phpPgAdmin 7.13.0 – COPY FROM PROGRAM Command Execution (Authenticated)
# Exploit Title: phpPgAdmin 7.13.0 - COPY FROM PROGRAM Command Execution (Authenticated)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: phpPgAdmin 7.13.0 - COPY FROM PROGRAM Command Execution (Authenticated)
# Exploit Title: Zabbix 3.4.7 - Stored XSS
# Exploit Title: DD-WRT 45723 - UPNP Buffer Overflow (PoC)
# Exploit Title: CourseMS 2.1 - 'name' Stored XSS
# Exploit Title: GetSimple CMS 3.3.16 - Reflected XSS to RCE
# Exploit Title: Openlitespeed 1.7.9 - 'Notes' Stored Cross-Site Scripting
# Exploit Title: WordPress Plugin WP Super Cache 1.7.1 - Remote Code Execution (Authenticated)
# Exploit Title: vsftpd 3.0.3 - Remote Denial of Service
# Exploit Title: TP-Link Devices - 'setDefaultHostname' Stored Cross-site Scripting (Unauthenticated)
# Exploit Title: Concrete5 8.5.4 - 'name' Stored XSS
# Exploit Title: Equipment Inventory System 1.0 - 'multiple' Stored XSS
# Exploit Title: Budget Management System 1.0 - 'Budget title' Stored XSS
# Exploit Title: Novel Boutique House-plus 3.5.1 - Arbitrary File Download
# Exploit Title: SyncBreeze 10.1.16 - XML Parsing Stack-based Buffer Overflow
# Exploit Title: GetSimple CMS Custom JS Plugin 0.1 - 'customhs_js_content' Cross-Site Request Forgery
# Title: Regis Inventory And Monitoring System 1.0 - 'Item List' Persistent Cross-Site Scripting
# Exploit Title: Moodle 3.10.3 - 'label' Persistent Cross Site Scripting
# Exploit Title: Ovidentia 6 - 'id' SQL injection (Authenticated)
# Exploit Title: Linksys EA7500 2.0.8.194281 - Cross-Site Scripting
# Exploit Title: Genexis Platinum-4410 P4410-V2-1.31A - 'start_addr' Persistent Cross-Site Scripting
# Exploit Title: Dolibarr ERP/CRM 11.0.4 - File Upload Restrictions Bypass (Authenticated RCE)
# Exploit Title: Ext2Fsd v0.68 - 'Ext2Srv' Unquoted Service Path
# Exploit Title: MyBB 1.8.25 - Poll Vote Count SQL Injection
# Exploit Title: Hotel And Lodge Management System 1.0 - 'Customer Details' Stored XSS
# Exploit Title: Hi-Rez Studios 5.1.6.3 - 'HiPatchService' Unquoted Service Path
# Exploit Title: ELAN Touchpad 15.2.13.1_X64_WHQL - 'ETDService' Unquoted Service Path
# Exploit Title: ActivIdentity 8.2 - 'ac.sharedstore' Unquoted Service Path
# Exploit Title: Elodea Event Collector 4.9.3 - 'ElodeaEventCollectorService' Unquoted Service Path
# Exploit Title: Codiad 2.8.4 - Remote Code Execution (Authenticated)
# Exploit Title: SAPSetup Automatic Workstation Update Service 750 - 'NWSAPAutoWorkstationUpdateSvc' Unquoted Service...
# Exploit Title: Winpakpro 4.8 - 'GuardTourService' Unquoted Service Path
# Exploit Title: Winpakpro 4.8 - 'ScheduleService' Unquoted Service Path
# Exploit Title: Winpakpro 4.8 - 'WPCommandFileService' Unquoted Service Path
# Exploit Title: WordPress Plugin Delightful Downloads Jquery File Tree 1.6.6 - Path Traversal
# Exploit Title: MacPaw Encrypto 1.0.1 - 'Encrypto Service' Unquoted Service Path
# Exploit Title: KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Weak Default WiFi Password Algorithm
# Exploit Title: MyBB 1.8.25 - Chained Remote Command Execution
# Exploit Title: ProFTPD 1.3.7a - Remote Denial of Service
# Exploit Title: OSAS Traverse Extension 11 - 'travextensionhostsvc' Unquoted Service Path
# Exploit Title: Plone CMS 5.2.3 - 'Title' Stored XSS
# Exploit Title: LiveZilla Server 8.0.1.0 - 'Accept-Language' Reflected XSS
# Exploit Title: Boonex Dolphin 7.4.2 - 'width' Stored XSS
# Exploit Title: BRAdmin Professional 3.75 - 'BRA_Scheduler' Unquoted Service Path
# Exploit Title: Profiling System for Human Resource Management 1.0 - Remote Code Execution (Unauthenticated)
# Exploit Title: Eclipse Mosquitto MQTT broker 2.0.9 - 'mosquitto' Unquoted Service Path
# Title: VestaCP 0.9.8 - 'v_sftp_licence' Command Injection
# Exploit Title: CouchCMS 2.2.1 - SSRF via SVG file upload
# Exploit Title: SOYAL Biometric Access Control System 5.0 - Master Code Disclosure
# Exploit Title: SOYAL Biometric Access Control System 5.0 - 'Change Admin Password' CSRF
# Exploit Title: SOYAL 701 Server 9.0.1 - Insecure Permissions