Java-springboot-codebase 1.1 – Arbitrary File Read
# Exploit Title: Java-springboot-codebase 1.1 - Arbitrary File Read
java 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Java-springboot-codebase 1.1 - Arbitrary File Read
# Exploit Title: Unrestricted File Upload
# Exploit Title: Apache HugeGraph Server 1.2.0 - Remote Code Execution (RCE)
# Exploit Title: DataEase 2.4.0 - Database Configuration Information Exposure
# Exploit Title: AppSmith 1.47 - Remote Code Execution (RCE)
# Exploit Title: Apache OFBiz 18.12.12 - Directory Traversal
# Exploit Title: Jenkins 2.441 - Local File Inclusion
#!/usr/bin/python
# Exploit Title: GitLab CE/EE < 16.7.2 - Password Reset
#- Exploit Title: JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE)
# Exploit Title: Spring Cloud 3.2.2 - Remote Command Execution (RCE)
# Exploit Title: Netlify CMS 2.10.192 - Stored Cross-Site Scripting (XSS)
# Exploit Title: Alkacon OpenCMS 15.0 - Multiple Cross-Site Scripting (XSS)
// Exploit Title: Goanywhere Encryption helper 7.1.1 - Remote Code Execution (RCE)
# Exploit Title: ERPNext 12.29 - Cross-Site Scripting (XSS)
# Exploit Title: Liferay Portal 6.2.5 - Insecure Permissions
# Exploit Title: Nacos 2.0.3 - Access Control vulnerability
# Exploit Title: AD Manager Plus 7122 - Remote Code Execution (RCE)
# Exploit Title: Confluence Data Center 7.18.0 - Remote Code Execution (RCE)
# Exploit Title: Spring Cloud Gateway 3.1.0 - Remote Code Execution (RCE)
# Exploit Title: Ametys CMS v4.4.1 - Cross Site Scripting (XSS)
# Exploit Title: Apache Log4j 2 - Remote Code Execution (RCE)
# Exploit Title: Apache Log4j2 2.14.1 - Information Disclosure
# Exploit Title: OpenAM 13.0 - LDAP Injection
# Exploit Title: Eclipse Jetty 11.0.5 - Sensitive File Disclosure
# Exploit Title: Jetty 9.4.37.v20210219 - Information Disclosure
# Exploit Title: Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)
# Exploit Title: Atlassian Confluence 7.12.2 - Pre-Authorization Arbitrary File Read
# Exploit Title: Confluence Server 7.12.4 - 'OGNL injection' Remote Code Execution (RCE) (Unauthenticated)
# Exploit Title: ApacheOfBiz 17.12.01 - Remote Command Execution (RCE) via Unsafe Deserialization of XMLRPC arguments
# Exploit Title: Neo4j 3.4.18 - RMI based Remote Code Execution (RCE)
# Exploit Title: CloverDX 5.9.0 - Cross-Site Request Forgery (CSRF) to Remote Code Execution (RCE)
# Exploit Title: ForgeRock Access Manager/OpenAM 14.6.3 - Remote Code Execution (RCE) (Unauthenticated)
# Exploit Title: Zoho ManageEngine ServiceDesk Plus MSP 9.4 - User Enumeration
# Exploit Title: Shopizer 2.16.0 - 'Multiple' Cross-Site Scripting (XSS)
# Exploit Title: CITSmart ITSM 9.1.2.27 - 'query' Time-based Blind SQL Injection (Authenticated)
# Exploit Title: CITSmart ITSM 9.1.2.22 - LDAP Injection
# Exploit Title: Novel Boutique House-plus 3.5.1 - Arbitrary File Download
# Exploit Title: CatDV 9.2 - RMI Authentication Bypass
# Exploit Title: Oracle WebLogic Server 12.2.1.0 - RCE (Unauthenticated)
# Exploit Title: Oracle WebLogic Server 14.1.1.0 - RCE (Authenticated)
# Exploit Title: Sonatype Nexus 3.21.1 - Remote Code Execution (Authenticated)
# Exploit Title: H2 Database 1.4.199 - JNI Code Execution
# Exploit Title: Jenkins 2.235.3 - 'X-Forwarded-For' Stored XSS
# Exploit Title: Jenkins 2.235.3 - 'Description' Stored XSS
# Exploit Title: Jenkins 2.235.3 - 'tooltip' Stored Cross-Site Scripting
#!/usr/bin/env python3
# Exploit Title: Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution