Canteen-Management v1.0 – SQL Injection
## Exploit Title: Canteen-Management v1.0 - SQL Injection
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
## Exploit Title: Canteen-Management v1.0 - SQL Injection
# Exploit Title: Mediconta 3.7.27 - 'servermedicontservice' Unquoted Service Path
# Exploit Title: Gestionale Open 12.00.00 - 'DB_GO_80' Unquoted Service Path
# Exploit Title: Sysax Multi Server 6.95 - 'Password' Denial of Service (PoC)
# Exploit Title: eXtplorerpython eXtplorer_auth_bypass.py -t https://target.com
# Exploit Title: FlatCore CMS 2.1.1 -Stored Cross Site Scripting
# Exploit Title: Zentao Project Management System 17.0 - Authenticated Remote Code Execution (RCE)
# Exploit Title: Clansphere CMS 2011.4 - Stored Cross-Site Scripting (XSS)
# Exploit Title: Zoneminder v1.36.26 - Log Injection -> CSRF Bypass -> Stored Cross-Site Scripting (XSS)
# Exploit Title: WiFi Mouse 1.8.3.2 - Remote Code Execution (RCE)
# Exploit Title: Grafana
# Exploit Title: Webgrind 1.1 - Reflected Cross-Site Scripting (XSS) & Remote Command Execution (RCE)
# Exploit Title: WPN-XM Serverstack for Windows 0.8.6 - Multiple Vulnerabilities
# Exploit Title: Tftpd32_SE 4.60 - 'Tftpd32_svc' Unquoted Service Path
# Exploit Title: Explorer32++ 1.3.5.531 - Buffer overflow
# Exploit Title: Frhed (Free hex editor) v1.6.0 - Buffer overflow
# Exploit Title: Resource Hacker 3.6.0.92 - Buffer overflow
# Exploit Title: Hex Workshop v6.7 - Buffer overflow DoS
# Exploit Title: Scdbg 1.0 - Buffer overflow DoS
# Exploit Title: Desktop Central 9.1.0 - Multiple Vulnerabilities
# Exploit Title: Aero CMS v0.0.1 - SQL Injection (no auth)
# Exploit Title: Aero CMS v0.0.1 - PHP Code Injection (auth)
# Exploit Title: Atom CMS v2.0 - SQL Injection (no auth)
# Exploit Title: WebTareas 2.4 - SQL Injection (Unauthorised)
# Exploit Title: WebTareas 2.4 - Reflected XSS (Unauthorised)
# Exploit Title: WebTareas 2.4 - RCE (Authorized)
# Exploit Title: AVS Audio Converter 10.3 - Stack Overflow (SEH)
# Exploit Title: MiniDVBLinux
# Exploit Title: Fortinet Authentication Bypass v7.2.1 - (FortiOS, FortiProxy, FortiSwitchManager)
# Exploit Title: MiniDVBLinux 5.4 Simple VideoDiskRecorder Protocol SVDRP - Remote Code Execution (RCE)
# Exploit Title: MiniDVBLinux 5.4 - Change Root Password
# Exploit Title: MiniDVBLinux 5.4 - Unauthenticated Stream Disclosure
# Exploit Title: MiniDVBLinux 5.4 - Remote Root Command Injection
# Exploit Title: MiniDVBLinux 5.4 - Arbitrary File Read
# Exploit Title: "camp" Raspberry Pi camera server 1.0 - Authentication Bypass
# Exploit Title: NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi
# Exploit Title: Translatepress Multilinugal WordPress plugin < 2.3.3 - Authenticated SQL Injection
# Exploit Title: System Mechanic v15.5.0.61 - Arbitrary Read/Write
# Exploit Title: Online Diagnostic Lab Management System v1.0 - Remote Code Execution (RCE) (Unauthenticated)
# Exploit Title: D-Link DNR-322L
# Exploit Title: Human Resources Management System v1.0 - Multiple SQLi
# Exploit Title: Yoga Class Registration System v1.0 - Multiple SQLi
## Exploit Title: Employee Performance Evaluation System v1.0 - File Inclusion and RCE
## Exploit Title: Lavalite v9.0.0 - XSRF-TOKEN cookie File path traversal
# Exploit Title: NVFLARE < 2.1.4 - Unsafe Deserialization due to Pickle
# Exploit Title: GuppY CMS v6.00.10 - Remote Code Execution
# Exploit Title: DLink DIR 819 A1 - Denial of Service
# Exploit Title: Bus Pass Management System 1.0 - Cross-Site Scripting (XSS)
# Exploit Title: Password Manager for IIS v2.0 - XSS
# Exploit Title: Authenticated Sql Injection in ImpressCMS v1.4.3