Cacti v1.2.8 – Unauthenticated Remote Code Execution (Metasploit)
# Exploit Title: Cacti v1.2.8 - Unauthenticated Remote Code Execution (Metasploit)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Cacti v1.2.8 - Unauthenticated Remote Code Execution (Metasploit)
# Exploit Title: Wing FTP Server 6.2.3 - Privilege Escalation
#!/usr/bin/env python3
#!/usr/bin/python
# Exploit Title: Business Live Chat Software 1.0 - Cross-Site Request Forgery (Add Admin)
# Title: Comtrend VR-3033 - Authenticated Command Injection
# Exploit Title: Core FTP LE 2.2 - Denial of Service (PoC)
# Title: PhpIX 2012 Professional - 'id' SQL Injection
# Title: OpenSMTPD 6.6.3 - Arbitrary File Read
# Exploit Title: SpotFTP-FTP Password Recover 2.4.8 - Denial of Service (PoC)
# Exploit Title: aSc TimeTables 2020.11.4 - Denial of Service (PoC)
# Exploit Title: WordPress Plugin WooCommerce CardGate Payment Gateway 3.1.15 - Payment Process Bypass
# Exploit Title: Magento WooCommerce CardGate Payment Gateway 2.0.30 - Payment Process Bypass
# Exploit Title : Odin Secure FTP Expert 7.6.3 - Denial of Service (PoC)
# Exploit Title: Avaya IP Office Application Server 11.0.0.0 - Reflective Cross-Site Scripting
# Exploit Title: GUnet OpenEclass E-learning platform 1.7.3 - 'uname' SQL Injection
# Title: ESCAM QD-900 WIFI HD Camera - Remote Configuration Disclosure
# Title : AMSS++ v 4.31 - 'id' SQL Injection
# Exploit Title: SecuSTATION IPCAM-130 HD Camera - Remote Configuration Disclosure
# Title: Quick N Easy Web Server 3.3.8 - Denial of Service (PoC)
# Title: CandidATS 2.1.0 - Cross-Site Request Forgery (Add Admin)
# Title: AMSS++ 4.7 - Backdoor Admin Account
# Exploit Title: SecuSTATION SC-831 HD Camera - Remote Configuration Disclosure
# Exploit Title: ATutor 2.2.4 - 'id' SQL Injection
# Exploit Title: I6032B-P POE 2.0MP Outdoor Camera - Remote Configuration Disclosure
# Exploit Title: ManageEngine EventLog Analyzer 10.0 - Information Disclosure
# Exploit Title: Go SSH servers 0.0.2 - Denial of Service (PoC)
# Title: eLection 2.0 - 'id' SQL Injection
# Exploit Title: DotNetNuke 9.5 - Persistent Cross-Site Scripting
# Exploit Title: DotNetNuke 9.5 - File Upload Restrictions Bypass
# Exploit Title: Aptina AR0130 960P 1.3MP Camera - Remote Configuration Disclosure
# Exploit Title: Cacti 1.2.8 - Remote Code Execution
# Exploit Title: Easy2Pilot 7 - Cross-Site Request Forgery (Add User)
# Exploit Title : Core FTP Lite 1.3 - Denial of Service (PoC)
#!/usr/bin/env python
# Exploit title : Virtual Freer 1.58 - Remote Command Execution
# Exploit Title: DBPower C300 HD Camera - Remote Configuration Disclosure
# Exploit Title: Nanometrics Centaur 4.3.23 - Unauthenticated Remote Memory Leak
# Exploit Title: WordPress Plugin WP Sitemap Page 1.6.2 - Persistent Cross-Site Scripting
# Exploit Title: SOPlanning 1.45 - 'by' SQL Injection
# Exploit Title: HP System Event 1.2.9.0 - 'HPWMISVC' Unquoted Service Path
# Exploit Title: Wordpress Plugin Strong Testimonials 2.40.0 - Persistent Cross-Site Scripting
# Exploit Title: Avaya Aura Communication Manager 5.2 - Remote Code Execution
# Exploit Title: BOOTP Turbo 2.0.1214 - 'BOOTP Turbo' Unquoted Service Path
# Exploit Title: MSI Packages Symbolic Links Processing - Windows 10 Privilege Escalation