BSA Radar 1.6.7234.24750 – Cross-Site Request Forgery (Change Password)
# Exploit title: BSA Radar 1.6.7234.24750 - Cross-Site Request Forgery (Change Password)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit title: BSA Radar 1.6.7234.24750 - Cross-Site Request Forgery (Change Password)
# Exploit Title: Sickbeard 0.1 - Remote Command Injection
# Exploit Title: Online Shopping Portal 3.1 - 'email' SQL Injection
# Exploit Title: Joomla! J2 JOBS 1.3.0 - 'sortby' Authenticated SQL Injection
# Exploit Title: BSA Radar 1.6.7234.24750 - Authenticated Privilege Escalation
# Exploit Title: Microsoft Windows mshta.exe 2019 - XML External Entity Injection
# Exploit Title: Exhibitor Web UI 1.7.1 - Remote Code Execution
# Exploit Title: File Management System 1.1 - Persistent Cross-Site Scripting
# Exploit Title: RiteCMS 2.2.1 - Authenticated Remote Code Execution
# Exploit Title: Fire Web Server 0.1 - Remote Denial of Service (PoC)
# Exploit Title: Grafana 7.0.1 - Denial of Service (PoC)
# Exploit Title: RSA IG&L Aveksa 7.1.1 - Remote Code Execution
# Exploit Title: Nagios XI 5.6.12 - 'export-rrd.php' Remote Code Execution
# Exploit Title: ZenTao Pro 8.8.2 - Command Injection
# Exploit Title: OCS Inventory NG 2.7 - Remote Code Execution
# Exploit Title: RM Downloader 2.50.60 2006.06.23 - 'Load' Local Buffer Overflow (EggHunter) (SEH) (PoC)
# Exploit Title: e-learning Php Script 0.1.0 - 'search' SQL Injection
# Exploit Title: PHP-Fusion 9.03.60 - PHP Object Injection
# Exploit Title: Online Shopping Portal 3.1 - Authentication Bypass
# Exploit Title: Victor CMS 1.0 - 'user_firstname' Persistent Cross-Site Scripting
# Exploit Title: Reside Property Management 3.0 - 'profile' SQL Injection
# Exploit Title: OpenEMR 5.0.1 - 'controller' Remote Code Execution
# Exploit Title: Windscribe 1.83 - 'WindscribeService' Unquoted Service Path
# Exploit Title: KiteService 1.2020.618.0 - Unquoted Service Path
# Exploit Title: mySCADA myPRO v7 Hardcoded Credentials
# Exploit Title: FHEM 6.0 - Local File Inclusion
# Exploit title: BSA Radar 1.6.7234.24750 - Persistent Cross-Site Scripting
# Exploit Title: Responsive Online Blog 1.0 - 'id' SQL Injection
# Exploit Title: Online Student Enrollment System 1.0 - Cross-Site Request Forgery (Add Student)
# Exploit Title: Code Blocks 20.03 - Denial Of Service (PoC)
# Exploit Title: Lansweeper 7.2 - Incorrect Access Control
# Exploit Title: FileRun 2019.05.21 - Reflected Cross-Site Scripting
# Exploit Title: Student Enrollment 1.0 - Unauthenticated Remote Code Execution
# Exploit Title: Odoo 12.0 - Local File Inclusion
# Exploit Title: Online Student Enrollment System 1.0 - Unauthenticated Arbitrary File Upload
# Exploit Title: WebPort 1.19.1 - Reflected Cross-Site Scripting
# Exploit Title: WebPort 1.19.1 - 'setup' Reflected Cross-Site Scripting
# Exploit Title: Frigate 2.02 - Denial Of Service (PoC)
# Exploit Title: Eaton Intelligent Power Manager 1.6 - Directory Traversal
# Exploit Title: Beauty Parlour Management System 1.0 - Authentication Bypass
# Exploit Title: College-Management-System-Php 1.0 - Authentication Bypass / SQL Injection
# Exploit Title: Code Blocks 17.12 - 'File Name' Local Buffer Overflow (Unicode) (SEH) (PoC)
# Exploit Title: OpenCTI 3.3.1 - Directory Traversal
# Exploit Title: Gila CMS 1.11.8 - 'query' SQL Injection
# Exploit Title: Bandwidth Monitor 3.9 - 'Svc10StrikeBandMontitor' Unquoted Service Path
# Exploit Title: SOS JobScheduler 1.13.3 - Stored Password Decryption
# EDB Note: Download ~ https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/48588.zip