Akaunting 3.1.8 – Server-Side Template Injection (SSTI)
# Exploit Title: Akaunting 3.1.8 - Server-Side Template Injection (SSTI)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Akaunting 3.1.8 - Server-Side Template Injection (SSTI)
# Exploit Title: FreePBX 16 - Remote Code Execution (RCE) (Authenticated)
Exploit Title: BWL Advanced FAQ Manager 2.0.3 - Authenticated SQL Injection
# Exploit Title: iMLog < 1.307 - Persistent Cross Site Scripting (XSS)
# Exploit Title : ElkArte Forum 1.1.9 - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: changedetection
#!/usr/bin/env python
# Exploit Title: Check Point Security Gateway - Information Disclosure (Unauthenticated)
# Title: Rocket LMS 1.9 - Persistent Cross Site Scripting (XSS)
# Exploit Title: Wordpress Theme XStore 9.3.8 - SQLi
# Exploit Title: Apache OFBiz 18.12.12 - Directory Traversal
# Exploit Title: Backdrop CMS 1.27.1 - Authenticated Remote Command Execution (RCE)
# Exploit Title: PopojiCMS 2.0.1 - Remote Command Execution
# Exploit Title: htmlLawed 1.2.5 - Remote Code Execution (RCE)
import requests
# Exploit Title: Plantronics Hub 3.25.1 – Arbitrary File Read
## Exploit Title: CrushFTP Directory Traversal
# Chyrp 2.5.2 - Stored Cross-Site Scripting (XSS)
# Leafpub 1.1.9 - Stored Cross-Site Scripting (XSS)
# Exploit Title: CE Phoenix Version 1.0.8.20 - Stored XSS
# Exploit Title: PyroCMS v3.0.1 - Stored XSS
# Exploit : Prison Management System Using PHP -SQL Injection Authentication Bypass
# Exploit Title: Clinic Queuing System 1.0 RCE
# Exploit Title: iboss Secure Web Gateway - Stored Cross-Site Scripting (XSS)
Elber Signum DVB-S/S2 IRD For Radio Networks 1.999 Authentication Bypass
Elber Signum DVB-S/S2 IRD For Radio Networks 1.999 Device Config
Elber Cleber/3 Broadcast Multi-Purpose Platform 1.0.0 Authentication Bypass
Elber Cleber/3 Broadcast Multi-Purpose Platform 1.0.0 Device Config
Elber Reble610 M/ODU XPIC IP-ASI-SDH Microwave Link Authentication Bypass
Elber Reble610 M/ODU XPIC IP-ASI-SDH Microwave Link Device Config
# Exploit Title: Palo Alto PAN-OS < v11.1.2-h3 - Command Injection and Arbitrary File Creation
# Exploit Title: FlatPress v1.3 - Remote Command Execution
# Exploit Title: Wordpress Plugin Background Image Cropper v1.2 - Remote Code Execution
# Exploit Title: SofaWiki 3.9.2 - Remote Command Execution (RCE) (Authenticated)
# Exploit Title: Laravel Framework 11 - Credential Leakage
# Exploit Title: Flowise 1.6.5 - Authentication Bypass
# Exploit Title: djangorestframework-simplejwt 5.3.1 - Information Disclosure
# Exploit Title: Jenkins 2.441 - Local File Inclusion
# Exploit Title: OpenClinic GA 5.247.01 - Information Disclosure
# Exploit Title: OpenClinic GA 5.247.01 - Path Traversal (Authenticated)
# Exploit Title: Savsoft Quiz v6.0 Enterprise - Persistent Cross-Site
# Exploit Title: Online Fire Reporting System SQL Injection Authentication Bypass
# Exploit Title: Stock Management System v1.0 - Unauthenticated SQL Injection
#!/usr/bin/env python3
# Exploit Title: GUnet OpenEclass E-learning platform 3.15 - 'certbadge.php' Unrestricted File Upload
# Exploit Title: MinIO < 2024-01-31T20-20-33Z - Privilege Escalation
# Exploit Title: Terratec dmx_6fire USB - Unquoted Service Path
# Exploit Title: Ray OS v2.6.3 - Command Injection RCE(Unauthorized)
# Exploit Title: HTMLy Version v2.9.6 - Stored XSS
# Exploit Title: Wordpress Plugin Playlist for Youtube - Stored Cross-Site Scripting (XSS)