qdPM 9.1 – Remote Code Execution (RCE) (Authenticated) (v2)
# Exploit Title: qdPM 9.1 - Remote Code Execution (RCE) (Authenticated)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: qdPM 9.1 - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: OpenCart v3.x Newsletter Module - Blind SQLi
# Exploit Title: m1k1o's Blog v.10 - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: SDT-CW3B1 1.1.0 - OS command injection
# Exploit Title: Survey Sparrow Enterprise Survey Software 2022 - Stored Cross-Site Scripting (XSS)
# Exploit Title: T-Soft E-Commerce 4 - 'UrunAdi' Stored Cross-Site Scripting (XSS)
# Exploit Title: T-Soft E-Commerce 4 - SQLi (Authenticated)
# Exploit Title: SolarView Compact 6.0 - OS Command Injection
# Exploit Title: Showdoc 2.10.3 - Stored Cross-Site Scripting (XSS)
# Exploit Title: F5 BIG-IP 16.0.x - Remote Code Execution (RCE)
# Exploit Title: College Management System - 'course_code' SQL Injection (Authenticated)
# Exploit Title: Royal Event Management System 1.0 - 'todate' SQL Injection (Authenticated)
# Exploit Title: TLR-2005KSH - Arbitrary File Delete
# Exploit Title: ImpressCMS v1.4.4 - Unrestricted File Upload
# Exploit Title: Microfinance Management System 1.0 - 'customer_number' SQLi
# Exploit Title: Akka HTTP Denial of Service via Nested Header Comments
# Exploit Title: WebTareas 2.4 - Blind SQLi (Authenticated)
# Exploit Title: USR IOT 4G LTE Industrial Cellular VPN Router 1.0.36 - Remote Root Backdoor
# Exploit Title: WordPress Plugin Advanced Uploader 4.2 - Arbitrary File Upload (Authenticated)
Exploit Title: Magento eCommerce CE v2.3.5-p2 - Blind SQLi
# Exploit Title: Bookeen Notea - Directory Traversal
# Exploit Title: Bitrix24 - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: CSZ CMS 1.3.0 - 'Multiple' Blind SQLi
# Exploit Title: SAP BusinessObjects Intelligence 4.3 - XML External Entity (XXE)
# Exploit Title: UDisk Monitor Z5 Phone - 'MonServiceUDisk.exe' Unquoted Service Path
# Exploit Title: TCQ - 'ITeCProteccioAppServer.exe' Unquoted Service Path
# Exploit Title: Wondershare Dr.Fone 11.4.10 - Insecure File Permissions
# Exploit Title: ManageEngine ADSelfService Plus Build 6118 - NTLMv2 Hash Exposure
# Exploit Title: Prime95 Version 30.7 build 9 - Remote Code Execution (RCE)
# Exploit Title: DLINK DIR850 - Insecure Access Control
# Exploit Title: DLINK DIR850 - Open Redirect
# Exploit Title: Cyclos 4.14.7 - DOM Based Cross-Site Scripting (XSS)
# Exploit Title: Cyclos 4.14.7 - 'groupId' DOM Based Cross-Site Scripting (XSS)
# Exploit Title: e107 CMS v3.2.1 - Multiple Vulnerabilities
# Exploit Title: ExifTool 12.23 - Arbitrary Code Execution
# Exploit Title: Wondershare Dr.Fone 12.0.7 - Privilege Escalation (ElevationService)
# Exploit Title: Wondershare Dr.Fone 12.0.7 - Remote Code Execution (RCE)
# Exploit Title: Apache CouchDB 3.2.1 - Remote Code Execution (RCE)
# Exploit Title: Anuko Time Tracker - SQLi (Authenticated)
# Exploit Title: Tenda HG6 v3.3.0 - Remote Command Injection
# Exploit Title: Google Chrome 78.0.3904.70 - Remote Code Execution
# Exploit Title: PyScript Remote Emscripten VMemory Python libraries
# Exploit Title: DLINK DAP-1620 A1 v1.01 - Directory Traversal
# Exploit Title: Explore CMS 1.0 - SQL Injection
#!/usr/bin/env python3
# Exploit Title: PHProjekt PhpSimplyGest v1.3.0 - Stored Cross-Site Scripting (XSS)
# Exploit Title: Beehive Forum - Account Takeover
# Exploit Title: MyBB 1.8.29 - Remote Code Execution (RCE) (Authenticated)
Exploit Title: WordPress Plugin Blue Admin 21.06.01 - Cross-Site Request Forgery (CSRF)
# Exploit Title: Joomla Plugin SexyPolling 2.1.7 - SQLi