Simple Library Management System 1.0 – ‘rollno’ SQL Injection
# Exploit Title: Simple Library Management System 1.0 - 'rollno' SQL Injection
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Simple Library Management System 1.0 - 'rollno' SQL Injection
# Exploit Title: CMSuno 1.7 - 'tgo' Stored Cross-Site Scripting (XSS) (Authenticated)
# Exploit Title: Moodle 3.9 - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: GFI Mail Archiver 15.1 - Telerik UI Component Arbitrary File Upload (Unauthenticated)
# Exploit Title: WordPress Plugin WP Customize Login 1.1 - 'Change Logo Title' Stored Cross-Site Scripting (XSS)
# Exploit Title: qdPM 9.1 - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: qdPM 9.2 - DB Connection String and Password Exposure (Unauthenticated)
# Exploit Title: Client Management System 1.1 - 'cname' Stored Cross-site scripting (XSS)
# Exploit Title: ApacheOfBiz 17.12.01 - Remote Command Execution (RCE) via Unsafe Deserialization of XMLRPC arguments
# Exploit Title: Hotel Management System 1.0 - Cross-Site Scripting (XSS) Arbitrary File Upload Remote Code Execution...
# Exploit Title: Men Salon Management System 1.0 - SQL Injection Authentication Bypass
# Exploit Title: Neo4j 3.4.18 - RMI based Remote Code Execution (RCE)
# Exploit Title: Online Hotel Reservation System 1.0 - 'Multiple' Cross-site scripting (XSS)
# Exploit Title: Panasonic Sanyo CCTV Network Camera 2.03-0x - 'Disable Authentication / Change Password' CSRF
# Exploit Title: Denver IP Camera SHO-110 - Unauthenticated Snapshot
# Exploit Title: Longjing Technology BEMS API 1.21 - Remote Arbitrary File Download
# Exploit Title: IntelliChoice eFORCE Software Suite 2.5.9 - Username Enumeration
# Exploit Title: Care2x Integrated Hospital Info System 2.7 - 'Multiple' SQL Injection
# Exploit Title: CloverDX 5.9.0 - Cross-Site Request Forgery (CSRF) to Remote Code Execution (RCE)
# Exploit Title: Oracle Fatwire 6.3 - Multiple Vulnerabilities
# Exploit Title: Event Registration System with QR Code 1.0 - Authentication Bypass & RCE
# Exploit Title: Denver Smart Wifi Camera SHC-150 - 'Telnet' Remote Code Execution (RCE)
# Exploit Title: TripSpark VEO Transportation - 'editOEN' Blind SQL Injection
# Exploit Title: PHP 7.3.15-3 - 'PHP_SESSION_UPLOAD_PROGRESS' Session Data Injection
# Exploit Title: Customer Relationship Management System (CRM) 1.0 - Sql Injection Authentication Bypass
# Exploit Title: Elasticsearch ECE 7.13.3 - Anonymous Database Dump
# Exploit Title: Leawo Prof. Media 11.0.0.1 - Denial of Service (DoS) (PoC)
# Exploit Title: NoteBurner 2.35 - Denial Of Service (DoS) (PoC)
# Exploit Title: XOS Shop 1.0.9 - 'Multiple' Arbitrary File Deletion (Authenticated)
# Exploit Title: ElasticSearch 7.13.3 - Memory disclosure
# Exploit Title: WordPress Plugin Simple Post 1.1 - 'Text field' Stored Cross-Site Scripting (XSS)
# Exploit Title: Microsoft SharePoint Server 2019 - Remote Code Execution (2)
# Exploit Title: KevinLAB BEMS 1.0 - Undocumented Backdoor Account
# Exploit Title: KevinLAB BEMS 1.0 - Unauthenticated SQL Injection / Authentication Bypass
# Exploit Title: KevinLAB BEMS 1.0 - File Path Traversal Information Disclosure (Authenticated)
# Exploit Title: CSZ CMS 1.2.9 - 'Multiple' Arbitrary File Deletion
# Exploit Title: WordPress Plugin KN Fix Your Title 1.0.1 - 'Separator' Stored Cross-Site Scripting (XSS)
# Exploit Title: Webmin 1.973 - 'run.cgi' Cross-Site Request Forgery (CSRF)
# Exploit Title: WordPress Plugin LearnPress 3.2.6.7 - 'current_items' SQL Injection (Authenticated)
# Exploit Title: WordPress Plugin LearnPress 3.2.6.8 - Privilege Escalation
# Exploit Title: WordPress Plugin Mimetic Books 0.2.13 - 'Default Publisher ID field' Stored Cross-Site Scripting (XSS)
# Exploit Title: PEEL Shopping 9.3.0 - 'id' Time-based SQL Injection
# Exploit Title: Argus Surveillance DVR 4.0 - Weak Password Encryption
# Exploit Title: ForgeRock Access Manager/OpenAM 14.6.3 - Remote Code Execution (RCE) (Unauthenticated)
# Exploit Title: Seagate BlackArmor NAS sg2000-2000.1331 - Command Injection
# Exploit Title: Aruba Instant 8.7.1.0 - Arbitrary File Modification
# Exploit Title: osCommerce 2.3.4.1 - Remote Code Execution (2)
# Exploit Title: WordPress Plugin Popular Posts 5.3.2 - Remote Code Execution (RCE) (Authenticated)
// clang-format off
import socket