phpMyFAQ 3.1.7 – Reflected Cross-Site Scripting (XSS)
# Exploit Title: phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS)
# Exploit Title: Hugging Face Transformers MobileViTV2 RCE
# Exploit Title: NagVis 1.9.33 - Arbitrary File Read
# Exploit Title: Zabbix 7.0.0 - SQL Injection
# Exploit title : ABB Cylon Aspect 4.00.00 (factorySetSerialNum.php) Remote Code Execution
# Exploit title: ABB Cylon Aspect 4.00.00 (factorySaved.php) Unauthenticated XSS
# Exploit title: ABB Cylon Aspect 3.08.03 (webServerDeviceLabelUpdate.php) File Write DoS
# Exploit Title: phpMyFAQ v3.2.10 - Unintended File Download Triggered by Embedded Frames
# Exploit Title: Garage Management System 1.0 (categoriesName) - Stored XSS
# Exploit Title: Fortinet FortiOS, FortiProxy, and FortiSwitchManager 7.2.0 - Authentication bypass
# Exploit Title: FLIR AX8 1.46.16 - Remote Command Injection
# Exploit Title: Ethercreative Logs 3.0.3 - Path Traversal
# Exploit Title: CommScope Ruckus IoT Controller 1.7.1.0 - Undocumented Account
# Exploit Title: Car Rental Project 1.0 - Remote Code Execution
# Exploit Title: ASUS ASMB8 iKVM 1.14.51 - Remote Code Execution (RCE)
# Exploit Title: KodExplorer 4.52 - Open Redirect
# Exploit Title: Smart Manager 8.27.0 - Post-Authenticated SQL Injection
# Exploit Title : Pymatgen 2024.1 - Remote Code Execution (RCE)
# Exploit Title: Unrestricted File Upload
#!/usr/bin/env python3
# Exploit Title: Adapt Authoring Tool 0.11.3 - Remote Command Execution (RCE)
# Exploit Title: OpenCMS 17.0 - Stored Cross Site Scripting (XSS)
# Author Title: John Page (aka hyp3rlinx)
# Exploit Title: Plane - Server side request forgery (SSRF)
# Author Title: John Page (aka hyp3rlinx)
# Exploit Title: Ivanti Connect Secure 22.7R2.5 - Remote Code Execution (RCE)
ABB Cylon Aspect 3.08.02 (licenseServerUpdate.php) Stored Cross-Site Scripting
ABB Cylon Aspect 3.08.02 (licenseUpload.php) Stored Cross-Site Scripting
ABB Cylon Aspect 3.08.02 (uploadDb.php) - Remote Code Execution
ABB Cylon Aspect 3.08.02 (bbmdUpdate.php) - Remote Code Execution
ABB Cylon Aspect 3.08.02 (escDevicesUpdate.php) Off-by-One Config Write DoS
ABB Cylon Aspect 3.08.02 (webServerUpdate.php) Input Validation Config Poisoning
ABB Cylon Aspect 3.08.03 (CookieDB) SQL Injection
ABB Cylon Aspect 3.07.02 (userManagement.php) - Weak Password Policy
ABB Cylon Aspect 3.08.03 (MapServicesHandler) - Authenticated Reflected XSS
ABB Cylon Aspect 3.08.03 Hard-coded Secrets
ABB Cylon Aspect 3.08.02 - Cookie User Password Disclosure
# Exploit Title: Cacti 1.2.26 - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: Authenticated Stored Cross-Site Scripting (XSS) Via Search
# Exploit Title: GestioIP 3.5.7 - Reflected Cross-Site Scripting (Reflected XSS)
# Exploit Title: ZTE ZXHN H168N 3.1 - RCE via authentication bypass
# Exploit Title: Xinet Elegant 6 Asset Lib Web UI 6.1.655 - SQL Injection
# Exploit Title: Pimcore customer-data-framework 4.2.0 - SQL injection
# Exploit Title: OpenPanel 0.3.4 - Directory Traversal
# Exploit Title: OpenPanel 0.3.4 - Incorrect Access Control
# Exploit Title: OpenPanel 0.3.4 - OS Command Injection
# Exploit Title: OpenPanel Copy and View functions in the File Manager 0.3.4 - Directory Traversal
# Exploit Title: SilverStripe 5.3.8 - Stored Cross Site Scripting (XSS) (Authenticated)
# Exploit Title: GestioIP 3.5.7 - GestioIP Vulnerability: Auth. Cross-Site Request Forgery (CSRF)