Zoo Management System 1.0 – Unauthenticated RCE
# Exploit Title: Zoo Management System 1.0 - Unauthenticated RCE
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Zoo Management System 1.0 - Unauthenticated RCE
# Exploit Title: Moodle 4.3 'id' Insecure Direct Object Reference (IDOR)
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
# Exploit Title: Automatic-Systems SOC FL9600 FastLine - Directory Transversal
# Exploit Title: Automatic-Systems SOC FL9600 FastLine - The device contains hardcoded login and password for super a...
# Exploit Title: Executables Created with perl2exe malicious.pl
# Exploit Title: Wordpress Plugin Canto < 3.0.5 - Remote File Inclusion (RFI) and Remote Code Execution (RCE)
TEM Opera Plus FM Family Transmitter 35.45 Remote Code Execution
CSRF Change Forward Power:
# Exploit Title: Simple Inventory Management System v1.0 - 'email' SQL Injection
# Exploit Title: POC-CVE-2023-3244
# Exploit Title: taskhub 2.8.7 - SQL Injection
# Exploit Title: Online Shopping System Advanced
# Exploit Title: Flashcard Quiz App v1.0 - 'card' SQL Injection
# Exploit Title: FAQ Management System v1.0 - 'faq' SQL Injection
[+] Credits: John Page (aka hyp3rlinx)
[+] Credits: John Page (aka hyp3rlinx)
[+] Credits: John Page (aka hyp3rlinx)
[+] Credits: John Page (aka hyp3rlinx)
# Exploit Title: WEBIGniter v28.7.23 Stored Cross Site Scripting (XSS)
# Exploit Title: XAMPP v3.3.0 — '.ini' Buffer Overflow (Unicode + SEH)
[+] Credits: John Page (aka hyp3rlinx)
[+] Credits: John Page (aka hyp3rlinx)
# Exploit Title: Employee Management System v1 - 'email' SQL Injection
# Exploit Title: SureMDM On-premise < 6.31 - CAPTCHA Bypass User Enumeration
# Author: prodigiousMind
# Exploit Title: artifactory low-privileged blind sql injection
# Exploit Title: SISQUALWFM 7.1.319.103 Host Header Injection
# Exploit Title: metabase 0.46.6 - Pre-Auth Remote Code Execution
# Exploit Title: DS Wireless Communication Remote Code Execution
# Exploit Title: Splunk 9.0.4 - Information Disclosure
VIMESA VHF/FM Transmitter Blue Plus 9.7.1 (doreboot) Remote Denial Of Service
# Exploit Title: ManageEngine ADManager Plus Build < 7183 - Recovery Password Disclosure
# Exploit Title: Lost and Found Information System v1.0 - idor leads to Account Take over
# Exploit Title: Advanced Page Visit Counter 1.0 - Admin+ Stored Cross-Site
#!/usr/bin/expect -f
# Exploit Author: TOUHAMI KASBAOUI
# Exploit Title: Wordpress Augmented-Reality - Remote Code Execution Unauthenticated
# Exploit Title: Wordpress Seotheme - Remote Code Execution Unauthenticated
# Exploit Title: Rail Pass Management System - 'searchdata' Time-Based SQL Injection
# Exploit Title: Online Nurse Hiring System 1.0 - 'bookid' Time-Based SQL Injection
# Exploit Title: GYM MS - GYM Management System - Cross Site Scripting (Stored)
# Exploit Title: Curfew e-Pass Management System 1.0 - FromDate SQL
# Exploit Title: Clinic's Patient Management System 1.0 - Unauthenticated RCE
# Exploit Title: MISP 2.4.171 Stored XSS [CVE-2023-37307] (Authenticated)
# Exploit Title: WhatsUpGold 22.1.0 - Stored Cross-Site Scripting (XSS)
# Exploit Title: WebCatalog 48.4 - Arbitrary Protocol Execution