Schneider Electric U.Motion Builder 1.3.4 – Authenticated Command Injection
# Exploit Title: Schneider Electric U.Motion Builder 1.3.4 - Authenticated Command Injection
hardware 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Schneider Electric U.Motion Builder 1.3.4 - Authenticated Command Injection
# Exploit Title: Fifthplay S.A.M.I 2019.2_HP - Persistent Cross-Site Scripting
# Exploit Title: Satellian 1.12 - Remote Code Execution
# Exploit Title: Genexis Platinum-4410 2.1 - Authentication Bypass
# Exploit Title: TP-Link TP-SG105E 1.0.0 - Unauthenticated Remote Reboot
// EDB Note: Download ~ https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/47936.zip
# Exploit Title: IBM RICOH 6400 Printer - HTML Injection
# Exploit Title: IBM RICOH InfoPrint 6500 Printer - HTML Injection
# Exploit Title: EBBISLAND EBBSHAVE 6100-09-04-1441 - Remote Buffer Overflow
# Exploit Title: piSignage 2.6.4 - Directory Traversal
# Exploit Title: IBM RICOH Infoprint 1532 Printer - Persistent Cross-Site Scripting
# Exploit Title: IBM InfoPrint 4247-Z03 Impact Matrix Printer - Directory Traversal
# Exploit Title: Heatmiser Netmonitor 3.03 - HTML Injection
# Exploit Title: RICOH Web Image Monitor 1.09 - HTML Injection
# Exploit Title: RICOH SP 4510SF Printer - HTML Injection
# Exploit: MyDomoAtHome REST API Domoticz ISS Gateway 0.2.40 - Information Disclosure
# Exploit Title: Heatmiser Netmonitor 3.03 - Hardcoded Credentials
# Exploit: AVE DOMINAplus 1.10.x - Authentication Bypass
# Exploit: AVE DOMINAplus 1.10.x - Cross-Site Request Forgery (enable/disable alarm)
# Exploit: AVE DOMINAplus 1.10.x - Unauthenticated Remote Reboot
# Exploit: AVE DOMINAplus 1.10.x - Credential Disclosure
# Exploit: WEMS BEMS 21.3.1 - Undocumented Backdoor Account
# Exploit Title: XEROX WorkCentre 7830 Printer - Cross-Site Request Forgery (Add Admin)
# Exploit Title: XEROX WorkCentre 7855 Printer - Cross-Site Request Forgery (Add Admin)
# Exploit Title: XEROX WorkCentre 6655 Printer - Cross-Site Request Forgery (Add Admin)
# Exploit: HomeAutomation 3.3.2 - Persistent Cross-Site Scripting
# Exploit Title: Deutsche Bahn Ticket Vending Machine Local Kiosk - Privilege Escalation
# Exploit Title: Xerox AltaLink C8035 Printer - Cross-Site Request Forgery (Add Admin)
# Exploit Title: Netgear R6400 - Remote Code Execution
# Exploit Title: D-Link DIR-615 - Privilege Escalation
# Exploit Title: D-Link DIR-615 Wireless Router - Persistent Cross-Site Scripting
# Title: NVMS-1000 - Directory Traversal
# Exploit Title: Inim Electronics Smartliving SmartLAN 6.x - Remote Command Execution
# Exploit Title: Inim Electronics Smartliving SmartLAN 6.x - Unauthenticated Server-Side Request Forgery
# Exploit Title: Inim Electronics Smartliving SmartLAN 6.x - Hard-coded Credentials
# Exploit Title: Yachtcontrol Webapplication 1.0 - Unauthenticated Remote Code Execution
# Exploit Title: Omron PLC 1.0.0 - Denial of Service (PoC)
# Exploit Title: Cisco WLC 2504 8.9 - Denial of Service (PoC)
# Exploit Title: Intelbras Router RF1200 1.1.3 - Cross-Site Request Forgery
# Exploit Title: Network Management Card 6.2.0 - Host Header Injection
# Exploit Title: TestLink 1.9.19 - Persistent Cross-Site Scripting
# Exploit Title: Centova Cast 3.2.12 - Denial of Service (PoC)
# Exploit Title: Centova Cast 3.2.11 - Arbitrary File Download
# Exploit Title: Lexmark Services Monitor 2.27.4.0.39 - Directory Traversal
# Title: Siemens Desigo PX 6.00 - Denial of Service (PoC)
# Exploit Title: Fastweb Fastgate 0.00.81 - Remote Code Execution
# Exploit Title: Technicolor TC7300.B0 - 'hostname' Persistent Cross-Site Scripting
# Exploit Title: Technicolor TD5130.2 - Remote Command Execution