GestioIP 3.5.7 – Stored Cross-Site Scripting (Stored XSS)
# Exploit Title: GestioIP 3.5.7 - GestioIP Vulnerability: Auth. Stored Cross-Site Scripting
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: GestioIP 3.5.7 - GestioIP Vulnerability: Auth. Stored Cross-Site Scripting
# Exploit Title: GestioIP 3.5.7 - GestioIP Vulnerability: Auth. Cross-Site Scripting (XSS)
# Exploit Title: GestioIP 3.5.7 - Remote Command Execution (RCE)
# Exploit Title: flatCore 1.5 - Cross Site Request Forgery (CSRF)
# Exploit Title: GetSimpleCMS 3.3.16 - Remote Code Execution (RCE)
# Exploit Title: RosarioSIS 7.6 - SQL Injection
# Exploit Title: MagnusSolution magnusbilling 7.3.0 - Command Injection
# Exploit Title: LearnPress WordPress LMS Plugin 4.2.7 - SQL Injection
# Exploit Title: CyberPanel 2.3.6 - Remote Code Execution (RCE)
# Exploit Title: Roundcube Webmail 1.6.6 - Stored Cross Site Scripting (XSS)
# Exploit Title: NEWS-BUZZ News Management System 1.0 - SQL Injection
# Exploit Title: MiniCMS 1.1 - Cross Site Scripting (XSS)
# Exploit Title: phpIPAM 1.6 - Reflected Cross Site Scripting (XSS)
# Exploit Title: Nagios Log Server 2024R1.3.1 - API Key Exposure
# Exploit Tiltle: ABB Cylon FLXeon 9.3.4 - System Logs Information Disclosure
ABB Cylon FLXeon 9.3.4 Default Credentials
# Exploit title: ABB Cylon FLXeon 9.3.4 Limited Cross-Site Request Forgery
# ABB Cylon FLXeon 9.3.4 (wsConnect.js) WebSocket Command Spawning PoC
# Exploit Title: WebFileSys 2.31.0 - Directory Path Traversal in relPath Parameter
# Exploit Tile: CMU CERT/CC VINCE 2.0.6 - Stored XSS
# Exploit title: ABB Cylon Aspect 3.08.02 PHP Session Fixation Vulnerability
# Exploit Title: Netman 204 - Remote command with out authentication
# Exploit title: ABB Cylon FLXeon 9.3.4 - Remote Code Execution (RCE)
# Exploit Title: GeoVision GV-ASManager 6.1.1.0 - CSRF
# Exploit Title: ABB Cylon FLXeon 9.3.4 - Remote Code Execution (Authenticated)
# Exploit Title: Broken Access Control in GeoVision GV-ASManager
# Exploit Title: qBittorrent 5.0.1 MITM RCE
# Exploit Title: Feng Office 3.11.1.2 - SQL Injection
# Exploit Title: Cisco Smart Software Manager On-Prem 8-202206 - Account Takeover
# Exploit Title : Centron 19.04 - Remote Code Execution (RCE)
# Exploit Title: PandoraFMS 7.0NG.772 - SQL Injection
# Exploit Title: K7 Ultimate Security K7RKScan.sys 17.0.2019 - Denial Of Service (DoS)
# Exploit Title: CodeAstro Online Railway Reservation System 1.0 - Cross Site Scripting (XSS)
# Exploit Title: Cosy+ firmware 21.2s7 - Command Injection
# Exploit Title: Typecho 1.3.0 - Race Condition
# Exploit Title: Typecho 1.3.0 - Stored Cross-Site Scripting (XSS)
# Exploit Title: AquilaCMS 1.409.20 - Remote Command Execution (RCE)
# Exploit Title: flatCore 1.5.5 - Arbitrary File Upload
# Exploit Title: Intelight X-1L Traffic controller Maxtime 1.9.6 - Remote Code Execution (RCE)
# Exploit Title: DocsGPT 0.12.0 - Remote Code Execution
# Exploit Title: Artica Proxy 4.50 - Remote Code Execution (RCE)
# Exploit Title: ManageEngine ADManager Plus Build < 7210 Elevation of
# Exploit Title: Apache HugeGraph Server 1.2.0 - Remote Code Execution (RCE)
# Exploit Title: ResidenceCMS 2.10.1 - Stored Cross-Site Scripting (XSS)
# Exploit Title: ChurchCRM 5.9.1 - SQL Injection
# Exploit Title: PZ Frontend Manager WordPress Plugin 1.0.5 - Cross Site Request Forgery (CSRF)
# Exploit Title: WordPress User Registration & Membership Plugin
# Exploit Title: Nagiosxi authenticated Remote Code Execution
# Exploit Title: UNA CMS
# Exploit Title: Jasmin Ransomware - (Authenticated) Arbitrary File Download