This Metasploit module exploits an unauthenticated directory traversal vulnerability in Cassandra Web Cassandra Web version 0.5.0 and earlier, allowing arbitrary file read with the web server privileges. This vulnerability occurred due to the disabled Rack::Protection module.
1fcf8bcb9a5c390a3d9ee4018429d16d6138dbe119755c56e7f809909dd5bccd
WordPress version 4.9.6 arbitrary file deletion exploit. Original discovery of this vulnerability is attributed to VulnSpy in June of 2018.
9e26b80d1679329336158f3cd64555119dd28f5c169070eeb582f83fd788eb26
phpMyAdmin version 4.8.1 remote code execution exploit.
c7fd500b6b33a3e044159ceaba0504a93de489c811db969c2903f7741e995f09
Whitepaper that gives an overview on brute-forcing login and bypassing account lockout on elabFTW version 1.8.5.
094a251f151a7eb62b59cfd2e713ac0c84510e643ec38087d3cafab6380e06e8