Online Internship Management System 1.0 – ’email’ SQL injection Auth Bypass
# Exploit Title: Online Internship Management System 1.0 - 'email' SQL injection Auth Bypass
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Online Internship Management System 1.0 - 'email' SQL injection Auth Bypass
# Exploit Title: BlackCat CMS 1.3.6 - 'Display name' Cross Site Scripting (XSS)
# Exploit Title: Managed Switch Port Mapping Tool 2.85.2 - Denial of Service (PoC)
# Exploit Title: AgataSoft PingMaster Pro 2.1 - Denial of Service (PoC)
# Exploit Title: Nsauditor 3.2.2.0 - 'Event Description' Denial of Service (PoC)
# Exploit Title: TestLink 1.9.20 - Unrestricted File Upload (Authenticated)
# Exploit Title: Teachers Record Management System 1.0 - 'searchteacher' SQL Injection
# Exploit Title: Tasks 9.7.3 - Insecure Permissions
# Exploit Title: PDFCOMPLETE Corporate Edition 4.1.45 - 'pdfcDispatcher' Unquoted Service Path
# Exploit Title: School File Management System 1.0 - 'multiple' Stored Cross-Site Scripting
# Exploit Title: School Event Attendance Monitoring System 1.0 - 'Item Name' Stored Cross-Site Scripting
# Exploit Title: PEEL Shopping 9.3.0 - 'address' Stored Cross-Site Scripting
# Exploit Title: b2evolution 6.11.6 - 'redirect_to' Open Redirect
# Exploit Title: b2evolution 6.11.6 - 'tab3' Reflected XSS
# Exploit Title: Openlitespeed WebServer 1.7.8 - Command Injection (Authenticated) (2)
# Exploit Title: Online Marriage Registration System (OMRS) 1.0 - Remote code execution (3)
# Exploit Title: b2evolution 6.11.6 - 'plugin name' Stored XSS
# Exploit Title: Node.JS - 'node-serialize' Remote Code Execution (2)
# Exploit Title: Online Car Rental System 1.0 - Stored Cross Site Scripting
# Exploit Title: Epson USB Display 1.6.0.0 - 'EMP_UDSA' Unquoted Service Path
# Exploit Title: AnyTXT Searcher 1.2.394 - 'ATService' Unquoted Service Path
# Title: Adobe Connect 10 - Username Disclosure
# Exploit Title: SmartFoxServer 2X 2.17.0 - God Mode Console Remote Code Execution
# Exploit Title: SmartFoxServer 2X 2.17.0 - Credentials Disclosure
# Exploit Title: SmartFoxServer 2X 2.17.0 - God Mode Console WebSocket XSS
# Exploit Title: Jenzabar 9.2.2 - 'query' Reflected XSS.
# Exploit Title: Millewin 13.39.146.1 - Local Privilege Escalation
# Exploit Title: WordPress Plugin Welcart e-Commerce 2.0.0 - 'search[order_column][0]' SQL injection
# Exploit Title: WordPress Plugin Supsystic Ultimate Maps 1.1.12 - 'sidx' SQL injection
# Exploit Title: WordPress Plugin Supsystic Pricing Table 1.8.7 - Multiple Vulnerabilities
# Title: YetiShare File Hosting Script 5.1.0 - 'url' Server-Side Request Forgery
# Exploit Title: AMD Fuel Service - 'Fuel.service' Unquote Service Path
# Exploit Title: Alt-N MDaemon webmail 20.0.0 - 'Contact name' Stored Cross Site Scripting (XSS)
# Exploit Title: Alt-N MDaemon webmail 20.0.0 - 'file name' Stored Cross Site Scripting (XSS)
# Exploit Title: WordPress Plugin Supsystic Newsletter 1.5.5 - 'sidx' SQL injection
# Exploit Title: WordPress Plugin Supsystic Membership 1.4.7 - 'sidx' SQL injection
# Exploit Title: Microsoft Internet Explorer 11 32-bit - Use-After-Free
# Exploit Title: WordPress Plugin Supsystic Digital Publications 1.6.9 - Multiple Vulnerabilities
# Exploit Title: WordPress Plugin Supsystic Data Tables Generator 1.9.96 - Multiple Vulnerabilities
# Exploit Title: WordPress Plugin Supsystic Contact Form 1.7.5 - Multiple Vulnerabilities
# Exploit Title: WordPress Plugin Supsystic Backup 2.3.9 - Local File Inclusion
# Exploit Title: LiteSpeed Web Server Enterprise 5.4.11 - Command Injection (Authenticated)
# Exploit Title: PhreeBooks 5.2.3 - Remote Code Execution
# Exploit Title: SEO Panel 4.6.0 - Remote Code Execution (2)
# Exploit Title: Pixelimity 1.0 - 'password' Cross-Site Request Forgery
# Exploit Title: Car Rental Project 2.0 - Arbitrary File Upload to Remote Code Execution
# Exploit Title: Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (1)
# Exploit Title: Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (2)
# Exploit Title: Student Record System 4.0 - 'cid' SQL Injection
# Exploit Title: Solaris 10 1/13 (Intel) - 'dtprintinfo' Local Privilege Escalation (2)