Hashtopus Project develops a distributed password-cracking tool that, despite a narrow product scope, represents a specialized attack-infrastructure component whose exposure is relevant to organizations defending against brute-force and credential-compromise attacks. Its disclosed vulnerabilities cluster around web-interface and input-handling issues, including cross-site request forgery, cross-site scripting, and SQL injection, reflecting the interactive web-management surface of the tool. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hashtopus Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-11679HIGH Cross-Site Request Forgery (CSRF) exists in Hashtopus 1.5g via the password parameter to admin.php in an a=config action. | Jul 27, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-11678HIGH SQL injection vulnerability in Hashtopus 1.5g allows remote authenticated users to execute arbitrary SQL commands via the format parameter in admin.php. | Jul 27, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-11677MEDIUM Cross-site scripting (XSS) vulnerability in Hashtopus 1.5g allows remote attackers to inject arbitrary web script or HTML via the query string to admin.php. | Jul 27, 2017 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hashtopus Project.
Media articles that mention a CVE ID that affects a product developed by Hashtopus Project — matched by CVE ID, not by vendor name.