Teachers Record Management System 1.0 – ‘Multiple’ SQL Injection (Authenticated)
# Exploit Title: Teachers Record Management System 1.0 – Multiple SQL Injection (Authenticated)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Teachers Record Management System 1.0 – Multiple SQL Injection (Authenticated)
# Exploit Title: Teachers Record Management System 1.0 – 'email' Stored Cross-site Scripting (XSS)
# Exploit Title: CKEditor 3 - Server-Side Request Forgery (SSRF)
# Exploit Title: Brother BRPrint Auditor 3.0.7 - 'Multiple' Unquoted Service Path
# Exploit Title: Client Management System 1.1 - 'username' Stored Cross-Site Scripting (XSS)
# Exploit Title: Client Management System 1.1 - 'Search' SQL Injection
# Exploit Title: SysGauge 7.9.18 - ' SysGauge Server' Unquoted Service Path
# Exploit Title: Brother BRAgent 1.38 - 'WBA_Agent_Client' Unquoted Service Path
# Exploit Title: Polkit 0.105-26 0.117-2 - Local Privilege Escalation
# Exploit Title: Accela Civic Platform 21.1 - 'successURL' Cross-Site-Scripting (XSS)
# Exploit Title: Accela Civic Platform 21.1 - 'contactSeqNumber' Insecure Direct Object References (IDOR)
# Exploit Title: GLPI 9.4.5 - Remote Code Execution (RCE)
# Exploit Title: COVID19 Testing Management System 1.0 - 'State' Stored Cross-Site-Scripting (XSS)
# Exploit Title: Stock Management System 1.0 - 'user_id' Blind SQL injection (Authenticated)
# Exploit Title: Small CRM 3.0 - 'Authentication Bypass' SQL Injection
# Exploit Title : TextPattern CMS 4.8.7 - Remote Command Execution (Authenticated)
# Exploit Title: Spy Emergency 25.0.650 - Unquoted Service Path
# Exploit Title: OpenEMR 5.0.1.3 - 'manage_site_files' Remote Code Execution (Authenticated)
# Exploit Title: WibuKey Runtime 6.51 - 'WkSvW32.exe' Unquoted Service Path
# Exploit Title: Secure Notepad Private Notes 3.0.3 - Denial of Service (PoC)
# Exploit Title: Post-it 5.0.1 - Denial of Service (PoC)
# Exploit Title: Notex the best notes 6.4 - Denial of Service (PoC)
# Exploit Title: Tftpd64 4.64 - 'Tftpd32_svc' Unquoted Service Path
# Exploit Title: Accela Civic Platform 21.1 - 'servProvCode' Cross-Site-Scripting (XSS)
# Exploit Title: Cerberus FTP web Service 11 - 'svg' Stored Cross-Site Scripting (XSS)
# Exploit Title: Microsoft SharePoint Server 16.0.10372.20060 - 'GetXmlDataFromDataSource' Server-Side Request Forger...
# Exploit Title: OpenEMR 5.0.0 - Remote Code Execution (Authenticated)
# Exploit Title: WordPress Plugin Database Backups 1.2.2.6 - 'Database Backup Download' CSRF
# Exploit Title: Grocery crud 1.6.4 - 'order_by' SQL Injection
# Exploit Title: Solar-Log 500 2.8.2 - Incorrect Access Control
# Exploit Title: Solar-Log 500 2.8.2 - Unprotected Storage of Credentials
# Exploit Title: Zenario CMS 8.8.52729 - 'cID' Blind & Error based SQL injection (Authenticated)
# Exploit Title: WoWonder Social Network Platform 3.1 - Authentication Bypass
# Exploit Title: Student Result Management System 1.0 - 'class' SQL Injection
# Exploit Title: TextPattern CMS 4.8.7 - Stored Cross-Site Scripting (XSS)
# Exploit Title: memono Notepad Version 4.2 - Denial of Service (PoC)
# Exploit Title: Sticky Notes Widget Version 3.0.6 - Denial of Service (PoC)
# Exploit Title: n+otes 1.6.2 - Denial of Service (PoC)
# Exploit Title: Intelbras Router RF 301K - 'DNS Hijacking' Cross-Site Request Forgery (CSRF)
# Exploit Title : OpenCart 3.0.3.7 - 'Change Password' Cross-Site Request Forgery (CSRF)
# Exploit Title: OpenCart 3.0.3.6 - 'subject' Stored Cross-Site Scripting
# Exploit Title: WordPress Plugin visitors-app 0.3 - 'user-agent' Stored Cross-Site Scripting (XSS)
# Exploit Title: GravCMS 1.10.7 - Arbitrary YAML Write/Update (Unauthenticated) (2)
# Exploit Title: NBMonitor 1.6.8 - Denial of Service (PoC)
# Exploit Title: Nsauditor 3.2.3 - Denial of Service (PoC)
# Exploit Title: Backup Key Recovery 2.2.7 - Denial of Service (PoC)
# Exploit Title: WordPress Plugin wpDiscuz 7.0.4 - Remote Code Execution (Unauthenticated)
# Exploit Title: OptiLink ONT1GEW GPON 2.1.11_X101 Build 1127.190306 - Remote Code Execution (Authenticated)
# Exploit Title: Sticky Notes & Color Widgets 1.4.2 - Denial of Service (PoC)
# Exploit Title: WordPress Plugin Smart Slider-3 3.5.0.8 - 'name' Stored Cross-Site Scripting (XSS)