MorawskiWeb.pl

Scripts and Vulnerabilities discovered by Dawid Morawski.

Blog About

Joomla com_aicontactsafe Arbitrary Attachment Download - 08.06.2017

Everyone can download arbitrary attachment, but website must have including field with attachments.

Read More

OLX phone number extractor - Selenium Webdriver - 26.03.2017

“OLX phone number extractor” - Script check every page one by one and save phone number to .txt

Read More

Facebook Fanpage Maker - Selenium Webdriver Script - 20.03.2017

“Facebook Fanpage Maker” Selenium Webdriver Automation - script example

Read More

Facebook status poster - Selenium Webdriver - 02.03.2017

“Facebook status poster” Selenium Webdriver Automation test - simple example

Read More

B2B Script v4.27 - SQL Injection - 18.01.2017

An attacker can exploit this vulnerability to read from the database. The parameters ‘keywords’ and ‘token’ are vulnerable.

Read More

Online Food Delivery v2.04 - Authentication bypass - 12.01.2017

Authentication bypass should give you access to the admin area.

Read More

Job Portal Script v9.11 - Authentication bypass - 12.01.2017

Authentication bypass should give you access to the admin area.

Read More

My link trader - SQL Injection - 11.01.2017

An attacker can exploit this vulnerability to read from the database. The parameter ‘id’ is vulnerable.

Read More

Dating Script v3.25 - SQL Injection - 11.01.2017

An attacker can exploit this vulnerability to read from the database. The parameter ‘id’ is vulnerable.

Read More