Paid Memberships Pro v2.9.8 (WordPress Plugin) – Unauthenticated SQL Injection
#!/usr/bin/env python
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
#!/usr/bin/env python
# Exploit Title: GeoVision Camera GV-ADR2701 - Authentication Bypass
## Exploit Title: Enlightenment v0.25.3 - Privilege escalation
# Exploit Title: GitLab v15.3 - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: Splashtop 8.71.12001.0 - Unquoted Service Path
# Exploit Title: AD Manager Plus 7122 - Remote Code Execution (RCE)
Exploit Title: XCMS v1.83 - Remote Command Execution (RCE)
# Exploit Title: Prizm Content Connect v10.5.1030.8315 - XXE
Exploit Title: perfSONAR v4.4.5 - Partial Blind CSRF
#!/usr/bin/env python
# Exploit Title: Reprise Software RLM v14.2BL4 - Cross-Site Scripting (XSS)
Exploit Title: Hughes Satellite Router HX200 v8.3.1.14 - Remote File Inclusion
# Exploit Title: Apache 2.4.x - Buffer Overflow
[+] Exploit Title: Centos Web Panel 7 v0.9.8.1147 - Unauthenticated Remote Code Execution (RCE)
# Exploit Title: Nexxt Router Firmware 42.103.1.5095 - Remote Code Executio=
## Title: AimOne Video Converter V2.04 Build 103 - Buffer Overflow (DoS)
# Exploit Title: PMB 7.4.6 - SQL Injection
# Exploit Title: Yahoo User Interface library (YUI2) TreeView v2.8.2 - Multiple Reflected Cross Site Scripting (XSS)
# Exploit Title: NetIQ/Microfocus Performance Endpoint v5.1 - remote root/SYSTEM exploit
# Exploit Title: ELSI Smart Floor V3.3.3 - Stored Cross-Site Scripting (XSS)
Exploit Title: EQ Enterprise management system v2.2.0 - SQL Injection
# Exploit Title: ASKEY RTF3505VW-N1 - Privilege escalation
# Title: Wordpress Plugin WooCommerce v7.1.0 - Remote Code Execution(RCE)
# Exploit Title: qubes-mirage-firewall v0.8.3 - Denial Of Service (DoS)
# Exploit Title: Router backdoor - ProLink PRS1841 PLDT Home fiber
# Exploit Title: CoolerMaster MasterPlus 1.8.5 - 'MPService' Unquoted Service Path
# Exploit Title: Bludit 3-14-1 Plugin 'UploadPlugin' - Remote Code Execution (RCE) (Authenticated)
## Exploit Title: Senayan Library Management System v9.0.0 - SQL Injection
# Exploit Title: Spitfire CMS 1.0.475 - PHP Object Injection
# Exploit Title: rconfig 3.9.7 - Sql Injection (Authenticated)
# Exploit Title: Judging Management System v1.0 - Remote Code Execution (RCE)
# Exploit Title: Judging Management System v1.0 - Authentication Bypass
# Exploit Title: Cacti v1.2.22 - Remote Command Execution (RCE)
# Exploit Title: SOUND4 Server Service 4.1.102 - Local Privilege Escalation
# Exploit Title: SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Cross-Site Request Forgery
# Exploit Title: SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Authorization Bypass (IDOR)
# Exploit Title: SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Denial Of Service (DoS)
# Exploit Title: SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Authentication Bypass
# Exploit Title: SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Directory Traversal File Write Exploit
# Exploit Title: SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Remote Command Execution (RCE)
# Exploit Title: SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Unauthenticated Factory Reset
## Exploit Title: Bangresto 1.0 - SQL Injection
# Exploit Title: Textpattern 4.8.8 - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: Dreamer CMS v4.0.0 - SQL Injection
## Title: ClicShopping v3.402 - Cross-Site Scripting (XSS)
# Exploit Title: myBB forums 1.8.26 - Stored Cross-Site Scripting (XSS)
# Exploit Title: ZTE-H108NS - Stack Buffer Overflow (DoS)
# Exploit Title: Router ZTE-H108NS - Authentication Bypass
# Exploit Title: Boa Web Server v0.94.14 - Authentication Bypass