M/Monit 3.7.4 – Privilege Escalation
# Title: M/Monit 3.7.4 - Privilege Escalation
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Title: M/Monit 3.7.4 - Privilege Escalation
# Title: M/Monit 3.7.4 - Password Disclosure
# Exploit Title: Nagios Log Server 2.1.7 - 'snapshot_name' Persistent Cross-Site Scripting
# Exploit Title: Internet Download Manager 6.38.12 - Scheduler Downloads Scheduler Buffer Overflow (PoC)
#Exploit Title : Wordpress Plugin WPForms 1.6.3.1 - Persistent Cross Site Scripting (Authenticated)
# Exploit Title: BigBlueButton 2.2.25 - Arbitrary File Disclosure and Server-Side Request Forgery
# Exploit Title: ZeroLogon - Netlogon Elevation of Privilege
# Exploit Title: EgavilanMedia User Registration & Login System with Admin Panel Exploit - SQLi Auth Bypass
# Exploit Title: Online Doctor Appointment Booking System PHP and Mysql 1.0 - 'q' SQL Injection
# Exploit Title: SugarCRM 6.5.18 - Persistent Cross-Site Scripting
# Exploit Title: WordPress Plugin Buddypress 6.2.0 - Persistent Cross-Site Scripting
# Exploit Title: Microsoft Internet Explorer 11 - Use-After-Free
# Exploit Title: Froxlor Froxlor Server Management Panel 0.10.16 - Persistent Cross-Site Scripting
# Exploit Title: Joomla Plugin Simple Image Gallery Extended (SIGE) 3.5.3 - Multiple Vulnerabilities
# Exploit Title: Huawei LCD_Service 1.0.1.0 - 'LCD_Service' Unquote Service Path
# Exploit Title: Aerospike Database 5.1.0.3 - OS Command Execution
# Exploit Title: Apache Struts 2.5.20 - Double OGNL evaluation
# Exploit Title: Pandora FMS 7.0 NG 749 - 'CG Items' SQL Injection (Authenticated)
# Exploit Title: KiteService 1.2020.1113.1 - 'KiteService.exe' Unquoted Service Path
# Exploit Title: Water Billing System 1.0 - 'id' SQL Injection (Authenticated)
# Title: Advanced System Care Service 13 - 'AdvancedSystemCareService13' Unquoted Service Path
# Title: Logitech Solar Keyboard Service - 'L4301_Solar' Unquoted Service Path
# Exploit Title: User Registration & Login and User Management System 2.1 - Login Bypass SQL Injection
#Exploit Title: Atheros Coex Service Application 8.0.0.255 -'ZAtheros Bt&Wlan Coex Agent' Unquoted Service Path
# Exploit Title: PMB 5.6 - 'chemin' Local File Disclosure
# Exploit Title: Car Rental Management System 1.0 - Remote Code Execution (Authenticated)
# Exploit Title: Car Rental Management System 1.0 - 'car_id' Sql Injection
# Exploit Title: Cisco 7937G 1-4-5-7 - DoS/Privilege Escalation
require "msf/core"
#Exploit Title: Touchbase.io 1.10 - Stored Cross Site Scripting
#Exploit Title: DigitalPersona 5.1.0.656 'DpHostW' - Unquoted Service Path
# Exploit Title: SAntivirus IC 10.0.21.61 - 'SAntivirusIC' Unquoted Service Path
# Exploit Title: IDT PC Audio 1.0.6425.0 - 'STacSV' Unquoted Service Path
# Exploit Title: OpenCart Theme Journal 3.1.0 - Sensitive Data Exposure
# Exploit Title: October CMS Build 465 - Arbitrary File Read Exploit (Authenticated)
# Exploit Title: Water Billing System 1.0 - 'username' and 'password' parameters SQL Injection
# Exploit Title: Wordpress Plugin Good LMS 2.1.4 - 'id' Unauthenticated SQL Injection
# Exploit Title: Nidesoft 3GP Video Converter 2.6.18 - Local Stack Buffer Overflow
const OFFSET_ELEMENT_REFCOUNT = 0x10;
# Exploit Title: Customer Support System 1.0 - 'description' Stored XSS in The Admin Panel
# Exploit Title: Customer Support System 1.0 - Cross-Site Request Forgery (Admin Account Takeover)
# Title: Customer Support System 1.0 - 'username' Authentication Bypass
# Exploit Title: CMSUno 1.6.2 - 'user' Remote Code Execution (Authenticated)
# Exploit Title: Car Rental Management System 1.0 - SQL injection + Arbitrary File Upload
# Exploit Title: ShoreTel Conferencing 19.46.1802.0 - Reflected Cross-Site Scripting
# Exploit Title: Anuko Time Tracker 1.19.23.5325 - CSV/Formula Injection
# Exploit Title: Genexis Platinum-4410 P4410-V2-1.28 - Broken Access Control and CSRF