Vianeos OctoPUS 5 – ‘login_user’ SQLi
# Exploit Title: Vianeos OctoPUS 5 - 'login_user' SQLi
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Vianeos OctoPUS 5 - 'login_user' SQLi
# Exploit Title: phpAbook 0.9i - SQL Injection
# Exploit Title: Apache Superset 1.1.0 - Time-Based Account Enumeration
# Exploit Title: Simple Traffic Offense System 1.0 - 'Multiple' Stored Cross Site Scripting (XSS)
# Exploit Title: Doctors Patients Management System 1.0 - SQL Injection (Authentication Bypass)
# Exploit Title: ES File Explorer 4.1.9.7.4 - Arbitrary File Read
# Exploit Title: WordPress Plugin YOP Polls 6.2.7 - Stored Cross Site Scripting (XSS)
# Exploit Title: Atlassian Jira Server/Data Center 8.16.0 - Reflected Cross-Site Scripting (XSS)
# Exploit Title: Netgear WNAP320 2.0.3 - 'macAddress' Remote Code Execution (RCE) (Unauthenticated)
# Exploit Title: SAPSprint 7.60 - 'SAPSprint' Unquoted Service Path
# Exploit Title: Seeddms 5.1.10 - Remote Command Execution (RCE) (Authenticated)
# Exploit Title: Simple Client Management System 1.0 - 'uemail' SQL Injection (Unauthenticated)
# Exploit Title: VMware vCenter Server RCE 6.5 / 6.7 / 7.0 - Remote Code Execution (RCE) (Unauthenticated)
# Exploit Title: Adobe ColdFusion 8 - Remote Command Execution (RCE)
# Exploit Title: TP-Link TL-WR841N - Command Injection
# Exploit Title: WordPress Plugin WP Google Maps 8.1.11 - Stored Cross-Site Scripting (XSS)
# Exploit Title: WordPress Plugin Poll, Survey, Questionnaire and Voting system 1.5.2 - 'date_answers' Blind SQL Inje...
# Exploit Title: Online Library Management System 1.0 - 'Search' SQL Injection
# Exploit Title: Online Library Management System 1.0 - Arbitrary File Upload Remote Code Execution (Unauthenticated)
# Exploit Title: Simple CRM 3.0 - 'email' SQL injection (Authentication Bypass)
# Exploit Title: Responsive Tourism Website 3.1 - Remote Code Execution (RCE) (Unauthenticated)
# Exploit Title: Phone Shop Sales Managements System 1.0 - Insecure Direct Object Reference (IDOR)
# Exploit Title: OpenEMR 5.0.1.7 - 'fileName' Path Traversal (Authenticated)
# Exploit Title: Wise Care 365 5.6.7.568 - 'WiseBootAssistant' Unquoted Service Path
# Exploit Title: Solaris SunSSH 11.0 x86 - libpam Remote Root (3)
# Exploit Title: iFunbox 4.2 - 'Apple Mobile Device Service' Unquoted Service Path
# Exploit Title: Websvn 2.6.0 - Remote Code Execution (Unauthenticated)
# Exploit Title: Simple CRM 3.0 - 'Change user information' Cross-Site Request Forgery (CSRF)
# Exploit Title: Simple CRM 3.0 - 'name' Stored Cross site scripting (XSS)
# Exploit Title: Lexmark Printer Software G2 Installation Package 1.8.0.0 - 'LM__bdsvc' Unquoted Service Path
# Exploit Title: Customer Relationship Management System (CRM) 1.0 - Remote Code Execution
# Exploit Title: Remote Mouse GUI 3.008 - Local Privilege Escalation
# Exploit Title: ICE Hrm 29.0.0.OS - 'Account Takeover' Cross-Site Request Forgery (CSRF)
# Exploit Title: ICE Hrm 29.0.0.OS - 'xml upload' Stored Cross-Site Scripting (XSS)
# Exploit Title: Dlink DSL2750U - 'Reboot' Command Injection
# Exploit Title: Node.JS - 'node-serialize' Remote Code Execution (3)
# Exploit Title: Unified Office Total Connect Now 1.0 – 'data' SQL Injection
# Exploit Title: Sync Breeze 13.6.18 - 'Multiple' Unquoted Service Path
# Exploit Title: Disk Savvy 13.6.14 - 'Multiple' Unquoted Service Path
# Exploit Title: Dup Scout 13.5.28 - 'Multiple' Unquoted Service Path
# Exploit Title: VX Search 13.5.28 - 'Multiple' Unquoted Service Path
# Exploit Title: Zoho ManageEngine ServiceDesk Plus MSP 9.4 - User Enumeration
# Exploit Title: Workspace ONE Intelligent Hub 20.3.8.0 - 'VMware Hub Health Monitoring Service' Unquoted Service Path
# Exploit Title: Online Shopping Portal 3.1 - Remote Code Execution (Unauthenticated)
# Exploit Title: DiskPulse 13.6.14 - 'Multiple' Unquoted Service Path
# Exploit Title: Disk Sorter Server 13.6.12 - 'Disk Sorter Server' Unquoted Service Path
# Exploit Title: Disk Sorter Enterprise 13.6.12 - 'Disk Sorter Enterprise' Unquoted Service Path
# Exploit Title: Cotonti Siena 0.9.19 - 'maintitle' Stored Cross-Site Scripting
# Exploit Title: OpenEMR 5.0.1.3 - '/portal/account/register.php' Authentication Bypass