Print Job Accounting 4.4.10 – ‘OkiJaSvc’ Unquoted Service Path
# Exploit Title: Print Job Accounting 4.4.10 - 'OkiJaSvc' Unquoted Service Path
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Print Job Accounting 4.4.10 - 'OkiJaSvc' Unquoted Service Path
# Exploit Title: Configuration Tool 1.6.53 - 'OpLclSrv' Unquoted Service Path
# Exploit Title: CatDV 9.2 - RMI Authentication Bypass
# Exploit Title: Fluig 1.7.0 - Path Traversal
# Exploit Title: e107 CMS 2.3.0 - CSRF
# Exploit Title: Online Ordering System 1.0 - Arbitrary File Upload to Remote Code Execution
# Exploit Title: Textpattern CMS 4.8.4 - 'Comments' Persistent Cross-Site Scripting (XSS)
# Exploit Title: Textpattern CMS 4.9.0-dev - 'Excerpt' Persistent Cross-Site Scripting (XSS)
# Exploit Title: Online Ordering System 1.0 - Blind SQL Injection (Unauthenticated)
# Exploit Title: Web Based Quiz System 1.0 - 'eid' Union Based Sql Injection (Authenticated)
# Exploit Title: Textpattern 4.8.3 - Remote code execution (Authenticated) (2)
# Exploit Title: Local Services Search Engine Management System (LSSMES) 1.0 - 'name' Persistent Cross-Site Scripting...
# Exploit Title: Local Services Search Engine Management System (LSSMES) 1.0 - Blind & Error based SQL injection (Aut...
# Exploit Title: AnyDesk 5.5.2 - Remote Code Execution
# Exploit Title: Web Based Quiz System 1.0 - 'MCQ options' Persistent/Stored Cross-Site Scripting
# Exploit Title: Tiny Tiny RSS - Remote Code Execution
# Exploit Title: Web Based Quiz System 1.0 - 'name' Persistent/Stored Cross-Site Scripting
# Exploit Title: WiFi Mouse 1.7.8.5 - Remote Code Execution
# Exploit Title: VMware vCenter Server 7.0 - Unauthenticated File Upload
# Exploit Title: Online Catering Reservation System 1.0 - Unauthenticated Remote Code Execution
# Exploit Title: Covid-19 Contact Tracing System 1.0 - Remote Code Execution (Unauthenticated)
# Exploit Title: Simple Employee Records System 1.0 - File Upload RCE (Unauthenticated)
# Exploit Title: Triconsole 3.75 - Reflected XSS
# Exploit Title: LightCMS 1.3.4 - 'exclusive' Stored XSS
#!/usr/bin/env python3
# Exploit: ASUS Remote Link 1.1.2.13 - Remote Code Execution
# Exploit Title: Vehicle Parking Management System 1.0 - 'catename' Persistent Cross-Site Scripting (XSS)
# Exploit Title: python jsonpickle 2.0.0 - Remote Code Execution
# Exploit Title: LogonExpert 8.1 - 'LogonExpertSvc' Unquoted Service Path
# Exploit Title: Unified Remote 3.9.0.2463 - Remote Code Execution
# Exploit Title: Softros LAN Messenger 9.6.4 - 'SoftrosSpellChecker' Unquoted Service Path
# Exploit Title: SpotAuditor 5.3.5 - 'multiple' Denial Of Service (PoC)
# Exploit Title: Product Key Explorer 4.2.7 - 'multiple' Denial of Service (PoC)
# Exploit Title: LayerBB 1.1.4 - 'search_query' SQL Injection
# Exploit Title: Monica 2.19.1 - 'last_name' Stored XSS
# Exploit Title: Batflat CMS 1.3.6 - 'multiple' Stored XSS
# Exploit Title: HFS (HTTP File Server) 2.3.x - Remote Command Execution (3)
# Exploit Title: PEEL Shopping 9.3.0 - 'Comments/Special Instructions' Stored Cross-Site Scripting
# Exploit Title: Comment System 1.0 - 'multiple' Stored Cross-Site Scripting
# Exploit Title: Online Exam System With Timer 1.0 - 'email' SQL injection Auth Bypass
# Exploit Title: dataSIMS Avionics ARINC 664-1 - Local Buffer Overflow (PoC)
# Exploit Title: OpenText Content Server 20.3 - 'multiple' Stored Cross-Site Scripting
# Exploit Title: Beauty Parlour Management System 1.0 - 'sername' SQL Injection
# Exploit Title: Gitea 1.12.5 - Remote Code Execution (Authenticated)
# Exploit Title: Apport 2.20 - Local Privilege Escalation
# Exploit Title: Batflat CMS 1.3.6 - Remote Code Execution (Authenticated)
# Exploit Title: Faulty Evaluation System 1.0 - 'multiple' Stored Cross-Site Scripting
# Exploit Title: Billing Management System 2.0 - 'email' SQL injection Auth Bypass