soosyze 2.0.0 – File Upload
## Title: soosyze 2.0.0 - File Upload
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
## Title: soosyze 2.0.0 - File Upload
# Exploit Title: GOM Player 2.3.90.5360 - Remote Code Execution (RCE)
# Exploit Title: Techview LA-5570 Wireless Gateway Home Automation Controller - Multiple Vulnerabilities
# Exploit Title: Axigen < 10.3.3.47, 10.2.3.12 - Reflected XSS
## Title: drupal-10.1.2 web-cache-poisoning-External-service-interaction
# Exploit Title: GOM Player 2.3.90.5360 - Buffer Overflow (PoC)
# Exploit Title: SyncBreeze 15.2.24 -'login' Denial of Service
# Exploit Title: Blood Donor Management System v1.0 - Stored XSS
# Exploit Title: Hyip Rio 2.1 - Arbitrary File Upload
# Exploit Title: NVClient v5.0 - Stack Buffer Overflow (DoS)
# Exploit Title: Credit Lite 1.5.4 - SQL Injection
# Exploit Title: Academy LMS 6.1 - Arbitrary File Upload
# Exploit Title: CSZ CMS 1.3.0 - Stored Cross-Site Scripting ('Photo URL' and 'YouTube URL' )
# Exploit Title: CSZ CMS 1.3.0 - Stored Cross-Site Scripting (Plugin 'Gallery')
# Exploit Title: AdminLTE PiHole < 5.18 - Broken Access Control
#Exploit title: Freefloat FTP Server 1.0 - 'PWD' Remote Buffer Overflow
#Exploit Title: Kingo ROOT 1.5.8 - Unquoted Service Path
# Exploit Title: FileMage Gateway 1.10.9 - Local File Inclusion
# Exploit Title : DLINK DPH-400SE - Exposure of Sensitive Information
## Title: Member Login Script 3.3 - Client-side desync
# Exploit Title: WP Statistics Plugin = 5.0:
## Title: Bus Reservation System-1.1 Multiple-SQLi
# Exploit Title: SPA-Cart eCommerce CMS 1.9.0.3 - Reflected XSS
# Exploit Title: User Registration & Login and User Management System v3.0 - Stored Cross-Site Scripting (XSS)
# Exploit Title: User Registration & Login and User Management System v3.0 - SQL Injection (Unauthenticated)
# Exploit Title: Uvdesk 1.1.4 - Stored XSS (Authenticated)
# Exploit Title: TSplus 16.0.2.14 - Remote Access Insecure Files and Folders Permissions
# Exploit Title: TSplus 16.0.0.0 - Remote Work Insecure Files and Folders Permissions
# Exploit Title: TSPlus 16.0.0.0 - Remote Work Insecure Credential storage
# Exploit Title: Inosoft VisiWin 7 2022-2.1 - Insecure Folders Permissions
# Exploit Title: Dolibarr Version 17.0.1 - Stored XSS
#Exploit Title: EuroTel ETL3100 Transmitter Default Credentials
# Exploit Title: EuroTel ETL3100 - Transmitter Authorization Bypass (IDOR)
# Exploit Title: EuroTel ETL3100 - Transmitter Unauthenticated Config/Log Download
# Exploit Title: PHPJabbers Business Directory Script v3.2 - Multiple Vulnerabilities
# Exploit Title: Crypto Currency Tracker (CCT) 9.5 - Admin Account Creation (Unauthenticated)
# Exploit Title: Color Prediction Game v1.0 - SQL Injection
# Exploit Title: Global - Multi School Management System Express v1.0- SQL Injection
# Exploit Title: OVOO Movie Portal CMS v3.3.3 - SQL Injection
# Exploit Title: Taskhub CRM Tool 2.8.6 - SQL Injection
#!/usr/bin/python3
# Exploit Title: OutSystems Service Studio 11.53.30 - DLL Hijacking
# Exploit Title: Adlisting Classified Ads 2.14.0 - WebPage Content Information Disclosure
# Exploit Title: Lucee 5.4.2.17 - Authenticated Reflected XSS
# Exploit Title: Pyro CMS 3.9 - Server-Side Template Injection (SSTI) (Authenticated)
# Exploit Title: mooSocial 3.1.8 - Reflected XSS
# Exploit Title: Social-Commerce 3.1.6 - Reflected XSS
# Exploit Title: PHPJabbers Vacation Rental Script 4.0 - CSRF