PCMan FTP Server 2.0 – ‘pwd’ Remote Buffer Overflow
# Exploit Title: PCMan FTP Server 2.0 - 'pwd' Remote Buffer Overflow
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: PCMan FTP Server 2.0 - 'pwd' Remote Buffer Overflow
# Exploit Title: TP-Link TL-WR740N UnAuthenticated Directory Transversal
# Exploit Title: TP-LINK TL-WR740N - Multiple HTML Injection Vulnerabilities
Electrolink FM/DAB/TV Transmitter (login.htm/mail.htm) Credentials Disclosure
Electrolink FM/DAB/TV Transmitter (controlloLogin.js) Credentials Disclosure
Electrolink FM/DAB/TV Transmitter (Login Cookie) Authentication Bypass
#!/usr/bin/env python
Electrolink FM/DAB/TV Transmitter Unauthenticated Remote DoS
Electrolink FM/DAB/TV Transmitter Pre-Auth MPFS Image Remote Code Execution
# ***************************************************************************************************
# Exploit Title: Academy LMS 6.2 - SQL Injection
## Title: 101 News-1.0 Multiple-SQLi
# Exploit Title: Grocy
# Exploit Title: GoAhead Web Server 2.5 - 'goform/formTest' Multiple HTML Injection Vulnerabilities
# Exploit Title: Proxmox VE TOTP Brute Force
RoyalTSX 6.0.1 RTSZ File Handling Heap Memory Corruption PoC
# Exploit Title: 7 Sticky Notes v1.9 - OS Command Injection
## Title: Equipment Rental Script-1.0 - SQLi
# Exploit Title: Blood Bank & Donor Management System using v2.2 - Stored XSS
# Exploit Title: Bank Locker Management System - SQL Injection
# Exploit Title: Typora v1.7.4 - OS Command Injection
## Title: Fundraising Script-1.0 SQLi
## Title: PHP Shopping Cart-4.2 Multiple-SQLi
#Exploit Title: Ricoh Printer Directory and File Exposure
#!/usr/bin/env python3
# Exploit Title: Ruijie Reyee Wireless Router firmware version B11P204 - MITM Remote Code Execution (RCE)
## Title: Online ID Generator 1.0 - Remote Code Execution (RCE)
# Exploit Title: Clcknshop 1.0.0 - SQL Injection
Exploit Title: Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Denial Of Service
#!/usr/bin/env python
#---------------------------------------------------------
# Exploit Title: Minio 2022-07-29T19-40-48Z - Path traversal
# Exploit Title: Wordpress Plugin Masterstudy LMS - 3.0.17 - Unauthenticated Instructor Account Creation
## Title: WEBIGniter v28.7.23 File Upload - Remote Code Execution
# Exploit Title: Media Library Assistant Wordpress Plugin - RCE and LFI
Exploit Title: coppermine-gallery 1.6.25 RCE
# Exploit Title: Wordpress Sonaar Music Plugin 4.7 - Stored XSS
# Exploit Title: Cacti 1.2.24 - Authenticated command injection when using SNMP options
#!/usr/bin/python3
# Exploit Title: Atcom 2.7.x.x - Authenticated Command Injection
Exploit Title: Webedition CMS v2.9.8.8 - Blind SSRF
## Title: Limo Booking Software v1.0 - CORS
## Title: Shuttle-Booking-Software v1.0 - Multiple-SQLi
# Exploit Title: OpenPLC WebServer 3 - Denial of Service
#!/usr/bin/env python3
# Exploit Title: SPA-Cart eCommerce CMS 1.9.0.3 - SQL Injection
## Title: Jorani v1.0.3-(c)2014-2023 - XSS Reflected & Information Disclosure
# Exploit Title: Wordpress Plugin Elementor < 3.5.5 - Iframe Injection
# Exploit Title: Wp2Fac v1.0 - OS Command Injection