Concrete5 8.5.4 – ‘name’ Stored XSS
# Exploit Title: Concrete5 8.5.4 - 'name' Stored XSS
php 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Concrete5 8.5.4 - 'name' Stored XSS
# Exploit Title: WordPress Plugin WP Super Cache 1.7.1 - Remote Code Execution (Authenticated)
# Exploit Title: Moodle 3.10.3 - 'label' Persistent Cross Site Scripting
# Title: Regis Inventory And Monitoring System 1.0 - 'Item List' Persistent Cross-Site Scripting
# Exploit Title: GetSimple CMS Custom JS Plugin 0.1 - 'customhs_js_content' Cross-Site Request Forgery
# Exploit Title: Dolibarr ERP/CRM 11.0.4 - File Upload Restrictions Bypass (Authenticated RCE)
# Exploit Title: Ovidentia 6 - 'id' SQL injection (Authenticated)
# Exploit Title: Hotel And Lodge Management System 1.0 - 'Customer Details' Stored XSS
# Exploit Title: MyBB 1.8.25 - Poll Vote Count SQL Injection
# Exploit Title: MyBB 1.8.25 - Chained Remote Command Execution
# Exploit Title: WordPress Plugin Delightful Downloads Jquery File Tree 1.6.6 - Path Traversal
# Exploit Title: Online News Portal 1.0 - 'Multiple' Stored Cross-Site Scripting
# Exploit Title: Online News Portal 1.0 - 'name' SQL Injection
# Exploit Title: CouchCMS 2.2.1 - SSRF via SVG file upload
# Exploit Title: Profiling System for Human Resource Management 1.0 - Remote Code Execution (Unauthenticated)
# Exploit Title: Boonex Dolphin 7.4.2 - 'width' Stored XSS
# Exploit Title: LiveZilla Server 8.0.1.0 - 'Accept-Language' Reflected XSS
# Title: Hestia Control Panel 1.3.2 - Arbitrary File Write
# Exploit Title: SEO Panel 4.8.0 - 'order_col' Blind SQL Injection (1)
# Exploit Title: rConfig 3.9.6 - Arbitrary File Upload to Remote Code Execution (Authenticated) (1)
# Exploit Title: WoWonder Social Network Platform 3.1 - 'event_id' SQL Injection
# Exploit Title: Alphaware E-Commerce System 1.0 - Unauthenicated Remote Code Execution (File Upload + SQL injection)
# Exploit Title: rConfig 3.9.6 - 'path' Local File Inclusion (Authenticated)
# Exploit Title: MagpieRSS 0.72 - 'url' Command Injection and Server Side Request Forgery
# Exploit Title: Zenario CMS 8.8.53370 - 'id' Blind SQL Injection
# Exploit Title: Monitoring System (Dashboard) 1.0 - File Upload RCE (Authenticated)
# Exploit Title: Monitoring System (Dashboard) 1.0 - 'uname' SQL Injection
# Exploit Title: CouchCMS 2.2.1 - XSS via SVG file upload
# Exploit Title: MyBB OUGC Feedback Plugin 1.8.22 - Cross-Site Scripting
# Exploit Title: GLPI 9.5.3 - 'fromtype' Unsafe Reflection
# Exploit Title: Joomla JCK Editor 6.4.4 - 'parent' SQL Injection (2)
# Exploit Title: Hotel and Lodge Management System 1.0 - Remote Code Execution (Unauthenticated)
# Exploit Title: Textpattern 4.8.3 - Remote code execution (Authenticated) (2)
# Exploit Title: Web Based Quiz System 1.0 - 'eid' Union Based Sql Injection (Authenticated)
# Exploit Title: Online Ordering System 1.0 - Blind SQL Injection (Unauthenticated)
# Exploit Title: Textpattern CMS 4.9.0-dev - 'Excerpt' Persistent Cross-Site Scripting (XSS)
# Exploit Title: Textpattern CMS 4.8.4 - 'Comments' Persistent Cross-Site Scripting (XSS)
# Exploit Title: Online Ordering System 1.0 - Arbitrary File Upload to Remote Code Execution
# Exploit Title: e107 CMS 2.3.0 - CSRF
# Exploit Title: Local Services Search Engine Management System (LSSMES) 1.0 - Blind & Error based SQL injection (Aut...
# Exploit Title: Local Services Search Engine Management System (LSSMES) 1.0 - 'name' Persistent Cross-Site Scripting...
# Exploit Title: Web Based Quiz System 1.0 - 'name' Persistent/Stored Cross-Site Scripting
# Exploit Title: Tiny Tiny RSS - Remote Code Execution
# Exploit Title: Web Based Quiz System 1.0 - 'MCQ options' Persistent/Stored Cross-Site Scripting
# Exploit Title: Covid-19 Contact Tracing System 1.0 - Remote Code Execution (Unauthenticated)
# Exploit Title: Online Catering Reservation System 1.0 - Unauthenticated Remote Code Execution
# Exploit Title: Triconsole 3.75 - Reflected XSS
# Exploit Title: Simple Employee Records System 1.0 - File Upload RCE (Unauthenticated)
# Exploit Title: Vehicle Parking Management System 1.0 - 'catename' Persistent Cross-Site Scripting (XSS)