SpamTitan 7.07 – Remote Code Execution (Authenticated)
# Exploit Title: SpamTitan 7.07 - Remote Code Execution (Authenticated)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: SpamTitan 7.07 - Remote Code Execution (Authenticated)
# Exploit Title: Mantis Bug Tracker 2.3.0 - Remote Code Execution (Unauthenticated)
# Exploit Title: Microsoft SQL Server Reporting Services 2016 - Remote Code Execution
# Exploit Title: Piwigo 2.10.1 - Cross Site Scripting
# Title: Windows TCPIP Finger Command - C2 Channel and Bypassing Security Software
# Exploit Title: ThinkAdmin 6 - Arbitrarily File Read
# Exploit Title: Tailor MS 1.0 - Reflected Cross-Site Scripting
# Exploit Title: RAD SecFlow-1v SF_0290_2.3.01.26 - Persistent Cross-Site Scripting
# Exploit Title: Rapid7 Nexpose Installer 6.6.39 - 'nexposeengine' Unquoted Service Path
# Exploit Title: RAD SecFlow-1v SF_0290_2.3.01.26 - Cross-Site Request Forgery (Reboot)
# Exploit Title: Pearson Vue VTS 2.3.1911 Installer - 'VUEApplicationWrapper' Unquoted Service Path
# Exploit Title: Joomla! paGO Commerce 2.5.9.0 - SQL Injection (Authenticated)
#!/usr/bin/env python3
#!/usr/bin/python3
# Exploit Title: Tea LaTex 1.0 - Remote Code Execution (Unauthenticated)
# Exploit Title: Tiandy IPC and NVR 9.12.7 - Credential Disclosure
# Exploit Title: CuteNews 2.1.2 - Remote Code Execution
# Exploit Title: ZTE Router F602W - Captcha Bypass
# Exploit Title: Input Director 1.4.3 - 'Input Director' Unquoted Service Path
# Exploit Title: Audio Playback Recorder 3.2.2 - Local Buffer Overflow (SEH)
# Exploit Title: Tailor Management System - 'id' SQL Injection
# Exploit Title: Scopia XT Desktop 8.3.915.4 - Cross-Site Request Forgery (change admin password)
# Exploit Title: ShareMouse 5.0.43 - 'ShareMouse Service' Unquoted Service Path
# Exploit Title: Cabot 0.11.12 - Persistent Cross-Site Scripting
# Exploit Title: grocy 2.7.1 - Persistent Cross-Site Scripting
# Exploit Title: Nord VPN-6.31.13.0 - 'nordvpn-service' Unquoted Service Path
# Exploit Title: Savsoft Quiz Enterprise Version 5.5 - Persistent Cross-Site Scripting
# Exploit Title: BloodX CMS 1.0 - Authentication Bypass
# Exploit Title: Daily Tracker System 1.0 - Authentication Bypass
# Exploit Title: SiteMagic CMS 4.4.2 - Arbitrary File Upload (Authenticated)
# Exploit Title: BarracudaDrive v6.5 - Insecure Folder Permissions
# Exploit Title: Stock Management System 1.0 - Cross-Site Request Forgery (Change Username)
#!/usr/bin/python3
# Exploit Title: Mara CMS 7.5 - Remote Code Execution (Authenticated)
# Exploit Title: moziloCMS 2.0 - Persistent Cross-Site Scripting (Authenticated)
# Title: Online Book Store 1.0 - 'id' SQL Injection
## Title: BlazeDVD 7.0 Professional - '.plf' Local Buffer Overflow (SEH,ASLR,DEP)
# Exploit Title: Mara CMS 7.5 - Reflective Cross-Site Scripting
# Exploit Title: Fuel CMS 1.4.8 - 'fuel_replace_id' SQL Injection (Authenticated)
#!/usr/bin/python3
# Title: Online Shopping Alphaware 1.0 - 'id' SQL Injection
# Exploit Title: Nagios Log Server 2.1.6 - Persistent Cross-Site Scripting
# Exploit Title: SymphonyCMS 3.0.0 - Persistent Cross-Site Scripting
# Exploit Title: Eibiz i-Media Server Digital Signage 3.8.0 - Privilege Escalation
# Exploit Title: Mida eFramework 2.9.0 - Remote Code Execution
# Exploit Title: ASX to MP3 converter 3.1.3.7.2010.11.05 - '.wax' Local Buffer Overflow (DEP,ASLR Bypass) (PoC)
# Exploit Title: Wordpress Plugin Autoptimize 2.7.6 - Arbitrary File Upload (Authenticated)
# Exploit Title: Ericom Access Server x64 9.2.0 - Server-Side Request Forgery
# Exploit Title: Eibiz i-Media Server Digital Signage 3.8.0 - Directory Traversal