Ghost CMS 5.59.1 – Arbitrary File Read
#!/usr/bin/env python3
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
#!/usr/bin/env python3
#!/usr/bin/env python3
#!/usr/bin/env python3
# Titles: Microsoft Virtual Hard Disk (VHDX) 11 - Remote Code Execution (RCE)
# Titles: Microsoft Edge (Chromium-based) 135.0.7049.114/.115 - Information Disclosure
allowing an attacker to inject and execute arbitrary JavaScript in a victim’s browser
#!/usr/bin/env python3
# Exploit Title: Xlight FTP 1.1 - Denial Of Service (DOS)
# Exploit Title: Invision Community
# Exploit Title: XWiki 14 - SQL Injection via getdeleteddocuments.vm
# Exploit Title: Mezzanine CMS 6.1.0 Stored Cross Site Scripting (XSS)
# Exploit Title: Linux PAM Environment - Variable Injection Local Privilege Escalation
# Exploit Title: Adobe ColdFusion 2023.6 - Remote File Read
# Exploit Title: Simple File List WordPress Plugin 4.2.2 - File Upload to RCE
# Exploit Title: Pie Register WordPress Plugin 3.7.1.4 - Authentication Bypass to RCE
# Titles: Microsoft Edge Windows 10 Version 1511 - Cross Site Scripting (XSS)
# Exploit Title: Joomla JS Jobs plugin 1.4.2 - SQL injection
#!/usr/bin/env ruby
# Exploit Title: LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS)
# Exploit Title: LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Operator Surname
# Exploit Title: LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS)
# Exploit Title: LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS)
# Exploit Title: LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via the Chat Transfer Function
# Exploit Title: LiveHelperChat
# Exploit Title: MikroTik RouterOS 7.19.1 - Reflected XSS
#!/usr/bin/env python3
# Titles: Microsoft Brokering File System Windows 11 Version 22H2 - Elevation of Privilege
# Exploit Title: PivotX v3.0.0 RC3 - Stored XSS to Remote Code Execution (RCE)
# Title: TOTOLINK N300RB 8.54 - Command Execution
#!/usr/bin/env python3
# Exploit Title : SugarCRM 14.0.0 - SSRF/Code Injection
# Exploit Title: White Star Software Protop 4.4.2-2024-11-27 - Local File Inclusion (LFI)
# Exploit Title: WP Publications WordPress Plugin 1.2 - Stored XSS
# Exploit Title : NodeJS 24.x - Path Traversal
#!/usr/bin/env python3
Exploit Title: Sudo chroot 1.9.17 - Local Privilege Escalation
# Exploit Title: ScriptCase 9.12.006 (23) - Remote Command Execution (RCE)
# Exploit Title: Sudo 1.9.17 Host Option - Elevation of Privilege
# Titles: Microsoft Outlook - Remote Code Execution (RCE)
# Exploit Title: Stacks Mobile App Builder 5.2.3 - Authentication Bypass via Account Takeover
#!/usr/bin/env python3
# Exploit Title: Wing FTP Server 7.4.3 - Unauthenticated Remote Code Execution (RCE)
# Exploit Title: gogs 0.13.0 - Remote Code Execution (RCE)
# Exploit Title: Moodle 4.4.0 - Authenticated Remote Code Execution