Online Computer and Laptop Store 1.0 – Remote Code Execution (RCE)
#!/usr/bin/env python3
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
#!/usr/bin/env python3
## Title: Microsoft-Edge-(Chromium-based)-Webview2-1.0.1661.34-Spoofing-Vulnerability
# Exploit Title: Altenergy Power Control Software C1.2.5 - OS command injection
# Exploit Title: FortiRecorder 6.4.3 - Denial of Service
# Title: Adobe Connect 11.4.5 - Local File Disclosure
## Exploit Title: Microsoft Excel 365 MSO (Version 2302 Build 16.0.16130.20186) 64-bit - Remote Code Execution (RCE)
#!/usr/bin/env python3
# Exploit Title: Restaurant Management System 1.0 - SQL Injection
#Exploit Title: Google Chrome 109.0.5414.74 - Code Execution via missing lib file (Ubuntu)
# Exploit Title: ActFax 10.10 - Unquoted Path Services
# Exploit Title: Lucee Scheduled Job v1.0 - Command Execution
#!/usr/bin/env ruby
Exploit Title: ENTAB ERP 1.0 - Username PII leak
# Exploit Title: RSA NetWitness Platform 12.2 - Incorrect Access Control / Code Execution
# Exploit Title: Online Appointment System V1.0 - Cross-Site Scripting (XSS)
# Exploit Title: Medicine Tracker System v1.0 - Sql Injection
// Exploit Title: Goanywhere Encryption helper 7.1.1 - Remote Code Execution (RCE)
# Exploit Title: Suprema BioStar 2 v2.8.16 - SQL Injection
# Exploit Title: Stonesoft VPN Client 6.2.0 / 6.8.0 - Local Privilege Escalation
# Exploit Title: Symantec Messaging Gateway 10.7.4 - Stored Cross-Site Scripting (XSS)
# Exploit Title: Palo Alto Cortex XSOAR 6.5.0 - Stored Cross-Site Scripting (XSS)
## Exploit Title: Online-Pizza-Ordering -1.0 - Remote Code Execution (RCE)
# Exploit Title: X2CRM v6.6/6.9 - Stored Cross-Site Scripting (XSS) (Authenticated)
# Exploit Title: X2CRM v6.6/6.9 - Reflected Cross-Site Scripting (XSS) (Authenticated)
# Exploit Title: ZCBS/ZBBS/ZPBS v4.14k - Reflected Cross-Site Scripting (XSS)
Exploit Title: WebsiteBaker v2.13.3 - Cross-Site Scripting (XSS)
# Exploit Title: Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated)
# Exploit Title: ESET Service 16.0.26.0 - 'Service ekrn' Unquoted Service Path
#!/usr/bin/python3
Exploit Title: dotclear 2.25.3 - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: Docker based datastores for IBM Instana 241-2 243-0 - No Authentication
# Exploit Title: MAC 1200R - Directory Traversal
# Exploit Title: IBM Aspera Faspex 4.4.1 - YAML deserialization (RCE)
#!/usr/bin/python3
# Exploit Title: NotrinosERP 0.7 - Authenticated Blind SQL Injection
# Exploit Title: ChurchCRM 4.5.1 - Authenticated SQL Injection
# Exploit Title: Schneider Electric v1.0 - Directory traversal & Broken Authentication
# Exploit Title: Franklin Fueling Systems TS-550 - Exploit and Default Password
Exploit Title: Rukovoditel 3.3.1 - Remote Code Execution (RCE)
# Exploit Title: Snitz Forum v1.0 - Blind SQL Injection
# Exploit Title: Wondershare Dr Fone 12.9.6 - Privilege Escalation
# Exploit Title: EasyNas 1.1.0 - OS Command Injection
#---------------------------------------------------------
# Exploit Title: TitanFTP 2.0.1.2102 - Path traversal to Remote Code Execution (RCE)
# Exploit Title: Arris Router Firmware 9.1.103 - Remote Code Execution (RCE) (Authenticated)
#!/usr/bin/python3
## Exploit Title: atrocore 1.5.25 User interaction - Unauthenticated File upload - RCE
# Exploit Title: Art Gallery Management System Project in PHP v 1.0 - SQL injection
# Exploit Title: Simple Task Managing System v1.0 - SQL Injection (Unauthenticated)
# Exploit Title: Intern Record System v1.0 - SQL Injection (Unauthenticated)