ABB Cylon Aspect 3.08.03 (webServerDeviceLabelUpdate.php) – File Write DoS
# Exploit title: ABB Cylon Aspect 3.08.03 (webServerDeviceLabelUpdate.php) File Write DoS
php 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit title: ABB Cylon Aspect 3.08.03 (webServerDeviceLabelUpdate.php) File Write DoS
# Exploit title: ABB Cylon Aspect 4.00.00 (factorySaved.php) Unauthenticated XSS
# Exploit title : ABB Cylon Aspect 4.00.00 (factorySetSerialNum.php) Remote Code Execution
# Exploit Title: Zabbix 7.0.0 - SQL Injection
# Exploit Title: NagVis 1.9.33 - Arbitrary File Read
# Exploit Title: phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS)
# Exploit Title: Cacti 1.2.26 - Remote Code Execution (RCE) (Authenticated)
ABB Cylon Aspect 3.08.02 (webServerUpdate.php) Input Validation Config Poisoning
ABB Cylon Aspect 3.08.02 (escDevicesUpdate.php) Off-by-One Config Write DoS
# Exploit Title: OpenCMS 17.0 - Stored Cross Site Scripting (XSS)
#!/usr/bin/env python3
# Exploit Title: phpIPAM 1.6 - Reflected Cross Site Scripting (XSS)
# Exploit Title: MiniCMS 1.1 - Cross Site Scripting (XSS)
# Exploit Title: NEWS-BUZZ News Management System 1.0 - SQL Injection
# Exploit Title: Roundcube Webmail 1.6.6 - Stored Cross Site Scripting (XSS)
# Exploit Title: LearnPress WordPress LMS Plugin 4.2.7 - SQL Injection
# Exploit Title: RosarioSIS 7.6 - SQL Injection
# Exploit Title: GetSimpleCMS 3.3.16 - Remote Code Execution (RCE)
# Exploit Title: flatCore 1.5 - Cross Site Request Forgery (CSRF)
# Exploit Title: flatCore 1.5.5 - Arbitrary File Upload
# Exploit Title: AquilaCMS 1.409.20 - Remote Command Execution (RCE)
# Exploit Title: Typecho 1.3.0 - Stored Cross-Site Scripting (XSS)
# Exploit Title: Typecho 1.3.0 - Race Condition
# Exploit Title: CodeAstro Online Railway Reservation System 1.0 - Cross Site Scripting (XSS)
# Exploit Title: PandoraFMS 7.0NG.772 - SQL Injection
# Exploit Title : Centron 19.04 - Remote Code Execution (RCE)
# Exploit Title: Feng Office 3.11.1.2 - SQL Injection
# Exploit Title: PZ Frontend Manager WordPress Plugin 1.0.5 - Cross Site Request Forgery (CSRF)
# Exploit Title: ChurchCRM 5.9.1 - SQL Injection
# Exploit Title: ResidenceCMS 2.10.1 - Stored Cross-Site Scripting (XSS)
# Exploit Title: Artica Proxy 4.50 - Remote Code Execution (RCE)
# Exploit Title: WordPress Backup and Staging Plugin ≤ 1.21.16 - Arbitrary File Upload to RCE
# Exploit Title : ABB Cylon Aspect 3.07.01 - Hard-coded Default Credentials
# Exploit Title : ABB Cylon Aspect 3.08.01 - Arbitrary File Delete
# Exploit Title: Elaine's Realtime CRM Automation 6.18.17 - Reflected XSS
# Exploit Title: CVE-2023-48292 Remote Code Execution Exploit
# Exploit Title: CodeCanyon RISE CRM 3.7.0 - SQL Injection
# Exploit Title: Litespeed Cache 6.5.0.1 - Authentication Bypass
# Exploit Title: X2CRM 8.5 - Stored Cross-Site Scripting (XSS)
# Exploit Title: MoziloCMS 3.0 - Remote Code Execution (RCE)
# Exploit Title: TeamPass SQL Injection
# Exploit Title: Jasmin Ransomware SQL Injection Login Bypass
# Exploit Title: FluxBB 1.5.11 Stored xss
# Exploit Title: JUX Real Estate 3.4.0 - SQL Injection
Exploit Title: TranzAxis 3.2.41.10.26 - Stored Cross-Site Scripting (XSS) (Authenticated)
# Exploit Title: Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
# Exploit Title: Loaded Commerce 6.6 Client-Side Template Injection(CSTI)
# Exploit Title: Chamilo LMS 1.11.24 - Remote Code Execution (RCE)
# Exploit Title: SOPlanning 1.52.01 (Simple Online Planning Tool) - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: openSIS 9.1 - SQLi (Authenticated)