Simple College Website 1.0 – ‘username’ SQL Injection / Remote Code Execution
# Exploit Title: Simple College Website 1.0 - SQL Injection / Remote Code Execution
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Simple College Website 1.0 - SQL Injection / Remote Code Execution
# Exploit Title: Online examination system 1.0 - 'name' Stored Cross Site Scripting
# Title: Mailman 1.x > 2.1.23 - Cross Site Scripting (XSS)
# Exploit Title: Genexis Platinum-4410 P4410-V2-1.28 - Cross Site Request Forgery to Reboot
# Exploit Title: Nagios XI 5.7.3 - 'mibs.php' Remote Command Injection (Authenticated)
# Exploit Title: CSE Bookstore Authentication Bypass
# Exploit Title: File Existence Disclosure in PackageKit < 1.1.13-2ubuntu1
# Exploit Title: File Existence Disclosure in aptdaemon
# Exploit Title: Local Privilege Escalation in Blueman < 2.1.4
# Exploit Title: Oracle Business Intelligence Enterprise Edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 - 'getPreviewIma...
# Exploit Title: EPSON 1.124 - 'seksmdb.exe' Unquoted Service Path
# Exploit Title: Program Access Controller v1.2.0.0 - 'PACService.exe' Unquoted Service Path
# Exploit Title: Prey 1.9.6 - "CronService" Unquoted Service Path
# Exploit Title: IP Watcher v3.0.0.30 - 'PACService.exe' Unquoted Service Path
# Exploit Title: TDM Digital Signage PC Player 4.1 - Insecure File Permissions
# Exploit Title: Adtec Digital Multiple Products - Default Hardcoded Credentials Remote Root
# Exploit Title: Sentrifugo 3.2 - File Upload Restriction Bypass (Authenticated)
# Exploit Title: Client Management System 1.0 - 'searchdata' SQL injection
# Exploit Title: Sphider Search Engine 1.3.6 - 'word_upper_bound' RCE (Authenticated)
# Exploit Title: GoAhead Web Server 5.1.1 - Digest Authentication Capture Replay Nonce Reuse
# Exploit Title: CMS Made Simple 2.1.6 - 'cntnt01detailtemplate' Server-Side Template Injection
# Exploit Title: Online Health Care System 1.0 - Multiple Cross Site Scripting (Stored)
#!/usr/bin/python
# Exploit Title: PDW File Browser
# Exploit Title: Persistent XSS in SSID
# Exploit Title: ReQuest Serious Play Media Player 3.0 - Directory Traversal File Disclosure Vulnerability
# Exploit Title: ReQuest Serious Play F3 Media Server 7.0.3 - Debug Log Disclosure
# Exploit Title: ReQuest Serious Play F3 Media Server 7.0.3 - Remote Denial of Service
# Exploit Title: ReQuest Serious Play F3 Media Server 7.0.3 - Remote Code Execution (Unauthenticated)
# Exploit Title: Online Library Management System 1.0 - Arbitrary File Upload
#!/usr/bin/python3
# Exploit Title: Stock Management System 1.0 - SQL Injection
# Exploit Title: Car Rental Management System 1.0 - Arbitrary File Upload
# Exploit Title: User Registration & Login and User Management System 2.1 - SQL Injection
#Exploit Title: Point of Sales 1.0 - SQL Injection
#Exploit Title: lot reservation management system 1.0 - Authentication Bypass
#Exploit Title: lot reservation management system 1.0 - Stored Cross Site Scripting
# Exploit Title: Gym Management System 1.0 - 'id' SQL Injection
# Exploit Title: Point of Sales 1.0 - 'username' SQL Injection
# Exploit Title: School Faculty Scheduling System 1.0 - 'id' SQL Injection
# Exploit Title: School Faculty Scheduling System 1.0 - 'username' SQL Injection
# Exploit Title: Gym Management System 1.0 - Authentication Bypass
# Exploit Title: Gym Management System 1.0 - Stored Cross Site Scripting
#!/usr/bin/python3
#!/usr/bin/python3
# Exploit Title: Hrsale 2.0.0 - Local File Inclusion
# Exploit Title: School Faculty Scheduling System 1.0 - Stored Cross Site Scripting
# Exploit Title: School Faculty Scheduling System 1.0 - Authentication Bypass
# Exploit Title: GOautodial 4.0 - Authenticated Shell Upload