ReyeeOS 1.204.1614 – MITM Remote Code Execution (RCE)
# Exploit Title: ReyeeOS 1.204.1614 - MITM Remote Code Execution (RCE)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: ReyeeOS 1.204.1614 - MITM Remote Code Execution (RCE)
# Exploit Title: Adiscon LogAnalyzer v.4.1.13 - Cross Site Scripting
# Exploit Title: WordPress Plugin Ninja Forms 3.6.25 - Reflected XSS (Authenticated)
# Exploit Title: Joomla JLex Review 6.0.1 - Reflected XSS
# Exploit Title: Ozeki 10 SMS Gateway 10.3.208 - Arbitrary File Read (Unauthenticated)
# Exploit Title: JLex GuestBook 1.6.4 - Reflected XSS
# Exploit Title: PHPJabbers Shuttle Booking Software 1.0 - Reflected XSS
# Exploit Title: PHPJabbers Service Booking Script 1.0 - Reflected XSS
# Exploit Title: PHPJabbers Night Club Booking 1.0 - Reflected XSS
# Exploit Title: PHPJabbers Cleaning Business 1.0 - Reflected XSS
# Exploit Title: PHPJabbers Taxi Booking 2.0 - Reflected XSS
# Exploit Title: PHPJabbers Rental Property Booking 2.0 - Reflected XSS
# Exploit Title: Academy LMS 6.0 - Reflected XSS
# Exploit Title: WordPress adivaha Travel Plugin 2.3 - SQL Injection
# Exploit Title: Online Matrimonial Website System v3.3 - Code Execution via malicious SVG file upload
#!/bin/bash
# Exploit Title: Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Event Access
# Exploit Title: Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Post Access via IDOR
Exploit Title: Webutler v3.2 - Remote Code Execution (RCE)
Exploit Title: Webedition CMS v2.9.8.8 - Remote Code Execution (RCE)
Exploit Title: Webedition CMS v2.9.8.8 - Stored XSS
# Exploit Title: WordPress adivaha Travel Plugin 2.3 - Reflected XSS
# Exploit Title: WordPress Plugin Forminator 1.24.6 - Unauthenticated Remote Command Execution
# Exploit Title: Xlight FTP Server 3.9.3.6 - 'Stack Buffer Overflow' (DOS)
# Exploit Title: Joomla Solidres 2.13.3 - Reflected XSS
# Exploit Title: Uvdesk v1.1.3 - File Upload Remote Code Execution (RCE) (Authenticated)
# Exploit Title: Joomla iProperty Real Estate 4.1.1 - Reflected XSS
# Exploit Title: General Device Manager 2.5.2.2 - Buffer Overflow (SEH)
# Exploit Title: RosarioSIS 10.8.4 - CSV Injection
# Exploit Title: Keeper Security desktop 16.10.2 & Browser Extension 16.5.4 - Password Dumping
#Exploit Title: zomplog 3.9 - Remote Code Execution (RCE)
Exploit Title: Zomplog 3.9 - Cross-site scripting (XSS)
# Exploit Title: Availability Booking Calendar v1.0 - Multiple Cross-site scripting (XSS)
# Exploit Title: Perch v3.2 - Persistent Cross Site Scripting (XSS)
# Exploit Title: mooDating 1.2 - Reflected Cross-site scripting (XSS)
# Exploit Title: Joomla HikaShop 4.7.4 - Reflected XSS
#Exploit Title: October CMS v3.4.4 - Stored Cross-Site Scripting (XSS) (Authenticated)
# Exploit Title: Joomla VirtueMart Shopping-Cart 4.0.12 - Reflected XSS
#!/usr/bin/python3
# Exploit Title: GreenShot 1.2.10 - Insecure Deserialization Arbitrary Code Execution
# Exploit Title: copyparty v1.8.6 - Reflected Cross Site Scripting (XSS)
# Exploit Title: copyparty 1.8.2 - Directory Traversal
# Exploit Title: mRemoteNG v1.77.3.1784-NB - Cleartext Storage of Sensitive Information in Memory
Exploit Title: Perch v3.2 - Remote Code Execution (RCE)
Exploit Title: Perch v3.2 - Stored XSS
# Exploit Title: pfSense v2.7.0 - OS Command Injection
## Title: Microsoft Office 365 Version 18.2305.1222.0 - Elevation of Privilege + RCE.
# Exploit Title: Wifi Soft Unibox Administration 3.0 & 3.1 Login Page - Sql Injection
# Exploit Title: RaidenFTPD 2.4.4005 - Buffer Overflow (SEH)
# Exploit Title: Boom CMS v8.0.7 - Cross Site Scripting