Life Insurance Management System 1.0 – Multiple Stored XSS
# Exploit Title: Life Insurance Management System 1.0 - Multiple Stored XSS
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Life Insurance Management System 1.0 - Multiple Stored XSS
# Exploit Title: Online Doctor Appointment System 1.0 - 'Multiple' Stored XSS
# Exploit Title: Cockpit Version 234 - Server-Side Request Forgery (Unauthenticated)
# Exploit Title: iBall-Baton WRA150N Rom-0 Backup - File Disclosure (Sensitive Information)
# Exploit Title: ECSIMAGING PACS 6.21.5 - Remote code execution
# Exploit Title: Employee Record System 1.0 - Unrestricted File Upload to Remote Code Execution
# Cockpit CMS 0.6.1 - Remote Code Execution
# Exploit Title: Curfew e-Pass Management System 1.0 - Stored XSS
# Exploit Title: ECSIMAGING PACS 6.21.5 - SQL injection
# Exploit Title: CRUD Operation 1.0 - Multiple Stored XSS
# Exploit Title: Advanced Webhost Billing System 3.7.0 - Cross-Site Request Forgery (CSRF)
# Exploit Title: dirsearch 0.4.1 - CSV Injection
# Exploit Title: IObit Uninstaller 10 Pro - Unquoted Service Path
# Exploit Title: IPeakCMS 3.5 - Boolean-based blind SQLi
# Exploit Title: Expense Tracker 1.0 - 'Expense Name' Stored Cross-Site Scripting
# Exploit Title: WordPress Plugin litespeed-cache 3.6 - 'server_ip' Cross-Site Scripting
# Exploit Title: Responsive E-Learning System 1.0 - Unrestricted File Upload to RCE
# Exploit Title: Responsive E-Learning System 1.0 – Stored Cross Site Scripting
# Exploit Title: WordPress Plugin WP24 Domain Check 1.6.2 - 'fieldnameDomain' Stored Cross Site Scripting
# Exploit Title: Newgen Correspondence Management System (corms) eGov 12.0 - IDOR
# Exploit Title: WinAVR Version 20100110 - Insecure Folder Permissions
# Exploit Title: Resumes Management and Job Application Website 1.0 - RCE (Unauthenticated)
# Exploit Title: PaperStream IP (TWAIN) 1.42.0.5685 - Local Privilege Escalation
# Exploit Title: Gitea 1.7.5 - Remote Code Execution
# Exploit Title: H2 Database 1.4.199 - JNI Code Execution
# Exploit Title: Sonatype Nexus 3.21.1 - Remote Code Execution (Authenticated)
# Exploit Title: Responsive E-Learning System 1.0 – 'id' Sql Injection
# Exploit Title: Baby Care System 1.0 - 'Post title' Stored XSS
# Exploit Title: Responsive FileManager 9.13.4 - 'path' Path Traversal
# Exploit Title: Zoom Meeting Connector 4.6.239.20200613 - Remote Root Exploit (Authenticated)
# Exploit Title: HPE Edgeline Infrastructure Manager 1.0 - Multiple Remote Vulnerabilities
# Exploit Title: Cassandra Web 0.5.0 - Remote File Read
# Exploit Title: Fluentd TD-agent plugin 4.0.1 - Insecure Folder Permission
# Exploit Title: CSZ CMS 1.2.9 - Multiple Cross-Site Scripting
# Exploit Title: Online Learning Management System 1.0 - RCE (Authenticated)
# Exploit Title: Klog Server 2.4.1 - Command Injection (Unauthenticated)
# Exploit Title: EgavilanMedia User Registration & Login System with Admin Panel 1.0 - Multiple Stored Cross-Site Scr...
# Exploit Title: Intel(R) Matrix Storage Event Monitor x86 8.0.0.1039 - 'IAANTMON' Unquoted Service Path
# Exploit Title: IncomCMS 2.0 - Insecure File Upload
# Exploit Title: Resumes Management and Job Application Website 1.0 - Authentication Bypass (Sql Injection)
# Exploit Title: WordPress Plugin Stripe Payments 2.0.39 - 'AcceptStripePayments-settings[currency_code]' Stored XSS
# Exploit Title: WordPress Plugin WP-Paginate 2.1.3 - 'preset' Stored XSS
# Exploit Title: Online Movie Streaming 1.0 - Authentication Bypass
# Exploit Title: MiniTool ShadowMaker 3.2 - 'MTAgentService' Unquoted Service Path
# Exploit Title: Easy CD & DVD Cover Creator 4.13 - Denial of Service (PoC)
# Exploit Title: Wordpress Core 5.2.2 - 'post previews' XSS
# Exploit Title: 4images v1.7.11 - 'Profile Image' Stored Cross-Site Scripting