Loaded Commerce 6.6 – Client-Side Template Injection(CSTI)
# Exploit Title: Loaded Commerce 6.6 Client-Side Template Injection(CSTI)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Loaded Commerce 6.6 Client-Side Template Injection(CSTI)
# Exploit Title: Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
Exploit Title: TranzAxis 3.2.41.10.26 - Stored Cross-Site Scripting (XSS) (Authenticated)
# Exploit Title: Gitea 1.24.0 - HTML Injection
# Exploit Title: VeeVPN 1.6.1 - 'VeePNService' Unquoted Service Path
# Exploit Title: Chamilo LMS 1.11.24 - Remote Code Execution (RCE)
# Exploit Title: SOPlanning 1.52.01 (Simple Online Planning Tool) - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: dizqueTV 1.5.3 - Remote Code Execution (RCE)
# Exploit Title: openSIS 9.1 - SQLi (Authenticated)
# Exploit Title: reNgine 2.2.0 - Command Injection (Authenticated)
#!/usr/bin/env python3
# Exploit Title: Invesalius 3.1 - Remote Code Execution (RCE)
# Exploit Title: Stored XSS in Gitea
# Exploit Title: Stored XSS in NoteMark
Elber ESE DVB-S/S2 Satellite Receiver 1.5.x Authentication Bypass
Elber ESE DVB-S/S2 Satellite Receiver 1.5.x Device Config
Elber Wayber Analog/Digital Audio STL 4.00 Authentication Bypass
Elber Wayber Analog/Digital Audio STL 4.00 Device Config
# Exploit Title: HughesNet HT2000W Satellite Modem (Arcadyan httpd 1.0) - Password Reset
# Exploit Title: Remote Command Execution | Aurba 501
# Exploit Title: Stored XSS in Calibre-web
# Exploit Title: Stored XSS Vulnerability via File Name
# Exploit Title: Ivanti vADC 9.9 - Authentication Bypass
# Exploit Title: Oracle Database 12c Release 1 - Unquoted Service Path
# Exploit Title: SolarWinds Kiwi Syslog Server 9.6.7.1 - Unquoted Service Path
#Exploit Title: Genexus Protection Server 9.7.2.10 - 'protsrvservice' Unquoted Service Path Service Path
# Exploit Title: Devika v1 - Path Traversal via 'snapshot_path' Parameter
# Exploit Title: Bonjour Service - 'mDNSResponder.exe' Unquoted Service
# Exploit Title: Customer Support System 1.0 - (XSS) Cross-Site
# Exploit Title: Stored XSS in Microweber
# Exploit Title: Azon Dominator - Affiliate Marketing Script - SQL Injection
# Exploit Title: xhibiter nft marketplace SQLI
# Exploit Title: Poultry Farm Management System v1.0 - Remote Code Execution (RCE)
# Exploit Title: Flatboard 3.2 - Stored Cross-Site Scripting (XSS) (Authenticated)
# Exploit Title: SolarWinds Platform 2024.1 SR1 - Race Condition
# Exploit Title: Automad 2.0.0-alpha.4 - Stored Cross-Site Scripting (XSS)
# Exploit Title: Life Insurance Management Stored System- cross-site scripting (XSS)
# Exploit Title: Persistent XSS in Carbon Forum 5.9.0 (Stored)
# Exploit Title: Persistent XSS in XMB 1.9.12.06
# Exploit Title: Life Insurance Management System- SQL injection vulnerability.
# Exploit Title: PHP Windows Remote Code Execution (Unauthenticated)
# Exploit Title: WP-UserOnline 2.88.0 - Stored Cross Site Scripting (XSS) (Authenticated)
# Exploit Title: SQL Injection Vulnerability in Boelter Blue System Management (version 1.3)
# Exploit Title: Sitefinity 15.0 - Cross-Site Scripting (XSS)
# Exploit Title: Serendipity 2.5.0 - Remote Code Execution (RCE)
# Exploit Title: Dotclear 2.29 - Remote Code Execution (RCE)
# Exploit Title: Monstra CMS 3.0.4 - Remote Code Execution (RCE)
# Exploit Title: WBCE CMS v1.6.2 - Remote Code Execution (RCE)
# Exploit Title: CMSimple 5.15 - Remote Command Execution
# Exploit Title: appRain CMF 4.0.5 - Remote Code Execution (RCE) (Authenticated)