Wondershare MirrorGo 2.0.11.346 – Insecure File Permissions
# Exploit Title: Wondershare MirrorGo 2.0.11.346 - Insecure File Permissions
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Wondershare MirrorGo 2.0.11.346 - Insecure File Permissions
# Exploit Title: Simple Real Estate Portal System 1.0 - 'id' SQL Injection
# Title: Air Cargo Management System v1.0 - SQLi
# Exploit Title: aaPanel 6.8.21 - Directory Traversal (Authenticated)
# Exploit Title: Adobe ColdFusion 11 - LDAP Java Object Deserialization Remode Code Execution (RCE)
# Exploit Title: Student Record System 1.0 - 'cid' SQLi (Authenticated)
# Exploit Title: CL ScadaFlex II SCADA Controllers SC-1/SC-2 1.03.07 Remote File CRUD
# Exploit Title: WebHMI 4.1.1 - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: WebHMI 4.1 - Stored Cross Site Scripting (XSS) (Authenticated)
# Exploit Title: Microweber CMS v1.2.10 Local File Inclusion (Authenticated)
# Exploit Title: HMA VPN 5.3 - Unquoted Service Path
# Exploit Title: WordPress Plugin Perfect Survey - 1.5.1 - SQLi (Unauthenticated)
# Exploit Title: Cab Management System 1.0 - 'id' SQLi (Authenticated)
# Exploit Title: Microweber 1.2.11 - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: Cab Management System 1.0 - Remote Code Execution (RCE) (Authenticated)
Exploit Title: Thinfinity VirtualUI 2.5.41.0 - IFRAME Injection
Exploit Title: Thinfinity VirtualUI 2.5.26.2 - Information Disclosure
# Exploit Title: WordPress Plugin WP User Frontend 3.5.25 - SQLi (Authenticated)
# Exploit Title: Cyclades Serial Console Server 3.3.0 - Local Privilege Escalation
# Exploit Title: FileCloud 21.2 - Cross-Site Request Forgery (CSRF)
# Exploit Title: Dbltek GoIP - Local File Inclusion
# Exploit Title: Microsoft Gaming Services 2.52.13001.0 - Unquoted Service Path
# Title: WordPress Plugin MasterStudy LMS 2.7.5 - Unauthenticated Admin Account Creation
# Exploit Title: WordPress Plugin dzs-zoomsounds - Remote Code Execution (RCE) (Unauthenticated)
# Exploit Title: Hotel Druid 3.0.3 - Remote Code Execution (RCE)
# Exploit Title: Wondershare Dr.Fone 11.4.9 - 'DFWSIDService' Unquoted Service Path
# Exploit Title: Wondershare MobileTrans 3.5.9 - 'ElevationService' Unquoted Service Path
# Exploit Title: Wondershare FamiSafe 1.0 - 'FSService' Unquoted Service Path
# Exploit Title: Wondershare UBackit 2.0.5 - 'wsbackup' Unquoted Service Path
# Exploit Title: Fortinet Fortimail 7.0.1 - Reflected Cross-Site Scripting (XSS)
#Exploit Title: TOSHIBA DVD PLAYER Navi Support Service - 'TNaviSrv' Unquoted Service Path
#Exploit Title: Bluetooth Application 5.4.277 - 'BlueSoleilCS' Unquoted Service Path
#Exploit Title: Intel(R) Management Engine Components 6.0.0.1189 - 'LMS' Unquoted Service Path
#Exploit Title: File Sanitizer for HP ProtectTools 5.0.1.3 - 'HPFSService' Unquoted Service Path
#Exploit Title: Connectify Hotspot 2018 'ConnectifyService' - Unquoted Service Path
# Exploit Title: Multi-Vendor Online Groceries Management System 1.0 - 'id' Blind SQL Injection
# Exploit Title: Simple Student Quarterly Result/Grade System 1.0 - SQLi Authentication Bypass
# Exploit Title: ServiceNow - Username Enumeration
# Exploit Title: H3C SSL VPN - Username Enumeration
# Exploit Title: TeamSpeak 3.5.6 - Insecure File Permissions
# Exploit Title: Network Video Recorder NVR304-16EP - Reflected Cross-Site Scripting (XSS) (Unauthenticated)
# Exploit Title: Emerson PAC Machine Edition 9.80 Build 8695 - 'TrapiServer' Unquoted Service Path
# Exploit Title: WordPress Plugin Error Log Viewer 1.1.1 - Arbitrary File Clearing (Authenticated)
# Exploit Title: Accounting Journal Management System 1.0 - 'id' SQLi (Authenticated)
# Exploit Title: Subrion CMS 4.2.1 - Cross Site Request Forgery (CSRF) (Add Amin)
# Exploit Title: Kyocera Command Center RX ECOSYS M2035dn - Directory Traversal File Disclosure (Unauthenticated)
# Exploit Title: Cain & Abel 4.9.56 - Unquoted Service Path
# Exploit Title: Hospital Management Startup 1.0 - 'loginid' SQLi
# Exploit Title: Home Owners Collection Management System 1.0 - Account Takeover (Unauthenticated)
# Exploit Title: Home Owners Collection Management System 1.0 - Remote Code Execution (RCE) (Authenticated)