LayerBB 1.1.4 – ‘search_query’ SQL Injection
# Exploit Title: LayerBB 1.1.4 - 'search_query' SQL Injection
php 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: LayerBB 1.1.4 - 'search_query' SQL Injection
# Exploit Title: Batflat CMS 1.3.6 - 'multiple' Stored XSS
# Exploit Title: Beauty Parlour Management System 1.0 - 'sername' SQL Injection
# Exploit Title: Online Exam System With Timer 1.0 - 'email' SQL injection Auth Bypass
# Exploit Title: Comment System 1.0 - 'multiple' Stored Cross-Site Scripting
# Exploit Title: PEEL Shopping 9.3.0 - 'Comments/Special Instructions' Stored Cross-Site Scripting
# Exploit Title: Batflat CMS 1.3.6 - Remote Code Execution (Authenticated)
# Exploit Title: Billing Management System 2.0 - 'email' SQL injection Auth Bypass
# Exploit Title: Faulty Evaluation System 1.0 - 'multiple' Stored Cross-Site Scripting
# Exploit Title: BlackCat CMS 1.3.6 - 'Display name' Cross Site Scripting (XSS)
# Exploit Title: Online Internship Management System 1.0 - 'email' SQL injection Auth Bypass
# Exploit Title: Teachers Record Management System 1.0 - 'searchteacher' SQL Injection
# Exploit Title: TestLink 1.9.20 - Unrestricted File Upload (Authenticated)
# Exploit Title: School Event Attendance Monitoring System 1.0 - 'Item Name' Stored Cross-Site Scripting
# Exploit Title: School File Management System 1.0 - 'multiple' Stored Cross-Site Scripting
# Exploit Title: Online Marriage Registration System (OMRS) 1.0 - Remote code execution (3)
# Exploit Title: b2evolution 6.11.6 - 'tab3' Reflected XSS
# Exploit Title: b2evolution 6.11.6 - 'redirect_to' Open Redirect
# Exploit Title: PEEL Shopping 9.3.0 - 'address' Stored Cross-Site Scripting
# Exploit Title: b2evolution 6.11.6 - 'plugin name' Stored XSS
# Exploit Title: Online Car Rental System 1.0 - Stored Cross Site Scripting
# Exploit Title: WordPress Plugin Supsystic Backup 2.3.9 - Local File Inclusion
# Exploit Title: WordPress Plugin Supsystic Contact Form 1.7.5 - Multiple Vulnerabilities
# Exploit Title: WordPress Plugin Supsystic Data Tables Generator 1.9.96 - Multiple Vulnerabilities
# Exploit Title: WordPress Plugin Supsystic Digital Publications 1.6.9 - Multiple Vulnerabilities
# Exploit Title: WordPress Plugin Supsystic Membership 1.4.7 - 'sidx' SQL injection
# Exploit Title: WordPress Plugin Supsystic Newsletter 1.5.5 - 'sidx' SQL injection
# Title: YetiShare File Hosting Script 5.1.0 - 'url' Server-Side Request Forgery
# Exploit Title: WordPress Plugin Supsystic Pricing Table 1.8.7 - Multiple Vulnerabilities
# Exploit Title: WordPress Plugin Supsystic Ultimate Maps 1.1.12 - 'sidx' SQL injection
# Exploit Title: WordPress Plugin Welcart e-Commerce 2.0.0 - 'search[order_column][0]' SQL injection
# Exploit Title: SEO Panel 4.6.0 - Remote Code Execution (2)
# Exploit Title: PhreeBooks 5.2.3 - Remote Code Execution
# Exploit Title: LiteSpeed Web Server Enterprise 5.4.11 - Command Injection (Authenticated)
# Exploit Title: Car Rental Project 2.0 - Arbitrary File Upload to Remote Code Execution
# Exploit Title: Student Record System 4.0 - 'cid' SQL Injection
# Exploit Title: WordPress 5.0.0 - Image Remote Code Execution
# Exploit Title: Klog Server 2.4.1 - Command Injection (Authenticated)
# Exploit Title: Roundcube Webmail 1.2 - File Disclosure
# Exploit Title: Vehicle Parking Tracker System 1.0 - 'Owner Name' Stored Cross-Site Scripting
# Title: bloofoxCMS 0.5.2.1 - CSRF (Add user)
# Exploit Title: MyBB Thread Redirect Plugin 0.2.1 - Cross-Site Scripting
# Exploit Title: MyBB Trending Widget Plugin 1.2 - Cross-Site Scripting
# Exploit Title: Park Ticketing Management System 1.0 - 'viewid' SQL Injection
# Exploit Title: User Management System 1.0 - 'uid' SQL Injection
# Exploit Title: Zoo Management System 1.0 - 'anid' SQL Injection
# Exploit Title: MyBB Delete Account Plugin 1.4 - Cross-Site Scripting
# Exploit Title: Simple Public Chat Room 1.0 - 'msg' Stored Cross-Site Scripting
# Exploit Title: Simple Public Chat Room 1.0 - Authentication Bypass SQLi
# Exploit Title: MyBB Hide Thread Content Plugin 1.0 - Information Disclosure