rights reserved. Privacy policy Terms of service
Date: 05.08.2018

Poc : Web design & development by: svc & smorkov SQL Injection Vulnerability
Dork: -
Date: 05.08.2018

Poc : Web Design gov.pk.php Pakistan www.pmo.gov.pk SQL injection Vulnerability


Dork: inurl gov.pk.php id=
Date: 03.08.2018

Poc : uhotel booking 2.79. XML external entity injection Vulnerability


Dork: intext:index.php?page=check_hotels
Date: 03.08.2018

Poc : Web Design gov www.multan.gov.pk SQL injection Vulnerability


Dork: php id=1 gov site
Date: 02.08.2018

Poc : Web Design American Clubs www.fofv.org ~ SQL Injection Vulnerability


Dork: php id=1 american club
Date: 02.08.2018

Poc : RVTECH Admin Panel Bypass


Dork: intext:Design By : RVTECH.
Date: 02.08.2018

Poc : Web Design india bank www.gulf1bank.com SQL injection Vulnerability


Dork: php id=1 india bank
Date: 02.08.2018

Poc : DataLife Engine 13.0 Cross Site Scripting


Dork: inurl:/index.php?subaction=userinfo
Date: 02.08.2018

Poc : sardasht-aj.ir sql Vulnerability


Dork: inurl:show.php?id= site:.ir
Date: 02.08.2018

Poc : DataLife Engine Core Cross Site Scripting (XSS) & Execution Code
Dork: inurl:/index.php?subaction=userinfo
Date: 01.08.2018

Poc : Web Design israel banks i-l.co.il Sql injection Vulnerability


Dork: php id=1 israel bank
Date: 31.07.2018

Poc : Web Design db/CART/product_details www.fakihonline.com Sql injection


Vulnerability
Dork: db/CART/product_details.php?product_id=
Date: 30.07.2018

Poc : Design : ANGLER Technologies fckeditor upload


Dork: site:co.in editor/fckeditor/editor/
Date: 30.07.2018

Poc : AsrarIT SQL Injection


Dork: intext:Powered By AsrarIT inurl:.php?id=
Date: 30.07.2018

Poc : web Design Select_Item sites www.bpc.gov.bd sql injection


Dork: intext:Web Select_Item.php?id=
Date: 30.07.2018

Poc : orientation4success Web Design israil Insert Image. File Manager upload
Dork: insert_image.php site:il
Date: 29.07.2018

Poc : Web Design itemDesc.php site sql injection


Dork: itemDesc.php?CartId=
Date: 29.07.2018

Poc : iConcept LLC - SQL Injection


Dork: intext:powered By. iConcept LLC
Date: 29.07.2018

Poc : iConcept LLC - SQL Injection


Dork: intext:powered By. iConcept LLC
Date: 29.07.2018

Poc : Designed and Developed by Why Web Developments SQL Injection


Dork: intext: Designed and Developed by Why Web Developments
Date: 29.07.2018

Poc : Unauthenticated Code Execution on EDU websites


Dork: intext:Designed By NextBarisal
Date: 29.07.2018

Poc : Designed by Cloud Innovators Solution SQL Injection Vulnerability


Dork: intext:Designed and Developed by Cloud Innovators Solution + inurl:.php?ID=
Date: 28.07.2018

Poc : Enosis Technology Admin Panel Bypass


Dork: intext:Powered by Enosis Technology.
Date: 28.07.2018

Poc : Design by Maru Widen SQL Injection Vulnerability


Dork: intext:Design by: Maru Widen inurl:.php?id=
Date: 26.07.2018

Poc : Virtual Snipers Digital Marketing Services Auth by pass Vulnerability


Dork: Design & Developed By:Virtual Snipers
Date: 26.07.2018

Poc : SocioQuiz v2.0.5 unauthorized administrative access Vulnerability


Dork: © Super Quiz - All rights reserved. Privacy policy Terms of service
Date: 26.07.2018

Poc : Developed By: Direct2Web Admin Panel Bypass


Dork: Developed By: Direct2Web
Date: 25.07.2018

Poc : MSVOD 10 cid SQL Injection


Dork: inurl:images/lists?cid=13
Date: 25.07.2018

Poc : BYDAS CMS Bypass Authentication Vulnerability


Dork: inurl:/admin/core/timthumb.php?src=files/
Date: 24.07.2018

Poc : Design & Developed by WAN IT LTD SQL Injection


Dork: intext:Design & Developed by WAN IT LTD
Date: 23.07.2018

Poc : Yourdoctor - Medical and Doctor Website CMS Unauthorised Administrative


Access Vulnerability
Dork: intext:Lorem ipsum dolor sit amet, omnis signiferumque in mei, mei ex.
Date: 23.07.2018

Poc : Web Mechanics CMS Admin Login Bypass


Dork: intext:Designed By Web Mechanics inurl:/adminlogin.php
Date: 21.07.2018

Poc : Pishgam Pardazesh Keyhan cms Cross Site Scripting Vulnerability


Dork: intext:‫ پیشگام پردازش کیهان‬: ‫طراح و پشتیبان‬
Date: 21.07.2018

Poc : ct web design by brown bear creative SQL Injection Vulnerability


Dork: intext:ct web design by brown bear creative inurl:.php?id=
Date: 21.07.2018

Poc : Binary Image Multi XSS Found


Dork: intext:Developed By:Binary Image inurl:?p=result-search
Date: 18.07.2018

Poc : Web Technology by Contedia SQL Injection Vulnerability


Dork: intext:Web Technology by Contedia™ inurl:.php?id=
Date: 16.07.2018

Poc : Mini Ajax Arbitrary File Upload


Dork: intitle:Mini Ajax File Upload Form
Date: 15.07.2018

Poc : TSMTS XSS Vulnerability


Dork: intext:TSMTS inurl:?p=result-search
Date: 15.07.2018

Poc : Developed By: VUBIT SQL Injection


Dork: intext:Developed By: VUBIT
Date: 14.07.2018

Poc : Design & Maintenance: Aalo IT SQL Injection


Dork: intext:Design & Maintenance: Aalo IT
Date: 14.07.2018

Poc : Lenule44ka CMS LFI Vulnerability


Dork: intext:by Lenule44ka
Date: 14.07.2018

Poc : NVIZION CMS SQL Injection


Dork: intext:Developed by: nvizioninc.com /display.php?id=
Date: 14.07.2018

Poc : Matrimonial Auth By Pass Vulnerability


Dork: intext:printprofile.php?id=
Date: 12.07.2018
Poc : Global Infotech Auth by pass Vulnerability
Dork: intext:Powered by : Global Infotech
Date: 12.07.2018

Poc : Myschool CMS LFD Vulnerability


Dork: inurl:/img_anekaweb/
Date: 11.07.2018

Poc : Matrimonial Script CSRF Vulnerability


Dork: intext:printprofile.php?id=
Date: 11.07.2018

Poc : Narm afzar Gostar Hegmataneh cms Authentication bypass Vulnerability


Dork: intext:Powered by Arash Zolfaghari © 2014 and improvment by Narm afzar Gostar
Hegmataneh
Date: 11.07.2018

Poc : Lokomedia CMS LFI Vulnerability


Dork: inurl:/semua-download.html
Date: 11.07.2018

Poc : Website Fueled and Designed by SocketWorks Internet Services ©2018 SQL
Injection
Dork: intext:Website Fueled and Designed by SocketWorks Internet Services ©2018
Date: 11.07.2018

Poc : Powered by บ้านเว็บไซต์ SQL Injection


Dork: intext:Powered by บ้านเว็บไซต์
Date: 11.07.2018

Poc : Made by SquareConcept SQL Injection


Dork: intext:Made by SquareConcept
Date: 11.07.2018

Poc : Courier Deprixa Pro - Integrated Web System v3.2.5 Auth by pass
Vulnerability
Dork: DEPRIXA 3.2.5 | lOGIN
Date: 10.07.2018

Poc : Courier Deprixa Pro - Integrated Web System v3.2.5 CSRF Vulnerability
Dork: DEPRIXA 3.2.5 | lOGIN
Date: 10.07.2018

Poc : İtalia Mediasky Xss Vulnerability


Dork: Mediasky - Lato Amministrativo
Date: 10.07.2018

Poc : Tamil Nadu National Law School cms Authentication bypass Vulnerability
Dork: intext:Designed by: Guhaa Soft Solutions (P) Limited
Date: 10.07.2018

Poc : Grundig Smart Inter@ctive 3.0 Insecure Direct Object Reference


Dork: Local Vulnerability
Date: 09.07.2018

Poc : Wchat - Fully Responsive PHP AJAX Chat Script 1.5 unrestricted file upload
Vulnerability
Dork: Wchat - Admin Login
Date: 09.07.2018

Poc : Conception e-partenaire SQL Injection Vulnerability


Dork: intext:Conception : e-partenaire inurl:.php?id=
Date: 09.07.2018

Poc : Buzzy - News Viral Lists Polls and Videos V 2.5.2 Backdoor Account
Vulnerability
Dork: intext:buzzy /profile/admin/ Copyright © Buzzy. All rights reserved.
Date: 09.07.2018

Poc : site design by Strawberry Design SQL Injection


Dork: intext:site design by Strawberry Design
Date: 08.07.2018

Poc : Designed & Maintained by It Globaliser - SQL Injection


Dork: intext:Designed & Maintained by It Globaliser. .php?id= [+]
Date: 08.07.2018

Poc : Web Stock 3.0 Unauthorised Administrative Access Vulnerability


Dork: Designed by Web Stock
Date: 08.07.2018

Poc : Buzzy - News Viral Lists Polls and Videos V 2.5.1 Backdoor Account
Vulnerability
Dork: intext:buzzy /profile/admin/ Copyright © Buzzy. All rights reserved.
Date: 08.07.2018

Poc : site by dotdot.media SQL Injection


Dork: intext:site by dotdot.media
Date: 08.07.2018

Poc : The Next Generation of Genealogy Sitebuilding ©, v. 11.1.2 xss Vulnerability


Dork: This site powered by The Next Generation of Genealogy Sitebuilding ©, v.
11.1.2, written by Darrin Lythgoe 2001-2018.
Date: 08.07.2018

Poc : PHPMailer Test Page < 5.0 Cross-Site-Scripting


Dork: inurl:phpmailer/test_script/
Date: 07.07.2018

Poc : Création site internet Adveris SQL Injection Vulnerability


Dork: intext:Création site internet : Adveris inurl:.php?id=
Date: 07.07.2018

Poc : Ukrainian Sites Url Poisoning


Dork: site:ua cfg contactform
Date: 07.07.2018

Poc : Designed By Studio Octavo Israel SQL Injection Vulnerability


Dork: intext:Designed By Studio Octavo site:il
Date: 07.07.2018

Poc : Software Developed By Copotronic Shikkhangon Iqbal Hossain Rimon Admin Login
Bypass Vulnerability
Dork: intext:© Copotronic InfoSystems Limited. All Right Reserved. -
intext:Copyright © 2018 Shikkhangon.com. All Right Reserved.
Date: 07.07.2018
Poc : Gettarget EduProTech © 2003-2016 EduPro Technology Pvt. Ltd. SQL Injection
Vulnerability
Dork: intext:© 2003-2016 EduPro Technology Pvt. Ltd.
Date: 07.07.2018

Poc : Website Design jhchoi Creative Consultancy SQL Injection Vulnerability


Dork: intext:Website Design jhchoi
Date: 07.07.2018

Poc : Design & Development World IT Expert Ahasan Habib Admin Login Bypass
Vulnerability
Dork: intext:Design & Development World IT Expert site:bd
Date: 07.07.2018

Poc : Global Infotech Auth by pass Vulnerability


Dork: intext:Powered by : Global Infotech
Date: 06.07.2018

Poc : BD Schools xss Vulnerability


Dork: inurl:teachers_details.php?teacher_ID site:edu.bd
Date: 06.07.2018

Poc : Buzzy - News Viral Lists Polls and Videos V 2.0 Backdoor Account
Vulnerability
Dork: intext:buzzy /profile/admin/ Copyright © Buzzy. All rights reserved.
Date: 06.07.2018

Poc : IT Division Bina Bakti cms Sql Injection Vulnerability


Dork: intext:Created by IT Division Bina Bakti
Date: 05.07.2018

Poc : Designed & Developed by Sacit.Lk SriLanka Improper Authentication


Vulnerability
Dork: intext:Designed & Developed by SACIT site:lk
Date: 05.07.2018

Poc : Lokomedia CMS Arbitrary File Upload


Dork: intitle:..::: Login User :::.. Pegawai yang belum
Date: 04.07.2018

Poc : Wordpres Simple 301 Redirects - Addon - Bulk CSV Uploader plugin Cross Site
Scripting Vulnerability
Dork: inurl:/wp-content/plugins/simple-301-redirects-addon-bulk-uploader/
Date: 04.07.2018

Poc : Design by DesignWise SQL Injection Vulnerability


Dork: intext:Design by DesignWise inurl:/.php?id=
Date: 04.07.2018

Poc : Designed By WeyalTech Developed By DjangoSuit Company Afghanistan SQL


Injection Vulnerability
Dork: intext:Designed by WeyalTech - intext:Developed by DjangoSuit.com
Date: 04.07.2018

Poc : Website Design & Development by LIFTOFF Digital SQL Injection Vulnerability
Dork: intext:Website Design & Development by LIFTOFF Digital inurl:php.?id=
Date: 02.07.2018

Poc : Powered by Admas Host & Developed by Asian IT SQL Injection Vulnerability
Dork: intext:Powered by Admas Host & Developed by Asian IT
Date: 02.07.2018

Poc : Design by Recursive Technologies Inc Nepal SQL Injection Vulnerability


Dork: intext:Design by Recursive Technologies Inc
Date: 02.07.2018

Poc : Design by Recursive Technologies Inc Nepal SQL Injection Vulnerability


Dork: intext:Design by Recursive Technologies Inc
Date: 02.07.2018

Poc : Powered By WorldTravelGuide HolidaySmart CMS SQL Injection Vulnerability


Dork: inurl:/cms.php?id= site:af
Date: 02.07.2018

Poc : Powered by Admas Host & Developed by Asian IT SQL Injection Vulnerability
Dork: intext:Powered by Admas Host & Developed by Asian IT
Date: 02.07.2018

Poc : Buzzy - News Viral Lists Polls and Videos V 1.4 Backdoor Account
Vulnerability
Dork: intext:buzzy /profile/admin/ Copyright © Buzzy. All rights reserved.
Date: 02.07.2018

Poc : Designed by EMH TheEmhGlobal SQL Injection Vulnerability


Dork: intext:Designed by EMH
Date: 02.07.2018

Poc : Website Hosted By MTC MtcMedia Scotland SQL Injection Vulnerability


Dork: intext:Website hosted by mtc.
Date: 02.07.2018

Poc : Maintained By Loojah Bajracharya SQL Injection Vulnerability


Dork: intext:Maintained By: Loojah Bajracharya
Date: 02.07.2018

Poc : Powered by Schoolsindia.Com School Management System SQL Injection


Vulnerability
Dork: intext:Powered by Schoolsindia
Date: 02.07.2018

Poc : Site Developed By İconify Web & Mobile Development SQL Injection
Vulnerability
Dork: intext:site developed by iconify
Date: 02.07.2018

Poc : ElevationDesign LeighDesignStudio WebDesign South Africa SQL Injection


Vulnerability
Dork: intext:All rights reserved | Web Design Elevation Design - intext:Web Design
Leigh Design Studio
Date: 02.07.2018

Poc : Developed By Inside Softwares Pvt. Ltd. Web Design Company India SQL
Injection Vulnerability
Dork: intext:DEVELOPED BY INSIDE SOFTWARES PVT. LTD
Date: 02.07.2018

Poc : Metaping SQL Injection


Dork: intext:site by metaping custom.asp?id=
Date: 01.07.2018

Poc : OVOO v2.5.1 - Movie & Video Streaming CMS with Unlimited TV-Series backdoor
account Vulnerability
Dork: intext:Ovoo movie & Tv Show streaming cms - Login
Date: 01.07.2018

Poc : Powered by Yii Framework RBAC Manager for Yii 2 Improper Authentication
Vulnerability
Dork: inurl:/emusrenbang/web/index.php?r=
Date: 01.07.2018

Poc : Infinity Market Classified Ads Script 1.6.2 xss via file uploads
Vulnerability
Dork: intext:InfinityMarket MultiPurpose Script is a multi-solution product made
with simplicity in mind so you can benefit
Date: 01.07.2018

Poc : Eden Design Xss Vulnerability


Dork: intext:Website by Eden Design
Date: 01.07.2018

Poc : Powered by IvansWeb IWGallery PhotoGallery © 2005/2007 SQL Injection


Vulnerability
Dork: intext:Powered by IvansWeb - All Rights Reserved © 2005/2007 - intext:Vietata
la riproduzione anche parziale delle immagini /iwgallery/
Date: 30.06.2018

Poc : The Web Portfolio of Franny Howes LittlePinkMafia Improper Authentication


Vulnerability
Dork: intext:email me at fhowes at vt dot edu
Date: 30.06.2018

Poc : Dj Twilight Ver 2.0 Copyright 1999 - 2018 PicturesGallery SQL Injection
Vulnerability
Dork: intext:DJ TWILIGHT.COM Ver 2.0 Copyright 1999 - 2018
Date: 30.06.2018

Poc : Bee Gees Italy © 1998-2017 Enzo Lo Piccolo SQL Injection Vulnerability
Dork: intext:Bee Gees Italy © 1998-2017 Enzo Lo Piccolo
Date: 30.06.2018

Poc : Powered by dBlog CMS ® Open Source Picture Gallery By InternetCamera.it SQL
Injection Vulnerability
Dork: intext:powered by dBlog CMS ® Open Source - intext:Picture gallery By
Internet camera
Date: 30.06.2018

Poc : Copyright © 2008 - 2018 by DaMa SOFT WebSiteX5 İwGallery Manager Privilege
Escalation Vulnerability
Dork: intext:by DaMa SOFTWARE 2015 - inurl:/filemanager/sfmanager.asp
Date: 30.06.2018

Poc : BirWebMaster AsmWebSitesi Graphics Web Design Services SQL Injection


Vulnerability
Dork: inurl:/index.php?sayfa=DuyuruOku
Date: 30.06.2018

Poc : E-learning Indonesian School SQL Injection


Dork: inurl:id_berita= e-learning
Date: 30.06.2018

Poc : News365 v4 Backdoor Account Vulnerability


Dork: intext:bdtask Theme | All right Reserved 2016 Login |
Date: 30.06.2018

Poc : Sultra CMS SQL Injection


Dork: inurl:?menu=baca_berita
Date: 30.06.2018

Poc : Design by FCT SQL Injection Vulnerability


Dork: intext:Design by FCT inurl:.php?id=
Date: 29.06.2018

Poc : Web design by JustSimple SQL Injection Vulnerability


Dork: intext:Web design by JustSimple inurl:.php?id=
Date: 29.06.2018

Poc : Design By Dr. Hardik Desai Developed By Chirag Lad India Admin Login Bypass
Vulnerability
Dork: intext:Design By Dr. Hardik Desai | Developed By Chirag Lad
Date: 29.06.2018

Poc : Developed By the DokaGroup Laboratory 2008-2011 Belarus Open Redirection


Vulnerability
Dork: intext:разработан лабораторией DokaGroup, 2008-2011
Date: 29.06.2018

Poc : Designed By Polypod Developed By Fusion Second SQL Injection Vulnerability


Dork: intext:Designed By Polypod Developed By Fusion Second
Date: 29.06.2018

Poc : Website Designed By Sanminds Hosting Nepal SQL Injection Vulnerability


Dork: intext:Website Designed By Sanminds
Date: 29.06.2018

Poc : Site By www.clayrose.com Web Design Hosting Management SQL Injection


Vulnerability
Dork: intext:Site by www.clayrose.com
Date: 29.06.2018

Poc : Web services provided by Ciphertek Systems, LLC SQL Injection Vulnerability
Dork: intext:Web services provided by Ciphertek Systems, LLC
Date: 29.06.2018

Poc : AlfineSolutions.Com Web Hosting SQL Injection Vulnerability


Dork: intext:Powered By ALFINE IT Solutions
Date: 29.06.2018

Poc : Powered by A Webs Design SQL Injection


Dork: intext: property.php?id=
Date: 28.06.2018

Poc : Pemesanan Katering SQL Injection


Dork: inurl:/menu.php?kategori= katering
Date: 28.06.2018

Poc : Buzzy - News Viral Lists Polls and Videos V 1.3.2 Backdoor Account
Vulnerability
Dork: intext:buzzy /profile/admin/ Copyright © Buzzy. All rights reserved.
Date: 28.06.2018

Poc : ERPnext 11.x.x XSS via file uploads upload Vulnerability


Dork: intext:Powered by ERPNext
Date: 28.06.2018

Poc : Infinity Market Classified Ads Script 1.6.1 xss via file uploads
Vulnerability
Dork: intext:InfinityMarket MultiPurpose Script is a multi-solution product made
with simplicity in mind so you can benefit
Date: 28.06.2018

Poc : İtalia Mediasky CSRF Vulnerability


Dork: Mediasky - Lato Amministrativo
Date: 28.06.2018

Poc : Design By Adequate SQL Injection Vulnerability


Dork: intext:Design By Adequate
Date: 27.06.2018

Poc : Powered by: The Colour Moon SQL Injection


Dork: intext:Powered by: The Colour Moon
Date: 27.06.2018

Poc : Powered by WPP SQL Injection


Dork: intext:Powered by WPP
Date: 27.06.2018

Poc : Pixaal CMS Admin Default Password


Dork: intext:Developed by Pixaal
Date: 27.06.2018

Poc : Stockh00lm360 SQL Injection Vulnerability


Dork: intext:Copyright stockholm360.net
Date: 26.06.2018

Poc : Designed by SriRam Soft Solutions Pvt. Ltd. India SQL Injection Vulnerability
Dork: intext:Designed by : SriRam Soft Solutions Pvt. Ltd.
Date: 26.06.2018

Poc : Developed By Jay4web Website Design and Development India SQL Injection
Vulnerability
Dork: intext:Developed By Jay4web
Date: 26.06.2018

Poc : Powered by ZTsolution Business England SQL Injection Vulnerability


Dork: intext:Powered by ZTsolution
Date: 26.06.2018

Poc : WebSolutions.Ca Web Design and Development Canada SQL Injection Vulnerability
Dork: intext:websolutions.ca
Date: 26.06.2018

Poc : Design By Atarim.Com Israel International Internet Agency SQL Injection


Vulnerability
Dork: intext:design: atarim
Date: 26.06.2018
Poc : Webdesign by Lennys Studio Produced by 21C Media Group SQL Injection
Vulnerability
Dork: intext:Webdesign by Lennys Studio | Produced by 21C Media Group
Date: 26.06.2018

Poc : Another Quality Site by Seabreeze Consulting Web Design SQL Injection
Vulnerability
Dork: intext:Another Quality Site by Seabreeze Consulting
Date: 26.06.2018

Poc : Powered by Quick.Cart & HOST[24] Fckeditor Arbitrary File Upload


Vulnerability
Dork: intext:Powered by Quick.Cart & HOST[24] - profi hosting za 24,- site:cz
Date: 26.06.2018

Poc : Designed & Maintained By Amrithaa.com Admin Panel Bypass


Dork: intext:Designed & Maintained By Amrithaa.com.
Date: 25.06.2018

Poc : Rivulets Admin Panel Bypass


Dork: intext:Powered by Rivulets.
Date: 25.06.2018

Poc : Powered byJWA ©2016 Website designed by THADV Admin Login Bypass
Vulnerability
Dork: intext:Powered byJWA ©2016 Website designed by THADV
Date: 25.06.2018

Poc : İtalia Mediasky Download Backup Vulnerability


Dork: Mediasky - Lato Amministrativo
Date: 25.06.2018

Poc : Indian Institute of Welding Admin Panel Bypass


Dork: intext:2017 The Indian Institute of Welding
Date: 25.06.2018

Poc : Double Benefit Malaysia Admin Panel Bypass


Dork: intext:Double Benefit Malaysia
Date: 25.06.2018

Poc : All India Bar Association Admin Panel Bypass


Dork: intext:All India Bar Association
Date: 25.06.2018

Poc : Developed by Regal Soft India WebDesign Admin Login Bypass Vulnerability
Dork: intext:Developed by Regal Soft India site:gov.in
Date: 25.06.2018

Poc : Rathna Softnet Admin Panel Bypass


Dork: intext:design and developed by rathna softnet
Date: 25.06.2018

Poc : Hong Kong Admin Login Bypass Powered By YSD SQL Injection
Dork: intext:Powered By YSD
Date: 25.06.2018

Poc : FAST RIDING SCHOOL Admin Panel Bypass


Dork: intext:FAST RIDING SCHOOL
Date: 25.06.2018

Poc : Indonesia Admin Login Bypass Copyright CMS Develop by: Anom Bramanjati SQL
Injection
Dork: intext:© 2010 PT. Oriental Asahi JP Carton Box
Date: 25.06.2018

Poc : Ujian Online Arbitrary File Upload


Dork: intext:Selamat Datang di Ujian Online
Date: 24.06.2018

Poc : Aplikasi Pembayaran Angsuran Admin Weak Password


Dork: intitle:Halaman Login Aplikasi Pembayaran Angsuran
Date: 24.06.2018

Poc : E-Reg Login Bypass


Dork: intext:E-Reg Login Form inurl:/login
Date: 24.06.2018

Poc : Yönetim Paneli default admin Vulnerability


Dork: inurl:/photos/galeri_sayfasi/
Date: 24.06.2018

Poc : Copyright © 1999-2005 NIP Kompanija "Novosti" A.D. Serbia SQL


Injection Vulnerability
Dork: intext:Copyright © 1999-2005 NIP Kompanija Novosti A.D. All Rights Reserved.
Date: 24.06.2018

Poc : Joomla Com_Techedu Courseview Developed in Association with Icta SriLanka SQL
Injection Vulnerability
Dork: intext:Developed in association with ICTA
Date: 24.06.2018

Poc : Designed & Developed by Web Based Business Systems BTOptions.Com SQL
Injection Vulnerability
Dork: intext:Designed & Developed by Web Based Business Systems, BT Options.
Date: 24.06.2018

Poc : Copyright © 2008-2011 NEX Studio Nex.Ba Web Design SQL Injection
Vulnerability
Dork: intext:NEX Studio. site:ba
Date: 24.06.2018

Poc : Joomla com_regionalm Icta Regional Museum SQL Injection Vulnerability


Dork: inurl:/index.php?option=com_regionalm
Date: 24.06.2018

Poc : Solution by Lankacom Internet Service Provider in Sri Lanka SQL Injection
Vulnerability
Dork: intext:Solution by Lankacom.
Date: 24.06.2018

Poc : Powered by Peernet Company Limited HkPeernet.Com SQL Injection Vulnerability


Dork: intext:Powered by Peernet Company Limited site:hk
Date: 24.06.2018

Poc : Created By Z Axis IT Solution WebDesign SQL Injection Vulnerability


Dork: intext:created by Z Axis IT Solution
Date: 24.06.2018
Poc : Hospital Management System auth by pass Vulnerability
Dork: © 2018 HMS. All rights reserved
Date: 24.06.2018

Poc : Web Design Agency ChromaAgency.Com SQL Injection Vulnerability


Dork: intext:Web design agency: Chroma.
Date: 24.06.2018

Poc : Projekt i wykonanie Pro-Link strony internetowe FCKEditor Exploit


Dork: intext:Projekt i wykonanie: Pro-Link strony internetowe
Date: 23.06.2018

Poc : Design By GII SQL Injection Vulnerability


Dork: intext:Design By GII
Date: 23.06.2018

Poc : WordPress Design By SmartCat.Net ImageManager Plugin Remote File Upload


Vulnerability
Dork: intext:Design By Smartcat
Date: 23.06.2018

Poc : WordPress Design By SmartCatDesign.Net ImageManager Plugin Remote File Upload


Vulnerability
Dork: intext:Design By Smartcat
Date: 23.06.2018

Poc : Designed & Powered by Gilgal Media Arts Admin Login Bypass Vulnerability
Dork: intext:Designed & Powered by Gilgal Media Arts
Date: 23.06.2018

Poc : Concept and development by Bearweb.com SQL Injection


Dork: prodetails.php?prodid=
Date: 23.06.2018

Poc : Realizzato da equo.biz Software Hosting Italia SQL Injection Vulnerability


Dork: intext:Realizzato da equo.biz
Date: 23.06.2018

Poc : Designed and Developed by Reliable Services GRHRCS Pvt Ltd Admin Login Bypass
Vulnerability
Dork: intext:Designed and developed by Reliable Services GRHRCS Pvt Ltd
Date: 23.06.2018

Poc : Developed by Rate it Services Business Solutions Mājas lapu izstrāde


FCKeditor Remote File Upload Vulnerability
Dork: intext:Developed by: RATE IT SERVICES - intext:Developed by: RATE Business
Soltuions
Date: 23.06.2018

Poc : Design by East Multimedia SQL Injection Vulnerability


Dork: intext:Design by East Multimedia inurl:/.php?id=
Date: 23.06.2018

Poc : PSB Online Admin Login Bypass


Dork: inurl:/?open=Pendaftaran-PSB
Date: 23.06.2018

Poc : SILAB Admin Login Bypass


Dork: inurl:/silab/ intitle:SILAB - Sistem Informasi Laboratorium login
Date: 22.06.2018

Poc : Drupal 7 ItalianGov Fi.it Scrivi Al Comune Arbitrary File Upload


Vulnerability
Dork: intext:Scrivi al Comune site:fi.it
Date: 22.06.2018

Poc : Desarrollado por Mancort Spain SQL Injection Vulnerability


Dork: intext:desarrollado por mancort
Date: 22.06.2018

Poc : DigiHost LMS Admin No Redirect


Dork: intext:DigiHost LMS
Date: 22.06.2018

Poc : 8webcom Cms SQL Injection


Dork: intext:Powered By : 8webcom.com inurl:?id=
Date: 22.06.2018

Poc : NewMark CMS 2.1 SQL Injection


Dork: /catalog/?sect_id=
Date: 22.06.2018

Poc : Creado por Crafi&Deso MachForm PHP Form Builder Spain SQL Injection
Vulnerability
Dork: intext:Creado por CRAFI&DESO - intext:MachForm - PHP Form Builder
Date: 22.06.2018

Poc : Creación y diseño White Solutions FactuSOL Web por Software DELSOL SQL
Injection Vulnerability
Dork: intext:FactuSOL Web por Software DELSOL - intext:Creación y diseño White
Solutions
Date: 22.06.2018

Poc : Website design by :: betrodesigns :: SQL Injection


Dork: getbook.php?bookid=
Date: 21.06.2018

Poc : WordPress DrcSystems EthicSolutions Jssor-Slider Library Plugin Arbitrary


File Upload Vulnerability
Dork: inurl:/wp-content/jssor-slider/jssor-uploads/
Date: 21.06.2018

Poc : Website Design by EDJE SQL Injection


Dork: giftDetail.php?id=
Date: 21.06.2018

Poc : Website Produced by USE FOR FUN Design Collective | Beirut SQL Injection
Dork: prodbycat.php?intCatalogID=
Date: 21.06.2018

Poc : Powered by Quaid Technologies QuaidTech Pakistan SQL Injection Vulnerability


Dork: intext:Powered by Quaid Technologies
Date: 21.06.2018

Poc : SleePedia.in an initiative of SleepwellFoundation India Nepal Bhutan SQL


Injection Vulnerability
Dork: inurl:/products/searchByKeyword/?keyword_search=
Date: 21.06.2018

Poc : © IMS Institute Management System by JS IT Park 2017-18 Version 1.0.1 Admin
Bypass Vulnerability
Dork: intext:Developed by JS IT Park
Date: 21.06.2018

Poc : Developed by Bitsolution ICT Consulting Firm Samoa Islands Improper


Authentication Vulnerability
Dork: intext:Developed by Bitsolution ICT Consulting Firm site:gov.ws
Date: 21.06.2018

Poc : Sipbar Sistem Informasi Pelaporan Indonesia Admin Login Bypass and SQL
Injection Vulnerability
Dork: inurl:/assets/media/logo_kanal/
Date: 21.06.2018

Poc : Provided By Green4Solutions EcommZone Open Redirection Vulnerability


Dork: inurl:/lz/EPLIVE/
Date: 21.06.2018

Poc : Site by t.i.p.p.server / Design by J.Lankisch SQL Injection


Dork: freedownload.php?bookid=
Date: 21.06.2018

Poc : Credits by : A R Infotech SQL Injection


Dork: myaccount.php?catid=
Date: 21.06.2018

Poc : Website by Neon Six SQL Injection


Dork: powersearch.php?CartId=
Date: 21.06.2018

Poc : Developed by Mr. Pich Sokunthea SQL Injection


Dork: intext:Developed by Mr. Pich Sokunthea
Date: 21.06.2018

Poc : Resumes File Upload Vulnerability


Dork: inurl:/fileupload/php/ , inurl:/pages/resumeupload.php
Date: 20.06.2018

Poc : Dise?o por Design-cr.com SQL Injection


Dork: inurl:viewtable?cid= site:com
Date: 20.06.2018

Poc : Redatam Web Server Directory Traversal


Dork: inurl: /redbin/rpwebutilities.exe/
Date: 18.06.2018

Poc : Sistem Informasi Surat Dinas SQL Injection


Dork: inurl:/masukview.php?key=
Date: 18.06.2018

Poc : Design by Andreas Viklund SQL Injection Vulnerability


Dork: intext:Design by Andreas Viklund inurl:/.php?id=
Date: 18.06.2018

Poc : Sistem Informasi Pelayanan Perizinan Admin Login Bypass


Dork: intitle:Sistem Informasi Pelayanan Perizinan inurl:/login.php
Date: 18.06.2018

Poc : Powered by linkrey SQL Injection


Dork: inurl:/details.php?id= site:do
Date: 18.06.2018

Poc : Designed by ibolo.mu SQL Injection


Dork: inurl:/details.php?id= site:mu
Date: 18.06.2018

Poc : Powered By Metro Business SQL Injectio


Dork: inurl:/details.php?id= site:sd
Date: 18.06.2018

Poc : Beporsam Script Remote file upload Vulnerability


Dork: intext:Designe By : Beporsam & SG Designer
Date: 17.06.2018

Poc : Website Design by Fee Creative SQL Injection Vulnerability


Dork: intext:Website Design by Fee Creative inurl:/.php?id=
Date: 17.06.2018

Poc : Design by WebsterIT Ltd SQL Injection Vulnerability


Dork: intext:Design by WebsterIT Ltd inurl:/.php?id=
Date: 17.06.2018

Poc : PerPusWeb Bypass Admin No Redirect


Dork: intext:Selamat Datang di Perpustakaan Berbasis Web (PerPusWeb)
Date: 17.06.2018

Poc : Eternysoft Shop Admin Login Bypass


Dork: inurl:/list_barang.php?category=
Date: 17.06.2018

Poc : DistroIT Admin Login Bypass


Dork: inurl:/index.html intitle:Admin Tokol DistroIT
Date: 17.06.2018

Poc : Indonesian E-Library Admin Login Bypass


Dork: inurl:/login-ad.php Login Admin
Date: 17.06.2018

Poc : designed by MAKS LB admin bypass Upload file


Dork: intext:designed by MAKS LB
Date: 17.06.2018

Poc : Sistem Informasi Nilai Siswa (SiNiS) Bypass Admin No Redirect


Dork: intext:Sistem Informasi Nilai Siswa (SiNiS) Sign in. atau login sebagai
Date: 17.06.2018

Poc : KBM Media Solutions - No Redirect Login


Dork: intext:Design & Developed By: KBM Media Solutions
Date: 17.06.2018

Poc : Indonesian School PPDB Admin Login Bypass


Dork: inurl:/login.php PPDB. Beranda (current) · Pendaftar Sementara(current).
Selamat datang Admin PPDB
Date: 17.06.2018
Poc : Site design by Maybury IT SQL Injection Vulnerability
Dork: intext:Site design by Maybury IT
Date: 16.06.2018

Poc : Live Zilla 7.x Remote File Upload Vulnerability


Dork: intitle:LiveZilla inurl:/upload.php
Date: 16.06.2018

Poc : Site design by SG Design SQL Injection Vulnerability


Dork: intext:Site design by SG Design
Date: 16.06.2018

Poc : Tim Balitbang Depdiknas versi 3.5 Sql injection Vulnerability


Dork: Tim Balitbang Depdiknas versi 3.5
Date: 15.06.2018

Poc : Tim Balitbang Depdiknas versi 3.5 xss stord Vulnerability


Dork: Tim Balitbang Depdiknas versi 3.5
Date: 15.06.2018

Poc : Website design by Richard Hodgett SQL Injection Vulnerability


Dork: intext:Website design by Richard Hodgett
Date: 15.06.2018

Poc : Elite CMS Pro - Version 2.01 Admin Panel sql injection Vulnerability
Dork: intext:Elite CMS Pro - Version 2.01
Date: 15.06.2018

Poc : RenDesKa12 Auth by pass Vulnerability


Dork: İnurl:/login/login.php
Date: 15.06.2018

Poc : Website design by duckfeet.co.uk SQL Injection Vulnerability


Dork: intext:Website design by duckfeet.co.uk
Date: 15.06.2018

Poc : Web design by Fluid Studios SQL Injection Vulnerability


Dork: intext:Web design by Fluid Studios
Date: 14.06.2018

Poc : Varient News Magazine Script V 1.3.0 Backdoor Account Vulnerability


Dork: intext:Varient - News Magazine - Varient
Date: 14.06.2018

Poc : original site design by petera SQL Injection Vulnerability


Dork: intext:original site design by petera
Date: 14.06.2018

Poc : Adiscon LogAnalyzer V 4.1.5 XSS Vulnerability


Dork: intext:Adiscon LogAnalyzer Version 4.1.5
Date: 13.06.2018

Poc : NETYGO Auth by pass Vulnerability


Dork: Site réalisé par NETYGO
Date: 12.06.2018

Poc : cms pro v.5.0 Sql injection Vulnerability


Dork: Wojoscripts Copyright © 2018 Wojoscripts.com
Date: 12.06.2018
Poc : Buzzy - News Viral Lists Polls and Videos V 1.3.1 Backdoor Account
Vulnerability
Dork: intext:buzzy /profile/admin/ Copyright © Buzzy. All rights reserved.
Date: 12.06.2018

Poc : Anonymous Feedback Script V2.1 xss Vulnerability


Dork: intext:Welcome to Anonymous Feedback - Anonymous Feedback
Date: 12.06.2018

Poc : wp-content themes clinell Local File Disclosure Vulnerability


Dork: inurl:wp-content/themes/clinell
Date: 11.06.2018

Poc : wp-content themes ypo-theme Local File Disclosure Vulnerability


Dork: inurl:wp-content/themes/ypo-theme
Date: 11.06.2018

Poc : wp-content uploads sb-download.php Local File Disclosure Vulnerability


Dork: inurl:uploads/sb-download.php?file=
Date: 11.06.2018

Poc : Amirtham Sweets Admin Panel Bypass


Dork: intext:Copyrights - 2017 Amirtham Sweets
Date: 11.06.2018

Poc : Amirtham Sweets Remote File Upload Vulnerability


Dork: intext:Copyrights - 2017 Amirtham Sweets
Date: 11.06.2018

Poc : Makeupbarr Remote File Upload Vulnerability


Dork: intext:Copyright Makeupbarr.Com
Date: 11.06.2018

Poc : Gardenoma Remote File Upload Vulnerability


Dork: intext:gardenoma happy planting.
Date: 11.06.2018

Poc : Rail Vikas Nigam Admin Panel Bypass


Dork: intext:Copyright Rail Vikas Nigam Limited.
Date: 11.06.2018

Poc : microMBA Remote File Upload Vulnerability


Dork: intext:microMBA 2018. Todos los derechos reservados.
Date: 11.06.2018

Poc : Baruque Casa Remote File Upload Vulnerability


Dork: intext:Copyright Baruque Casa.
Date: 11.06.2018

Poc : RVSiteBuilder RVGlobalSoft CMS High-Performance Hosting Provider Serious


Multiple Vulnerabilities
Dork: inurl:/rvsindex.php/
Date: 11.06.2018

Poc : KALIMATAN GOVERNMENT SQLi Grafik.php


Dork: inurl:/front/grafik.php?tahun=
Date: 11.06.2018
Poc : Belgium Panel Admin Bypass JSDeface & SQLi
Dork: intext:Design & development by Digital Productions
Date: 11.06.2018

Poc : GHS TEAM Xss Vulnerability


Dork: inurl: news.php?id=
Date: 11.06.2018

Poc : Dashboard Bypass Register New User or Admin


Dork: inurl:/dashboard/index.php/login/
Date: 10.06.2018

Poc : Zombi Bot V3 2018 || SHELLS 1000+ || 520+ vulns Exploit ||


Dork: intext:inurl:/wp-content/plugins/revslider/ inurl:sites/default/files
inurl:/index.php?option= inurl:inurloption=com in inurl:intext.php?
options=com_hello
inurl:/wp-content/plugins/framework/plugins/revslider/temp/update_extract/revslider
inurl:wp-content/themes/hospital
Date: 10.06.2018

Poc : Technical Support A2i-PMO Bangladesh e-Government Open Redirection


Vulnerability
Dork: intext:কারিগরি সহায়তায় a2i
Date: 10.06.2018

Poc : Sistem Informasi Perpustakaan Admin Login Bypass


Dork: inurl:/depan/cari_buku
Date: 10.06.2018

Poc : design by Strawberry Design SQL Injection Vulnerability


Dork: intext:design by Strawberry Design
Date: 09.06.2018

Poc : WordPress Theme Sydney by aThemes 2018 GravityForms Input Remote File Upload
Vulnerability
Dork: intext:Proudly powered by WordPress | Theme: Sydney by aThemes.
Date: 08.06.2018

Poc : Copyright © 2014 Indian Performing Art Center Admin Control Panel ByPass
Vulnerability
Dork: intext:Copyright © 2014- All Rights Reserved Press| Indian Performing Art
Center ::
Date: 08.06.2018

Poc : Design & Development By i5t.in India Admin Control Panel ByPass Vulnerability
Dork: intext:Design & Development by i5t
Date: 08.06.2018

Poc : WEB GUYS SQL Injection Vulnerability


Dork: intext:Powered By: THE WEB GUYS inurl:.php?id=
Date: 08.06.2018

Poc : Jbimages TinyMCE Combine 3.04 Vulnerability


Dork: intext:intext:Powered By combine.or.id site:
Date: 08.06.2018

Poc : Design By SWS SQL Injection Vulnerability


Dork: intext:Design By SWS
Date: 08.06.2018
Poc : Website Design and SEO Services from Z Web Solutions SQL Injection
Vulnerability
Dork: intext:Website Design and SEO Services from Z Web Solutions
Date: 08.06.2018

Poc : Canon Company Printers Error Access Bypass


Dork: intitle:Remote UI: Login: MF210 Series: MF210 Series
Date: 07.06.2018

Poc : Sito internet e Web marketing realizzati da CyberMarket.it SQL Injection


Vulnerability
Dork: intext:Sito internet e Web marketing realizzati da cybermarket
Date: 06.06.2018

Poc : Web Design RGB Multimedia Perugia Italy SQL Injection Vulnerability
Dork: intext:Web Design RGB Multimedia Perugia - Italy
Date: 06.06.2018

Poc : Powered By 3dee.it Web Design SQL Injection Vulnerability


Dork: intext:powered by 3dee
Date: 06.06.2018

Poc : Varient News Magazine Script V 1.3.0 Backdoor Account Vulnerability


Dork: intext:Varient - News Magazine - Varient
Date: 06.06.2018

Poc : Varient News Magazine Script V 1.3.2 Backdoor Account Vulnerability


Dork: intext:Varient - News Magazine - Varient
Date: 06.06.2018

Poc : Videoplay V 1.3.0 Backdoor Account Vulnerability


Dork: VideoPlay - The best video subscription platform
Date: 06.06.2018

Poc : Desenvolvido e Hospedado por CWD Internet Brazil SQL Injection Vulnerability
Dork: intext:Desenvolvido e Hospedado por CWD Internet
Date: 05.06.2018

Poc : A M Technologies CSRF Vulnerability


Dork: intext:Powered by A M Technologies inurl:php?id=
Date: 05.06.2018

Poc : Powered by : ahprinters.com and ahwebexperts.com Web SQL Injection


Vulnerability
Dork: intext:Powered by : ahprinters.com and ahwebexperts.com
Date: 05.06.2018

Poc : Copyright CTWare.it © 2014-2018 Italy SQL Injection Vulnerability


Dork: intext:copyright CTWARE © 2014-2018
Date: 05.06.2018

Poc : Nametest Script v1.0 Auth By Pass Vulnerability


Dork: intext:testing ZDK
Date: 05.06.2018

Poc : Israel PGN Network Web Development AppGate SQL Injection Vulnerability
Dork: intext:Pgn - ‫ | בניית אתרים‬AppGate
Date: 04.06.2018
Poc : Intercom Solutions developer website SQLi
Dork: inurl:index.jsp? intext:sviluppato da intercom solutions
Date: 04.06.2018

Poc : Realizzato da Seobox di Massimo Sgambato SQL Injection Vulnerability


Dork: intext:Realizzato da Seobox di Massimo Sgambato
Date: 04.06.2018

Poc : MinorSchool v3.2 Reset Admin Password Vulnerability


Dork: intext:© Minor School, 2018
Date: 04.06.2018

Poc : Website Design By PolarSoft® Inc. GoPolar SQL Injection Vulnerability


Dork: intext:website design: PolarSoft® Inc.
Date: 03.06.2018

Poc : Elite CMS Pro - Version 2.01 Sql injection Vulnerability


Dork: Powered by Elite CMS Pro - Version 2.01
Date: 03.06.2018

Poc : Designed by ATOM STUDIO XSS Vulnerability


Dork: inurl:/details.php?id= site:th
Date: 03.06.2018

Poc : ArticleSetup Script Your Version: 1.00 Vulnerability


Dork: intext:© 2011 - Article Setup
Date: 02.06.2018

Poc : CopyRight © 2015 Hainan Pingan Car Rental Network China SQL Injection
Vulnerability
Dork: intext:CopyRight © 2015 海南平安租车网 版权所有
Date: 02.06.2018

Poc : ARTISTRY LIMITED Multi Vulnerability


Dork: intext:Developed By ARTISTRY LIMITED
Date: 02.06.2018

Poc : CREDITS PREVICINIDESIGN Xss Vulnerability


Dork: inurl:id= Or Web by PREVICINIDESIGN & php?id=
Date: 02.06.2018

Poc : chatone social networking php script v1.6 Add Admin Vulnerability
Dork: intext:chatone - online
Date: 02.06.2018

Poc : Israel Mp100.info Systems Web Design SQL Injection Vulnerability


Dork: intext:mp100 systems - ‫בניית אתרים‬
Date: 02.06.2018

Poc : Drupal PaisDigital ArgentinaGov Municipality ContactForm Arbitrary File


Upload Vulnerability
Dork: inurl:/?q=contacto site:gob.ar
Date: 02.06.2018

Poc : Buİnteractive Web Design E-Commerce Social Media Digital Marketing SQL
Injection
Dork: intext:Bu interactive
Date: 02.06.2018
Poc : AtelyeDigital.Com Web Design and Development SQL Injection Vulnerability
Dork: intext:Atelye Digital
Date: 02.06.2018

Poc : 3T1K Design and Coding İnternet Services W3Turk SQL Injection
Dork: inurl:/?ref=3t1k
Date: 02.06.2018

Poc : Israel © All rights reserved Tvan Servitex Company Ltd. SQL Injection
Dork: intext:© ‫כל הזכויות שמורות תוואן סרוויטקס בעמ‬
Date: 01.06.2018

Poc : Thai CMS Administrator Bypass and Shell Upload


Dork: inurl:/administrator/modules/mod_photo/ & inurl:path/administrator/admin.php
site:.th
Date: 01.06.2018

Poc : Designed by Federox Tech Studio SQL Injection Vulnerability


Dork: intext:Designed by Federox Tech Studio
Date: 01.06.2018

Poc : Investor Ningbo Liangzhu Culture Industrial Pack Development Management Co.
Ltd. SQL Injection Vulnerability
Dork: inurl:/liangzhutd.php?catid=
Date: 01.06.2018

Poc : Middle East Design and Programming GT4Host.Com Hosting SQL Injection
Vulnerability
Dork: intext:‫ الشرق الأوسطتصميم وبرمجة‬GT4Host
Date: 01.06.2018

Poc : Chitasoft 3.6.2 SQL Injection


Dork: O*O+-OSSOU O3OSSUOa : UUOaOSSO3OSSUOa
Date: 01.06.2018

Poc : NUUO NVRmini2 / NVRsolo Arbitrary File Upload


Dork: intitle:NUUO Network Video Recorder Login
Date: 31.05.2018

Poc : Technical Support Huaxia Chemical Network Background Management X-Mobio.Com


SQL Injection Vulnerability
Dork: intext:技术支持:华夏化工网 后台管理
Date: 31.05.2018

Poc : Taiwan 本公司已投保 GPS 衛星定位乘客險捌佰萬元 | 網頁設計 Web Design SQL Injection Vulnerability
Dork: intext:本公司已投保 GPS 衛星定位乘客險捌佰萬元 | 網頁設計 site:tw
Date: 31.05.2018

Poc : Arabia On-Liners.Com WebDesign SiteManager V2.3 Onliners S.A.R.L SQL


Injection Vulnerability
Dork: intext:SITEMANAGER V2.3 Onliners s.a.r.l.
Date: 31.05.2018

Poc : Arabia Developed by Smart Online Marketing SARL SomLB.Com SQL Injection
Vulnerability
Dork: intext:Developed by Smart Online Marketing SARL
Date: 31.05.2018
Poc : Aplikasi CBT Indonesian School Admin Weak Password
Dork: inurl:/panel/pages/login.php
Date: 31.05.2018

Poc : China Design by Qianli Humanities Technology 3q168.Com SQL Injection


Vulnerability
Dork: intext:design by 千立人文科技
Date: 31.05.2018

Poc : China Hangzhou City Technical Technology Support Juxiang Network 技术支持:聚翔网络
SQL Injection
Dork: intext:技术支持:聚翔网络
Date: 31.05.2018

Poc : Indonesian Government Delegation Bypass Admin No Redirect


Dork: inurl:/formdelegasi.php
Date: 31.05.2018

Poc : Design & Developed by MR Technology Sql Injection & Shell Upload
Dork: intext:Design & Developed by MR Technology & site:edu.bd
Date: 30.05.2018

Poc : Powered by AnimaxTechnology.in India SQL Injection Vulnerability


Dork: intext:Powered by Animaxtechnology.in
Date: 30.05.2018

Poc : Design by E-share Alibaba Hfceec.Com China SQL Injection Vulnerability


Dork: intext:Design by:E-share
Date: 30.05.2018

Poc : Melbourne FineArt Gallery Australia SQL Injection Vulnerability


Dork: inurl:/gallery.php?id= site:com.au
Date: 30.05.2018

Poc : Copyright © 2013 - 2018 Shumool.Com.Sa Real Estate Company Arabia SQL
Injection Vulnerability
Dork: intext:Copyright © 2013 - 2018 Shumool Company, All Rights Reserved
Date: 30.05.2018

Poc : Powered by Expert Web Worx and AnaghaSofTech SQL Injection Vulnerability
Dork: intext:powered by : Expert Web Worx
Date: 30.05.2018

Poc : Copyright © 2013 Powered by NWebProcess India SQL Injection Vulnerability


Dork: intext:Copyright © 2013 Powered by NWebProcess
Date: 30.05.2018

Poc : DESIGNED BY DADIAN DESIGN STUDIO XSS Vulnerability


Dork: inurl:/details.php?id= site:cn
Date: 30.05.2018

Poc : Web Design & Development by Easy Superweb Admin Control Panel ByPass
Vulnerability
Dork: intext:Web Design & Development by Superweb site:gr
Date: 30.05.2018

Poc : WordPress Headway Theme The Drag and Drop SQL Injection Vulnerability
Dork: inurl:/hindex.php?lT=
Date: 30.05.2018
Poc : Total Comfort Solutions A Commercial Heating and Air Conditioning Company SQL
Injection Vulnerability
Dork: intext:Total Comfort Solutions
Date: 30.05.2018

Poc : Packaging Printing © 2012 Powered by SmartWorks Systems Pakistan SQL


Injection Vulnerability
Dork: intext:Packaging Printing © 2012. Powered by : SmartWorks Systems.
Date: 30.05.2018

Poc : Base content Copyright ©2018 Lennox Industries USA SQL Injection
Vulnerability
Dork: intext:Base content Copyright ©2018 Lennox Industries.
Date: 30.05.2018

Poc : Basque Community by Readywebgo and NorthendCreative SQL Injection


Vulnerability
Dork: inurl:/content.asp?id=
Date: 30.05.2018

Poc : Regulated by Rics.Org PDF News England SQL Injection Vulnerability


Dork: inurl:/admin/pdf-news.php?id=
Date: 30.05.2018

Poc : Copyright © 2018 Designed by ArabPortals Development Egypt SQL Injection


Vulnerability
Dork: intext:Copyright © 2018 Designed by Arab Portals
Date: 30.05.2018

Poc : Designed by ATOM STUDIO XSS Vulnerability


Dork: inurl:/details.php?id= site:th
Date: 30.05.2018

Poc : IssueTrak 7.0 SQL Injection


Dork: inurl:IssueTrak inurl:asp
Date: 30.05.2018

Poc : Czech Realizováno: Diversite.cz Editor Vulnerability


Dork: intext:realizováno: diversite.cz
Date: 29.05.2018

Poc : TUNES SQL Injection Vulnerability


Dork: intext:Copyright 2010 TUNES inurl:product.php?id=
Date: 29.05.2018

Poc : Stockholm360 SQL Injection Vulnerability


Dork: intext:Copyright stockholm360.net inurl:list.php?id=
Date: 29.05.2018

Poc : Konstar SQL Injection Vulnerability


Dork: intext:Konstar Industries Ltd inurl:product_list.php?id=
Date: 29.05.2018

Poc : Stockholm360 SQL Injection Vulnerability


Dork: intext:Copyright stockholm360.net inurl:list.php?id=
Date: 29.05.2018

Poc : Ukesh School Admin Account ByPass Exploit


Dork: inurl:ukesh.com
Date: 29.05.2018

Poc : File Uploading Class Vulnerability


Dork: intitle:class.php.upload test forms
Date: 29.05.2018

Poc : FormattoDigital Mibew Messenger Open-Source Live Support Software Multiple


Vulnerability
Dork: intext:Formattoweb site:br / inurl:/site/pagina/sobre/ site:br
Date: 29.05.2018

Poc : The Kafe v2.0 Backdoor Account Vulnerability


Dork: intext:The Kafe - Ultimate Freelance Marketplace
Date: 29.05.2018

Poc : The Kafe v2.0 Xss / html inject Vulnerability


Dork: intext:The Kafe - Ultimate Freelance Marketplace
Date: 29.05.2018

Poc : Videoflix - Tv Series Movie Subscription Portal Cms v1.3 Backdoor Account
Vulnerability
Dork: intext:Made with by Vmax-Studio.
Date: 29.05.2018

Poc : Slims Senayan Library Management The Winner of OSS Indonesia 2009 ICT Award
Exploit
Dork: intext:The Winner in the Category of OSS Indonesia ICT Award 2009
Date: 28.05.2018

Poc : PetraHosting Desenvolvimento e Hospedagem Admin ByPass Shell Upload


Vulnerability
Dork: intext:PetraHost - Desenvolvimento e Hospedagem
Date: 28.05.2018

Poc : Copper Cup Images SQLi


Dork: intext:Site by Copper Cup Images inurl:cat_id= or inurl:gallery_id=
Date: 28.05.2018

Poc : SAP Internet Transaction Server 6200.x Session Fixation / Cross Site
Scripting
Dork: /scripts/wgate/
Date: 28.05.2018

Poc : Lig Serüveni Admin Account ByPass Exploit


Dork: inurl:ligseruveni
Date: 27.05.2018

Poc : FourSeasonsTravel SQL Injection Vulnerability


Dork: intext:© 2018 Four Seasons Travel - All rights reserved
Date: 27.05.2018

Poc : Argentina ElAguanteTorneos Torneo_Esp_Eq SQL Injection Vulnerability


Dork: inurl:/torneo_esp_eq.php?id_sc=
Date: 27.05.2018

Poc : JcomItalia WebSolutions SQL Injection Vulnerability


Dork: inurl:/eng/itinerari_turistici_descr.php?id=
Date: 27.05.2018
Poc : Bulgaria Net4you WebSense WebHosting SQL Injection Vulnerability
Dork: intext:Създадено от: net4you.bg
Date: 27.05.2018

Poc : Powered by The Banyan Infotech SQL Injection


Dork: Powered by The Banyan Infotech
Date: 27.05.2018

Poc : Seagull Project 1.0.5 Database Backup Download Vulnerability


Dork: intext:/rvsindex.php?/user/login
Date: 27.05.2018

Poc : Custom Web Development & WebSite Design by Dizyn SQL Injection
Dork: inurl:past.php?id=
Date: 27.05.2018

Poc : The Colour Moon Admin Control Panel Bypass Vulnerability


Dork: intext:Website designed by The Colour Moon
Date: 26.05.2018

Poc : Copyright © 2011 - 2018 Vitalex Computers Tvorba školních webů SQL Injection
Dork: intext: Vitalex Computers - Tvorba školních webů site:cz
Date: 26.05.2018

Poc : Greece BitsnBytes Powered by Byte © Finvent Solutions SQL Injection


Dork: inurl:/details.php?id= site:gr
Date: 26.05.2018

Poc : Hosted and Developed by GAK Technologies SQL Injection


Dork: intext:Hosted and Developed by GAK Technologies
Date: 26.05.2018

Poc : Design by Via Oceânica SQL Injection


Dork: inurl:past.php?id=
Date: 26.05.2018

Poc : Expediensolutions Upload Shell and Sql injection Vulnerability


Dork: intext:Design & Developed by Expedien esolutions Ltd
Date: 26.05.2018

Poc : stockboxphoto SQLi


Dork: Powered by Lightbox™ Gallery Software index.php?category=
Date: 25.05.2018

Poc : tourismus-marketing-bayerischer-wald SQLi


Dork: intext:Tourismus Marketing Bayerischer Wald inurl:index.php?PageName=
Date: 25.05.2018

Poc : Apollo Info Systems Admin Panel Bypass


Dork: intext:Powered By : Apollo Info Systems
Date: 25.05.2018

Poc : START Admin Panel Bypass


Dork: intitle:START Student Alcohol Responsiblity Training
Date: 25.05.2018

Poc : Gayloard Admin Panel Bypass


Dork: intext:Gayloard Admin
Date: 25.05.2018

Poc : Felicia Buthelezi Admin Panel Bypass


Dork: intext:www.feliciabuthelezi.co.za. All rights Reserved
Date: 25.05.2018

Poc : Capitol Banquet Centre Admin Panel Bypass


Dork: intext:Capitol Banquet Centre
Date: 25.05.2018

Poc : Brightspark Admin Panel Bypass


Dork: intext:Login to Brightspark
Date: 25.05.2018

Poc : WordPress Peugeot Music 1.0 Shell Upload / Cross Site Request Forgery
Dork: inurl:/wp-content/plugins/peugeot-music-plugin/
Date: 25.05.2018

Poc : Chile Desarrollodo por FactoryWeb Aguasan Editor Filemanager Vulnerability


Dork: inurl:/aguasan-web/FCKeditor/UserFiles/
Date: 24.05.2018

Poc : PPTQ Indonesian School Sql injection Vulnerability


Dork: intext:Copyright 2018 PPTQ By
Date: 24.05.2018

Poc : PPTQ Indonesian School Authentication Bypass Vulnerability


Dork: intext:Copyright 2018 PPTQ By
Date: 24.05.2018

Poc : Education Time Indonesian School Sql injection Vulnerability


Dork: intext:media.php?module=detailberita&id=
Date: 24.05.2018

Poc : Education Time Indonesian School Directory Traversal Vulnerability


Dork: intext:media.php?module=detailberita&id=
Date: 24.05.2018

Poc : Education Time Indonesian School Xss Vulnerability


Dork: intext:media.php?module=detailberita&id=
Date: 24.05.2018

Poc : LikeSoftware CMS - Arbitrary File Upload


Dork: inurl:/painel/kcfinder/upload/ (For easy you can using Google Search Image)
Date: 24.05.2018

Poc : Joomla Content Editor JCE ImageManager Vulnerability Mass Auto Exploiter
Dork: inurl:/index.php?option=com_jce
Date: 24.05.2018

Poc : WordPress Plugin Peugeot Music Arbitrary File Upload


Dork: inurl:/wp-content/plugins/peugeot-music-plugin/
Date: 24.05.2018

Poc : Portugal Municipality © Portal das Freguesias Editor Filemanager


Vulnerability
Dork: intext:© Portal das Freguesias, Todos os direitos reservados
Date: 23.05.2018
Poc : WP-Plugins Peugeot Music Plugin Arbitrary File Upload
Dork: inurl:/wp-content/plugins/peugeot-music-plugin/
Date: 23.05.2018

Poc : E-Cups All Subdomain Remote Private Method


Dork: inurl:e-cups.org
Date: 23.05.2018

Poc : Copyright © 2018 WebCentrePlus CMS by Webcastle Insecure Control Panel


Vulnerability
Dork: intext:Copyright © 2018 WebCentrePlus - intext:CMS by Webcastle
Date: 23.05.2018

Poc : CCT95 Design - SQL Injection


Dork: intext:Design by cct95 design SEO by 365SEO
Date: 23.05.2018

Poc : WordPress Muller Design Studio DiyThemes Rich-Widget Editor Arbitrary File
Upload
Dork: Designed and Hosted by Muller Design Studio.
Date: 23.05.2018

Poc : Siemens SIMATIC S7-1500 CPU - Remote Denial of Service


Dork: inurl:/Portal/Portal.mwsl
Date: 23.05.2018

Poc : Indonesia Official CarDealer MediaTech TinyMcPuk Filemanager Arbitrary File


Upload
Dork: All rights reserved. © 2015 Media Tech Indonesia
Date: 22.05.2018

Poc : Tik-Tak Israel webPro Codeclient CKFinder Arbitrary File Upload Vulnerability
Dork: inurl:/webPro/index.asp?codeclient=
Date: 22.05.2018

Poc : Miniblog Bypass Admin No Redirect


Dork: intext:Powered by miniblog
Date: 22.05.2018

Poc : Charter Sports Admin Account Bypass Vuln.


Dork: intext:© Copyright 2010. chartersports.com. All Rights Reserved.
Date: 22.05.2018

Poc : Powered by Tech Integra Solutions auth by pass Vulnerability


Dork: inurl:/php.?id= Powered by Tech Integra Solutions
Date: 22.05.2018

Poc : Powered by Tech Integra Solutions XSS Vulnerability


Dork: inurl:/php.?id= Powered by Tech Integra Solutions
Date: 22.05.2018

Poc : KG-Group Admin Account bypass


Dork: intext:2017 © KG-Group Store Management | Powered By Open-i.
Date: 22.05.2018

Poc : NSP Multiserve - SQL Injection


Dork: intext: By NSP Multiserve
Date: 22.05.2018
Poc : Siemens SIMATIC S7-1200 CPU Cross-Site Scripting
Dork: inurl:/Portal/Portal.mwsl
Date: 22.05.2018

Poc : Powered By:Iran Tech XSS Vulnerability


Dork: inurl:/php.?id= Powered by Iran Tech
Date: 20.05.2018

Poc : Powered by Tech Integra Solutions SQL Injection


Dork: inurl:/php.?id= Powered by Tech Integra Solutions
Date: 20.05.2018

Poc : Website By Neudimenxion SQLi


Dork: intext:Website by Neudimenxion ext:php
Date: 20.05.2018

Poc : İsrail Sql İnjection dork


Dork: inurl:’’page.php?type=activity id=1’’
Date: 19.05.2018

Poc : eVorticity - SQL Injection


Dork: intext:Design by eVorticity
Date: 19.05.2018

Poc : BlackburnGraphics - SQL Injection


Dork: intext:Powered by - BlackburnGraphics.com
Date: 19.05.2018

Poc : BiopPharma - SQL Injection


Dork: inurl:past-events.php?id=
Date: 19.05.2018

Poc : Baanwebsite Sql İnjection Vulnerability


Dork: inurl:/php.?id= Powered by บ้านเว็บไซต์
Date: 19.05.2018

Poc : "Aplikasi Sistem Informasi Kelulusan" JSOverlay


Dork: intext:Aplikasi Sistem Informasi Kelulusan site:sch.id
Date: 19.05.2018

Poc : Doplphinsoft Panel ByPass Injection Vuln.


Dork: intext:Powered By Doplphinsoft
Date: 13.05.2018

Poc : XATABoost CMS Sql Injection


Dork: inurl:php?id= Powered by XATABOOST
Date: 13.05.2018

Poc : Developed By SM SOFT TECH CMS - Cross Site Scripting


Dork: inurl:table.php?type=Routine site:edu.bd
Date: 12.05.2018

Poc : Element Ajans Admin ByPass Injection


Dork: intext:Copyright © Element Ajans
Date: 12.05.2018

Poc : Israel Media Vendor Pupload - Arbitary File Upload


Dork: inurl:/plupload/ -inurl:(php) intitle:index of site:co.il
Date: 11.05.2018
Poc : ArticleSetup Script Your Version: 1.00 Login by pass
Dork: intext:© 2011 - Article Setup
Date: 10.05.2018

Poc : Soleixa Communication Sql İnjection Vulnerability


Dork: intext:Webdesign : Soleixa Communication. inurl:catid=
Date: 09.05.2018

Poc : Wordpress wp-js-external-link-info redirect


Dork: inurl:/wp-content/plugins/wp-js-external-link-info/redirect.php?url=
Date: 09.05.2018

Poc : DataWeb CMS - SQL Injection


Dork: inur:/berita.php?dtl=
Date: 07.05.2018

Poc : Editpub RUF Vulnerability


Dork: intext:Powered By Editpub
Date: 06.05.2018

Poc : CMS designed by MODERNETH Xss Vulnerability


Dork: designed by MODERNETH
Date: 06.05.2018

Poc : Efeito Design Auth by pass Vulnerability


Dork: intext: desenvolvido por Efeito Design
Date: 06.05.2018

Poc : ArabInfotech L.L.C Xss Vulnerability


Dork: intext:Powered By Editpub
Date: 06.05.2018

Poc : LifeRay (Fckeditor) Arbitrary File Upload Vulnerability


Dork: inurl:/web/guest/
Date: 06.05.2018

Poc : CSP MySQL User Manager 2.3.1 SQL Injection


Dork: intitle:CSP MySQL User Manager
Date: 05.05.2018

Poc : WebAgentSolutions SQL Injection


Dork: Copyright © 2013 WebAgentSolutions.com
Date: 04.05.2018

Poc : CMS WebSite Design by Dizyn Xss Vulnerability


Dork: Custom Web Development & WebSite Design by Dizyn
Date: 04.05.2018

Poc : zipperSNAP 7.0.28 Directory traversal Vulnerability


Dork: intext:site design by zipperSNAP 7.0.29
Date: 02.05.2018

Poc : Sun GlassFish Enterprise Server v2.1 CSRF RFU Vulnerability


Dork: intext:Directory Listing Sun GlassFish Enterprise Server v2.1
Date: 02.05.2018

Poc : zipperSNAP 7.0.28 Xss reflected Vulnerability


Dork: intext:site design by zipperSNAP 7.0.29
Date: 02.05.2018

Poc : Liferay Portal Standard Edition 5.2.3 RFU Vulnerability


Dork: Welcome to Liferay Portal Standard Edition 5.2.3
Date: 01.05.2018

Poc : marasem admin/login.asp XSS Vulnerability


Dork: Powered By : GalaxyCMS@Emroziha
Date: 30.04.2018

Poc : Usina da Criação CSRF Add Admin Vulnerability


Dork: intext:Desenvolvido por Usina da Criação
Date: 30.04.2018

Poc : Kribensis web admin bypass & Upload file


Dork: intext:Powered by Kribensis web or intext:Powered by Kribensis web &
inurl:member-login.php
Date: 30.04.2018

Poc : Grecee İnfocus Sql İnjection Vulnerability


Dork: intext:Design by infocus. inurl:searchStr site:gr OR => intext:Design by
infocus. inurl:catId site:gr
Date: 29.04.2018

Poc : CMNiceSolution Remote file upload Vulnerability


Dork: Powered by CMNiceSolution
Date: 29.04.2018

Poc : CMNiceSolution FileManager Vulnerabilities


Dork: Powered by CMNiceSolution
Date: 28.04.2018

Poc : hamayeshnegar CMS - downloadpaper.php SQL Injection


Dork: intext:( ‫[ ) پورتال آنالین مدیریت و داوری مجله‬+]
Date: 28.04.2018

Poc : cmnice solutions admin bypass with noredirect


Dork: intext:by cmnice solutions
Date: 27.04.2018

Poc : toutlemonde Municipality Portal RFU Vulnerabilities


Dork: site:.fr editor/fckeditor/editor/
Date: 27.04.2018

Poc : WordPress WP With Spritz 1.0 File Inclusion


Dork: intitle:(Spritz Login Success) AND
inurl:(wp-with-spritz/wp.spritz.login.success.html)
Date: 27.04.2018

Poc : portal.fccoop Municipality Portal RFU Vulnerabilities


Dork: site:.org editor/fckeditor/editor/
Date: 26.04.2018

Poc : evasa Municipality Portal RFU Vulnerabilities


Dork: site:.net editor/fckeditor/editor/
Date: 26.04.2018

Poc : qazvinshora Municipality Portal RFU Vulnerabilities


Dork: site:.ir /html/js/editor/fckeditor/editor/
Date: 26.04.2018

Poc : Quixplorer 2.4.1 Beta Cross Site Scripting


Dork: intitle:My Download Server
Date: 25.04.2018

Poc : Qazvin Municipality Portal RFU Vulnerabilities


Dork: /html/js/editor/fckeditor/editor/
Date: 24.04.2018

Poc : sitefinity CMS file upload vulnerability


Dork: inurl:/Sitefinity/login.aspx
Date: 24.04.2018

Poc : Powered By Codoforum Upload Shell


Dork: intext:powered by codoforum inurl:/user/register
Date: 22.04.2018

Poc : Supercon - No Redirect Login Admin


Dork: intext:Developed By:Supercon Infoservices Pvt.Ltd.
Date: 19.04.2018

Poc : Rvsitebuilder CMS Database Backup Download


Dork: inurl:rvsindex.php & /rvsindex.php?/user/login
Date: 19.04.2018

Poc : Nazyh.net MySQL credentials in html source code Vulnerability


Dork: Conception : nazyh.net
Date: 18.04.2018

Poc : Satara Shiksha Authentication by pass Vulnerability


Dork: Design & Developed By Satara Shiksha
Date: 18.04.2018

Poc : Golem [CMS] v1.0 - SQL Injection


Dork: inurl:cms-admin
Date: 17.04.2018

Poc : DotNetNuke CATALooKStore Cross Site Scripting (XSS)


Dork: inurl:/desktopmodules/CATALooKStore/
Date: 16.04.2018

Poc : IBOOKING CMS - SQL INJECTION


Dork: intext:Desenvolvido por ibooking
Date: 16.04.2018

Poc : Xataface - Admin Authentication Bypass


Dork: intext:powered by dataface powered by xataface
Date: 16.04.2018

Poc : Nielsen Wordpress Theme Xss Stored Exploit


Dork: inurl:/wp-content/themes/nielsen
Date: 14.04.2018

Poc : 2X Ajans SQL injection


Dork: intext:Design by 2X Ajans inurl:id=
Date: 14.04.2018

Poc : iran Info SQL Injection Vulnerability


Dork: site:.ir inurl : php?id=12
Date: 14.04.2018

Poc : Asia Pacific Institute of Information Technology (APIIT) Ref. XSS


Dork: webspace login
Date: 13.04.2018

Poc : IMP XForm 2.0 DatalifeEngine SQL Injection


Dork: inurl:xform/1.html OR inurl:xform/2.html and etc...
Date: 13.04.2018

Poc : Iranian Social Network Multiple Exploit


Dork: inurl:/register.php intitle:‫شبکه اجتماعی‬
Date: 12.04.2018

Poc : WordPress Viral Optins Plugin Exploit and File Upload


Dork: inurl:/wp-content/plugins/viral-optins/
Date: 10.04.2018

Poc : ICS Site Building / SQL Injection Vulnerability in Search Bar


Dork: -
Date: 10.04.2018

Poc : Design & Hosting by Mando Hosting / SQL Injection


Dork: -
Date: 10.04.2018

Poc : Yahei PHP Prober 0.4.7 Cross Site Scripting


Dork: intitle:Proberv0. | inurl:/proberv.php
Date: 10.04.2018

Poc : Joomla com_foxcontact Shell Upload Vulnerability Exploit


Dork: inurl:index.php?option=com_foxcontact
Date: 09.04.2018

Poc : Admin Page Faspi Enterprises Pvt. Ltd. NOREDIRECT Admin Bypass
Dork: Powered By Faspi Enterprises Pvt. Ltd.
Date: 09.04.2018

Poc : Web services and hosting by ArkansasWeb.com Cross Site Scripting


Dork: -
Date: 09.04.2018

Poc : CMS TECNET SQL Injection Vulnerability


Dork: intext:site:ir intext:Desing By TECNET
Date: 09.04.2018

Poc : iByte Solutions Admin Bypass (NoRedirect)


Dork: intext:Powered by iByte Solutions
Date: 07.04.2018

Poc : Template by OS Templates SQL Injection vulnerability


Dork: -
Date: 07.04.2018

Poc : dgnet cms SQL Injection


Dork: intext:dgNet webDesign & inurl:/.php?id=
Date: 04.04.2018
Poc : Microsoft-sharepoint FilterValue Cross Site Scripting (XSS)
Dork: inurl:/_layouts/mobile/view.aspx?List=
Date: 04.04.2018

Poc : Norasoft - SQL Injection


Dork: inurl:/links/browse.php?id=
Date: 03.04.2018

Poc : Enser Communications - SQL Injection


Dork: intext:Developed By : Enser Communications
Date: 03.04.2018

Poc : Hangzhou Lebang Technology - SQL Injection


Dork: intext:Designed by Lebang.com
Date: 03.04.2018

Poc : B.N.COMTECH - SQL Injection


Dork: intext:Design by BNcomtech.com
Date: 03.04.2018

Poc : JZInternet - SQL Injection


Dork: intext:Website by: JZInternet.com
Date: 03.04.2018

Poc : code/backend/config Multiple Targets


Dork: inurl:code/backend/config
Date: 02.04.2018

Poc : KJK CMS - Arbitrary File Upload


Dork: intext:webSEO.cz
Date: 02.04.2018

Poc : Web-SEO Optimalizace - Arbitrary File Upload


Dork: intext:webSEO.cz
Date: 02.04.2018

Poc : US Academy Admin Login Bypass


Dork: intext: Designed & Developed by Maxwell Technologies
Date: 01.04.2018

Poc : Bostion Design - SQL Injection


Dork: intext:Бастион дизайн
Date: 01.04.2018

Poc : Agência Gleba - Jquery File Upload


Dork: intext:Powered by Gleba - Agência Digital
Date: 01.04.2018

Poc : POWERED BY Versatile Software Services Bypass Admin


Dork: Powered By :- Versatile Software Services
Date: 31.03.2018

Poc : Rss Infotech cms Sql Injection vulnerability


Dork: intext:Designed by Rss Infotech Pvt.Ltd. inurl:id=
Date: 31.03.2018

Poc : Powered by NEXBUR - SQL Injection


Dork: intext:Powered by NEXBUR
Date: 31.03.2018
Poc : G&G srl - Web Agency Sql İnjection Vulnerability
Dork: intext:Powered by G&G srl - Web Agency & Communication inurl:php?id
Date: 30.03.2018

Poc : Website israel admin bypass


Dork: co.il admin login.php
Date: 30.03.2018

Poc : Developed By Webbizasia Sql Injection Vulnerability


Dork: -
Date: 30.03.2018

Poc : Alogis Ag Default Admin Password And Sql İnjection Vulnerability


Dork: intext:powered by alogis ag OR intext:powered by ztonline inurl:?rub=
Date: 29.03.2018

Poc : Electronic Village Sql injection


Dork: Copyrights @ ElectronicVillage.org | All rights reserved
Date: 28.03.2018

Poc : XenForo 2 CSS Loader Denial of Service


Dork: intext:Forum software by XenForo™ inurl:css.php ext:php
Date: 28.03.2018

Poc : Turkish Meb.Gov.tr Subdomains Upload File Vulnerability


Dork: site:meb.gov.tr intext:/ucretliogretmenlik/
Date: 26.03.2018

Poc : Colombia Admin Login Bypass & SQLi


Dork: intext:DISEÑO WEB : www.creasotol.com
Date: 26.03.2018

Poc : CMS Website Designed & Developed by NOBRAND SQL Injection


Dork: intext: produc php?id=
Date: 25.03.2018

Poc : Telecommunication Infrastructure Company Portal SQL INJECT Vulnerabilities


Dork: site:stats.tic.ir inurl:index.php?id=1 # site:stats.tic.ir inurl:?id=1
Date: 25.03.2018

Poc : Kriscent Admin Login Bypass


Dork: intext:intext: Powered By KRISCENT TECHNO HUB
Date: 24.03.2018

Poc : Global Education Admin Login Bypass


Dork: intext:intext: Design by Assam Technologies
Date: 24.03.2018

Poc : NYNM IPA Admin Login Bypass and upload shell


Dork: intext:inurl:/Admin/aLogin.aspx intext: NYNM IPA
Date: 24.03.2018

Poc : SNVM CMS Admin Login Bypass


Dork: Dork:inurl:/alogin.aspx intext: Powered By :- Versatile Software Services
Date: 23.03.2018

Poc : VSSPL CMS Admin Login Bypass


Dork: “ inurl:/alogin.aspx intext: Powered By :- Versatile Software Services ”
Date: 23.03.2018

Poc : Intelbras Telefone Local File Disclosure


Dork: Intelbras Telefone IP TIP200 LITE
Date: 22.03.2018

Poc : Powered by phpmyfaq 2.7.9 PHP Code Injection


Dork: intext:powered by phpMyFAQ 2.7.9 inurl:/admin/index.php
Date: 22.03.2018

Poc : Sea-lion Multi Vulnerability


Dork: intext:Designed by Sea-lion
Date: 22.03.2018

Poc : PHPBoost 4.0 Add Admin Vulnerability


Dork: Boosté par PHPBoost 4.0
Date: 22.03.2018

Poc : plogger1.0RC1 Xss Vulnerability


Dork: Powered by Plogger
Date: 21.03.2018

Poc : PixCMS v1 Auth by pass Vulnerability


Dork: Developed By Pixelart Interactive
Date: 21.03.2018

Poc : PHPValley Micro Jobs 2.0 Multi Vulnerability


Dork: Copyright (C) 2012 Ozgur Zeren (unity100@gmail.com)
Date: 21.03.2018

Poc : Social Directory Script 2.0 File Upload vulnerability


Dork: intext:Copyright poSocial Directory
Date: 20.03.2018

Poc : Popup Famo (ir) Multi Vulnerability


Dork: ‫ تمامی حقوق برای‬popup.yekbux.com ‫ طراحی شده توسط مهدی عابدی‬.‫محفوظ است‬
Date: 20.03.2018

Poc : Popup Famo (ir) Multi Vulnerability


Dork: ‫ تمامی حقوق برای‬popup.yekbux.com ‫ طراحی شده توسط مهدی عابدی‬.‫محفوظ است‬
Date: 19.03.2018

Poc : CMS Powered By LT SQL Injection


Dork: inurl index.php id= Qatar
Date: 19.03.2018

Poc : RealWebIdea CMS SQL Injection Vulnerability


Dork: intext: inurl:.php?id= Powered by: SEO Training Courses Lahore RealWebIdea
Date: 18.03.2018

Poc : Cross Site Scripting ( XSS ) Vulnerability in Cognolabs CMS


Dork: -
Date: 18.03.2018

Poc : Mantis 1.3.0 Bug Trackers Arbitrary File Download Vulnerability


Dork: Powered by MantisBT 1.3.0-rc1-dev master-5ee4075
Date: 15.03.2018

Poc : Conference Management Software) Ver. 3.5.1 Sql injection


Dork: Designer Asan Hamayesh (Conference Management Software) Ver. 3.5.1
Date: 15.03.2018

Poc : Maian Gallery v2.0 Mulllti Vulnerability


Dork: Maian Gallery v2.0. Copyright © 2006-2015 Maian Script World. All Rights
Reserved
Date: 15.03.2018

Poc : Kolifa.net Download Script 1.2 Vulnerability


Dork: Kolifa.net Download Script 1.2 | Copyright of Kolifa
Date: 15.03.2018

Poc : Job Portal Script version 3.0 Unrestricted file upload Vulnerability
Dork: intext:categorysearch.php?indus=
Date: 15.03.2018

Poc : Lenny CMS - SQL Injection Vulnerability


Dork: “ Webdesign by Lenny inurl:news.php?id= ”
Date: 15.03.2018

Poc : Design by Concept4 Sql İnjection Vulnerability


Dork: Website Design by Concept4 0R School website by Concept4
Date: 15.03.2018

Poc : ‫ رسانه پرداز پارس‬- SQL INJECTION


Dork: intext:‫ رسانه پرداز پارس‬:‫ طراحی و میزبانی‬inurl:id=
Date: 14.03.2018

Poc : Design NSI SQL Injection


Dork: intext: Notícias php?id=
Date: 14.03.2018

Poc : Developed By Hamid Reza Norah - Sql Injection


Dork: intext:DevelopedByHamidRezaNorah inurl:id=
Date: 14.03.2018

Poc : CMS Design & Developed by Tek Heights SQL Injection


Dork: intext: produc php?id=
Date: 13.03.2018

Poc : CMS Developed by Cloud Innovators Solution SQL Injection


Dork: intext: store php?id=
Date: 13.03.2018

Poc : By Alpha Sql İnjection Vulnerability


Dork: intext:created by alpha inurl:php?cat
Date: 13.03.2018

Poc : Tesla Arabic SQL Injection


Dork: intext: ‫ كهربائي‬php?id=
Date: 12.03.2018

Poc : ATnet Communications Sql İnjection Vulnerability


Dork: intext:Κατασκευή ιστοσελίδων: ATnet Communications Α.Ε. inurl:ArticleId=
Date: 12.03.2018

Poc : DL Tech CMS SQLi Vulnerability


Dork: intext:Designed & Developed By: DL TECH
Date: 11.03.2018
Poc : SoftHof CMS SQLi Vulnerability
Dork: intext:Designed By SoftHof (PVT) Ltd.
Date: 11.03.2018

Poc : ATnet Communications Sql İnjection Vulnerability


Dork: Κατασκευή ιστοσελίδων | qualityweb inurl:cat_id=
Date: 11.03.2018

Poc : qualityweb Sql İnjection Vulnerability


Dork: Κατασκευή ιστοσελίδων | qualityweb inurl:cat_id=
Date: 11.03.2018

Poc : Wordpress Theme Distributel SQLi


Dork: inurl:wp-content/themes/distributel/
Date: 10.03.2018

Poc : Photo Sharing Script Xss Vulnerability


Dork: Copyright © 2011 Photo Sharing Script Nulled By P30vel.ir Powered by Free PHP
Script
Date: 09.03.2018

Poc : Millenium cms Sql Injection vulnerability


Dork: intext:Designed by Reza Farzam
Date: 09.03.2018

Poc : BD Schools Multi SQL Injection Vulanable


Dork: inurl:teachers_details.php?teacher_ID site:edu.bd
Date: 08.03.2018

Poc : Empowerment Technology SQL Injection


Dork: intext:Designing & Developed By Empowerment Technology
Date: 08.03.2018

Poc : SLEKI CMS BUGS SQL INJECTION POST DATA


Dork: intext:SLEKI CMS
Date: 07.03.2018

Poc : Designe-Master Private Script suffer from SQL Injection


Dork: intext:Designed by : Design-Master php?id=
Date: 07.03.2018

Poc : kleeja 1.5.4 ( XSS / HTML Inject ) Vulnerability


Dork: Powered by Kleeja
Date: 06.03.2018

Poc : Joomla! Component Joomanager 2.0.0 com_Joomanager Arbitrary File Download


Dork: allinurl:index.php?option=com_joomanager
Date: 06.03.2018

Poc : Joomla com_fireboard SQL Injection Vulnerability


Dork: intext:categorysearch.php?indus=
Date: 05.03.2018

Poc : InterPhoto 2.3.0 Persians Database directory listing Vulnerability


Dork: InterPhoto 2.3.0
Date: 04.03.2018

Poc : impresscms-1.3.9 Open Redirect vulnerability


Dork: Powered by ImpressCMS
Date: 03.03.2018

Poc : iSmile multi Vulnerability


Dork: JamalCom ‫هذا السكربت مبرمج بواسطة‬
Date: 03.03.2018

Poc : iBilling v4.5.0 – CRM Add Admin vulnerability


Dork: intext:Login - iBilling
Date: 02.03.2018

Poc : FastMatch v2.0 İddaa Tahmin Scripti auth by pass vulnerability


Dork: intext:FastMatch | İddaa Tahminleri Beta
Date: 02.03.2018

Poc : Hloun Version 1.0.0 Rinstall Script Vulnerability


Dork: Powered by Hloun © Version 1.0.0
Date: 02.03.2018

Poc : Hesk Rtl By Vahid Majidi(ir) MUlti Vulnerability


Dork: ‫ اسکریپت دات کام‬/ ‫فارسی سازی توسط وحید مجیدی‬
Date: 01.03.2018

Poc : ASFAA organization SQL Injection


Dork: inurl:php?id= intitle:asfaa
Date: 01.03.2018

Poc : Asanhamayesh CMS 3.4.6 Directory traversal Vulnerability


Dork: 3.4.6 ‫ آسان همایش (نرم افزار مدیریت همایش و کنفرانس) ویرایش‬: ‫طراح و پشتیبان‬
Date: 01.03.2018

Poc : Coupons CMS 6 URL redirection Vulnerability


Dork: Powered by CouponsCMS.com
Date: 01.03.2018

Poc : QuickTalk 1.x and 2.x Reinstall Script Vulnerability


Dork: powered by QT-cute
Date: 01.03.2018

Poc : Journal Management Software Ver. 1.2.4 Sql injection


Dork: Designer Asan Journal (Journal Management Software) Ver. 1.2.4
Date: 28.02.2018

Poc : C.COM 0.1.02 Events CMS upload Vulnerability


Dork: intext:details_news.php?id_news=
Date: 28.02.2018

Poc : East Multimedia CMS - SQL Injection Vulnerability


Dork: intext:Design by East Multimedia inurl:.php?id=
Date: 28.02.2018

Poc : freshregister.php remote file deleting


Dork: inurl:freshregister.php
Date: 28.02.2018

Poc : Nik Poyesh CMS Bypass Vulnerability


Dork: intext:‫نیک پویش پرداز‬: ‫طراحی سایت‬
Date: 27.02.2018
Poc : 05Informatica S.n.c CMS Bypass Vulnerability
Dork: intext:Powered by 05Informatica S.n.c.
Date: 27.02.2018

Poc : Premium URL Shortener v4.2.3 Add Admin Vulnerability


Dork: 2012-2015 © KBRmedia - All Rights Reserved
Date: 26.02.2018

Poc : pppBLOG v 0.3.11 Mullti Vulnerability


Dork: powered by pppBLOG v 0.3.11
Date: 26.02.2018

Poc : Quicktick v2 Upload Vulnerability


Dork: Quicktick Login
Date: 26.02.2018

Poc : QuickTalk 1.x and 2.x Reinstall Script / Password Hash Disclosure
Vulnerability
Dork: powered by QT-cute
Date: 26.02.2018

Poc : Global IT Support Pvt. Ltd CMS SQL injection vulnerability


Dork: inurl :/view-gallery.php?id=[SQLi]
Date: 25.02.2018

Poc : Amazepixels CMS SQL Injection Vulnerability


Dork: Inurl: /gallery.php?id=
Date: 25.02.2018

Poc : MagicNines Infotech Pvt. Ltd - SQL Injection Vulnerability


Dork: intext:Powered by MagicNines Infotech Pvt. Ltd inurl:.php?id=
Date: 25.02.2018

Poc : Weblife Infotech CMS - SQL Injection Vulnerability


Dork: intext:Developed & Designed by Weblife Infotech inurl:.php?id=
Date: 24.02.2018

Poc : Phoenix Softwarez - SQL Injection Vulnerability


Dork: intext:Designed & Maintained By: Phoenix Softwarez inurl:.php?id=
Date: 24.02.2018

Poc : Pharax cms Sql Injection vulnerability


Dork: intext:Designed By Pharax
Date: 24.02.2018

Poc : hudaallah Linker Xss Vulnerability


Dork: ‫تصميم وبرمجة موقع هدى الله‬
Date: 24.02.2018

Poc : i-Gallery version 4.1 Arbitrary File Download vulnerability


Dork: intext:Powered By: i-Gallery 4.1
Date: 24.02.2018

Poc : powered by Spherica ADV s.r.l.SQL Injection


Dork: website.php?id=
Date: 23.02.2018

Poc : haraj V1.1 free Add ADmin Vulnerability


Dork: V1.1 free ‫ سكربت حراج‬: ‫برمجة وتصميم‬
Date: 23.02.2018

Poc : GetSimpleCMS_3.3.2 multi Vulnerability


Dork: © 2009-2014 GetSimple CMS – Version 3.3.2
Date: 23.02.2018

Poc : Groupoffice.com 3.4.21 Directory Traversal Vulnerability


Dork: Powered by Group-Office
Date: 23.02.2018

Poc : Geeklog 2.1.0b1 Multi Vulnerability


Dork: Powered by Geeklog
Date: 23.02.2018

Poc : Global Domains International Directory traversal Vulnerability 0-Day


Dork: Copyright © 2014 by Global Domains International, Inc · All Rights Reserved
Date: 23.02.2018

Poc : GEN4 v4.0 PTCPay Multi Vulnerability


Dork: GeN4 © 2009
Date: 22.02.2018

Poc : Gestion du catalogue en ligne PEEL v2.7 (Fr)SQl Vulnerability


Dork: GeN4 © 2009
Date: 22.02.2018

Poc : GetSimpleCMS 3.3.3 multi Vulnerability


Dork: © 2009-2014 GetSimple CMS – Version 3.3.3
Date: 22.02.2018

Poc : Roxy filemnager ckeditor upload shell


Dork: inurl:ckeditor/fileman
Date: 22.02.2018

Poc : Softman Software System Admin Login Bypass


Dork: inurl /admin login.asp + inurl /admin login.aspx
Date: 21.02.2018

Poc : Mihalism Multi Host - download.php SQL Injection


Dork: intext:Powered by Mihalism Multi Host [+]
Date: 21.02.2018

Poc : Bihar Web Solutions Admin Bypass


Dork: intext:Site Designed By : Bihar Web Solutions Pvt. Ltd.
Date: 18.02.2018

Poc : EPIC MyChart SQL Injection


Dork: MyChartA(r) licensed from Epic Systems Corporation
Date: 17.02.2018

Poc : QuickTicket v2.5 build:20101222 Mulllti Vulnerability


Dork: powered by QT-cute
Date: 16.02.2018

Poc : Smart Blog v 1.3 Multi Vulnerability


Dork: Actionnée par smartblog
Date: 16.02.2018

Poc : theilit upV0.3.4 Upload Vulnerability


Dork: ‫ برمجة‬- 0.3.4 ‫مركز رفع النسخة‬The Ilit - ‫ تطوير‬T.p.O.s
Date: 15.02.2018

Poc : RobotStats v1.0 Mullti Vulnerability


Dork: RobotStats v1.0 : analyse temps réel
Date: 15.02.2018

Poc : script islamnt 2.1.0 multi Vulnerability


Dork: Powered By Islamnt 2.1.0
Date: 15.02.2018

Poc : Thailand Government Sql İnjection Vulnerability


Dork: inurl:select_news.php?news_id=
Date: 12.02.2018

Poc : Curious Group Sql İnjection Vulnerability


Dork: powered by Curious Group inurl:nieuws
Date: 12.02.2018

Poc : NADWebs v3.1 Professional (Login Page) Bypass


Dork: bing.com *nadsoft.co 0R powered by NADWebs
Date: 12.02.2018

Poc : TrS WebDesign Hungarian Admin Login Page Bypass Vulnerability


Dork: intext:Publikálta: TrS WebDesign
Date: 11.02.2018

Poc : Restaurant Script (PizzaInn_Project) Add Admin Vulnerability


Dork: RSv1.0.0
Date: 07.02.2018

Poc : REDAXO 5.2.0 XSS vulnerability


Dork: Powered by Redaxo - Opensource CMS.
Date: 07.02.2018

Poc : Datastone Solutions Admin Login Bypass


Dork: intext:Powered By : Datastone Solutions
Date: 06.02.2018

Poc : WonderCMS Default Credential


Dork: intext:Powered by WonderCMS
Date: 06.02.2018

Poc : Student Profile Management System Script 2.0.6 Authentication Bypass


Dork: intext:Powered by: i-Net Solution
Date: 06.02.2018

Poc : Shop Cms SQL Injection Vulnerability


Dork: inurl:shop.php?id=
Date: 06.02.2018

Poc : Seo Trend Pro2 FullVersion jQuery XSS EXploits


Dork: Powered By SeoTrendPro v1.2
Date: 06.02.2018

Poc : Semantic sm short url script v2.0 Sql injection Vulnerability


Dork: v2.0 © 2012 Semantic, Inc. All rights reserved. Home - Custom - Bookmarklet
- API - Statistics - Buy this Script
Date: 06.02.2018
Poc : SanyBee Gallery V0.2.10 special Add Admin Vulnerability
Dork: SanyBee Gallery Version : 0.2.10 special free.fr
Date: 06.02.2018

Poc : SanyBee Gallery V0.2.9 special Add Admin Vulnerability


Dork: SanyBee Gallery Version : 0.2.9 special free.fr
Date: 06.02.2018

Poc : SanyBee Gallery V0.2.9 and v0.2.10 special Multi Vulnerability


Dork: SanyBee Gallery Version : 0.2.9 special free.fr
Date: 06.02.2018

Poc : Bloly version 1.3 SQl injection vulnerability


Dork: intext:Bloly v1.3 by SoftCab Inc
Date: 05.02.2018

Poc : Subdreamer CMS-v3.7.1 Mullti Vulnerability


Dork: Website powered by Subdreamer CMS & Sequel Theme Designed by indiqo.media
Date: 05.02.2018

Poc : Social Directory Script 2.0 File Upload vulnerability


Dork: intext:Copyright poSocial Directory
Date: 05.02.2018

Poc : Simple Mailing List 1.5 arbitrary file access Vulnerability


Dork: © 2006 NotOneBit.com
Date: 04.02.2018

Poc : Site opener SQL Injection Vulnerability


Dork: intext:Powered by : Site Opener php?id=
Date: 04.02.2018

Poc : Smart Blog v 1.x Multi Vulnerability


Dork: Actionnée par smartblog
Date: 04.02.2018

Poc : Small Message v 0.1 Multi Vulnerability


Dork: ! ‫© سمآل ميسآج‬
Date: 04.02.2018

Poc : Simple Machines Forum SMF 2.0.8 Host header attack Vulnerability
Dork: SMF 2.0.8 | SMF © 2014, Simple Machines
Date: 04.02.2018

Poc : Simple Gallery 2.2 XSS / HTML Inject Vulnerability


Dork: Simple Gallery 2.2 © www.celerondude.com
Date: 04.02.2018

Poc : Evoluted Directory Hidden Uploader


Dork: intext: Directory Listing Script © 2018 Evoluted, Web Design Sheffield
Date: 04.02.2018

Poc : Lada.ge plugins wsupload Arbitrary File Upload


Dork: inurl:admin/plugins/wsupload
Date: 03.02.2018

Poc : Stock Management System 1.1 Multi Vulnerability


Dork: Developed by PlusKB Innovations
Date: 03.02.2018

Poc : Streamo - Online Radio And Tv Streaming CMS XSS vulnerability


Dork: inurl:rjdetails.php?id=
Date: 03.02.2018

Poc : Stsw Galeria Sql injection Vulnerability


Dork: inurl:galeria/album.php?id=
Date: 03.02.2018

Poc : Syria2u You Shop v1.0 Mullti Vulnerability


Dork: ‫ قم باختيار المدينة ثم تمتع بالتسوق في‬, ‫سكربت يوشــوب للتسوق عبر االنترنت‬
‫مدينتك من أي مكان‬
Date: 03.02.2018

Poc : Subrion CMS all version Multiple Vulnerability


Dork: ©2015 Your website | Powered by WonderCMS | Login
Date: 03.02.2018

Poc : Super Simple Blog Script v2.5.3 Sql inj Vulnerability


Dork: super simple blog script super simple RSS script
Date: 03.02.2018

Poc : Syria2u Arbahtube v1.0 Mullti Vulnerability


Dork: Copyright ©2014 script syria2u version1. All Rights Reserved.
Date: 03.02.2018

Poc : Uebimiau 3.2.0-2.0 BACK UP FILE BROWSER Vulnerability


Dork: Uebimiau Webmail v3.2.0
Date: 03.02.2018

Poc : AGVirtues Galeria Sql injection Vulnerability


Dork: inurl:galeria/album.php?id=4
Date: 02.02.2018

Poc : joomla! com_joomlabook components SQL Injection


Dork: inurl:index.php?option=com_joomlabook
Date: 02.02.2018

Poc : Fast Edit v1.0 Multi Vulnerability


Dork: Focus on Function Web Design | Fast Edit © 2010-2018 Beverley Hooton
Date: 02.02.2018

Poc : Web.Com(India) 1.0 Auth By pass Vulnerability


Dork: intext:Powered by Web.Com(India) Pvt. Ltd
Date: 02.02.2018

Poc : Voodoo Chat 2.1.0 xss Vulnerability


Dork: intext:Powered by Voc-Ar
Date: 02.02.2018

Poc : Tiki Wiki CMS 17.1 Host header attack Vulnerability


Dork: intext:Powered by Tiki Wiki CMS Groupware | Theme: Default
Date: 02.02.2018

Poc : Wikindx5.2.1 xss Vulnerability


Dork: intext:wikindx 5.2.1 ©2017 |
Date: 02.02.2018
Poc : Web Edition V 5.1.2.3 Multi Vulnerability
Dork: Copyright © nw7.eu / Fotolia.com
Date: 02.02.2018

Poc : Web Edition V 2.9.4.6 LFI Vulnerability


Dork: Copyright © nw7.eu / Fotolia.com
Date: 02.02.2018

Poc : WeBid 1.0.3 Directory traversal Vulnerability


Dork: Powered by WeBid © 2008 - 2011 WeBid
Date: 02.02.2018

Poc : Migrateshop 1.0 xss Vulnerability


Dork: Powered By Migrateshop
Date: 02.02.2018

Poc : Blue Webeyes Admin Panel Bypass And Sql İnjection Vulnerability
Dork: Powered by Blue Webeyes
Date: 01.02.2018

Poc : Cloud Dreams CMS - SQL Injection + XSS + Week Admin Password Vulnerability
Dork: intext: Web Design Company - Clouddreams inurl:.php?id=
Date: 30.01.2018

Poc : Colour Moon CMS - SQL Injection Vulnerability


Dork: intext: Designed By Colour Moon. inurl:.php?id=
Date: 30.01.2018

Poc : Persian Link cms Stored xss vulnerability


Dork: intext: Powered By Persian Link CMS - Design By MahdiY
Date: 30.01.2018

Poc : Joomla JEXTN FAQ Pro 4.0.0 - SQL Injection


Dork: inurl:com_jefaqpro
Date: 30.01.2018

Poc : Fast Edit v2.0 Multi Vulnerability


Dork: Focus on Function Web Design | Fast Edit © 2010-2018 Beverley Hooton
Date: 30.01.2018

Poc : Rich FileManager v2.7.0 xss via file uploads Vulnerability


Dork: intext:Rich FileManager
Date: 29.01.2018

Poc : Powered by Dailybread.in Admin panel bypass & upload shell


Dork: intext:Powered by Dailybread.in
Date: 29.01.2018

Poc : Automatic Link Box CMS cross site scripting (stored) vulnerability
Dork: intext: System Powered By : Mehrdad Design
Date: 29.01.2018

Poc : Mono Blog multiple vulnerability


Dork: intext:POWERED BY monoblog.ir
Date: 29.01.2018

Poc : PACSOne Server 6.6.2 DICOM Web Viewer Directory Traversal


Dork: inurl:pacs/login.php inurl:pacsone/login.php inurl:pacsone filetype:php home
inurl:pacsone filetype:php login
Date: 29.01.2018

Poc : PACSOne Server 6.6.2 DICOM Web Viewer SQL Injection


Dork: inurl:pacs/login.php inurl:pacsone/login.php inurl:pacsone filetype:php home
inurl:pacsone filetype:php login
Date: 29.01.2018

Poc : alhotphp - article 1.0 add/admin Vulnerability


Dork: ‫ جميع الحقوق محفوظة لمنتديات الحوت للبرمجة || المبرمج والمصمم‬: Hasan Hatem
2014 © 1.0 ‫النسخة‬
Date: 27.01.2018

Poc : Uebimiau 3.2.0-2.0 BACK UP FILE BROWSER Vulnerability


Dork: Uebimiau Webmail v3.2.0
Date: 27.01.2018

Poc : VirtueMart2.6.12.2 Joomla 2.5.27 Stable Full Package Sql Vulnerability


Dork: Powered by Joomla!® and VirtueMart
Date: 27.01.2018

Poc : Victor Muller v 2.0.14 & 2.0.15 sql injection vulnerability


Dork: intext:Victor Muller © 2015 shows.php?id=
Date: 27.01.2018

Poc : ViArt Shop 4.2.1 Mullti Vulnerability


Dork: PHP Ecommerce Solutions by ViArt
Date: 27.01.2018

Poc : UserCake v1.3 Multi Vulnerability


Dork: PHP Ecommerce Solutions by ViArt
Date: 27.01.2018

Poc : plupload 2.3.6 Remote File Upload Vulnerability


Dork: Powered by phpEnter.net 4.2.7
Date: 26.01.2018

Poc : endonesia 8.7 en Sql Injection Vulnerability


Dork: intext:Powered by Endonesia 8.7
Date: 26.01.2018

Poc : phpEnter 4.2.7 add Admin Vulnerability


Dork: Powered by phpEnter.net 4.2.7
Date: 26.01.2018

Poc : PVP Server Listesi v2.4 Sql injection Vulnerability


Dork: intext:PVP Server Tanıtım Scripti
Date: 26.01.2018

Poc : Trellis Desk 2.0 Alpha 4 Application error message Vulnerability


Dork: intext:Powered By Trellis Desk 2.0 Alpha
Date: 26.01.2018

Poc : Webtech Solutions cms authentication bypass vulnerability


Dork: intext:Design by : Webtech Solutions
Date: 26.01.2018

Poc : Winnglo cms - admin login bypass


Dork: intext:Powered by Winnglo
Date: 25.01.2018
Poc : vBulletin redirector 3.x.x & 4.2.x Open Redirect Vulnerability
Dork: inurl:/redirector.php?url=
Date: 24.01.2018

Poc : Cms Made Simple unvaliated file upload Vulnerability


Dork: intext:This site is powered by CMS Made Simple version 2.2.5
Date: 23.01.2018

Poc : Tayland government Upload File and Cross Site Scripting Vulnerability
Dork: inurl://index.php?mod=
Date: 23.01.2018

Poc : WP Linenity Theme - Arbitrary File Download


Dork: inurl:wp-content/themes/linenity/ intext:Index of /
Date: 23.01.2018

Poc : inoerp 0.5.1 Backdoor Account Vulnerability


Dork: intext:Copyright @ 2016 inoERP - Powered By inoCMS
Date: 22.01.2018

Poc : Admidio 3.2.12 Arbitrary File Download Vulnerability


Dork: intext:© 2004 - 2017 Admidio Team
Date: 22.01.2018

Poc : Wordpress Tips Wp-Config Setup Vulnerable


Dork: intext:Below you should enter your database connection details. If you’re not
sure about these, contact your host inurl:setup-config.php
Date: 22.01.2018

Poc : video whisper conference XSS Vulnerability


Dork: intext:Video Conference by VideoWhisper.com
Date: 21.01.2018

Poc : Wordpress newspro2891 theme - Arbitrary file download


Dork: inurl:/wp-content/themes/newspro2891
Date: 21.01.2018

Poc : Wordpress File Manager plugin Version 5.0.1 SSRF/XSPA Vulnerability


Dork: inurl:/wp-content/plugins/file-manager
Date: 21.01.2018

Poc : endonesia 8.7 en Sql Injection Vulnerability


Dork: intext:Powered by Endonesia 8.7
Date: 21.01.2018

Poc : Maison CMS Arbitrary File Upload


Dork: intext:intext:assets/admin/plugins/plupload
Date: 19.01.2018

Poc : Incom 2.0 arbitrary file upload


Dork: intext:incom 2.0
Date: 19.01.2018

Poc : Bypass Admin WebositeZ Noredirect Bypass


Dork: intext:Powered By WebositeZ
Date: 19.01.2018

Poc : Arisa cms sql injection vulnerability


Dork: intext:‫گروه نرم افزاری آریسا‬
Date: 17.01.2018

Poc : FEED ON FEEDS 0.5 insecure cookie handling Vulnerability


Dork: Feed on Feeds - Log on
Date: 17.01.2018

Poc : SeoIn cms sql injection vulnerability


Dork: intext:‫ طراحی شده توسط سئو این‬inurl:id=
Date: 16.01.2018

Poc : CMS SAUDI SOFTECH Sql injection Vulnerability


Dork: intext:DESIGNED BY: SAUDI SOFTECH (MST)
Date: 16.01.2018

Poc : Creative Commons Attribution 3.0 Unported Auth by pass Vulnerability


Dork: intext:Design by Third Eye Digital Media.
Date: 16.01.2018

Poc : Doma all version xss Vulnerability


Dork: Digital Orienteering Map Archive, version 1.0 | Log in
Date: 16.01.2018

Poc : Job Portal Script version 3.0 Unrestricted file upload Vulnerability
Dork: intext:categorysearch.php?indus=
Date: 16.01.2018

Poc : Datta cms Authentication bypass vulnerability


Dork: intext:Designed by Datta
Date: 16.01.2018

Poc : Oracle E-Business Suite 12.1.3 / 12.2.x Open Redirect


Dork: inurl:OA_HTML/cabo/
Date: 16.01.2018

Poc : Bonza Digital Cart Script version 1 XSS Vulnerability


Dork: intext:cms_pages.php?pn=Disclaimer
Date: 15.01.2018

Poc : Webeveron Technologies cms sql injection vulnerability


Dork: intext:Powered By: Webeveron Technologies inurl:id=
Date: 13.01.2018

Poc : Design by Third Eye Digital Media Admin Panel Bypass


Dork: intext:Design by Third Eye Digital Media.
Date: 13.01.2018

Poc : Media Uploader - File Uploader


Dork: inurl:/index.php?/mediauploader/uploader/
Date: 10.01.2018

Poc : RYNA Consulting Sql İnjection Vulnerability


Dork: intext:Site designed by RYNA Consulting inurl:?id=
Date: 09.01.2018

Poc : Aonestar CMS BackDoor Vulnerability


Dork: intext:D & D by Aonestar
Date: 09.01.2018
Poc : Netcare System - SQL Injection Vulnerability
Dork: intext:Design by Netcare System inurl:.php?id=
Date: 07.01.2018

Poc : OFFPoster all version database Disclosure Vulnerability


Dork: Index of /assets/backup_db
Date: 07.01.2018

Poc : K-LOANS 1.4.5 Backdoor account Vulnerability


Dork: K-LOANS 1.4.5
Date: 06.01.2018

Poc : Grawlix 1.1.1 xss Vulnerability


Dork: Powered by The Grawlix CMS
Date: 05.01.2018

Poc : Joomla JUX Real Estate 3.3.0 SQL Injection


Dork: inurl:index.php?option=com_jux_real_estate
Date: 05.01.2018

Poc : Joomla J-BusinessDirectory 4.7.3 SQL Injection


Dork: inurl:Google is your Friend
Date: 05.01.2018

Poc : Wowonder CMS - Privilege Escalation


Dork: inurl: ? link1 = welcome
Date: 04.01.2018

Poc : DnP Firewall Gateway v1.4 DoS


Dork: DnP Firewall Gateway v1.4
Date: 04.01.2018

Poc : Forum Fire Soft Board 2.* Multi Vulnerability


Dork: intext:Forum Fire-Soft-Board © 2004 - 2014
Date: 04.01.2018

Poc : 2X Ajans Multiple Vulnerability


Dork: intext:Design by 2X Ajans
Date: 04.01.2018

Poc : WordPress Smart Google Code Inserter SQL Injection


Dork: inurl:wp-content/plugins/smart-google-code-inserter/
Date: 04.01.2018

Poc : MCI Portal SQL INJECT Vulnerabilities


Dork: intext:inurl:mci.ir/Notrino-Comics?story=
Date: 03.01.2018

You might also like