Control Web Panel 7 (CWP7) v0.9.8.1147 – Remote Code Execution (RCE)
// Exploit Title: Control Web Panel 7 (CWP7) v0.9.8.1147 - Remote Code Execution (RCE)
php 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
// Exploit Title: Control Web Panel 7 (CWP7) v0.9.8.1147 - Remote Code Execution (RCE)
# Exploit Title: Online Eyewear Shop 1.0 - SQL Injection (Unauthenticated)
## Title: bgERP v22.31 (Orlovets) - Cookie Session vulnerability & Cross-Site Scripting (XSS)
# Exploit Title: Bus Pass Management System 1.0 - Stored Cross-Site Scripting (XSS)
# Exploit Title: Calendar Event Multi View 1.4.07 - Unauthenticated Arbitrary Event Creation to Cross-Site Scripting...
## Exploit Title: zstore 6.6.0 - Cross-Site Scripting (XSS)
Exploit Title: projectSend r1605 - Remote Code Exectution RCE
# Exploit Title: PhotoShow 3.0 - Remote Code Execution
#!/usr/bin/env python
# Exploit Title: GLPI Cartography Plugin v6.0.0 - Unauthenticated Remote Code Execution (RCE)
# ADVISORY INFORMATION
# Exploit Title: GLPI Activity v3.1.0 - Authenticated Local File Inclusion on Activity plugin
# ADVISORY INFORMATION
# ADVISORY INFORMATION
# Exploit Title: ERPGo SaaS 3.9 - CSV Injection
# Exploit Title: AmazCart CMS 3.4 - Cross-Site-Scripting (XSS)
# Exploit Title: Art Gallery Management System Project v1.0 - SQL Injection (editid) authenticated
# Exploit Title: Art Gallery Management System Project v1.0 - SQL Injection (cid) Unauthenticated
# Exploit Title: Art Gallery Management System Project v1.0 - Reflected Cross-Site Scripting (XSS)
# Exploit Title: MyBB 1.8.32 - Chained LFI Remote Code Execution (RCE) (Authenticated)
## Exploit Title: SLIMSV 9.5.2 - Cross-Site Scripting (XSS)
## Exploit Title: Zstore 6.5.4 - Reflected Cross-Site Scripting (XSS)
# Exploit Title: Metform Elementor Contact Form Builder v3.1.2 - Unauthenticated Stored Cross-Site Scripting (XSS)
## Title: ChiKoi-1.0 SQLi
## Exploit Title: pimCore v5.4.18-skeleton - Sensitive Cookie with Improper SameSite Attribute
# Exploit Title: Yahoo User Interface library (YUI2) TreeView v2.8.2 - Multiple Reflected Cross Site Scripting (XSS)
# Exploit Title: PMB 7.4.6 - SQL Injection
#!/usr/bin/env python
# Exploit Title: Prizm Content Connect v10.5.1030.8315 - XXE
Exploit Title: XCMS v1.83 - Remote Command Execution (RCE)
# Exploit Title: Textpattern 4.8.8 - Remote Code Execution (RCE) (Authenticated)
## Exploit Title: Bangresto 1.0 - SQL Injection
# Exploit Title: Cacti v1.2.22 - Remote Command Execution (RCE)
# Exploit Title: Judging Management System v1.0 - Authentication Bypass
# Exploit Title: Judging Management System v1.0 - Remote Code Execution (RCE)
# Exploit Title: rconfig 3.9.7 - Sql Injection (Authenticated)
# Exploit Title: Spitfire CMS 1.0.475 - PHP Object Injection
## Exploit Title: Senayan Library Management System v9.0.0 - SQL Injection
# Exploit Title: Bludit 3-14-1 Plugin 'UploadPlugin' - Remote Code Execution (RCE) (Authenticated)
# Title: Wordpress Plugin WooCommerce v7.1.0 - Remote Code Execution(RCE)
# Exploit Title: Eve-ng 5.0.1-13 - Stored Cross-Site Scripting (XSS)
# Exploit Title: WPForms 1.7.8 - Cross-Site Scripting (XSS)
# Exploit Title: 4images 1.9 - Remote Command Execution (RCE)
# Exploit Title: Device Manager Express 7.8.20002.47752 - Remote Code Execution (RCE)
## Exploit Title: Concrete5 CME v9.1.3 - Xpath injection
## Title: Ecommerse v1.0 - Cross-Site Scripting (XSS)
# Exploit Title: myBB forums 1.8.26 - Stored Cross-Site Scripting (XSS)
## Title: ClicShopping v3.402 - Cross-Site Scripting (XSS)
# Exploit Title: Revenue Collection System v1.0 - Remote Code Execution (RCE)