PostgreSQL 9.6.1 – Remote Code Execution (RCE) (Authenticated)
# Exploit Title: PostgreSQL 9.6.1 - Remote Code Execution (RCE) (Authenticated)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: PostgreSQL 9.6.1 - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: Dell EMC Networking PC5500 firmware versions 4.1.0.22 and Cisco Sx / SMB - Information Disclosure
# Exploit Title: Binwalk v2.3.2 - Remote Command Execution (RCE)
// Exploit Title: Control Web Panel 7 (CWP7) v0.9.8.1147 - Remote Code Execution (RCE)
# Exploit Title: Responsive FileManager 9.9.5 - Remote Code Execution (RCE)
# Exploit Title: GNU screen v4.9.0 - Privilege Escalation
# Exploit Title: itech TrainSmart r1044 - SQL injection
# Exploit Title: BTCPay Server v1.7.4 - HTML Injection
# Exploit Title: ERPNext 12.29 - Cross-Site Scripting (XSS)
## Exploit Title: ImageMagick 7.1.0-49 - DoS
# Exploit Title: Answerdev 1.0.3 - Account Takeover
# Exploit Title: SOUND4 LinkAndShare Transmitter 1.1.2 - Format String Stack Buffer Overflow
# Exploit Title: CKEditor 5 35.4.0 - Cross-Site Scripting (XSS)
# Exploit Title: ImageMagick 7.1.0-49 - Arbitrary File Read
# Exploit Title: Apache Tomcat 10.1 - Denial Of Service
#!/usr/bin/python3
# Exploit Title: Provide Server v.14.4 XSS - CSRF & Remote Code Execution (RCE)
#Exploit Author: XWorm Trojan 2.1 - Null Pointer Derefernce DoS
## Exploit Title: pimCore v5.4.18-skeleton - Sensitive Cookie with Improper SameSite Attribute
## Title: ChiKoi-1.0 SQLi
## Title: Windows 11 10.0.22000 - Backup service Privilege Escalation
# Exploit Title: Metform Elementor Contact Form Builder v3.1.2 - Unauthenticated Stored Cross-Site Scripting (XSS)
# Exploit Title: Nacos 2.0.3 - Access Control vulnerability
# Exploit Title: HotKey Clipboard 2.1.0.6 - Privilege Escalation Unquoted Service Path
## Exploit Title: Zstore 6.5.4 - Reflected Cross-Site Scripting (XSS)
fprintf(stderr, "usage: %s xserver:display [safe_addr]\n\n",
# Exploit Title: Chromacam 4.0.3.0 - PsyFrameGrabberService Unquoted Service Path
## Exploit Title: SLIMSV 9.5.2 - Cross-Site Scripting (XSS)
# Exploit Title: Microsoft Exchange Active Directory Topology 15.02.1118.007 - 'Service MSExchangeADTopology' Unquote...
# Exploit Title: MyBB 1.8.32 - Chained LFI Remote Code Execution (RCE) (Authenticated)
# Exploit Title: Art Gallery Management System Project v1.0 - Reflected Cross-Site Scripting (XSS)
# Exploit Title: Art Gallery Management System Project v1.0 - SQL Injection (cid) Unauthenticated
# Exploit Title: Art Gallery Management System Project v1.0 - SQL Injection (editid) authenticated
#!/usr/bin/env bash
# Exploit Title: SQL Monitor 12.1.31.893 - Cross-Site Scripting (XSS)
# Exploit Title: AmazCart CMS 3.4 - Cross-Site-Scripting (XSS)
# Exploit Title: ERPGo SaaS 3.9 - CSV Injection
# Exploit Title: Active eCommerce CMS 6.5.0 - Stored Cross-Site Scripting (XSS)
## Exploit Title: ManageEngine Access Manager Plus 4.3.0 - File-path-traversal
# Exploit Title: Grand Theft Auto III/Vice City Skin File v1.1 - Buffer Overflow
# Exploit Title: sleuthkit 4.11.1 - Command Injection
# Exploit Title: Roxy WI v6.1.0.0 - Improper Authentication Control
# ADVISORY INFORMATION
# ADVISORY INFORMATION
# ADVISORY INFORMATION
# ADVISORY INFORMATION
# Exploit Title: GLPI Activity v3.1.0 - Authenticated Local File Inclusion on Activity plugin
# ADVISORY INFORMATION
# Exploit Title: GLPI Cartography Plugin v6.0.0 - Unauthenticated Remote Code Execution (RCE)