Vishesh Auto Index 3.1 – ‘fid’ SQL Injection
# Exploit Title: Vishesh Auto Index 3.1 - 'fid' SQL Injection
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Vishesh Auto Index 3.1 - 'fid' SQL Injection
# Exploit Title: Wordpress Plugin Support Board 1.2.3 - Cross-Site Scripting
# Exploit Title: Rukovoditel Project Management CRM 2.3 - 'path' SQL Injection
# Exploit Title: MV Video Sharing Software 1.2 - 'searchname' SQL Injection
# Exploit Title: GIU Gallery Image Upload 0.3.1 - 'category' SQL Injection
# Exploit Title: Heatmiser Wifi Thermostat 1.7 - Credential Disclosure
Windows: FSCTL_FIND_FILES_BY_SID Information Disclosure
# CVE-2018-17456
# Exploit Title: Academic Timetable Final Build 7.0a-7.0b - 'id' SQL Injection
# Exploit Title: FLIR AX8 Thermal Camera 1.32.16 - Arbitrary File Disclosure
# Exploit Title: Snes9K 0.0.9z - Buffer Overflow (SEH)
# Exploit Title: FLIR Brickstream 3D+ 2.1.742.1842 - Config File Disclosure
# Exploit Title: Academic Timetable Final Build 7.0b - Cross-Site Request Forgery (Add Admin)
# Exploit Title: AlchemyCMS 4.1 - Cross-Site Scripting
# Exploit Title: FLIR AX8 Thermal Camera 1.32.16 - Remote Code Execution
# Exploit Title: College Notes Management System 1.0 - 'user' SQL Injection
# Exploit Title: Advanced HRM 1.6 - Remote Code Execution
# Exploit Title: MaxOn ERP Software 8.x-9.x - 'nomor' SQL Injection
# Exploit Title: FLIR AX8 Thermal Camera 1.32.16 - RTSP Stream Disclosure
FLIR Systems FLIR Brickstream 3D+ Unauthenticated RTSP Stream Disclosure
# Exploit Title: Centos Web Panel 0.9.8.480 Multiple Vulnerabilities
[+] Credits: John Page (aka hyp3rlinx)
# Exploit Title: KORA 2.7.0 - SQL Injection
# Exploit Title: HaPe PKH 1.1 - 'id' SQL Injection
# Exploit Title: LUYA CMS 1.0.12 - Cross-Site Scripting
# Exploit Title: Phoenix Contact WebVisit 2985725 - Authentication Bypass
# Exploit Title: HaPe PKH 1.1 - Cross-Site Request Forgery (Update Admin)
# Exploit Title: CAMALEON CMS 2.4 - Cross-Site Scripting
# Exploit Title: HaPe PKH 1.1 - Arbitrary File Upload
# Exploit Title: SugarCRM 6.5.26 - Cross-Site Scripting
## Shell command injection
## Password stored in plaintext
Directory Traversal
# Exploit Title: Wikidforum 2.20 - Cross-Site Scripting
# Exploit Title: WAGO 750-881 01.09.18 - Cross-Site Scripting
# Exploit Title: E-Registrasi Pencak Silat 18.10 - 'id_partai' SQL Injection
# Exploit Title: Microsoft SQL Server Management Studio 17.9 - XML External Entity Injection
# Title: jQuery-File-Upload 9.22.0 - Arbitrary File Upload
# Exploit Title: Microsoft SQL Server Management Studio 17.9 - '.xel' XML External Entity Injection
# Exploit Title: Phoenix Contact WebVisit 6.40.00 - Password Disclosure
# Exploit Title: Microsoft SQL Server Management Studio 17.9 - '.xmla' XML External Entity Injection
# Exploit Title: FileZilla 3.33 Buffer-Overflow (PoC)
# Exploit Title: RouterOS Remote Rooting
Heap corruption can occur when the WhatsApp mobile application receives a malformed RTP packet.
# Exploit Title: Wikidforum 2.20 - 'select_sort' SQL Injection
# Exploit Title: Free MP3 CD Ripper 2.8 - '.wma' Buffer Overflow (SEH) (DEP Bypass)