Dork Pentakil Team
Dork Pentakil Team
Poc : Urvanov Syntax Highlighter <= 2.8.33 - Highlighting Blocks Mgt via CSRF
Dork: site:adroom.ir inurl:/wp-admin/admin-ajax.php
Date: 31.10.2023
Poc : Urvanov Syntax Highlighter <= 2.8.33 - Highlighting Blocks Mgt via CSRF
Dork: wp-admin/admin-ajax.php
Date: 27.10.2023
Poc : WordPress Theme Medic v1.0.0 Weak Password Recovery Mechanism for Forgotten
Password
Dork: inurl:/wp-includes/class-wp-query.php
Date: 19.06.2023
Poc : WordPress Theme Workreap 2.2.2 Unauthenticated Upload Leading to Remote Code
Execution
Dork: inurl:/wp-content/themes/workreap/
Date: 10.06.2023
Poc : WordPress Real Estate 7 Theme <= 3.3.4 - Multiple Cross-Site Request
Forgery (CSRF) Vulnerabilities
Dork: inurl:/wp-content/themes/realestate-7/
Date: 05.03.2023
Poc : WordPress Real Estate 7 Theme <= 3.3.4 - Unauthenticated Reflected Cross-
Site Scripting (XSS)
Dork: inurl:/wp-content/themes/realestate-7/
Date: 05.03.2023
Poc : WordPress WoodMart Theme <= 7.1.1 - Theme License Options Change via CSRF
Dork: inurl:/wp-content/themes/woodmart/
Date: 05.03.2023
Poc : Active eCommerce Laravel CMS 5.x to 6.1.2 - Cross Site request forgery (CSRF)
to Cross-site Scripting (XSS) (Authenticated)
Dork: intext:|| WHOPPS!!!THIS IS PIRATED COPY OF ACTIVE ECOMMERCE CMS
Date: 20.07.2022
Poc : Designed By Sevy INC. - SQL Injection Vulnerability, Unrestricted File Upload
Vulnerability and Default Admin Credentials
Dork: intext:Designed By Sevy INC.
Date: 06.07.2022
Poc : Will VPN App - VPN App With Admin Panel - Phpthumb Command Injection
Dork: - / use your brain
Date: 19.05.2022
Poc : USR IOT 4G LTE Industrial Cellular VPN Router 1.0.36 Remote Root Backdoor
Dork: title:usr-* // 4,648 ed ao 15042022
Date: 22.04.2022
Poc : Copyright 2021 Reobiz. All Rights Reserved. - SQL Injection Vulnerability
Dork: intext:© Copyright 2021 Reobiz. All Rights Reserved.
Date: 21.03.2022
Poc : Behkad CMS - Technical And Vocational University Yazd / Iran - Cross-Site
Scripting (XSS)
Dork: -
Date: 06.03.2022
Poc : Eticaret Turkey CMS Kcfinder & Roxy File Manager Exploit
Dork: inurl:/nedmin/production/ (dorking on google images)
Date: 01.03.2022
Poc : Support Board 3.4.5 WP and NonWP Arbitrary File Upload / CSRF File Upload
Dork: use your brain brother
Date: 01.03.2022
Poc : Quiz Maker 6.2 - Sensitive Data Exposure (Authenticated User Credentials)
Dork: inurl:/wp-content/plugins/quiz-maker
Date: 26.01.2022
Poc : ALFA TEAM SHELL TESLA 4.1 - Remote Code Execution (Unauthenticated)
Dork: inurl:/alfacgiapi intext:alfa
Date: 19.12.2021
Poc : FiveM & Gmod Loading Screen Maker Free | SQL Injection Vulnerability
Dork: ip:213.202.247.8 .php?id=
Date: 11.12.2021
Poc : WordPress Plugin DZS Zoomsounds 6.45 Arbitrary File Read (Unauthenticated)
Dork: inurl:/wp-content/plugins/dzs-zoomsounds/
Date: 03.12.2021
Poc : WP Google Maps PRO Add-on Plugin < 8.1.12 - Authenticated Persistent XSS
Dork: inurl:/wp-content/plugins/wp-google-maps-pro/
Date: 20.09.2021
Poc : WordPress Themes Haberadam IDOR and Full Path Disclosure via JSON API
( Unathenticated )
Dork: inurl:/wp-content/themes/haberadam
Date: 13.09.2021
Poc : Pricelist Stock Bangladesh Ltd. Center For Financial Analysis | SQL Injection
Vulnerability
Dork: .php?id= stockbangladesh.mobi
Date: 05.09.2021
Poc : Sensitive Data Exposure AWS Access Key & Secret Key
Dork: intext:Copyright © Dennis Publishing Limited 2021. All rights reserved.
Date: 05.09.2021
Poc : Santo Domingo School (CSD) / Web Ratings | SQL Injection Vulnerability
Dork: .php?id= csd.atenas.tech
Date: 05.09.2021
Poc : Athens School / Atenas Familia / Atenas Tech / Bitnami LAMP | SQL Injection
Vulnerability
Dork: .php?id= prod.atenas.tech
Date: 05.09.2021
Poc : Online Notice Board System 1.0 - Remote Command Execution (RCE) throw upload
file
Dork: intext:© 2020 ONBS
Date: 19.08.2021
Poc : Testa Online Test Management System 3.4.5 - 'q' SQL Injection
Dork: intext:Powered by Testa 3.4.5
Date: 03.08.2021
Poc : Real Estate 7 WordPress Theme < 3.1.1 - Unauthenticated Reflected XSS
Dork: inurl:/wp-content/themes/realestate-7/
Date: 05.07.2021
Poc : Bello WordPress Theme <= 1.5.9 - Unauthenticated Blind SQL Injection
Dork: inurl:/wp-content/themes/bello/
Date: 17.05.2021
Poc : Mediumish WordPress Theme <= 1.0.47 - Unauthenticated Reflected XSS & XFS
Dork: inurl:/wp-content/themes/mediumish/
Date: 17.05.2021
Poc : Listeo WordPress Theme <= 1.6.10 - Multiple XSS & XFS vulnerabilities
Dork: inurl:/wp-content/themes/listeo/
Date: 17.05.2021
Poc : Bello WordPress Theme <= 1.5.9 - Unauthenticated Reflected XSS & XFS
Dork: inurl:/wp-content/themes/bello/
Date: 17.05.2021
Poc : Controlled Admin Access WordPress Plugin <= 1.4.0 - Improper Access
Control & Privilege Escalation
Dork: inurl:/wp-content/plugins/controlled-admin-access/
Date: 23.03.2021
Poc : Urvanov Syntax Highlighter <= 2.8.33 - Highlighting Blocks Mgt via CSRF
Dork: site:adroom.ir inurl:/wp-admin/admin-ajax.php
Date: 31.10.2023
Poc : Urvanov Syntax Highlighter <= 2.8.33 - Highlighting Blocks Mgt via CSRF
Dork: wp-admin/admin-ajax.php
Date: 27.10.2023
Poc : WordPress Theme Medic v1.0.0 Weak Password Recovery Mechanism for Forgotten
Password
Dork: inurl:/wp-includes/class-wp-query.php
Date: 19.06.2023
Poc : WordPress Real Estate 7 Theme <= 3.3.4 - Multiple Cross-Site Request
Forgery (CSRF) Vulnerabilities
Dork: inurl:/wp-content/themes/realestate-7/
Date: 05.03.2023
Poc : WordPress Real Estate 7 Theme <= 3.3.4 - Unauthenticated Reflected Cross-
Site Scripting (XSS)
Dork: inurl:/wp-content/themes/realestate-7/
Date: 05.03.2023
Poc : WordPress WoodMart Theme <= 7.1.1 - Theme License Options Change via CSRF
Dork: inurl:/wp-content/themes/woodmart/
Date: 05.03.2023
Poc : Active eCommerce Laravel CMS 5.x to 6.1.2 - Cross Site request forgery (CSRF)
to Cross-site Scripting (XSS) (Authenticated)
Dork: intext:|| WHOPPS!!!THIS IS PIRATED COPY OF ACTIVE ECOMMERCE CMS
Date: 20.07.2022
Poc : Designed By Sevy INC. - SQL Injection Vulnerability, Unrestricted File Upload
Vulnerability and Default Admin Credentials
Dork: intext:Designed By Sevy INC.
Date: 06.07.2022
Poc : Will VPN App - VPN App With Admin Panel - Phpthumb Command Injection
Dork: - / use your brain
Date: 19.05.2022
Poc : USR IOT 4G LTE Industrial Cellular VPN Router 1.0.36 Remote Root Backdoor
Dork: title:usr-* // 4,648 ed ao 15042022
Date: 22.04.2022
Poc : iRZ Mobile Router Cross Site Request Forgery / Remote Code Execution
Dork: intitle:iRZ Mobile Router
Date: 22.03.2022
Poc : Copyright 2021 Reobiz. All Rights Reserved. - SQL Injection Vulnerability
Dork: intext:© Copyright 2021 Reobiz. All Rights Reserved.
Date: 21.03.2022
Poc : Behkad CMS - Technical And Vocational University Yazd / Iran - Cross-Site
Scripting (XSS)
Dork: -
Date: 06.03.2022
Poc : Eticaret Turkey CMS Kcfinder & Roxy File Manager Exploit
Dork: inurl:/nedmin/production/ (dorking on google images)
Date: 01.03.2022
Poc : Support Board 3.4.5 WP and NonWP Arbitrary File Upload / CSRF File Upload
Dork: use your brain brother
Date: 01.03.2022
Poc : ALFA TEAM SHELL TESLA 4.1 - Remote Code Execution (Unauthenticated)
Dork: inurl:/alfacgiapi intext:alfa
Date: 19.12.2021
Poc : FiveM & Gmod Loading Screen Maker Free | SQL Injection Vulnerability
Dork: ip:213.202.247.8 .php?id=
Date: 11.12.2021
Poc : WordPress Plugin DZS Zoomsounds 6.45 Arbitrary File Read (Unauthenticated)
Dork: inurl:/wp-content/plugins/dzs-zoomsounds/
Date: 03.12.2021
Poc : WP Google Maps PRO Add-on Plugin < 8.1.12 - Authenticated Persistent XSS
Dork: inurl:/wp-content/plugins/wp-google-maps-pro/
Date: 20.09.2021
Poc : WordPress Themes Haberadam IDOR and Full Path Disclosure via JSON API
( Unathenticated )
Dork: inurl:/wp-content/themes/haberadam
Date: 13.09.2021
Poc : Pricelist Stock Bangladesh Ltd. Center For Financial Analysis | SQL Injection
Vulnerability
Dork: .php?id= stockbangladesh.mobi
Date: 05.09.2021
Poc : Sensitive Data Exposure AWS Access Key & Secret Key
Dork: intext:Copyright © Dennis Publishing Limited 2021. All rights reserved.
Date: 05.09.2021
Poc : Santo Domingo School (CSD) / Web Ratings | SQL Injection Vulnerability
Dork: .php?id= csd.atenas.tech
Date: 05.09.2021
Poc : Athens School / Atenas Familia / Atenas Tech / Bitnami LAMP | SQL Injection
Vulnerability
Dork: .php?id= prod.atenas.tech
Date: 05.09.2021
Poc : Online Notice Board System 1.0 - Remote Command Execution (RCE) throw upload
file
Dork: intext:© 2020 ONBS
Date: 19.08.2021
Poc : Testa Online Test Management System 3.4.5 - 'q' SQL Injection
Dork: intext:Powered by Testa 3.4.5
Date: 03.08.2021
Poc : Real Estate 7 WordPress Theme < 3.1.1 - Unauthenticated Reflected XSS
Dork: inurl:/wp-content/themes/realestate-7/
Date: 05.07.2021
Poc : Bello WordPress Theme <= 1.5.9 - Unauthenticated Blind SQL Injection
Dork: inurl:/wp-content/themes/bello/
Date: 17.05.2021
Poc : Mediumish WordPress Theme <= 1.0.47 - Unauthenticated Reflected XSS & XFS
Dork: inurl:/wp-content/themes/mediumish/
Date: 17.05.2021
Poc : Listeo WordPress Theme <= 1.6.10 - Multiple XSS & XFS vulnerabilities
Dork: inurl:/wp-content/themes/listeo/
Date: 17.05.2021
Poc : Bello WordPress Theme <= 1.5.9 - Unauthenticated Reflected XSS & XFS
Dork: inurl:/wp-content/themes/bello/
Date: 17.05.2021
Poc : Controlled Admin Access WordPress Plugin <= 1.4.0 - Improper Access
Control & Privilege Escalation
Dork: inurl:/wp-content/plugins/controlled-admin-access/
Date: 23.03.2021
Poc : Developed by Five design Vulnerability SQL Injection And Admin Default Pass
Dork: intext:developed by Five design
Date: 22.03.2021
Poc : WP Super Cache WordPress Plugin <= 1.7.1 - Authenticated RCE / XSS ->
RCE
Dork: inurl:/wp-content/plugins/wp-super-cache/
Date: 19.03.2021
Poc : WordPress Plugin SuperForms 4.9 - Arbitrary File Upload to Remote Code
Dork: inurl:wp-content/plugins/super-forms
Date: 24.02.2021
Poc : CHEditor CMS CSRF Vulnerability Leading to Shell Upload ( RCE ) + Bypass
Image Validation
Dork: inurl:/cheditor/imageUpload/ index of intext:upload.php
Date: 14.02.2021
Poc : SW3 Solutions CMS Shell Upload thru weak default admin credentials
Dork: intext: Website Design & Developed by SW3 Solutions
Date: 12.02.2021
Poc : AXIS Camera View {CCTV} Exploit version 4.11 4.03 4.05
Dork: intitle:Live View AXIS
Date: 11.02.2021
Poc : Designed & Developed by SNT Infotech Pvt Ltd - Sql Injection
Dork: intext:Designed & Developed by SNT Infotech Pvt Ltd
Date: 09.02.2021
Poc : Wordpress [SuperForms] Plugin Unsecured File Upload leads to remote code
execution
Dork: inurl:/wp-content/plugins/super-forms/
Date: 29.01.2021
Poc : Water Billing System 1.0 - username and password parameters SQL Injection
Dork: Water Billing System Exploit
Date: 18.11.2020
Poc : SW Ajax WooCommerce Search plugin v1.2.6 - Unauthenticated Reflected XSS &
XFS
Dork: inurl:/wp-content/plugins/sw_ajax_woocommerce_search/
Date: 12.11.2020
Poc : BA Book Everything WordPress plugin v1.3.24 - Unauthenticated Reflected XSS &
XFS
Dork: inurl:/wp-content/plugins/ba-book-everything/
Date: 11.11.2020
Poc : Copyright © 2019 Bangkok Hospital Udon All rights reserved SQL Injection
Dork: intext:Copyright © 2019 Bangkok Hospital Udon All rights reserved Or
intext:Copyright © 2019 Bangkok Hospital Udon All rights reserved inurl:.php?id=
Date: 09.11.2020
Poc : OneMall WordPress theme v1.7.7 - Unauthenticated Reflected XSS & XFS
Dork: inurl:/wp-content/themes/onemall/
Date: 28.10.2020
Poc : WordPress Plugin Rest Google Maps < 7.11.18 SQL Injection
Dork: inurl:index.php?rest_route=3D/wpgmza/
Date: 26.10.2020
Poc : Sensitive Directories & Usernames and Passwords and all other tables
Dork: intext:-- table `users` | `category` | `structure` ext:sql | ext:txt
Date: 18.10.2020
Poc : Sony IPELA Network Camera 1.82.01 ftpclient.cgi Remote Stack Buffer Overflow
Dork: Server: Mida eFramework
Date: 07.10.2020
Poc : Microsoft SQL Server Reporting Services 2016 Remote Code Execution
Dork: inurl:ReportViewer.aspx
Date: 18.09.2020
Poc : Lokomedia CMS - SQL Injection & Bypass SQL Login Vulnerabilities
Dork: inurl:media.php?module= | &id=
Date: 10.09.2020
Poc : Home Page Pro CMS Pro Designz Bypass Admin No Redirect
Dork: Powered By : Pro Designz
Date: 17.08.2020
Poc : WordPress Plugin Email Subscribers & Newsletters 4.2.2 Unauthenticated File
Download
Dork: intext:Stable tag inurl:wp-content/plugins/email-subscribers/readme.txt
Date: 07.08.2020
Poc : Testa OTMS 2.0 - Online Test Management System - uname,pass Time Based SQL
Injection
Dork: intitle:Testa - Online Test Management System
Date: 30.07.2020
Poc : Cisco Adaptive Security Appliance Software 9.7 Arbitrary File Deletion
Dork: inurl:/+CSCOE+/
Date: 30.07.2020
Poc : WordPress Plugin Email Subscribers & Newsletters 4.2.2 hash SQL Injection
(Unauthenticated)
Dork: inurl:wp-content/plugins/email-subscribers/readme.txt
Date: 27.07.2020
Poc : Geo Magazine | Modern Responsive Newspaper | News Portal WordPress Theme v2.0
- Unauthenticated Reflected XSS
Dork: inurl:/wp-content/themes/geomagazine/
Date: 27.07.2020
Poc : Home Villas | Real Estate WordPress Theme v2.2 - Multiple Vulnerabilities
Dork: inurl:/wp-content/themes/homevillas-real-estate/
Date: 27.07.2020
Poc : Careerfy - Job Board WordPress Theme v4.3.0 - Unauthenticated Reflected XSS
Dork: inurl:/wp-content/themes/careerfy/
Date: 25.07.2020
Poc : upRedSun Port Forwarding Wizard 4.8.0 and earlier version- SEH based Buffer
Overflow in Register
Dork: Port Forwarding Wizard buffer overflow
Date: 23.07.2020
Poc : Workup – Job Board WordPress Theme v2.1.5 - Unauthenticated Reflected XSS
Dork: inurl:/wp-content/themes/workup/
Date: 21.07.2020
Poc : Workio – Job Board WordPress Theme v1.0.1 - Unauthenticated Reflected XSS
Dork: inurl:/wp-content/themes/workio/
Date: 21.07.2020
Poc : Careerfy - Job Board WordPress Theme v4.2.0 - Unauthenticated Reflected XSS
Dork: inurl:/wp-content/themes/careerfy/
Date: 21.07.2020
Poc : CarePlus - Health & Medical Responsive WordPress Theme v1.2 - Unauthenticated
Reflected XSS
Dork: inurl:/wp-content/themes/careplus/
Date: 21.07.2020
Poc : InJob | Multi features for recruitment WordPress Theme v3.4.0 - Authenticated
Reflected XSS
Dork: inurl:/wp-content/themes/injob/
Date: 21.07.2020
Poc : Reality | Estate Multipurpose WordPress Theme v2.5.3 - Multiple Reflected XSS
Dork: inurl:/wp-content/themes/reality/
Date: 17.07.2020
Poc : Golo - City Travel Guide WordPress Theme v1.3.2 - Unauthenticated Reflected
XSS
Dork: inurl:/wp-content/themes/golo/
Date: 13.07.2020
Poc : CareerUp - Job Board WordPress Theme v2.3.0 - Unauthenticated Reflected XSS
Dork: inurl:/wp-content/themes/careerup/
Date: 13.07.2020
Poc : HomeSweet - Real Estate WordPress Theme v1.4 - IDOR leading to arbitrary
deletion of ads
Dork: inurl:/wp-content/themes/homesweet/
Date: 13.07.2020
Poc : Monalisa | Hotel & Resort WordPress Theme v2.1.2 - Unauthenticated Reflected
XSS
Dork: inurl:/wp-content/themes/monalisa/
Date: 13.07.2020
Poc : Kormosala – Job Board WordPress Theme v1.0.22 - Unauthenticated Reflected XSS
Dork: inurl:/wp-content/themes/kormosala/
Date: 13.07.2020
Poc : Health Insurance Organization of the Islamic Republic of Iran SQL INJECTION
Vulnerabilities
Dork: site:gov.ir index.php?id=1
Date: 02.07.2020
Poc : Bangladesh EDU CMS SQL Injection => Recovery Login Info
Dork: inurl:/admission/recovery/ site:edu.bd
Date: 27.06.2020
Poc : TABS MailCarrier 2.51 - EHLO SEH Based Remote Buffer Overflow
Dork: MailCarrier exploit
Date: 20.06.2020
Poc : Powered by © 2019 All Rights Reserved by MTech Default U/P admin
Dork: Powered by © 2019 All Rights Res[+]erved by MTech
Date: 13.06.2020
Poc : Qualcomm WorldMail 3.0 - IMAPd Remote Buffer Overflow in LOGIN command
Dork: https://github.com/sartlabs/OSCE-Prep/blob/master/Qualcomm_IMAP_Login_BOF.py
Date: 13.06.2020
Poc : News website CMS SQL injection & Bypass Admin Panel & XSS Vulnerability &
Remote code Execution By Aryan Chehreghani
Dork: inurl:php?id= intext:Design By Dassinfotech.com
Date: 05.06.2020
Poc : MiniShare 1.4.1 - PUT Remote Buffer Overflow, allows remote attackers to
execute arbitrary code via a long HTTP PUT request.
Dork:
https://github.com/sartlabs/OSCE-Prep/blob/9a9d2471a9de09457f970be4ea1b57a74d26705a
/My
20CVEs/Minishare_BOF_PUT.py
Date: 05.06.2020
Poc : Chamilo © 2020 Campus v1 ElFinder Backdoor Access Shell Upload Vulnerability
Dork: Powered by Chamilo © 2020 site:com
Date: 27.05.2020
Poc : Default U/P admin on Powered by © 2019 All Rights Reserved by MTech
Websolution
Dork: Powered by © 2019 All Rights Reserved by MTech
Date: 22.05.2020
Poc : 2018 © جميع الحقوق محفوظة لمعهد صناعة الحياة للتدريب واالستشاراتSQL
Injection Vulnerability
Dork: intext:2018 © جميع الحقوق محفوظة لمعهد صناعة الحياة للتدريب واالستشارات
Date: 17.05.2020
Poc : johncaruso PHP Photo Gallery Remote File Inculsion Vulnerability [ RFI ]
Dork: intext:Created with Simple PHP Photo Gallery
Date: 05.05.2020
Poc : 2020 © ClasesIT - SIREA. Derechos reservados Admin Panel Bypass Exploit
Dork: intext:2020 © ClasesIT - SIREA. Derechos reservados (edu.ve)
Date: 04.04.2020
Poc : Webexcels Ecommerce CMS 2.x SQL Injection / Cross Site Scripting
Dork: intext:intext: By WEB EXCELS +inurl:?Id=
Date: 29.03.2020
Poc : SialWeb CMS eCommerce 1.0 / 1.1 Cross Site Scripting / SQL Injection
Dork: intext: By Sial Web +inurl:/.php?id=
Date: 25.03.2020
Poc : Dinamik İşler Tasarım ve Tanıtım Hizmetleri - Bypass Admin Panel with
Noredirect
Dork: /sayfa/form/01/iletisimformu
Date: 24.03.2020
Poc : WordPress FxInfinityTheme Themes 2.2.1 Open Redirection Remote File Inclusion
Dork: inurl:/wp-content/themes/fxinfinitytheme/
Date: 24.03.2020
Poc : ATC India - Express Delivery, Courier & Shipping Services Admin Login bypass
Dork: intext:Designed By Afireweb
Date: 28.01.2020
Poc : Built with WordPress and WP FanZone Themes 3.1 SQL Injection
Dork: Built with WordPress and WP FanZone site:ca
Date: 21.01.2020
Poc : La Universidad Nacional Tecnológica de Lima Sur Untels Peru XSS SQL Injection
Dork: Catálogo en línea Red de Biblioteca UTM. site:untels.edu.pe
Date: 10.01.2020
Poc : TownHub - Directory & Listing WordPress Theme v1.0.2 Multiple Vulnerabilities
Dork: /wp-content/themes/townhub/
Date: 27.12.2019
Poc : Rumpus FTP Web File Manager 8.2.9.1 Reflected Cross-Site Scripting
Dork: site:*.*.com Web File Manager inurl:?login=
Date: 18.12.2019
Poc : Design By RABS Net Solutions Vulnrability Bypass Page Admin Login
Dork: intext:Design By RABS Net Solutions (Use Your brain :v)
=======================================
Date: 11.12.2019
Poc : ListingPro - WordPress Directory Theme v2.0.14.2 Reflected & Persistent XSS
Dork: /wp-content/themes/listingpro/
Date: 29.11.2019
Poc : Powered By Komquest Solutions Vulnerability Bypass Admin Default & Register
User
Dork: intext:Powered By Komquest Solutions
Date: 12.11.2019
Poc : ham3d Information Processing Script Local File Download & Default Password
Vulnerability
Dork: inurl:fa/forgotpass.html
Date: 29.10.2019
Poc : Zoner - Real Estate WordPress Theme v4.1.1 Persistent XSS & IDOR
Dork: inurl:/wp-content/themes/zoner/
Date: 27.09.2019
Poc : InJob | Multi-purpose for recruitment WordPress Theme v3.3.6 Reflected &
Persistent XSS
Dork: inurl:/wp-content/themes/injob/
Date: 16.09.2019
Poc : Design by Yuvantra pvt ltd bypass admin panel and upload shell
Dork: intext:Design by Yuvantra pvt ltd
Date: 08.09.2019
Poc : Joomla 2.5.28 Com_JomEstate Real Estate Components 4.1 SQL Injection
Dork: inurl:/index.php?option=com_jomestate
Date: 30.08.2019
Poc : Joomla 1.0.15 Easy GuestBook Com_EasyGB Components 1.0 SQL Injection
Dork: inurl:/index.php?option=com_easygb
Date: 29.08.2019
Poc : © All Rights Are Reserved | Designed By Keywe Solution Bypass Authentication
Dork: /kadmin/login.php
Date: 26.08.2019
Poc : Plexo Torresoft Alex Torres Software 2.0 XSS SQL Injection
Dork: intext:Powered By Plexo Torresoft Alex Torres Software site:gov.co
Date: 26.08.2019
Poc : DomusMondo AgestaNet BeniaStudio Domini e Web Hosting XSS SQL Injection
Dork: inurl:/ricerca-immobile.php?prov_imm=
Date: 22.08.2019
Poc : WordPress Add Mime Types Plugin 2.2.1 Cross-Site Request Forgery
Dork: inurl:”/wp-content/plugins/wp-add-mime-types”
Date: 20.08.2019
Poc : BSI Advance Hotel Booking System 2.0 Cross Site Scripting
Dork: intext:Hotel Booking System v2.0 © 2008 - 2012 Copyright Best Soft Inc
Date: 13.08.2019
Poc : GigToDo - Freelance Marketplace Script v1.3 Persistent XSS Injection &
WebShell Upload
Dork: -
Date: 24.07.2019
Poc : Real Estate 7 - Real Estate WordPress Theme v2.8.9 Persistent XSS Injection
Dork: inurl:/wp-content/themes/realestate-7/
Date: 24.07.2019
Poc : Coming Soon Page & Maintenance Mode v1.8.0 Unauthenticated Persistent XSS
Injection
Dork: inurl:wp-content/plugins/responsive-coming-soon
Date: 23.07.2019
Poc : Carpool Web App 1.0 Cross Site Scripting / SQL Injection
Dork: intext:Powered by Prosentient Systems
Date: 01.07.2019
Poc : Sistem Informasi Kesehatan Daerah v1.4 (SIKDA) Xpath Injection Vulnerability
Dork: intext:SIKDA Generik - All Rights Reserved
Date: 24.06.2019
Poc : Cloud Base Multiple school Generate & Management System Backdoor Account
Vulnerability
Dork: intext:/website_upzilla/noticeUno/
Date: 20.06.2019
Poc : Websmart Inc Moose Jaw Area Canada XSS SQL Injection
Dork: intext:Web Site by Websmart Inc site:ca
Date: 14.06.2019
Poc : Design By : Web India Solution.Net Basic SQLI || SQLi Authentication bypass
|| XSS || Html injection
Dork: allintext:Design By : Web India Solution.Net Basic SQLI || SQLi
Authentication bypass || XSS || Html injection
Date: 12.06.2019
Poc : Pendaftaran Kontributor Indonesian sites BUG File Upload Vulnerability + Add
Berita
Dork: inurl:kontributor Allowed File : gif, jpg, png, jpeg
Date: 10.06.2019
Poc : WordPress Satoshi 2.0 Cross Site Request Forgery / File Upload
Dork: intext:Design By Voosh Themes
Date: 06.06.2019
Poc : CitraWeb Local File Inclusion to Remote Code Execution and get Cpanel
Dork: inurl:/cni-system/
Date: 03.06.2019
Poc : Designed and Developed by Web Experts SQL Injection (Greece script)
Dork: intext:Designed and Developed by Web Experts inurl:english/article.php?id=
Date: 02.06.2019
Poc : Création du Site Internet Agence Digitale NetSkiss France SQL Injection
Dork: intext:Création du site Internet : Agence digitale Netskiss site:fr
Date: 19.05.2019
Poc : Delhi Jain Public School or Jinvani Bharati School SQL Injection
Dork: intext:Powered by Schoolsindia download.php?id=5
Date: 19.05.2019
Poc : WordPress Share Buttons Plugin – AddThis Path Disclosure 6.2.3 Vulnerability
Dork: intext:/wp-content/plugins/addthis/backend/AddThisPlugin.php
Date: 17.05.2019
Poc : fire Shop IRANIAN CMS SQL injection & Remote File Upload
Dork: intext:قدرت گرفته از فروشگاه ساز فايرشاپ
Date: 10.05.2019
Poc : Thailand Majesty PhraCharoen Provincial Police Region P1 XSS SQL Injection
Dork: ทรงพระเจริญ | ตำรวจภูธรภาคที่ 1
Date: 04.05.2019
Poc : Web Dinas Pariwisata dan Kebudayaan Provinsi Jawa Barat Indonesia XSS SQL
Injection
Dork: Beranda - Web Dinas Pariwisata dan Kebudayaan Provinsi Jawa Barat site:go.id
Date: 04.05.2019
Poc : ThailandGov Agricultural Commodity and Food Standards XSS SQL Injection
Dork: National Bureau of Agricultural Commodity and Food Standards - ACFS
site:go.th
Date: 04.05.2019
Poc : Kementerian Perindustrian Balai Besar Pulp dan Kertas Indonesia SQL Injection
Dork: Kementerian Perindustrian Balai Besar Pulp dan Kertas site:go.id
Date: 03.05.2019
Poc : Kementerian Pekerjaan Umum dan Perumahan Rakyat Indonesia XSS SQL Injection
Dork: Biro Hukum PU - Kementerian Pekerjaan Umum dan Perumahan Rakyat site:go.id
Date: 03.05.2019
Poc : Badan Pengawas Obat dan Makanan Republik Indonesia XSS SQL Injection
Dork: Notifkos Badan Pengawas Obat dan Makanan Republik Indonesia site:go.id
Date: 02.05.2019
Poc : Thailand Ministry of Public and Mental Health Union Library Management SQL
Injection - Reflected Cross Site Scripting
Dork: Library dmh.go.th ULibM (Union Library Management)
Date: 18.04.2019
Poc : Site Desenvolvido Por Buscazip Guiaking Empresas Brazil SQL Injection
Dork: intext:Site desenvolvido por Buscazip, Guiaking Empresas
Date: 17.04.2019
Poc : Cloud Base Multiple school Generate & Management System Sql injection
Vulnerability
Dork: intext:/website_upzilla/noticeUno/
Date: 17.04.2019
Poc : DigaSell - Digital store PHP Script V1.0.0 Blind Sql Injection Vulnerability
Dork: intext:Copyright © DigaSell All Rights Reserved.
Date: 17.04.2019
Poc : Joomla omponent iPhone homepage icon 2.0.0 Parameter SQL Injection
Dork: : inurl:index.php?option=com_iPhone homepage
Date: 08.04.2019
Poc : C T & T SQL Injection Vulnerability And Bypass Admin page Login
Dork: intext:Design & Developed By C T & T
Date: 25.03.2019
Poc : WordPress Menu Plugin - Mega Main Menu v2.1.2 unauthorized backup download
Vulnerability
Dork: intext:/wp-content/plugins/mega_main_menu/
Date: 19.03.2019
Poc : WordPress 5.0.4 FormCraft Plugins 2.0 CSRF Backdoor Access Vulnerability
Dork: inurl:/wp-content/plugins/formcraft/
Date: 18.03.2019
Poc : ISPROJEK Bypass SQL Login Admin Indonesia School PMB Sites Upload Shell
Vulnerability
Dork: intext:ISPROJEK
Date: 14.03.2019
Poc : SIMPONIE v2.3 Indonesia Government Responsive File Manager File Upload
Dork: intext:SIMPONIE v2.3
Date: 12.03.2019
Poc : 1up! Software Going1up The Newspaper CMS 1998-2019 1.x Open Redirection
Dork: intext:Software © 1998-2019 1up! Software, All Rights Reserved
Date: 26.02.2019
Poc : HAM3D Shop CMS Security Hole XSS & SQlinjection [Nullix TM]
Dork: intext:ham3d.net inurl:id=
Date: 20.02.2019
Poc : Stock Manager Advance with Point of Sale Module v3.4.11 - nulled Backdoor
Account Vulnerability
Dork: intext:© SMA Shop. All rights reserved. or product/minion-crazy
Date: 08.02.2019
Poc : Design & Developed By Seawind Solution Pvt Ltd. Sql injection
Dork: inurl:.php?id= intext:Design & Developed By Seawind Solution Pvt Ltd.
Date: 03.02.2019
Poc : Joomla Zoo by YooTheme Components 3.3.10 SQL Injection / Database Disclosure
Dork: inurl:/index.php?option=com_zoo
Date: 29.01.2019
Poc : WordPress Add Code To Head upsite_analytics_plugin Plugins 1.13 SQL Injection
Dork: inurl:/wp-content/plugins/upsite_analytics_plugin/
Date: 28.01.2019
Poc : WordPress Advanced Custom Fields Pro Plugins 5.7.10 SQL Injection
Dork: inurl:/wp-content/plugins/advanced-custom-fields-pro/
Date: 28.01.2019
Poc : WordPress Yeloni Free Exit Popup Plugins 8.1.9 SQL Injection
Dork: inurl:/wp-content/plugins/yeloni-free-exit-popup/wordpress/
Date: 28.01.2019
Poc : WordPress MM-Forms-Community Plugins 2.2.7 Backdoor Access and SQL Injection
Vulnerability
Dork: inurl:/wp-content/plugins/mm-forms-community/
Date: 27.01.2019
Poc : Perfex v2.2.1 - Powerful Open Source CRM Backdoor Account Vulnerability
Dork: intext: Copyright Perfex INC
Date: 21.01.2019
Poc : Joomla FPSS Art Frontpage Slideshow Components 1.6.0 Database Disclosure /
Open Redirection / SQL Injection
Dork: inurl:/index.php?option=com_fpss
Date: 19.01.2019
Poc : Joomla YoutubeGallery Components 4.5.8 Database Disclosure and SQL Injection
Dork: inurl:/index.php?option=com_youtubegallery
Date: 18.01.2019
Poc : Blueimps jQuery file upload <=v9.22.0 Exploit for file upload
vulnerability
Dork: inurl: /jquery-file-upload/server/php
Date: 16.01.2019
Poc : WordPress topcsstools Plugins 1.0 Remote File Inclusion and Open Redirect
Dork: inurl:/wp-content/plugins/topcsstools/
Date: 15.01.2019
Poc : ModX Open Source CMS Babel Modules 3.0.0 Open Redirect
Dork: inurl:/modules/babel/
Date: 15.01.2019
Poc : Joomla Simple RSS Feed Reader mod_jw_srfr 3.6.0 Modules Open Redirect
Dork: inurl:/modules/mod_jw_srfr/
Date: 15.01.2019
Poc : Desenvolvimento MSoftX Brasil Web Design SQL Injection and Open Redirection
Dork: intext:Desenvolvimento MSoftX
Date: 11.01.2019
Poc : Informatica Icarus Diteh Web Design Spain SQL Injection Vulnerability
Dork: intext:diseno web informatica icarus diteh
Date: 10.01.2019
Poc : Wordpress Plugin UserPro < 4.9.21 User Registration Privilege Escalation
Dork: inurl:/wp-content/plugins/userpro/
Date: 09.01.2019
Poc : Educational Websites Developper - Chris Deotte - Cross Site Scripting (XSS)
Dork: dork : intext: Website developed by Chris Deotte
Date: 09.01.2019
Poc : Tariqul Computer & Internet Point TcipBD SQL Injection Vulnerability
Dork: intext:Developed By: Tariqul Computer & Internet Point site:edu.bd
Date: 07.01.2019
Poc : Typo3 CMS YAG Themepack jQuery Extension 1.3.2 Database Disclosure
Dork: inurl:/typo3conf/ext/yag_themepack_jquery/
Date: 04.01.2019
Poc : Typo3 CMS Static Info Tables Extension 6.7.3 Database Disclosure
Dork: inurl:/typo3conf/ext/static_info_tables/
Date: 04.01.2019
Poc : ModelAgency - Complete Model Agency and Directory System Backdoor Account
Vulnerability
Dork: Powered By GeniousOcean
Date: 03.01.2019
Poc : Designed & Developed By TAS TasPK Pakistan Education XSS Vulnerability
Dork: intext:Designed & Developed By TAS site:edu.pk
Date: 31.12.2018
Poc : WordPress Plugin Baggage Freight Shipping Australia 0.1.0 - Arbitrary File
Upload
Dork: none
Date: 29.12.2018
Poc : WordPress St_Newsletter Swift Mailer Plugins 2.7 Remote Shell Upload
Vulnerability
Dork: inurl:/wp-content/plugins/st_newsletter/
Date: 20.12.2018
Poc : Acon - Architecture and Construction Website CMS v1.2 Backdoor Account
Vulnerability
Dork: Acon - Building and Architecture Website CMS
Date: 17.12.2018
Poc : designed and developed by : japno IT department " SQL Injection "
Dork: intext:designed and developed by : japno IT department
Date: 15.12.2018
Poc : WordPress Events Made Easy Plugins 2.0.68 Database Backup Disclosure
Dork: inurl:/wp-content/plugins/events-made-easy/
Date: 11.12.2018
Poc : WordPress CSS & JavaScript Toolbox Plugins 8.4.1 Database Backup Disclosure
Dork: inurl:/wp-content/plugins/css-javascript-toolbox/models/
Date: 10.12.2018
Poc : WordPress Disqus Comment System Plugins 2.87 Database Backup Disclosure
Dork: inurl:/wp-content/plugins/disqus-comment-system/tests/
Date: 10.12.2018
Poc : Lider - The Best Social Network v 1.0.1 Blind Sql injection Vulnerability
Dork: intext:© 2018 SocialNetwork
Date: 10.12.2018
Poc : OVOO v2.5.5 - Movie & Video Streaming CMS with Unlimited TV-Series backup
disclosure Vulnerability
Dork: intext:Ovoo movie & Tv Show streaming cms - Login
Date: 09.12.2018
Poc : myIgniter v4.0.2 - Admin CRUD and Page Generator Backdoor Account
Vulnerability
Dork: Version 4.0.3 Copyright © 2018 kotaxdev. All rights reserved.
Date: 09.12.2018
Poc : myIgniter v4.0.2 - Admin CRUD and Page Generator export users list
Vulnerability
Dork: Version 4.0.3 Copyright © 2018 kotaxdev. All rights reserved.
Date: 09.12.2018
Poc : Web Portal People LLC 2018 OurClassOnline USA URL redirection Vulnerability
Dork: intext:To obtain a site like this for your class visit
www.ourclassonline.com.
Date: 07.12.2018
Poc : Web Portal People LLC 2018 OurClassOnline USA XSS Vulnerability
Dork: intext:To obtain a site like this for your class visit
www.ourclassonline.com.
Date: 07.12.2018
Poc : Chipsa Hosting Дизайн: «Чипса» Разработка сайта: weltgroup Hosting Russia XSS
Vulnerability
Dork: intext:Дизайн: «Чипса» Разработка сайта: weltgroup site:ru
Date: 06.12.2018
Poc : Joomla Content Editor Com_JCE Components 2.5.24 Database Backup Disclosure
Dork: inurl:/index.php?option=com_jce
Date: 01.12.2018
Poc : WordPress Pods Plugins 2.7.9 Database Backup Arbitrary File Download
Vulnerability
Dork: inurl:/wp-content/plugins/pods/
Date: 22.11.2018
Poc : Joomla com_admin Components from V2.5.4 to V3.7.4 Database Backup Arbitrary
File Download Vulnerability
Dork: inurl:/administrator/components/com_admin/sql/
Date: 20.11.2018
Poc : WB4Host Saudi Arabia Hosting Company النطاق الواسع لالستضافةSQL Injection
Vulnerability
Dork: intext: النطاق الواسع لالستضافةsite:sa
Date: 10.11.2018
Poc : Sadv.Com.Sa Hosting شعوب المتقدمةShooub Adv CMS V.1 SQL Injection
Vulnerability
Dork: intext:© جميع الحقوق محفوظة لشركة شعوب المتقدمةsite:sa
Date: 10.11.2018
Poc : Dreams Ultimate Solutions DreamSus India Improper Authorization and SQL
Injection Vulnerability
Dork: intext:Designed and Developed by Dreams Ultimate Solutions site:edu.in
Date: 09.11.2018
Poc : Designed & Developed By TAS TasPK Pakistan Education SQL Injection
Vulnerability
Dork: intext:Designed & Developed By TAS site:edu.pk
Date: 08.11.2018
Poc : Design By Orica Technology OricaWorld India Education SQL Injection
Vulnerability
Dork: intext:Design By Orica Technology site:edu.in
Date: 08.11.2018
Poc : Designed & Developed By Mars Software International Ltd Marssil Bangladesh
Education SQL Injection Vulnerability
Dork: intext:Designed & Developed By : Mars Software International Ltd. site:edu.bd
Date: 06.11.2018
Poc : Powered by ODHYYON A product of ADDIE Soft Ltd Bangladesh Education SQL
Injection Vulnerability
Dork: intext:Powered by ODHYYON, A product of ADDIE Soft Ltd. site:edu.bd
Date: 05.11.2018
Poc : Technical Support Corporate System Solutions Limited SIB Web Portal
Bangladesh Education SQL Injection Vulnerability
Dork: intext:কারিগরি সহায়তায়: কর্পোরেট সিস্টেম সলিউশনস লিমিটেড site:edu.bd
site:gov.bd
Date: 02.11.2018
Poc : 2018 © جميع الحقوق محفوظة لمعهد صناعة الحياة للتدريب واالستشاراتSQL
Injection Vulnerability
Dork: intext:2018 © جميع الحقوق محفوظة لمعهد صناعة الحياة للتدريب واالستشارات
inurl:abroad/page.php?cid=
Date: 20.10.2018
Poc : Web Design by Mark Nakamura Web Development by Ben Greeley SQL Injection
Vulnerability
Dork: intext:Web Design by Mark Nakamura / Web Development by Ben Greeley
Date: 06.10.2018
Poc : Created by Vanavi.com Digital Agency Web Design SQL Injection Vulnerability
Dork: intext:Created by Vanavi.com site:cz
Date: 05.10.2018
Poc : Chipsa Hosting Дизайн: «Чипса» Разработка сайта: weltgroup Hosting Russia SQL
Injection Vulnerability
Dork: intext:Дизайн: «Чипса» Разработка сайта: weltgroup site:ru -
intext:Разработка сайта Weltgroup site:ru
Date: 04.10.2018
Poc : Designed By Catpops Technobiz Graphic Design Company in Raipur SQL Injection
Vulnerability
Dork: intext:Desgined By Catpops Technobiz - intext:Designed By Catpops Technobiz
Date: 04.10.2018
Poc : OPAC EasyWeb Five 5.7 biblio SQL Injection
Dork: inurl:index.php?scelta=campi
Date: 04.10.2018
Poc : Site Specken.NL + Starque.Com Groningen Web Design Netherlands SQL Injection
Vulnerability
Dork: intext:SITE: SPECKEN.NL + STARQUE.COM
Date: 01.10.2018
Poc : Powered by Giga Soft Systems Pvt. Ltd. India SQL Injection Vulnerability
Dork: intext:Powered by : Giga Soft Systems Pvt. Ltd.
Date: 01.10.2018
Poc : Media-Art.ir HaaYahoo Web Design Studio Iran هنر رسانه: طراحی و اجراSQL
Injection Vulnerability
Dork: intext: هنر رسانه: طراحی و اجرا- intext: هنررسانه: مجری سایت- intext:طراحی و
توسعه هیاهـو
Date: 01.10.2018
Poc : Web Development Invasor Diagonal SQL Injection and Open Redirection
Vulnerability
Dork: intext:web development // invasor diagonal
Date: 01.10.2018
Poc : BidSun.ir Web Design بیدسان: طراحی و پیاده سازی توسطSQL Injection
Vulnerability
Dork: intext: بیدسان:طراحی و پیاده سازی توسط
Date: 29.09.2018
Poc : ZAMAN Graphic Web Design Iran SQL Injection Vulnerability
Dork: intext:Designed and Powered by ZAMAN
Date: 29.09.2018
Poc : Powered By XEDteam گروه زد: راحی و توسعهIran SQL Injection Vulnerability
Dork: intext:Powered By: XEDteam. - intext: گروه زد:طراحی و توسعه.
Date: 29.09.2018
Poc : Gwebbook Yash Computers Company Hosting India SQL Injection Vulnerability
Dork: intext:Powered by Gwebbook.com - intext:Panel Develope By YASH COMPUTERS
COMPANY
Date: 29.09.2018
Poc : Developed by Aathesh Soft Infotech Pvt Ltd SQL Injection Vulnerability
Dork: intext:Developed by Aathesh Soft Infotech Pvt Ltd
Date: 29.09.2018
Poc : Designed & Hosted By MWC Design England Authentication Bypass Vulnerability
Dork: intext:Designe & Hosted By. MWC - intext:Design By: MWC
Date: 29.09.2018
Poc : Acelle Email Marketing Web Application v3.0.15 file uploads Vulnerability
Dork: intext:. Acelle Email Marketing Application by acellemail.com
Date: 22.09.2018
Poc : Sito Creato Da Amaka Web Agency e Posizionamento Siti SQL Injection
Vulnerability
Dork: intext:sito creato da Amaka web agency e posizionamento siti
Date: 22.09.2018
Poc : Acelle Email Marketing Web Application v3.0.18 file uploads Vulnerability
Dork: intext:© 2018. Acelle Email Marketing Application by acellemail.com
Date: 22.09.2018
Poc : 3CX Open Standards Software IP PBX Thailand SQL Injection Vulnerability
Dork: intext:3CX: Open Standards Software IP PBX
Date: 21.09.2018
Poc : WebEmpire.co.il &נבנה עquot; יHosting Web Design Israel SQL Injection
Vulnerability
Dork: intext:WebEmpire נבנה עי
Date: 15.09.2018
Poc : Desarrollado por Kodfee Constultores IT. Mexico SQL Injection Vulnerability
Dork: intext:Desarrollado por Kodfee - Constultores IT.
Date: 15.09.2018
Poc : Design G. Wolfgang Build Y. Neuman 1234 Up.Co.il Hosting Israel SQL Injection
Vulnerability
Dork: intext:Design G. Wolfgang | Build Y. Neuman site:il
Date: 15.09.2018
Poc : MNW Digital Agency Mnw.Pt Hosting Portugal SQL Injection Vulnerability
Dork: intext:MNW Digital Agency
Date: 15.09.2018
Poc : OVOO v2.5.1 - Movie & Video Streaming CMS with Unlimited TV-Series backup
disclosure Vulnerability
Dork: intext:Ovoo movie & Tv Show streaming cms - Login
Date: 12.09.2018
Poc : Powered By Exnet Exclusive Solution Network Nepal SQL Injection Vulnerability
Dork: intext:Powered by Exnet Exclusive Solution Network site:np
Date: 12.09.2018
Poc : Powered By PAS World Communitcation Ltd and Nakhonkorat ThailandGov SQL
Injection
Dork: intext:Powered By :: PAS World Communitcation,.ltd. AND nakhonkorat.com
Date: 10.09.2018
Poc : Hoteliraqua Todos los Derechos Reservados © 2013 SQL Injection Vulnerability
Dork: intext:www.hoteliraqua.com - Todos los Derechos Reservados © 2013
Date: 07.09.2018
Poc : ReturnDates is under the care of (c) ThePopeRope SQL Injection Vulnerability
Dork: intext:Returndates.com is under the care of (c) Thepoperope.
Date: 07.09.2018
Poc : © Inter Alia 2013 InterAliaProject Web Design SQL Injection Vulnerability
Dork: intext:© Inter Alia 2013
Date: 07.09.2018
Poc : Apache Roller 5.0.3 XML External Entity Injection (File Disclosure)
Dork: intext:apache roller weblogger version {vulnerable_version_number}
Date: 06.09.2018
Poc : Developed By Jay4web Web Design Company Kochi Kerala India SQL Injection
Vulnerability
Dork: intext:Developed By Jay4web site:in
Date: 06.09.2018
Poc : Website designed & developed by Radical Reflex India SQL Injection
Vulnerability
Dork: intext:Website designed & developed by Radical Reflex
Date: 06.09.2018
Poc : Designed and Hosted By WebGen Internet Technologies Pvt Ltd India SQL
Injection Vulnerability
Dork: intext:Designed and Hosted By : WebGen
Date: 06.09.2018
Poc : © 2015 Math4All India All Rights Reserved SQL Injection Vulnerability
Dork: intext:© 2015 Math4All. All Rights Reserved
Date: 06.09.2018
Poc : Website Maintained By Ankur Biswas SASLAB Technologies Pvt Ltd SQL Injection
Vulnerability
Dork: intext:Website Maintained By : Ankur Biswas ( SASLAB Technologies Pvt Ltd )
Date: 06.09.2018
Poc : BRIGHTBRIX® Web Producer - Extending the Internet Add Admin Vulnerability
Dork: Dashboard for BRIGHTBRIX® Web Producer - Extending the Internet
Date: 06.09.2018
Poc : Design & Developed By Target Soft BD Bangladesh SQL Injection Vulnerability
Dork: intext:Design & Develope By : Target Soft site:edu.bd
Date: 05.09.2018
Poc : Design & Developed by SoftBd Ltd. Bangladesh Education Portals Multiple
Vulnerabilities
Dork: intext:DEVELOPED BY : SOFTBD Ltd. site:edu.bd
Date: 04.09.2018
Poc : Site Design & Developed by G4 Tech Solutions Bangladesh SQL Injection
Vulnerability
Dork: intext:Powered by : G4 Tech Solutions
Date: 04.09.2018
Poc : MenorahMarket Multi Vendor Digital Goods Market Place Script V 2.0 Backdoor
Account Vulnerability
Dork: intext:COPYRIGHTS 2017 ALL RIGHTS RESERVED BY - EDD MARKET PLACE
Date: 03.09.2018
Poc : The Next Gen School Management Software - Menorah Academy 7.0 Backdoor
Account Vulnerability
Dork: intext:Menorah Academy System
Date: 02.09.2018
Poc : IceWarp WebMail Cross Site Scripting (XSS) & Execution Code
Dork: intext:Sign in to WebClient
Date: 14.08.2018
Poc : Carbiz - Buy Sell Car Marketplace Script V 1.2.0 Backdoor Account
Vulnerability
Dork: intext:© Copyright 2018 Webhelios . All rights reserved
Date: 07.08.2018
Poc : Premium URL Shortener (c) KBRmedia Version 5.0.2 Add Admin Vulnerability
Dork: 2012-2018 © KBRmedia - All Rights Reserved
Date: 07.08.2018
Poc : Web design & development by: svc & smorkov SQL Injection Vulnerability
Dork: -
Date: 05.08.2018
Poc : DataLife Engine Core Cross Site Scripting (XSS) & Execution Code
Dork: inurl:/index.php?subaction=userinfo
Date: 01.08.2018
Poc : orientation4success Web Design israil Insert Image. File Manager upload
Dork: insert_image.php site:il
Date: 29.07.2018
Poc : Website Fueled and Designed by SocketWorks Internet Services ©2018 SQL
Injection
Dork: intext:Website Fueled and Designed by SocketWorks Internet Services ©2018
Date: 11.07.2018
Poc : Courier Deprixa Pro - Integrated Web System v3.2.5 Auth by pass
Vulnerability
Dork: DEPRIXA 3.2.5 | lOGIN
Date: 10.07.2018
Poc : Courier Deprixa Pro - Integrated Web System v3.2.5 CSRF Vulnerability
Dork: DEPRIXA 3.2.5 | lOGIN
Date: 10.07.2018
Poc : Tamil Nadu National Law School cms Authentication bypass Vulnerability
Dork: intext:Designed by: Guhaa Soft Solutions (P) Limited
Date: 10.07.2018
Poc : Wchat - Fully Responsive PHP AJAX Chat Script 1.5 unrestricted file upload
Vulnerability
Dork: Wchat - Admin Login
Date: 09.07.2018
Poc : Buzzy - News Viral Lists Polls and Videos V 2.5.2 Backdoor Account
Vulnerability
Dork: intext:buzzy /profile/admin/ Copyright © Buzzy. All rights reserved.
Date: 09.07.2018
Poc : Buzzy - News Viral Lists Polls and Videos V 2.5.1 Backdoor Account
Vulnerability
Dork: intext:buzzy /profile/admin/ Copyright © Buzzy. All rights reserved.
Date: 08.07.2018
Poc : Software Developed By Copotronic Shikkhangon Iqbal Hossain Rimon Admin Login
Bypass Vulnerability
Dork: intext:© Copotronic InfoSystems Limited. All Right Reserved. -
intext:Copyright © 2018 Shikkhangon.com. All Right Reserved.
Date: 07.07.2018
Poc : Gettarget EduProTech © 2003-2016 EduPro Technology Pvt. Ltd. SQL Injection
Vulnerability
Dork: intext:© 2003-2016 EduPro Technology Pvt. Ltd.
Date: 07.07.2018
Poc : Design & Development World IT Expert Ahasan Habib Admin Login Bypass
Vulnerability
Dork: intext:Design & Development World IT Expert site:bd
Date: 07.07.2018
Poc : Buzzy - News Viral Lists Polls and Videos V 2.0 Backdoor Account
Vulnerability
Dork: intext:buzzy /profile/admin/ Copyright © Buzzy. All rights reserved.
Date: 06.07.2018
Poc : Wordpres Simple 301 Redirects - Addon - Bulk CSV Uploader plugin Cross Site
Scripting Vulnerability
Dork: inurl:/wp-content/plugins/simple-301-redirects-addon-bulk-uploader/
Date: 04.07.2018
Poc : Website Design & Development by LIFTOFF Digital SQL Injection Vulnerability
Dork: intext:Website Design & Development by LIFTOFF Digital inurl:php.?id=
Date: 02.07.2018
Poc : Powered by Admas Host & Developed by Asian IT SQL Injection Vulnerability
Dork: intext:Powered by Admas Host & Developed by Asian IT
Date: 02.07.2018
Poc : Powered by Admas Host & Developed by Asian IT SQL Injection Vulnerability
Dork: intext:Powered by Admas Host & Developed by Asian IT
Date: 02.07.2018
Poc : Buzzy - News Viral Lists Polls and Videos V 1.4 Backdoor Account
Vulnerability
Dork: intext:buzzy /profile/admin/ Copyright © Buzzy. All rights reserved.
Date: 02.07.2018
Poc : Site Developed By İconify Web & Mobile Development SQL Injection
Vulnerability
Dork: intext:site developed by iconify
Date: 02.07.2018
Poc : Developed By Inside Softwares Pvt. Ltd. Web Design Company India SQL
Injection Vulnerability
Dork: intext:DEVELOPED BY INSIDE SOFTWARES PVT. LTD
Date: 02.07.2018
Poc : OVOO v2.5.1 - Movie & Video Streaming CMS with Unlimited TV-Series backdoor
account Vulnerability
Dork: intext:Ovoo movie & Tv Show streaming cms - Login
Date: 01.07.2018
Poc : Powered by Yii Framework RBAC Manager for Yii 2 Improper Authentication
Vulnerability
Dork: inurl:/emusrenbang/web/index.php?r=
Date: 01.07.2018
Poc : Infinity Market Classified Ads Script 1.6.2 xss via file uploads
Vulnerability
Dork: intext:InfinityMarket MultiPurpose Script is a multi-solution product made
with simplicity in mind so you can benefit
Date: 01.07.2018
Poc : Dj Twilight Ver 2.0 Copyright 1999 - 2018 PicturesGallery SQL Injection
Vulnerability
Dork: intext:DJ TWILIGHT.COM Ver 2.0 Copyright 1999 - 2018
Date: 30.06.2018
Poc : Bee Gees Italy © 1998-2017 Enzo Lo Piccolo SQL Injection Vulnerability
Dork: intext:Bee Gees Italy © 1998-2017 Enzo Lo Piccolo
Date: 30.06.2018
Poc : Powered by dBlog CMS ® Open Source Picture Gallery By InternetCamera.it SQL
Injection Vulnerability
Dork: intext:powered by dBlog CMS ® Open Source - intext:Picture gallery By
Internet camera
Date: 30.06.2018
Poc : Copyright © 2008 - 2018 by DaMa SOFT WebSiteX5 İwGallery Manager Privilege
Escalation Vulnerability
Dork: intext:by DaMa SOFTWARE 2015 - inurl:/filemanager/sfmanager.asp
Date: 30.06.2018
Poc : Design By Dr. Hardik Desai Developed By Chirag Lad India Admin Login Bypass
Vulnerability
Dork: intext:Design By Dr. Hardik Desai | Developed By Chirag Lad
Date: 29.06.2018
Poc : Web services provided by Ciphertek Systems, LLC SQL Injection Vulnerability
Dork: intext:Web services provided by Ciphertek Systems, LLC
Date: 29.06.2018
Poc : Buzzy - News Viral Lists Polls and Videos V 1.3.2 Backdoor Account
Vulnerability
Dork: intext:buzzy /profile/admin/ Copyright © Buzzy. All rights reserved.
Date: 28.06.2018
Poc : Infinity Market Classified Ads Script 1.6.1 xss via file uploads
Vulnerability
Dork: intext:InfinityMarket MultiPurpose Script is a multi-solution product made
with simplicity in mind so you can benefit
Date: 28.06.2018
Poc : Designed by SriRam Soft Solutions Pvt. Ltd. India SQL Injection Vulnerability
Dork: intext:Designed by : SriRam Soft Solutions Pvt. Ltd.
Date: 26.06.2018
Poc : Developed By Jay4web Website Design and Development India SQL Injection
Vulnerability
Dork: intext:Developed By Jay4web
Date: 26.06.2018
Poc : WebSolutions.Ca Web Design and Development Canada SQL Injection Vulnerability
Dork: intext:websolutions.ca
Date: 26.06.2018
Poc : Another Quality Site by Seabreeze Consulting Web Design SQL Injection
Vulnerability
Dork: intext:Another Quality Site by Seabreeze Consulting
Date: 26.06.2018
Poc : Powered byJWA ©2016 Website designed by THADV Admin Login Bypass
Vulnerability
Dork: intext:Powered byJWA ©2016 Website designed by THADV
Date: 25.06.2018
Poc : Developed by Regal Soft India WebDesign Admin Login Bypass Vulnerability
Dork: intext:Developed by Regal Soft India site:gov.in
Date: 25.06.2018
Poc : Hong Kong Admin Login Bypass Powered By YSD SQL Injection
Dork: intext:Powered By YSD
Date: 25.06.2018
Poc : Indonesia Admin Login Bypass Copyright CMS Develop by: Anom Bramanjati SQL
Injection
Dork: intext:© 2010 PT. Oriental Asahi JP Carton Box
Date: 25.06.2018
Poc : Joomla Com_Techedu Courseview Developed in Association with Icta SriLanka SQL
Injection Vulnerability
Dork: intext:Developed in association with ICTA
Date: 24.06.2018
Poc : Designed & Developed by Web Based Business Systems BTOptions.Com SQL
Injection Vulnerability
Dork: intext:Designed & Developed by Web Based Business Systems, BT Options.
Date: 24.06.2018
Poc : Copyright © 2008-2011 NEX Studio Nex.Ba Web Design SQL Injection
Vulnerability
Dork: intext:NEX Studio. site:ba
Date: 24.06.2018
Poc : Solution by Lankacom Internet Service Provider in Sri Lanka SQL Injection
Vulnerability
Dork: intext:Solution by Lankacom.
Date: 24.06.2018
Poc : Designed & Powered by Gilgal Media Arts Admin Login Bypass Vulnerability
Dork: intext:Designed & Powered by Gilgal Media Arts
Date: 23.06.2018
Poc : Designed and Developed by Reliable Services GRHRCS Pvt Ltd Admin Login Bypass
Vulnerability
Dork: intext:Designed and developed by Reliable Services GRHRCS Pvt Ltd
Date: 23.06.2018
Poc : Creado por Crafi&Deso MachForm PHP Form Builder Spain SQL Injection
Vulnerability
Dork: intext:Creado por CRAFI&DESO - intext:MachForm - PHP Form Builder
Date: 22.06.2018
Poc : Creación y diseño White Solutions FactuSOL Web por Software DELSOL SQL
Injection Vulnerability
Dork: intext:FactuSOL Web por Software DELSOL - intext:Creación y diseño White
Solutions
Date: 22.06.2018
Poc : Website Produced by USE FOR FUN Design Collective | Beirut SQL Injection
Dork: prodbycat.php?intCatalogID=
Date: 21.06.2018
Poc : © IMS Institute Management System by JS IT Park 2017-18 Version 1.0.1 Admin
Bypass Vulnerability
Dork: intext:Developed by JS IT Park
Date: 21.06.2018
Poc : Sipbar Sistem Informasi Pelaporan Indonesia Admin Login Bypass and SQL
Injection Vulnerability
Dork: inurl:/assets/media/logo_kanal/
Date: 21.06.2018
Poc : Elite CMS Pro - Version 2.01 Admin Panel sql injection Vulnerability
Dork: intext:Elite CMS Pro - Version 2.01
Date: 15.06.2018
Poc : WordPress Theme Sydney by aThemes 2018 GravityForms Input Remote File Upload
Vulnerability
Dork: intext:Proudly powered by WordPress | Theme: Sydney by aThemes.
Date: 08.06.2018
Poc : Copyright © 2014 Indian Performing Art Center Admin Control Panel ByPass
Vulnerability
Dork: intext:Copyright © 2014- All Rights Reserved Press| Indian Performing Art
Center ::
Date: 08.06.2018
Poc : Design & Development By i5t.in India Admin Control Panel ByPass Vulnerability
Dork: intext:Design & Development by i5t
Date: 08.06.2018
Poc : Web Design RGB Multimedia Perugia Italy SQL Injection Vulnerability
Dork: intext:Web Design RGB Multimedia Perugia - Italy
Date: 06.06.2018
Poc : Desenvolvido e Hospedado por CWD Internet Brazil SQL Injection Vulnerability
Dork: intext:Desenvolvido e Hospedado por CWD Internet
Date: 05.06.2018
Poc : Israel PGN Network Web Development AppGate SQL Injection Vulnerability
Dork: intext:Pgn - | בניית אתריםAppGate
Date: 04.06.2018
Poc : Intercom Solutions developer website SQLi
Dork: inurl:index.jsp? intext:sviluppato da intercom solutions
Date: 04.06.2018
Poc : CopyRight © 2015 Hainan Pingan Car Rental Network China SQL Injection
Vulnerability
Dork: intext:CopyRight © 2015 海南平安租车网 版权所有
Date: 02.06.2018
Poc : chatone social networking php script v1.6 Add Admin Vulnerability
Dork: intext:chatone - online
Date: 02.06.2018
Poc : Buİnteractive Web Design E-Commerce Social Media Digital Marketing SQL
Injection
Dork: intext:Bu interactive
Date: 02.06.2018
Poc : AtelyeDigital.Com Web Design and Development SQL Injection Vulnerability
Dork: intext:Atelye Digital
Date: 02.06.2018
Poc : 3T1K Design and Coding İnternet Services W3Turk SQL Injection
Dork: inurl:/?ref=3t1k
Date: 02.06.2018
Poc : Israel © All rights reserved Tvan Servitex Company Ltd. SQL Injection
Dork: intext:© כל הזכויות שמורות תוואן סרוויטקס בעמ
Date: 01.06.2018
Poc : Investor Ningbo Liangzhu Culture Industrial Pack Development Management Co.
Ltd. SQL Injection Vulnerability
Dork: inurl:/liangzhutd.php?catid=
Date: 01.06.2018
Poc : Middle East Design and Programming GT4Host.Com Hosting SQL Injection
Vulnerability
Dork: intext: الشرق الأوسطتصميم وبرمجةGT4Host
Date: 01.06.2018
Poc : Taiwan 本公司已投保 GPS 衛星定位乘客險捌佰萬元 | 網頁設計 Web Design SQL Injection Vulnerability
Dork: intext:本公司已投保 GPS 衛星定位乘客險捌佰萬元 | 網頁設計 site:tw
Date: 31.05.2018
Poc : Arabia Developed by Smart Online Marketing SARL SomLB.Com SQL Injection
Vulnerability
Dork: intext:Developed by Smart Online Marketing SARL
Date: 31.05.2018
Poc : Aplikasi CBT Indonesian School Admin Weak Password
Dork: inurl:/panel/pages/login.php
Date: 31.05.2018
Poc : China Hangzhou City Technical Technology Support Juxiang Network 技术支持:聚翔网络
SQL Injection
Dork: intext:技术支持:聚翔网络
Date: 31.05.2018
Poc : Design & Developed by MR Technology Sql Injection & Shell Upload
Dork: intext:Design & Developed by MR Technology & site:edu.bd
Date: 30.05.2018
Poc : Copyright © 2013 - 2018 Shumool.Com.Sa Real Estate Company Arabia SQL
Injection Vulnerability
Dork: intext:Copyright © 2013 - 2018 Shumool Company, All Rights Reserved
Date: 30.05.2018
Poc : Powered by Expert Web Worx and AnaghaSofTech SQL Injection Vulnerability
Dork: intext:powered by : Expert Web Worx
Date: 30.05.2018
Poc : Web Design & Development by Easy Superweb Admin Control Panel ByPass
Vulnerability
Dork: intext:Web Design & Development by Superweb site:gr
Date: 30.05.2018
Poc : WordPress Headway Theme The Drag and Drop SQL Injection Vulnerability
Dork: inurl:/hindex.php?lT=
Date: 30.05.2018
Poc : Total Comfort Solutions A Commercial Heating and Air Conditioning Company SQL
Injection Vulnerability
Dork: intext:Total Comfort Solutions
Date: 30.05.2018
Poc : Base content Copyright ©2018 Lennox Industries USA SQL Injection
Vulnerability
Dork: intext:Base content Copyright ©2018 Lennox Industries.
Date: 30.05.2018
Poc : Videoflix - Tv Series Movie Subscription Portal Cms v1.3 Backdoor Account
Vulnerability
Dork: intext:Made with by Vmax-Studio.
Date: 29.05.2018
Poc : Slims Senayan Library Management The Winner of OSS Indonesia 2009 ICT Award
Exploit
Dork: intext:The Winner in the Category of OSS Indonesia ICT Award 2009
Date: 28.05.2018
Poc : SAP Internet Transaction Server 6200.x Session Fixation / Cross Site
Scripting
Dork: /scripts/wgate/
Date: 28.05.2018
Poc : Custom Web Development & WebSite Design by Dizyn SQL Injection
Dork: inurl:past.php?id=
Date: 27.05.2018
Poc : Copyright © 2011 - 2018 Vitalex Computers Tvorba školních webů SQL Injection
Dork: intext: Vitalex Computers - Tvorba školních webů site:cz
Date: 26.05.2018
Poc : WordPress Peugeot Music 1.0 Shell Upload / Cross Site Request Forgery
Dork: inurl:/wp-content/plugins/peugeot-music-plugin/
Date: 25.05.2018
Poc : Joomla Content Editor JCE ImageManager Vulnerability Mass Auto Exploiter
Dork: inurl:/index.php?option=com_jce
Date: 24.05.2018
Poc : WordPress Muller Design Studio DiyThemes Rich-Widget Editor Arbitrary File
Upload
Dork: Designed and Hosted by Muller Design Studio.
Date: 23.05.2018
Poc : Tik-Tak Israel webPro Codeclient CKFinder Arbitrary File Upload Vulnerability
Dork: inurl:/webPro/index.asp?codeclient=
Date: 22.05.2018
Poc : Admin Page Faspi Enterprises Pvt. Ltd. NOREDIRECT Admin Bypass
Dork: Powered By Faspi Enterprises Pvt. Ltd.
Date: 09.04.2018
Poc : Job Portal Script version 3.0 Unrestricted file upload Vulnerability
Dork: intext:categorysearch.php?indus=
Date: 15.03.2018
Poc : QuickTalk 1.x and 2.x Reinstall Script / Password Hash Disclosure
Vulnerability
Dork: powered by QT-cute
Date: 26.02.2018
Poc : Simple Machines Forum SMF 2.0.8 Host header attack Vulnerability
Dork: SMF 2.0.8 | SMF © 2014, Simple Machines
Date: 04.02.2018
Poc : Blue Webeyes Admin Panel Bypass And Sql İnjection Vulnerability
Dork: Powered by Blue Webeyes
Date: 01.02.2018
Poc : Cloud Dreams CMS - SQL Injection + XSS + Week Admin Password Vulnerability
Dork: intext: Web Design Company - Clouddreams inurl:.php?id=
Date: 30.01.2018
Poc : Automatic Link Box CMS cross site scripting (stored) vulnerability
Dork: intext: System Powered By : Mehrdad Design
Date: 29.01.2018
Poc : Tayland government Upload File and Cross Site Scripting Vulnerability
Dork: inurl://index.php?mod=
Date: 23.01.2018
Poc : Job Portal Script version 3.0 Unrestricted file upload Vulnerability
Dork: intext:categorysearch.php?indus=
Date: 16.01.2018