Active Super Shop CMS v2.5 – HTML Injection Vulnerabilities
# Exploit Title: Active Super Shop CMS v2.5 - HTML Injection Vulnerabilities
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Active Super Shop CMS v2.5 - HTML Injection Vulnerabilities
Exploit Title: PaulPrinting CMS - (Search Delivery) Cross Site Scripting
#Exploit Title: Dooblou WiFi File Explorer 1.13.3 - Multiple Vulnerabilities
Exploit Title: Webile v1.0.1 - Multiple Cross Site Scripting
Exploit Title: Aures Booking & POS Terminal - Local Privilege Escalation
Exploit Title: PaulPrinting CMS - Multiple Cross Site Web Vulnerabilities
Exploit Title: RWS WorldServer 11.7.3 - Session Token Enumeration
# Exploit Title: PimpMyLog v1.7.14 - Improper access control
# Exploit Title: phpfm v1.7.9 - Authentication type juggling
# Exploit Title: Joomla! com_booking component 2.4.9 - Information Leak (Account enumeration)
## Title: Vaidya-Mitra 1.0 - Multiple SQLi
#Exploit Title: Backdrop Cms v1.25.1 - Stored Cross-Site Scripting (XSS)
#Exploit Title: CmsMadeSimple v2.2.17 - session hijacking via Server-Side Template Injection (SSTI)
#Exploit Title: CmsMadeSimple v2.2.17 - Remote Code Execution (RCE)
#Exploit Title: CmsMadeSimple v2.2.17 - Stored Cross-Site Scripting (XSS)
## Title: Statamic 4.7.0 - File-Inclusion
# Exploit Title: ABB FlowX v4.00 - Exposure of Sensitive Information
Exploit Title: Blackcat Cms v1.4 - Stored XSS
Exploit Title: Blackcat Cms v1.4 - Remote Code Execution (RCE)
# Exploit Title: TP-Link TL-WR740N - Authenticated Directory Transversal
# Exploit Title: Hikvision Hybrid SAN Ds-a71024 Firmware - Multiple Remote Code Execution
# Exploit Title: XAMPP 8.2.4 - Unquoted Path
#!/usr/bin/env python3
# Exploit Title: News Portal v4.0 - SQL Injection (Unauthorized)
Exploit Title: ProjeQtOr Project Management System V10.4.1 - Multiple XSS
[+] Exploit Title: Cisco UCS-IMC Supervisor 2.2.0.0 - Authentication Bypass
Exploit Title: Admidio v4.2.10 - Remote Code Execution (RCE)
# Exploit Title: WinterCMS < 1.2.3 - Persistent Cross-Site Scripting
#Exploit Title: Pluck v4.7.18 - Remote Code Execution (RCE)
# Exploit Title: Netlify CMS 2.10.192 - Stored Cross-Site Scripting (XSS)
# Exploit Title: Spring Cloud 3.2.2 - Remote Command Execution (RCE)
# Exploit Title: MiniTool Partition Wizard ShadowMaker v.12.7 - Unquoted Service Path
# Exploit Title: MiniTool Partition Wizard ShadowMaker v.12.7 - Unquoted Service Path
# Exploit Title: Frappe Framework (ERPNext) 13.4.0 - Remote Code Execution (Authenticated)
# Exploit Title: BuildaGate5library v5 - Reflected Cross-Site Scripting (XSS)
#Exploit Title: Ateme TITAN File 3.9 - SSRF File Enumeration
# Exploit Title: AVG Anti Spyware 7.5 - Unquoted Service Path
# Exploit Title: Game Jackal Server v5 - Unquoted Service Path
# Exploit Title: Faculty Evaluation System v1.0 - SQL Injection
## Title: Microsoft Outlook Microsoft 365 MSO (Version 2306 Build 16.0.16529.20100) 32-bit - Remote Code Execution
## Title: Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution
# Exploit Title: Gila CMS 1.10.9 - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: Lost and Found Information System v1.0 - SQL Injection
## Title:Microsoft Edge 114.0.1823.67 (64-bit) - Information Disclosure
#Exploit Title: Piwigo v13.7.0 - Stored Cross-Site Scripting (XSS) (Authenticated)
# Exploit Title: Car Rental Script 1.8 - Stored Cross-site scripting (XSS)
# Exploit Title: Beauty Salon Management System v1.0 - SQLi
Exploit Title: Rukovoditel 3.4.1 - Multiple Stored XSS
# Exploit Title: Sales of Cashier Goods v1.0 - Cross Site Scripting (XSS)