WordPress Plugin Easy Cookie Policy 1.6.2 – Broken Access Control to Stored XSS
# Exploit Title: WordPress Plugin Easy Cookie Policy 1.6.2 - Broken Access Control to Stored XSS
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: WordPress Plugin Easy Cookie Policy 1.6.2 - Broken Access Control to Stored XSS
# Exploit Title: ProtonVPN 1.26.0 - Unquoted Service Path
# Exploit Title: WordPress Plugin amministrazione-aperta 3.7.3 - Local File Read - Unauthenticated
# Exploit Title: ICEHRM 31.0.0.0S - Cross-site Request Forgery (CSRF) to Account Takeover
# Exploit Title: iRZ Mobile Router - CSRF to RCE
# Exploit Title: Ivanti Endpoint Manager 4.6 - Remote Code Execution (RCE)
# Exploit Author: bzyo (@bzyo_)
# Exploit Title: ICT Protege GX/WX 2.08 - Stored Cross-Site Scripting (XSS)
# Exploit Title: ICT Protege GX/WX 2.08 - Client-Side SHA1 Password Hash Disclosure
# Exploit Title: Wordpress Plugin iQ Block Country 1.2.13 - Arbitrary File Deletion via Zip Slip (Authenticated)
# Exploit Title: Moodle 3.11.5 - SQLi (Authenticated)
# Exploit Title: Pluck CMS 4.7.16 - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: Tiny File Manager 2.4.6 - Remote Code Execution (RCE)
# Exploit Title: Apache APISIX 2.12.1 - Remote Code Execution (RCE)
# Exploit Title: Baixar GLPI Project 9.4.6 - SQLi
# Exploit Title: VIVE Runtime Service - 'ViveAgentService' Unquoted Service Path
# Exploit Title: Seowon SLR-120 Router - Remote Code Execution (Unauthenticated)
# Exploit Title: Tdarr 2.00.15 - Command Injection
# Exploit Title: McAfee® Safe Connect VPN - Unquoted Service Path Elevation Of Privilege
# Exploit Title: BattlEye 0.9 - 'BEService' Unquoted Service Path
# Exploit Title: Zabbix 5.0.17 - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: Sony playmemories home - 'PMBDeviceInfoProvider' Unquoted Service Path
# Exploit Title: WOW21 5.0.1.9 - 'Service WOW21_Service' Unquoted Service Path
# Exploit Title: Sandboxie-Plus 5.50.2 - 'Service SbieSvc' Unquoted Service Path
# Exploit Title: Webmin 1.984 - Remote Code Execution (Authenticated)
# Exploit Title: Cobian Backup 0.9 - Unquoted Service Path
# Exploit Title: Audio Conversion Wizard v2.01 - Buffer Overflow
# Exploit Title: Printix Client 1.3.1106.0 - Privilege Escalation
# Exploit Title: Wondershare Dr.Fone 12.0.18 - 'Wondershare InstallAssist' Unquoted Service Path
// Exploit Title: Linux Kernel 5.8 < 5.16.11 - Local Privilege Escalation (DirtyPipe)
# Exploit Title: Spring Cloud Gateway 3.1.0 - Remote Code Execution (RCE)
# Exploit Title: part-db 0.5.11 - Remote Code Execution (RCE)
# Exploit Title: Attendance and Payroll System v1.0 - Remote Code Execution (RCE)
# Exploit Title: Attendance and Payroll System v1.0 - SQLi Authentication Bypass
# Exploit Title: Hasura GraphQL 2.2.0 - Information Disclosure
# Exploit Title: Private Internet Access 3.3 - 'pia-service' Unquoted Service Path
# Exploit Title: Cloudflare WARP 1.4 - Unquoted Service Path
# Exploit Title: Malwarebytes 4.5 - Unquoted Service Path
# Exploit Title: Foxit PDF Reader 11.0 - Unquoted Service Path
# Exploit Title: Xerte 3.10.3 - Directory Traversal (Authenticated)
# Exploit Title: Xerte 3.9 - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: Prowise Reflect v1.0.9 - Remote Keystroke Injection
# Exploit Title: Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting (XSS)
# Exploit Title: Printix Client 1.3.1106.0 - Remote Code Execution (RCE)
# Exploit Title: Cipi Control Panel 3.1.15 - Stored Cross-Site Scripting (XSS) (Authenticated)
# Exploit Title: Cobian Reflector 0.9.93 RC1 - 'Password' Denial of Service (PoC)
# Exploit Title: Cobian Backup 11 Gravity 11.2.0.582 - 'Password' Denial of Service (PoC)
# Exploit Title: Cobian Backup Gravity 11.2.0.582 - 'CobianBackup11' Unquoted Service Path
// Exploit Title: Casdoor 1.13.0 - SQL Injection (Unauthenticated)
# Exploit Title: WAGO 750-8212 PFC200 G2 2ETH RS Privilege Escalation