PackWeb Formap E-learning 1.0 – ‘NumCours’ SQL Injection
# Exploit Title: PackWeb Formap E-learning 1.0 - 'NumCours' SQL Injection
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: PackWeb Formap E-learning 1.0 - 'NumCours' SQL Injection
# Exploit Title: EyesOfNetwork 5.3 - Remote Code Execution
[+] Exploit Title: ExpertGPS 6.38 - XML External Entity Injection
# Exploit Title: Google Invisible RECAPTCHA 3 - Spoof Bypass
# Exploit Title: AbsoluteTelnet 11.12 - "license name" Denial of Service (PoC)
# Exploit Title: AbsoluteTelnet 11.12 - "license name" Denial of Service (PoC)
# Exploit Title: Online Job Portal 1.0 - 'user_email' SQL Injection
# Exploit Title: VIM 8.2 - Denial of Service (PoC)
#Exploit Title: ELAN Smart-Pad 11.10.15.1 - 'ETDService' Unquoted Service Path
# Exploit Title: AbsoluteTelnet 11.12 - 'SSH2/username' Denial of Service (PoC)
# Exploit Title: TapinRadio 2.12.3 - 'address' Denial of Service (PoC)
# Exploit Title: Online Job Portal 1.0 - Remote Code Execution
# Exploit Title: TapinRadio 2.12.3 - 'username' Denial of Service (PoC)
# Exploit Title: RarmaRadio 2.72.4 - 'username' Denial of Service (PoC)
# Exploit Title: RarmaRadio 2.72.4 - 'server' Denial of Service (PoC)
# Exploit Title: Online Job Portal 1.0 - Cross Site Request Forgery (Add User)
# Exploit Title: Ecommerce Systempay 1.0 - Production KEY Brute Force
#!/usr/bin/python
#!/usr/bin/python
#!/bin/bash
# Exploit Title: AVideo Platform 8.1 - Information Disclosure (User Enumeration)
# Exploit Title: Wago PFC200 - Authenticated Remote Code Execution (Metasploit)
# Exploit Title: Socat 1.7.3.4 - Heap Based Overflow (PoC)
# Exploit Title: xglance-bin 11.00 - Privilege Escalation
# Exploit Title: Kronos WebTA 4.0 - Authenticated Remote Privilege Escalation
# Exploit Title: Verodin Director Web Console 3.5.4.0 - Remote Authenticated Password Disclosure (PoC)
# Exploit Title: AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset)
# Exploit Title: HiSilicon DVR/NVR hi3520d firmware - Remote Backdoor Account
# Title: Sudo 1.8.25p - Buffer Overflow
# Title: F-Secure Internet Gatekeeper 5.40 - Heap Overflow (PoC)
# Exploit Title: BearFTP 0.1.0 - 'PASV' Denial of Service
# Title: IceWarp WebMail 11.4.4.1 - Reflective Cross-Site Scripting
# Exploit Title: phpList 3.5.0 - Authentication Bypass
# Exploit Title: Jira 8.3.4 - Information Disclosure (Username Enumeration)
# Exploit Title: Schneider Electric U.Motion Builder 1.3.4 - Authenticated Command Injection
# Title: School ERP System 1.0 - Cross Site Request Forgery (Add Admin)
# Exploit Title: P2PWIFICAM2 for iOS 10.4.1 - 'Camera ID' Denial of Service (PoC)
#!/usr/bin/python3
#!/usr/bin/python3
# Exploit Title: Lotus Core CMS 1.0.1 - Local File Inclusion
# Exploit Title: FlexNet Publisher 11.12.1 - Cross-Site Request Forgery (Add Local Admin)
# Exploit Title: Microsoft Windows Media Center WMV or WMA 6.3.9600.16384 - Code Execution
# Exploit Title: rConfig 3.9.3 - Authenticated Remote Code Execution
# Exploit Title: OpenSMTPD 6.6.1 - Remote Code Execution
# Exploit Title: Kibana 6.6.1 - CSV Injection
# Exploit Title: Liferay CE Portal 6.0.2 - Remote Command Execution
# Title: Cups Easy 1.0 - Cross Site Request Forgery (Password Reset)