Selea Targa IP OCR-ANPR Camera – Directory Traversal File Disclosure (Unauthenticated)
# Exploit Title: Selea Targa IP OCR-ANPR Camera - Directory Traversal File Disclosure (Unauthenticated)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Selea Targa IP OCR-ANPR Camera - Directory Traversal File Disclosure (Unauthenticated)
# Exploit Title: Selea Targa IP OCR-ANPR Camera - Multiple SSRF (Unauthenticated)
# Exploit Title: Selea Targa IP OCR-ANPR Camera - CSRF Add Admin
# Exploit Title: Selea Targa IP OCR-ANPR Camera - RTP/RTSP/M-JPEG Stream Disclosure (Unauthenticated)
# Exploit Title: Selea Targa IP OCR-ANPR Camera - 'addr' Remote Code Execution (Unauthenticated)
# Exploit Title: Oracle WebLogic Server 14.1.1.0 - RCE (Authenticated)
# Exploit Title: Library System 1.0 - Authentication Bypass Via SQL Injection
# Exploit Title: CASAP Automated Enrollment System 1.0 - Authentication Bypass
# Exploit Title: ERPNext 12.14.0 - SQL Injection (Authenticated)
# Exploit Title: Atlassian Confluence Widget Connector Macro - SSTI
# Exploit Title: Online Documents Sharing Platform 1.0 - 'user' SQL Injection
# Exploit Title: Apartment Visitors Management System 1.0 - 'email' SQL Injection
# Exploit Title: Nagios XI 5.7.5 - Multiple Persistent Cross-Site Scripting
# Exploit Title: Anchor CMS 0.12.7 - CSRF (Delete user)
# Exploit Title: ChurchRota 2.6.4 - RCE (Authenticated)
# Exploit Title: Oracle Business Intelligence Enterprise Edition 11.1.1.7.140715 - Stored XSS
# Exploit Title: Voting System 1.0 - File Upload RCE (Authenticated Remote Code Execution)
# Exploit Title: osTicket 1.14.2 - SSRF
# Exploit Title: Cisco UCS Manager 2.2(1d) - Remote Command Execution
# Exploit Title: Xwiki CMS 12.10.2 - Cross Site Scripting (XSS)
# Exploit Title: Life Insurance Management System 1.0 - 'client_id' SQL Injection
# Exploit Title: Life Insurance Management System 1.0 - File Upload RCE (Authenticated)
# Exploit Title: PHP-Fusion CMS 9.03.90 - Cross-Site Request Forgery (Delete admin shoutbox message)
# Exploit Title: WordPress Plugin Easy Contact Form 1.1.7 - 'Name' Stored Cross-Site Scripting (XSS)
# Exploit Title: Online Hotel Reservation System 1.0 - Stored Cross-site Scripting
# Exploit Title: Online Hotel Reservation System 1.0 - 'id' Time-based SQL Injection
# Exploit Title: Online Hotel Reservation System 1.0 - Cross-site request forgery (CSRF)
# Exploit Title: Online Hotel Reservation System 1.0 - 'person' time-based SQL Injection
# Exploit Title: EyesOfNetwork 5.3 - File Upload Remote Code Execution
# Exploit Title: Alumni Management System 1.0 - "Last Name field in Registration page" Stored XSS
# Exploit Title: E-Learning System 1.0 - Authentication Bypass & RCE
# Exploit Title: Online Movie Streaming 1.0 - Admin Authentication Bypass
# Exploit Title: Nagios XI 5.7.X - Remote Code Execution RCE (Authenticated)
# Exploit Title: Online Shopping Cart System 1.0 - 'id' SQL Injection
# Exploit Title: Laravel 8.4.2 debug mode - Remote code execution
# Exploit Title: Erlang Cookie - Remote Code Execution
# Exploit Title: Online Hotel Reservation System 1.0 - Admin Authentication Bypass
# Exploit Title: Gila CMS 2.0.0 - Remote Code Execution (Unauthenticated)
# Exploit Title: Cemetry Mapping and Information System 1.0 - Multiple SQL Injections
# Exploit Title: SmartAgent 3.1.0 - Privilege Escalation
# Exploit Title: EyesOfNetwork 5.3 - RCE & PrivEsc
# Exploit Title: Anchor CMS 0.12.7 - 'markdown' Stored Cross-Site Scripting
# Exploit Title: EyesOfNetwork 5.3 - LFI
# Exploit Title: Cemetry Mapping and Information System 1.0 - Multiple Stored Cross-Site Scripting
# Exploit Title: WordPress Plugin Custom Global Variables 1.0.5 - 'name' Stored Cross-Site Scripting (XSS)
# Exploit Title: OpenCart 3.0.36 - ATO via Cross Site Request Forgery
# Exploit Title: PortableKanban 4.3.6578.38136 - Encrypted Password Retrieval
# Exploit Title: Prestashop 1.7.7.0 - 'id_product' Time Based Blind SQL Injection