PopojiCMS Version 2.0.1 – Remote Command Execution
# Exploit Title: PopojiCMS Version : 2.0.1 Remote Command Execution
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: PopojiCMS Version : 2.0.1 Remote Command Execution
# Exploit Title: PrusaSlicer 2.6.1 - Arbitrary code execution on g-code export
# Exploit Title: Moodle Authenticated Time-Based Blind SQL Injection - "sort" Parameter
# Exploit Title: |Unauthenticated SQL injection in WBCE 1.6.0
# Exploit Title: WBCE CMS Version : 1.6.1 Remote Command Execution
# Exploit Title: Wordpress Plugin WP Video Playlist 1.1.1 - Stored Cross-Site Scripting (XSS)
# Exploit Title: AnyDesk 7.0.15 - Unquoted Service Path
# Exploit Title: Wordpress Theme Travelscape v1.0.3 - Arbitrary File Upload
# Exploit Title: Positron Broadcast Signal Processor TRA7005 v1.20 - Authentication Bypass
## Title: Human Resource Management System v1.0 - Multiple SQLi
## Title: Best Student Result Management System v1.0 - Multiple SQLi
# Exploit Title: Daily Expense Manager 1.0 - 'term' SQLi
# Exploit Title : Open Source Medicine Ordering System v1.0 - SQLi
# Exploit Title: ESET NOD32 Antivirus 17.0.16.0 - Unquoted Service Path
# Title: Computer Laboratory Management System v1.0 - Multiple-SQLi
# Exploit Title: Wordpress Plugin Alemha Watermarker 1.3.1 - Stored Cross-Site Scripting (XSS)
# Exploit Title: Simple Backup Plugin < 2.7.10 - Arbitrary File Download via Path Traversal
# Exploit Title: Online Hotel Booking In PHP 1.0 - Blind SQL Injection (Unauthenticated)
# Exploit Title: ASUS Control Center Express 01.06.15 - Unquoted Service Path
# Exploit Title: OpenCart Core 4.0.2.3 - 'search' SQLi
# Exploit Title: Rapid7 nexpose - 'nexposeconsole' Unquoted Service Path
# Exploit Title: GL-iNet MT6000 4.5.5 - Arbitrary File Download
# Exploit Title: Petrol Pump Management Software v1.0 - Remote Code Execution (RCE)
# Exploit Title: E-INSUARANCE v1.0 - Stored Cross Site Scripting (XSS)
# Exploit Title: Hospital Management System v1.0 - Stored Cross Site Scripting (XSS)
#############################################
Exploit Title: FoF Pretty Mail 1.1.2 - Local File Inclusion (LFI)
Exploit Title: FoF Pretty Mail 1.1.2 - Server Side Template Injection (SSTI)
# Exploit Title: LeptonCMS 7.0.0 - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: Employee Management System 1.0 - `txtfullname` and `txtphone` SQL Injection
# Exploit Title: Employee Management System 1.0 - `txtusername` and `txtpassword` SQL Injection (Admin Login)
# Exploit Title: Daily Habit Tracker 1.0 - Stored Cross-Site Scripting (XSS)
# Exploit Title: Daily Habit Tracker 1.0 - SQL Injection
# Exploit Title: Daily Habit Tracker 1.0 - Broken Access Control
# Exploit Title: Blood Bank v1.0 Stored Cross Site Scripting (XSS)
#EXPLOIT Elementor Website Builder < 3.12.2 - Admin+ SQLi
## Exploit Title: CE Phoenix v1.0.8.20 - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: Smart School 6.4.1 - SQL Injection
# Exploit Title: Wordpress Plugin - Membership For WooCommerce < v2.1.7 - Arbitrary File Upload to Shell (Unauthentic...
[+] Credits: John Page (aka hyp3rlinx)
# Exploit Title: Casdoor < v1.331.0 - '/api/set-password' CSRF
# Exploit Title: Gibbon LMS v26.0.00 - SSTI vulnerability
# Exploit Title: Axigen < 10.5.7 - Persistent Cross-Site Scripting
# Exploit Title: Asterisk AMI - Partial File Content & Path Disclosure (Authenticated)
# Exploit Title: Workout Journal App 1.0 - Stored XSS
# Exploit Title: Purei CMS 1.0 - SQL Injection
Exploit Title: Broken Access Control - on NodeBB v3.6.7
# Exploit Title: CVE-2024-27686: RouterOS-SMB-DOS
# Exploit Title: Siklu MultiHaul TG series - unauthenticated credential disclosure
# Exploit Title: [title] Dell Security Management Server versions prior to