Ecommerse v1.0 – Cross-Site Scripting (XSS)
## Title: Ecommerse v1.0 - Cross-Site Scripting (XSS)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
## Title: Ecommerse v1.0 - Cross-Site Scripting (XSS)
# Exploit Title: Covenant v0.5 - Remote Code Execution (RCE)
# Exploit Title: Virtual Reception v1.0 - Web Server Directory Traversal
#Exploit Title: Lavasoft web companion 4.1.0.409 - 'DCIservice' Unquoted Service Path
## Exploit Title: Concrete5 CME v9.1.3 - Xpath injection
# Exploit Title: Device Manager Express 7.8.20002.47752 - Remote Code Execution (RCE)
# Exploit Title: CrowdStrike Falcon AGENT 6.44.15806 - Uninstall without Installation Token
# Exploit Title: 4images 1.9 - Remote Command Execution (RCE)
# Exploit Title: LISTSERV 17 - Reflected Cross Site Scripting (XSS)
# Exploit Title: LISTSERV 17 - Insecure Direct Object Reference (IDOR)
# Exploit Title: Shoplazza 1.1 - Stored Cross-Site Scripting (XSS)
# Exploit Title: Zillya Total Security 3.0.2367.0 - Local Privilege Escalation
# Exploit Title: WPForms 1.7.8 - Cross-Site Scripting (XSS)
# Exploit Title: Eve-ng 5.0.1-13 - Stored Cross-Site Scripting (XSS)
# Exploit Title: WP All Import v3.6.7 - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: Book Store Management System 1.0.0 - Stored Cross-Site Scripting (XSS)
# Exploit Title: Human Resource Management System - SQL Injection (unauthenticated)
# Exploit Title: Inbit Messenger v4.9.0 - Unauthenticated Remote SEH Overflow
# Exploit Title: Inbit Messenger v4.9.0 - Unauthenticated Remote Command Execution (RCE)
# Exploit Title: Outline V1.6.0 - Unquoted Service Path
# Exploit Title: DSL-124 Wireless N300 ADSL2+ - Backup File Disclosure
# Exploit Title: Uniview NVR301-04S2-P4 - Reflected Cross-Site Scripting (XSS)
# Exploit Title: Internet Download Manager v6.41 Build 3 - Remote Code Execution (RCE)
# Exploit Title: Helmet Store Showroom v1.0 - SQL Injection
# Exploit Title: Revenue Collection System v1.0 - Remote Code Execution (RCE)
## Exploit Title: Beauty-salon v1.0 - Remote Code Execution (RCE)
# Exploit Title: Pega Platform 8.1.0 - Remote Code Execution (RCE)
#Title: VMware Workstation 15 Pro - Denial of Service
# Exploit Title: YouPHPTube
# Exploit Title: SuperMailer v11.20 - Buffer overflow DoS
# Exploit Title: Online shopping system advanced 1.0 - Multiple
# Exploit Title: Jetpack 11.4 - Cross Site Scripting (XSS)
# Exploit Title: HDD Health 4.2.0.112 - 'HDDHealth' Unquoted Service Path
# Exploit Title: SugarSync 4.1.3 - 'SugarSync Service' Unquoted Service Path
# Exploit Title: Tapo C310 RTSP server v1.3.0- Unauthorised Video Stream Access
# Exploit Title: BoxBilling
# Exploit Title: Label Studio 1.5.0 - Authenticated Server Side Request Forgery (SSRF)
# Exploit Title: Subrion CMS 4.2.1 - Stored Cross-Site Scripting (XSS)
#Exploit Title: X-Skipper-Proxy v0.13.237 - Server Side Request Forgery (SSRF)
# Exploit Title: ZKTeco ZEM/ZMM 8.88 - Missing Authentication
# Exploit Title: OPSWAT Metadefender Core - Privilege Escalation
// Exploit Title: Tunnel Interface Driver - Denial of Service
# Exploit Title: Moodle LMS 4.0 - Cross-Site Scripting (XSS)
## Title: Social-Share-Buttons v2.2.3 - SQL Injection
# Exploit Title: Hashicorp Consul v1.0 - Remote Command Execution (RCE)
# Exploit Title: ReQlogic v11.3 - Reflected Cross-Site Scripting (XSS)
# Exploit Title: iBooking v1.0.8 - Arbitrary File Upload
## Title: Senayan Library Management System v9.5.0 - SQL Injection
## Title: rukovoditel 3.2.1 - Cross-Site Scripting (XSS)
## Exploit Title: Canteen-Management v1.0 - XSS-Reflected