Click2Magic 1.1.5 – Stored Cross-Site Scripting
# Exploit Title: Click2Magic 1.1.5 - Stored Cross-Site Scripting
multiple 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Click2Magic 1.1.5 - Stored Cross-Site Scripting
# Exploit Title: Flexmonster Pivot Table & Charts 2.7.17 - 'Remote JSON' Reflected XSS
# Exploit Title: Flexmonster Pivot Table & Charts 2.7.17 - 'To remote CSV' Reflected XSS
# Exploit Title: Flexmonster Pivot Table & Charts 2.7.17 - 'To OLAP' Reflected XSS
# Exploit Title: Flexmonster Pivot Table & Charts 2.7.17 - 'Remote Report' Reflected XSS
# Exploit Title: Academy-LMS 4.3 - Stored XSS
# Exploit Title: Spotweb 1.4.9 - 'search' SQL Injection
# Exploit Title: Nxlog Community Edition 2.10.2150 - DoS (Poc)
# Exploit Title: Rumble Mail Server 0.51.3135 - 'username' Stored XSS
# Exploit Title: Rumble Mail Server 0.51.3135 - 'domain and path' Stored XSS
# Exploit Title: Rumble Mail Server 0.51.3135 - 'servername' Stored XSS
# Exploit Title: WordPress Plugin Total Upkeep 1.14.9 - Database and Files Backup Download
# Exploit Title: Seacms 11.1 - 'checkuser' Stored XSS
# Exploit Title: Seacms 11.1 - 'file' Local File Inclusion
# Exploit Title: Seacms 11.1 - 'ip and weburl' Remote Command Execution
# Exploit Title: MiniWeb HTTP Server 0.8.19 - Buffer Overflow (PoC)
# Exploit Title: LibreNMS 1.46 - MAC Accounting Graph Authenticated SQL Injection
# Exploit Title: Tibco ObfuscationEngine 5.11 - Fixed Key Password Decryption
# Exploit Title: VestaCP 0.9.8-26 - 'backup' Information Disclosure
# Exploit Title: VestaCP 0.9.8-26 - 'LoginAs' Insufficient Session Validation
#Title: Chromium 83 - Full CSP Bypass
# Exploit Title: Testa Online Test Management System 3.4.7 - 'q' SQL Injection
# Exploit Title: Phpscript-sgh 0.1.0 - Time Based Blind SQL Injection
# Exploit Title: Wordpress Plugin Canto 1.3.0 - Blind SSRF (Unauthenticated)
# Exploit Title: Invision Community 4.5.4 - 'Field Name' Stored Cross-Site Scripting
# Exploit Title: mojoPortal forums 2.7.0.0 - 'Title' Persistent Cross-Site Scripting
# Exploit Title: EgavilanMedia Address Book 1.0 Exploit - SQLi Auth Bypass
#Exploit Title: ChurchCRM 4.2.1- Persistent Cross Site Scripting(XSS)
#Exploit Title: ChurchCRM 4.2.1- CSV/Formula Injection
# Exploit Title: WebDamn User Registration & Login System with User Panel - SQLi Auth Bypass
# Exploit Title: Ksix Zigbee Devices - Playback Protection Bypass (PoC)
# Exploit Title: DotCMS 20.11 - Stored Cross-Site Scripting
# Exploit Title: Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit Profile
# Exploit Title: Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated)
# Exploit Title: Employee Record Management System 1.1 - Login Bypass SQL Injection
# Exploit Title: Local Service Search Engine Management System 1.0 - SQLi Authentication Bypass
# Exploit Title: Online News Portal System 1.0 - 'Title' Stored Cross Site Scripting
# Exploit Title: Bakeshop Online Ordering System 1.0 - 'Owner' Persistent Cross-site scripting
# Exploit Title: NewsLister - Authenticated Persistent Cross-Site Scripting
# Exploit Title: Online Voting System Project in PHP - 'username' Persistent Cross-Site Scripting
# Exploit Title: EgavilanMedia User Registration & Login System with Admin Panel 1.0 - Stored Cross Site Scripting
# Exploit Title: Student Result Management System 1.0 - Authentication Bypass SQL Injection
# Exploit Title: EgavilanMedia User Registration & Login System with Admin Panel 1.0 - CSRF
# Exploit Title: Under Construction Page with CPanel 1.0 - SQL injection
# Exploit Title: ILIAS Learning Management System 4.3 - SSRF
# Exploit Title: Expense Management System - 'description' Stored Cross Site Scripting
#Exploit Title: Tendenci 12.3.1 - CSV/ Formula Injection
# Exploit Title: Setelsa Conacwin 3.7.1.2 - Local File Inclusion
# Exploit Title: Acronis Cyber Backup 12.5 Build 16341 - Unauthenticated SSRF
# Exploit Title: SAP Lumira 1.31 - Stored Cross-Site Scripting