thesystem 1.0 – Cross-Site Scripting
# Exploit Title: thesystem Persistent XSS
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: thesystem Persistent XSS
# Exploit Title: thesystem Command Injection
#!/usr/bin/python2.7
#!/usr/bin/env ruby
# Exploit Title: InoERP 0.7.2 - Persistent Cross-Site Scripting
# Title: Mobatek MobaXterm 12.1 - Buffer Overflow (SEH)
# Exploit Title: thesystem 1.0 - 'server_name' SQL Injection
# Exploit Title: thesystem App 1.0 - Persistent Cross-Site Scripting
# Exploit Title: thesystem App 1.0 - 'username' SQL Injection
# Title: V-SOL GPON/EPON OLT Platform 2.03 - Unauthenticated Configuration Download
# Exploit Title: V-SOL GPON/EPON OLT Platform 2.03 - Cross-Site Request Forgery
# Exploit Title: V-SOL GPON/EPON OLT Platform 2.03 - Remote Privilege Escalation
# Exploit Title: WordPress Theme Zoner Real Estate - 4.1.1 Persistent Cross-Site Scripting
# Exploit Title: Chamillo LMS 1.11.8 - Arbitrary File Upload
# Exploit Title: Duplicate-Post 3.2.3 - Persistent Cross-Site Scripting
# Exploit Title: all-in-one-seo-pack 3.2.7 - Persistent Cross-Site Scripting
# Exploit Title: inoERP 4.15 - 'download' SQL Injection
# Exploit Title: citecodecrashers Pic-A-Point 1.1 - 'Consignment' SQL Injection
# Exploit Title: Microsoft SharePoint 2013 SP1 - 'DestinationFolder' Persistent Cross-Site Scripting
# Exploit Title: SpotIE Internet Explorer Password Recovery 2.9.5 - 'Key' Denial of Service
# Exploit Title: WP Server Log Viewer 1.0 - 'logfile' Persistent Cross-Site Scripting
# Exploit Title: NPMJS gitlabhook 0.0.17 - 'repository' Remote Command Execution
# Exploit Title: YzmCMS 5.3 - 'Host' Header Injection
#!/usr/bin/python
#!/usr/bin/python
import socket
# Exploit Title: Pfsense 2.3.4 / 2.4.4-p3 - Remote Code Injection
There's a bug in the SymCrypt multi-precision arithmetic routines that can cause an infinite loop when calculating th...
When an NSKeyedUnarchiver decodes an object, it first allocates the object using allocWithZone, and then puts the obj...
#!/usr/bin/perl -w
# Exploit Title: InputMapper < 1.6.10 Local Denial of Service
# Exploit Title: Authenticated Local File Inclusion(LFI) in GilaCMS
#!/opt/local/bin/python2.7
Exploit Title: SockPuppet 3
# Exploit Title: LayerBB 1.1.3 - Multiple CSRF
# Exploit Title: SpotIE Internet Explorer Password Recovery 2.9.5 - 'Key' Denial of Service (DoS)
// ref : https://medium.com/tenable-techblog/uac-bypass-by-mocking-trusted-directories-24a96675f6e
# Exploit Title: Western Digital My Book World II NAS
# macOS-Kernel-Exploit
# Exploit Title: DIGIT CENTRIS 4 ERP - 'datum1' SQL Injection
# Exploit Title: GOautodial 4.0 - 'CreateEvent' Persistent Cross-Site Scripting
# Exploit Title: Hospital-Management 1.26 - 'fname' SQL Injection
#-----------------------------------------------------------------------------#
# Exploit Title: Inteno IOPSYS Gateway 3DES Key Extraction - Improper Access Restrictions
# Exploit Title: NetGain EM Plus