• Earn real money by being active: Hello Guest, earn real money by simply being active on the forum — post quality content, get reactions, and help the community. Once you reach the minimum credit amount, you’ll be able to withdraw your balance directly. Learn how it works.

lfi

  1. dEEpEst

    35K HQ LFI DORKS

    Hidden content
  2. itsMe

    Agartha { LFI | RCE | Auth | SQLi | Http-Js }

    Agartha is a penetration testing tool which creates dynamic payload lists and user access matrix to reveal injection flaws and authentication/authorization issues. There are many different attack payloads exists, but Agartha creates run-time, systematic and vendor-neutral payloads with many...
  3. itsMe

    BurpParamFlagger: indicate a possible insertion point for SSRF or LFI

    BurpParamFlagger A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or LFI. Note: I believe that Burp Pro is required to use this extension since it adds to the scanner functionality, which isn’t included in the...
  4. 1

    Exploits WordPress Contact Form Builder 1.0.67 CSRF / LFI

    WordPress Contact Form Builder plugin version 1.0.67 suffers from cross site request forgery and local file inclusion vulnerabilities. View the full article
  5. 1

    Exploits Joomla Fabrik 3.9 CSRF / LFI / Shell Upload

    Joomla Fabrik component version 3.9 suffers from cross site request forgery, local file inclusion, and remote shell upload vulnerabilities. View the full article
  6. 1

    Exploits LibreHealth 2.0.0 File Read / File Delete / LFI

    LibreHealth version 2.0.0 suffers from arbitrary file read, file delete, and local file inclusion vulnerabilities. View the full article
  7. 1

    Exploits Centos Web Panel 0.9.8.480 XSS / LFI / Code Execution

    Centos Web Panel version 0.9.8.480 suffers from code execution, cross site scripting, and local file inclusion vulnerabilities. View the full article
  8. 1

    Exploits KONE KGC 4.6.4 DoS / Code Execution / LFI / Bypass

    KONE KGC versions 4.6.4 and below suffer from unauthenticated remote code execution, denial of service, local file inclusion, and missing FTP access control vulnerabilities. View the full article
Back
Top