Xeroneit Library Management System 3.1 – “Add Book Category ” Stored XSS
# Exploit Title: Xeroneit Library Management System 3.1 - "Add Book Category " Stored XSS
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Xeroneit Library Management System 3.1 - "Add Book Category " Stored XSS
# Exploit Title: FRITZ!Box 7.20 - DNS Rebinding Protection Bypass
# Exploit Title: Dolibarr ERP-CRM 12.0.3 - Remote Code Execution (Authenticated)
# Exploit Title: Linksys RE6500 1.0.11.001 - Unauthenticated RCE
# Exploit Title:Content Management System 1.0 - 'First Name' Stored XSS
# Exploit Title: Content Management System 1.0 - 'email' SQL Injection
# Exploit Title: Content Management System 1.0 - 'id' SQL Injection
# Exploit Title: Medical Center Portal Management System 1.0 - 'id' SQL Injection
# Exploit Title: Customer Support System 1.0 - "First Name" & "Last Name" Stored XSS
# Exploit Title: Customer Support System 1.0 - 'id' SQL Injection
# Exploit Title: Online Tours & Travels Management System 1.0 - "id" SQL Injection
# Exploit Title: Interview Management System 1.0 - Stored XSS in Add New Question
# Exploit Title: Interview Management System 1.0 - 'id' SQL Injection
# Exploit Title: Employee Record System 1.0 - Multiple Stored XSS
# Exploit Title: PHPJabbers Appointment Scheduler 2.3 - Reflected XSS (Cross-Site Scripting)
# Exploit Title: Victor CMS 1.0 - Multiple SQL Injection (Authenticated)
# Exploit Title: Nxlog Community Edition 2.10.2150 - DoS (Poc)
# Exploit Title: Grav CMS 1.6.30 Admin Plugin 1.9.18 - 'Page Title' Persistent Cross-Site Scripting
# Exploit Title: Raysync 3.3.3.8 - RCE
# Exploit Title: Magic Home Pro 1.5.1 - Authentication Bypass
# Exploit Title: PrestaShop ProductComments 4.2.0 - 'id_products' Time Based Blind SQL Injection
# Exploit Title: Seotoaster 3.2.0 - Stored XSS on Edit page properties
const OFFSET_ELEMENT_REFCOUNT = 0x10;
# Exploit Title: Task Management System 1.0 - 'page' Local File Inclusion
# Exploit Title: libbabl 0.1.62 - Broken Double Free Detection (PoC)
# Exploit Title: Online Marriage Registration System (OMRS) 1.0 - Remote Code Execution (Authenticated)
# Exploit Title: Solaris SunSSH 11.0 x86 - libpam Remote Root
# Exploit Title: Cisco ASA 9.14.1.10 and FTD 6.6.0.1 - Path Traversal (2)
# Exploit Title: Jenkins 2.235.3 - 'X-Forwarded-For' Stored XSS
# Exploit Title: Rukovoditel 2.6.1 - Cross-Site Request Forgery (Change
# Exploit Title: LibreNMS 1.46 - MAC Accounting Graph Authenticated SQL Injection
# Exploit Title: MiniWeb HTTP Server 0.8.19 - Buffer Overflow (PoC)
# Exploit Title: System Explorer 7.0.0 - 'SystemExplorerHelpService' Unquoted Service Path
# Exploit Title: Seacms 11.1 - 'ip and weburl' Remote Command Execution
# Exploit Title: Seacms 11.1 - 'file' Local File Inclusion
# Exploit Title: Seacms 11.1 - 'checkuser' Stored XSS
# Exploit Title: WordPress Plugin Total Upkeep 1.14.9 - Database and Files Backup Download
# Exploit Title: Rumble Mail Server 0.51.3135 - 'servername' Stored XSS
# Exploit Title: Rumble Mail Server 0.51.3135 - 'domain and path' Stored XSS
# Exploit Title: Rumble Mail Server 0.51.3135 - 'username' Stored XSS
# Exploit Title: Macally WIFISD2-2A82 2.000.010 - Guest to Root Privilege Escalation
# Exploit Title: Gitlab 11.4.7 - Remote Code Execution
# Exploit Title: Jenkins 2.235.3 - 'tooltip' Stored Cross-Site Scripting
# Exploit Title: Openfire 4.6.0 - 'groupchatJID' Stored XSS
# Exploit Title: Openfire 4.6.0 - 'users' Stored XSS
# Exploit Title: Openfire 4.6.0 - 'sql' Stored XSS
# Exploit Title: Medical Center Portal Management System 1.0 - Multiple Stored XSS
# Exploit Title: Jenkins 2.235.3 - 'Description' Stored XSS
# Exploit Title: Rukovoditel 2.6.1 - RCE
# Exploit Title: Supply Chain Management System - Auth Bypass SQL Injection