WordPress Plugin Event Tickets 4.10.7.1 – CSV Injection
# Exploit Title: WordPress Plugin Event Tickets >= 4.10.7.1 - CSV Injection
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: WordPress Plugin Event Tickets >= 4.10.7.1 - CSV Injection
#!/usr/bin/perl -w
# Exploit Title: Alkacon OpenCMS 10.5.x - Multiple XSS in Apollo Template
# Exploit Title: Alkacon OpenCMS 10.5.x - Multiple XSS in Alkacon OpenCms
# Exploit Title: Alkacon OpenCMS 10.5.x - Multiple LFI in Alkacon OpenCms
# Exploit Title: Kaseya VSA agent
# Exploit Title : CraftCms Users information disclosure From uploaded File
#### Fileless UAC bypass (WSReset.exe)
#Exploit Title: SQL Server Password Changer v1.90 Denial of Service Exploit
#!/usr/bin/python
# Exploit Title: Content Provider URI Injection on Canon PRINT 2.5.5
#!/usr/bin/python
# Exploit Title: Sentrifugo 3.2 - File Upload Restriction Bypass
# Exploit Title: Sentrifugo 3.2 - Persistent Cross-Site Scripting
# Exploit Title: DomainMod
# Exploit Title: YouPHPTube
# Exploit Title: WordPress Plugin WooCommerce Product Feed
# Exploit Title: VX Search Enterprise v10.4.16 DoS
#!/bin/bash
# Exploit Title: PilusCart
https://github.com/WebKit/webkit/blob/94e868c940d46c5745869192d07255331d00102b/Source/JavaScriptCore/dfg/DFGArguments...
#Exploit Title: Outlook Password Recovery v2.10 Denial of Service Exploit
# Exploit Title: Jobberbase 2.0 CMS - 'jobs-in' SQL Injection
# Exploit Title: Tableau XXE
# Exploit Title: LSoft ListServ < 16.5 - Cross-Site Scripting (XSS)
# Exploit Title: Wordpress Plugin Import Export WordPress Users
# Exploit Title: UserPro
# Exploit Title: openITCOCKPIT 3.6.1-2 - CSRF 2 RCE
Windows: SET_REPARSE_POINT_EX Mount Point Security Feature Bypass
# Nimble Streamer 3.0.2-2 to 3.5.4-9 - Path Traversal
# Exploit Title: File disclosure in Pulse Secure SSL VPN (metasploit)
>> Multiple critical vulnerabilities in Cisco UCS Director, Cisco Integrated Management Controller Supervisor and Cis...
# Exploit Title: CSRF vulnerabilities in WP Add Mime Types Plugin
#include
# Exploit Title: RAR Password Recovery v1.80 Denial of Service Exploit
# Exploit Title: Kimai 2- persistent cross-site scripting (XSS)
# Exploit Title: Fortinet FortiOS Leak file - Reading login/passwords in clear text.
# Exploit Title: Fortinet FortiOS Leak file - Reading login/passwords in clear text.
# Exploit Title: Neo Billing 3.5 - Stored Cross Site Scripting Vulnerability
#!/bin/sh
# Exploit Title: YouPHPTube < 7.3 SQL Injection
# Exploit Title: EyesOfNetwork 5.1 - Authenticated Remote Command Execution
# Exploit Title: Joomla! component com_jsjobs 1.2.6 - Arbitrary File Deletion
# Exploit Title : GetGo Download Manager 6.2.2.3300 - Denial of Service
# Exploit Title: Integria IMS 5.0.86 - Arbitrary File Upload