BlogEngine 3.3 – ‘syndication.axd’ XML External Entity Injection
# Title: BlogEngine 3.3 - 'syndication.axd' XML External Entity Injection
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Title: BlogEngine 3.3 - 'syndication.axd' XML External Entity Injection
# Exploit Title: PhreeBooks ERP 5.2.5 - Remote Command Execution
# Title: SimplePHPGal 0.7 - Remote File Inclusion
# Title: NEC Electra Elite IPK II WebPro 01.03.01 - Session Enumeration
# Exploit Title: BoltWire 6.03 - Local File Inclusion
# Title: osTicket 1.14.1 - Persistent Authenticated Cross-Site Scripting
# Exploit Title: Outline Service 1.3.3 - 'Outline Service ' Unquoted Service Path
# Exploit Title: Frigate 3.36 - Buffer Overflow (SEH)
# Title: addressbook 9.0.0.1 - 'id' SQL Injection
# Exploit Title: ChemInv 1.0 - Authenticated Persistent Cross-Site Scripting
# Title: VirtualTablet Server 3.0.2 - Denial of Service (PoC)
# Exploit Title: Online Scheduling System 1.0 - Persistent Cross-Site Scripting
# Exploit Title: php-fusion 9.03.50 - Persistent Cross-Site Scripting
# Title: Super Backup 2.0.5 for iOS - Directory Traversal
# Title: HardDrive 2.1 for iOS - Arbitrary File Upload
# Exploit Title: Apache OFBiz 17.12.03 - Cross-Site Request Forgery (Account Takeover)
# Exploit Title: Online Scheduling System 1.0 - Authentication Bypass
# Exploit Title: Open-AudIT Professional 3.3.1 - Remote Code Execution
# Exploit Title: School ERP Pro 1.0 - Arbitrary File Read
# Title: Easy Transfer 1.7 for iOS - Directory Traversal
# Exploit Title: Andrea ST Filters Service 1.0.64.7 - 'Andrea ST Filters Service ' Unquoted Service Path
# Title: Internet Download Manager 6.37.11.1 - Stack Buffer Overflow (PoC)
# Exploit Title: EmEditor 19.8 - Insecure File Permissions
# Exploit Title: hits script 1.0 - 'item_name' SQL Injection
# Exploit Title: Druva inSync Windows Client 6.5.2 - Local Privilege Escalation
# Exploit Title: CloudMe 1.11.2 - Buffer Overflow (PoC)
# Exploit Title: School ERP Pro 1.0 - 'es_messagesid' SQL Injection
# Exploit Title: NVIDIA Update Service Daemon 1.0.21 - 'nvUpdatusService' Unquoted Service Path
# Exploit Title: School ERP Pro 1.0 - Remote Code Execution
# Exploit Title: PHP-Fusion 9.03.50 - 'Edit Profile' Arbitrary File Upload
# Exploit Title: Netis E1+ 1.2.32533 - Backdoor Account (root)
# Exploit Title: Online shopping system advanced 1.0 - 'p' SQL Injection
# Exploit Title: Netis E1+ 1.2.32533 - Unauthenticated WiFi Password Leak
# Exploit Title: Online Course Registration 2.0 - Authentication Bypass
# Exploit Title: Maian Support Helpdesk 4.3 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: Source Engine CS:GO BuildID: 4937372 - Arbitrary Code Execution
# Exploit Title: EspoCRM 5.8.5 - Privilege Escalation
# Exploit Title: Edimax EW-7438RPn 1.13 - Remote Code Execution
# Exploit Title: Popcorn Time 6.2 - 'Update service' Unquoted Service Path
# Exploit Title: Furukawa Electric ConsciusMAP 2.8.1 - Remote Code Execution
# Exploit Title: User Management System 2.0 - Persistent Cross-Site Scripting
# Exploit Title: User Management System 2.0 - Authentication Bypass
# Exploit Title: Complaint Management System 4.2 - Persistent Cross-Site Scripting
# Exploit Title: Complaint Management System 4.2 - Authentication Bypass
# Exploit Title: Complaint Management System 4.2 - Cross-Site Request Forgery (Delete User)
# Exploit Title: Library CMS Powerful Book Management System 2.2.0 - Session Fixation
# Title: Sky File 2.1.0 iOS - Directory Traversal