LimeSurvey 4.3.10 – ‘Survey Menu’ Persistent Cross-Site Scripting
# Exploit Title: LimeSurvey 4.3.10 - 'Survey Menu' Persistent Cross-Site Scripting
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: LimeSurvey 4.3.10 - 'Survey Menu' Persistent Cross-Site Scripting
# Exploit Title: Eibiz i-Media Server Digital Signage 3.8.0 - Authentication Bypass
# Exploit Title: Eibiz i-Media Server Digital Signage 3.8.0 - Configuration Disclosure
# Title: Complaint Management System 1.0 - 'cid' SQL Injection
# Exploit Title: Seowon SlC 130 Router - Remote Code Execution
# Exploit Title: ElkarBackup 1.3.3 - Persistent Cross-Site Scripting
# Exploit Title: PNPSCADA 2.200816204020 - 'interf' SQL Injection (Authenticated)
# Exploit Title: Ruijie Networks Switch eWeb S29_RGOS 11.4 - Directory Traversal
# Title: Pharmacy Medical Store and Sale Point 1.0 - 'catid' SQL Injection
# Exploit Title: Savsoft Quiz 5 - Stored Cross-Site Scripting
#!/usr/bin/env ruby
# Exploit Title: Microsoft SharePoint Server 2019 - Remote Code Execution
# Exploit Title: QiHang Media Web Digital Signage 3.0.9 - Cleartext Credential Disclosure
# Exploit Title: QiHang Media Web Digital Signage 3.0.9 - Unauthenticated Arbitrary File Deletion
# Exploit Title: QiHang Media Web Digital Signage 3.0.9 - Unauthenticated Arbitrary File Disclosure
# Exploit Title: QiHang Media Web Digital Signage 3.0.9 - Remote Code Execution (Unauthenticated)
# Exploit Title: Artica Proxy 4.3.0 - Authentication Bypass
# Exploit Title: GetSimple CMS Plugin Multi User v1.8.2 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: CMS Made Simple 2.2.14 - Arbitrary File Upload (Authenticated)
# Exploit Title: vBulletin 5.6.2 - 'widget_tabbedContainer_tab_panel' Remote Code Execution
# Exploit Title: Fuel CMS 1.4.7 - 'col' SQL Injection (Authenticated)
# Exploit Title: Warehouse Inventory System 1.0 - Cross-Site Request Forgery (Change Admin Password)
# Exploit Title: ManageEngine ADSelfService Plus 6000 – Unauthenticated Remote Code Execution
# Exploit Title: BarcodeOCR 19.3.6 - 'BarcodeOCR' Unquoted Service Path
# Exploit Title: All-Dynamics Digital Signage System 2.0.2 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: Daily Expenses Management System 1.0 - 'item' SQL Injection
# Exploit Title: Victor CMS 1.0 - 'Search' SQL Injection
# Exploit Title: CodeMeter 6.60 - 'CodeMeter.exe' Unquoted Service Path
# Exploit Title: ACTi NVR3 Standard or Professional Server 3.0.12.42 - Denial of Service (PoC) #
# Exploit Title: QlikView 12.50.20000.0 - 'FTP Server Address' Denial of Service (PoC)
# Exploit Title: Stock Management System 1.0 - Authentication Bypass
#!/usr/bin/env python2
# Exploit Title: Mocha Telnet Lite for iOS 4.2 - 'User' Denial of Service (PoC)
# Exploit Title: RTSP for iOS 1.0 - 'IP Address' Denial of Service (PoC)
# Exploit Title: Daily Expenses Management System 1.0 - 'username' SQL Injection
# Exploit Title: BacklinkSpeed 2.4 - Buffer Overflow PoC (SEH)
# Title: Online Shopping Alphaware 1.0 - Authentication Bypass
# Exploit Title: Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary File Deletion
# Exploit Title: Wordpress Plugin Maintenance Mode by SeedProd 5.1.1 - Persistent Cross-Site Scripting
# Exploit Title: Cisco Adaptive Security Appliance Software 9.11 - Local File Inclusion
# Exploit Title: eGroupWare 1.14 - 'spellchecker.php' Remote Command Execution
# Exploit Title: Nidesoft DVD Ripper 5.2.18 - Local Buffer Overflow (SEH)
# Exploit Title: Frigate Professional 3.36.0.9 - 'Pack File' Buffer Overflow (SEH Egghunter)
# Exploit Title: DiskBoss 7.7.14 - 'Reports and Data Directory' Buffer Overflow (SEH Egghunter)
# Exploit Title: GOautodial 4.0 - Persistent Cross-Site Scripting (Authenticated)
# Exploit Title: Socusoft Photo to Video Converter Professional 8.07 - 'Output Folder' Buffer Overflow (SEH Egghunter)
# Exploit Title: ManageEngine Applications Manager 13 - 'MenuHandlerServlet' SQL Injection
# Exploit Title: INNEO Startup TOOLS 2018 M040 13.0.70.3804 - Remote Code Execution
# Title: UBICOD Medivision Digital Signage 1.5.1 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: Port Forwarding Wizard 4.8.0 - Buffer Overflow (SEH)