SuiteCRM 7.11.15 – ‘last_name’ Remote Code Execution (Authenticated)
# Exploit Title: SuiteCRM 7.11.15 - 'last_name' Remote Code Execution (Authenticated)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: SuiteCRM 7.11.15 - 'last_name' Remote Code Execution (Authenticated)
# Exploit Title: HP Display Assistant x64 Edition 3.20 - 'DTSRVC' Unquoted Service Path
#Exploit Title: KMSpico 17.1.0.0 - 'Service KMSELDI' Unquoted Service Path
#Exploit Title: Winstep 18.06.0096 - 'Xtreme Service' Unquoted Service Path
# Exploit Title: OKI sPSV Port Manager 1.0.41 - 'sPSVOpLclSrv' Unquoted Service Path
#Exploit Title: IPTInstaller 4.0.9 - 'PassThru Service' Unquoted Service Path
#Exploit Title: Genexus Protection Server 9.6.4.2 - 'protsrvservice' Unquoted Service Path
#Exploit Title: DigitalPersona 4.5.0.2213 - 'DpHostW' Unquoted Service Path
# Exploit Title: Syncplify.me Server! 5.0.37 - 'SMWebRestServicev5' Unquoted Service Path
#Exploit Title: HP WMI Service 1.4.8.0 - 'HPWMISVC.exe' Unquoted Service Path
# Exploit Title: Motorola Device Manager 2.4.5 - 'ForwardDaemon.exe ' Unquoted Service Path
# Exploit Title: Motorola Device Manager 2.5.4 - 'MotoHelperService.exe' Unquoted Service Path
# Exploit Title: Motorola Device Manager 2.5.4 - 'ForwardDaemon.exe 'Unquoted Service Path
# Exploit Title: Realtek Andrea RT Filters 1.0.64.10 - 'AERTSr64.EXE' Unquoted Service Path
# Exploit Title: Realtek Audio Service 1.0.0.55 - 'RtkAudioService64.exe' Unquoted Service Path
#Exploit Title: MEMU PLAY 3.7.0 - 'MEmusvc' Unquoted Service Path
#Exploit Title: Magic Mouse 2 utilities 2.20 - 'magicmouse2service' Unquoted Service Path
# Exploit Title: iDeskService 3.0.2.1 - 'iDeskService' Unquoted Service Path
# Exploit Title: Canon Inkjet Extended Survey Program 5.1.0.8 - 'IJPLMSVC.EXE' - Unquoted Service Path
# Exploit Title: Deep Instinct Windows Agent 1.2.24.0 - 'DeepNetworkService' Unquoted Service Path
# Exploit Title: RealTimes Desktop Service 18.1.4 - 'rpdsvc.exe' Unquoted Service Path
# Exploit Title: DiskBoss v11.7.28 - Multiple Services Unquoted Service Path
# Exploit Title: Privacy Drive v3.17.0 - 'pdsvc.exe' Unquoted Service Path
# Exploit Title: Joplin 1.2.6 - 'link' Cross Site Scripting
# Exploit Title: SmartBlog 2.0.1 - 'id_post' Blind SQL injection
# Exploit Title: CMSUno 1.6.2 - 'lang' Remote Code Execution (Authenticated)
# Exploit Title: Sentrifugo 3.2 - 'assets' Remote Code Execution (Authenticated)
# Exploit Title: Sentrifugo Version 3.2 - 'announcements' Remote Code Execution (Authenticated)
# Exploit Title: BlogEngine 3.3.8 - 'Content' Stored XSS
# Exploit Title: iDS6 DSSPro Digital Signage System 6.2 - Cross-Site Request Forgery (CSRF)
# Exploit Title: iDS6 DSSPro Digital Signage System 6.2 - CAPTCHA Security Bypass
# Exploit Title: iDS6 DSSPro Digital Signage System 6.2 - Improper Access Control Privilege Escalation
# Exploit Title: Amarok 2.8.0 - Denial-of-Service
# Exploit Title: TP-Link WDR4300 - Remote Code Execution (Authenticated)
# Exploit Title: [Local File Inclusion Processwire CMS 2.4.0]
# Exploit Title: PDW File Browser 1.3 - Remote Code Execution
# Exploit Title: School Log Management System 1.0 - 'username' SQL Injection / Remote Code Execution
# Exploit Title: Student Attendance Management System 1.0 - 'username' SQL Injection / Remote Code Execution
# Title: Multi Restaurant Table Reservation System 1.0 - 'table_id' Unauthenticated SQL Injection
# Exploit Title: Complaints Report Management System 1.0 - 'username' SQL Injection / Remote Code Execution
#!/usr/bin/env python3
#!/usr/bin/python
#!/usr/bin/python
#!/usr/bin/python
# Exploit Title: Foxit Reader 9.7.1 - Remote Command Execution (Javascript API)
# Exploit Title: Quick 'n Easy FTP Service 3.2 - Unquoted Service Path
# Exploit Title: CSE Bookstore 1.0 - 'quantity' Persistent Cross-site Scripting
# Exploit Title: DedeCMS v.5.8 - "keyword" Cross-Site Scripting
# Exploit Title: Citadel WebCit < 926 - Session Hijacking Exploit
# Exploit Title: Online Job Portal 1.0 - 'userid' SQL Injection