BlackCat CMS 1.3.6 – ‘Multiple’ Stored Cross-Site Scripting (XSS)
# Exploit Title: BlackCat CMS 1.3.6 - 'Multiple' Stored Cross-Site Scripting (XSS)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: BlackCat CMS 1.3.6 - 'Multiple' Stored Cross-Site Scripting (XSS)
# Exploit Title: RemoteClinic 2 - 'Multiple' Cross-Site Scripting (XSS)
# Exploit Title: Tenda D151 & D301 - Configuration Download (Unauthenticated)
# Exploit Title: rconfig 3.9.6 - Arbitrary File Upload to Remote Code Execution (Authenticated) (2)
# Exploit Title: OpenEMR 5.0.2.1 - Remote Code Execution
# Exploit Title: Adtran Personal Phone Manager 10.8.1 - 'emailAddress' Stored Cross-Site Scripting (XSS)
# Exploit Title: Adtran Personal Phone Manager 10.8.1 - 'Multiple' Reflected Cross-Site Scripting (XSS)
# Exploit Title: Adtran Personal Phone Manager 10.8.1 - DNS Exfiltration
# Exploit Title: Hasura GraphQL 1.3.3 - Denial of Service
# Exploit Title: Hasura GraphQL 1.3.3 - Local File Read
# Exploit Title: Hasura GraphQL 1.3.3 - Service Side Request Forgery (SSRF)
# Exploit Title: GetSimple CMS My SMTP Contact Plugin 1.1.1 - CSRF to RCE
# Exploit Title: Horde Groupware Webmail 5.2.22 - Stored XSS
# Exploit Title: Tileserver-gl 3.0.0 - 'key' Reflected Cross-Site Scripting (XSS)
# Exploit Title: htmly 2.8.0 - 'description' Stored Cross-Site Scripting (XSS)
# Exploit Title: glFTPd 2.11a - Remote Denial of Service
# Exploit Title: Digital Crime Report Management System 1.0 - SQL Injection (Authentication Bypass)
# Exploit Title: CITSmart ITSM 9.1.2.22 - LDAP Injection
# Exploit Title: CITSmart ITSM 9.1.2.27 - 'query' Time-based Blind SQL Injection (Authenticated)
# Exploit Title: Genexis PLATINUM 4410 2.1 P4410-V2-1.28 - RCE
# Exploit Title: MariaDB 10.2 /MySQL - 'wsrep_provider' OS Command Execution
# Exploit Title: jQuery 1.2 - Cross-Site Scripting (XSS)
# Exploit Title: jQuery 1.0.3 - Cross-Site Scripting (XSS)
# Exploit Title: Simple Student Information System 1.0 - SQL Injection (Authentication Bypass)
# Exploit Title: Blitar Tourism 1.0 - Authentication Bypass SQLi
# Exploit Title: ExpressVPN VPN Router 1.0 - Router Login Panel's Integer Overflow
# Exploit Title: vsftpd 2.3.4 - Backdoor Command Execution
# Exploit Title: PrestaShop 1.7.6.7 - 'location' Blind Sql Injection
# Exploit Title: CMSimple 5.2 - 'External' Stored XSS
# Exploit Title: DMA Radius Manager 4.4.0 - Cross-Site Request Forgery (CSRF)
# Exploit Title: Composr 10.0.36 - Remote Code Execution
# Exploit Title: Linux Kernel 5.4 - 'BleedingTooth' Bluetooth Zero-Click Remote Code Execution
# Exploit Title: Atlassian Jira Service Desk 4.9.1 - Unrestricted File Upload to XSS
# Exploit Title: Composr CMS 10.0.36 - Cross Site Scripting
# Exploit Title: Dell OpenManage Server Administrator 9.4.0.0 - Arbitrary File Read
# Exploit Title: Google Chrome 86.0.4240 V8 - Remote Code Execution
# Exploit Title: Google Chrome 81.0.4044 V8 - Remote Code Execution
# Exploit Title: Mini Mouse 9.3.0 - Local File inclusion / Path Traversal
# Exploit Title: Rockstar Service - Insecure File Permissions
# Exploit Title: Simple Food Website 1.0 - Authentication Bypass
# Exploit Title: Basic Shopping Cart 1.0 - Authentication Bypass
# Exploit Title: OpenEMR 4.1.0 - 'u' SQL Injection
# Exploit Title: Mini Mouse 9.2.0 - Remote Code Execution
# Exploit Title: Mini Mouse 9.2.0 - Path Traversal
# Exploit Title: ZBL EPON ONU Broadband Router 1.0 - Remote Privilege Escalation
# Exploit Title: F5 BIG-IP 16.0.x - iControl REST Remote Code Execution (Unauthenticated)
# Exploit Title: Latrix 0.6.0 – 'txtaccesscode' SQL Injection
# Exploit Title: ScadaBR 1.0 - Arbitrary File Upload (Authenticated) (1)
# Exploit Title: ScadaBR 1.0 - Arbitrary File Upload (Authenticated) (2)