Mantis Bug Tracker 2.24.3 – ‘access’ SQL Injection
# Exploit Title: Mantis Bug Tracker 2.24.3 - 'access' SQL Injection
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Mantis Bug Tracker 2.24.3 - 'access' SQL Injection
# Exploit Title: Knockpy 4.1.1 - CSV Injection
# Exploit Title: Advanced Comment System 1.0 - 'ACS_path' Path Traversal
# Exploit Title: sar2html 3.2.1 - 'plot' Remote Code Execution
# Exploit Title: CMS Made Simple 2.2.15 - RCE (Authenticated)
# Exploit Title: Subrion CMS 4.2.1 - 'avatar[path]' XSS
# Exploit Title: Click2Magic 1.1.5 - Stored Cross-Site Scripting
# Exploit Title: Arteco Web Client DVR/NVR - 'SessionId' Brute Force
# Exploit Title: WordPress Plugin WP-PostRatings 1.86 - 'postratings_image' Cross-Site Scripting
# Exploit Title: WordPress Plugin Adning Advertising 1.5.5 - Arbitrary File Upload
# Exploit Title: GitLab 11.4.7 RCE (POC)
# Exploit Title: Apartment Visitors Management System 1.0 - Authentication Bypass
# Exploit Title: Class Scheduling System 1.0 - Multiple Stored XSS
# Exploit Title: Online Learning Management System 1.0 - Authentication Bypass
# Exploit Title: Online Learning Management System 1.0 - Multiple Stored XSS
# Exploit Title: Online Learning Management System 1.0 - 'id' SQL Injection
# Exploit Title: Wordpress Epsilon Framework Multiple Themes - Unauthenticated Function Injection
# Exploit Title: Sales and Inventory System for Grocery Store 1.0 - Multiple Stored XSS
# Exploit Title: Baby Care System 1.0 - 'roleid' SQL Injection
# Exploit Title: Victor CMS 1.0 - File Upload To RCE
# Exploit Title: Pandora FMS 7.0 NG 750 - 'Network Scan' SQL Injection (Authenticated)
# Exploit Title : CSE Bookstore 1.0 - Multiple SQL Injection
# Exploit Title: Library Management System 3.0 - "Add Category" Stored XSS
# Exploit Title: Multi Branch School Management System 3.5 - "Create Branch" Stored XSS
# Exploit Title: Artworks Gallery Management System 1.0 - 'id' SQL Injection
# Exploit Title: Faculty Evaluation System 1.0 - Stored XSS
# Exploit Title: TerraMaster TOS 4.2.06 - RCE (Unauthenticated)
# Exploit Title: 10-Strike Network Inventory Explorer Pro 9.05 - Buffer Overflow (SEH)
# Exploit Title: Queue Management System 4.0.0 - "Add User" Stored XSS
# Exploit Title: Spotweb 1.4.9 - 'search' SQL Injection
# Exploit Title: Academy-LMS 4.3 - Stored XSS
# Exploit Title: Spiceworks 7.5 - HTTP Header Injection
# Exploit Title: SCO Openserver 5.0.7 - 'section' Reflected XSS
# Exploit Title: SCO Openserver 5.0.7 - 'outputform' Command Injection
# Exploit Title: Flexmonster Pivot Table & Charts 2.7.17 - 'Remote Report' Reflected XSS
# Exploit Title: Flexmonster Pivot Table & Charts 2.7.17 - 'To OLAP' Reflected XSS
# Exploit Title: Flexmonster Pivot Table & Charts 2.7.17 - 'To remote CSV' Reflected XSS
# Exploit Title: Flexmonster Pivot Table & Charts 2.7.17 - 'Remote JSON' Reflected XSS
# Exploit Title: Point of Sale System 1.0 - Multiple Stored XSS
# Exploit Title: Online Marriage Registration System 1.0 - 'searchdata' SQL Injection
# Exploit Title: Point of Sale System 1.0 - Authentication Bypass
# Exploit Title: Alumni Management System 1.0 - Unrestricted File Upload To RCE
# Exploit Title: Alumni Management System 1.0 - "Course Form" Stored XSS
# Exploit Title: Alumni Management System 1.0 - 'id' SQL Injection
# Exploit Title: Smart Hospital 3.1 - "Add Patient" Stored XSS
# Exploit Title: SyncBreeze 10.0.28 - 'login' Denial of Service (Poc)