vBulletin 5.6.1 – ‘nodeId’ SQL Injection
# Exploit Title: vBulletin 5.6.1 - 'nodeId' SQL Injection
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: vBulletin 5.6.1 - 'nodeId' SQL Injection
# Exploit Title: ManageEngine Service Desk 10.0 - Cross-Site Scripting
# Exploit Title: Complaint Management System 1.0 - 'username' SQL Injection
# Exploit Title: Dameware Remote Support 12.1.1.273 - Buffer Overflow (SEH)
# Exploit Title: Netlink XPON 1GE WiFi V2801RGW - Remote Command Execution
# Exploit Title: E-Commerce System 1.0 - Unauthenticated Remote Code Execution
# Exploit Title: Remote Desktop Audit 2.3.0.157 - Buffer Overflow (SEH)
# Exploit Title: Tryton 5.4 - Persistent Cross-Site Scripting
# Exploit Title: Sellacious eCommerce 4.6 - Persistent Cross-Site Scripting
# Exploit Title: Orchard Core RC1 - Persistent Cross-Site Scripting
# Exploit Title: ChopSlider3 Wordpress Plugin3.4 - 'id' SQL Injection
# Exploit Title: CuteNews 2.1.2 - Authenticated Arbitrary File Upload
# Exploit Title: Cisco Digital Network Architecture Center 1.3.1.4 - Persistent Cross-Site Scripting
# Exploit Title: qdPM 9.1 - Arbitrary File Upload
# Exploit Title: LanSend 3.2 - Buffer Overflow (SEH)
# Exploit Title: TylerTech Eagle 2018.3.11 - Remote Code Execution
# Exploit Title: MacOS 320.whatis Script - Privilege Escalation
# Exploit Title: Online AgroCulture Farm Management System 1.0 - 'uname' SQL Injection
# Exploit Title: Kartris 1.6 - Arbitrary File Upload
# Exploit Title: Sentrifugo CMS 3.2 - Persistent Cross-Site Scripting
# Exploit Title: CuteNews 2.1.2 - Arbitrary File Deletion
# Title: SolarWinds MSP PME Cache Service 1.1.14 - Insecure File Permissions
# Exploit Title: Wordpress Plugin Simple File List 4.2.2 - Remote Code Execution
# Exploit Title: OpenZ ERP 3.6.60 - Persistent Cross-Site Scripting
# Exploit Title: Victor CMS 1.0 - 'post' SQL Injection
# Exploit Title: complaint management system 1.0 - Authentication Bypass
# Exploit Title: LibreNMS 1.46 - 'search' SQL Injection
#!/usr/bin/env python3
#!/usr/bin/env python3
# Exploit title : Extreme Networks Aerohive HiveOS 11.0 - Remote Denial of Service (PoC)
# Exploit Title: FlashGet 1.9.6 - Denial of Service (PoC)
# Exploit Title: Car Park Management System 1.0 - Authentication Bypass
# Title: Draytek VigorAP 1000C - Persistent Cross-Site Scripting
# Exploit Title: School File Management System 1.0 - 'username' SQL Injection
# Exploit Title: Online Clothing Store 1.0 - Arbitrary File Upload
# Exploit Title: Pisay Online E-Learning System 1.0 - Remote Code Execution
# Exploit Title: Online AgroCulture Farm Management System 1.0 - 'pid' SQL Injection
# Exploit Title: Online Clothing Store 1.0 - Persistent Cross-Site Scripting
# Exploit Title: i-doit Open Source CMDB 1.14.1 - Arbitrary File Deletion
# Exploit Title: Booked Scheduler 2.7.7 - Authenticated Directory Traversal
# Exploit Title: Online Clothing Store 1.0 - 'username' SQL Injection
# Exploit Title: webTareas 2.0.p8 - Arbitrary File Deletion
# Exploit Title: GitLab 12.9.0 - Arbitrary File Read
# Exploit Title: YesWiki cercopitheque 2020.04.18.1 - 'id' SQL Injection
# Exploit title : MPC Sharj 3.11.1 - Arbitrary File Download
# Title: Fishing Reservation System 7.5 - 'uid' SQL Injection
# Exploit Title: Oracle Database 11g Release 2 - 'OracleDBConsoleorcl' Unquoted Service Path
# Exploit Title: Online Scheduling System 1.0 - 'username' SQL Injection
# Exploit Title: webERP 4.15.1 - Unauthenticated Backup File Access
# Exploit Title: Saltstack 3000.1 - Remote Code Execution