Queue Management System 4.0.0 – “Add User” Stored XSS
# Exploit Title: Queue Management System 4.0.0 - "Add User" Stored XSS
php 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Queue Management System 4.0.0 - "Add User" Stored XSS
# Exploit Title: Xeroneit Library Management System 3.1 - "Add Book Category " Stored XSS
# Exploit Title: Smart Hospital 3.1 - "Add Patient" Stored XSS
# Exploit Title: Alumni Management System 1.0 - 'id' SQL Injection
# Exploit Title: Alumni Management System 1.0 - "Course Form" Stored XSS
# Exploit Title: Alumni Management System 1.0 - Unrestricted File Upload To RCE
# Exploit Title: Point of Sale System 1.0 - Authentication Bypass
# Exploit Title: Victor CMS 1.0 - Multiple SQL Injection (Authenticated)
# Exploit Title: PHPJabbers Appointment Scheduler 2.3 - Reflected XSS (Cross-Site Scripting)
# Exploit Title: Employee Record System 1.0 - Multiple Stored XSS
# Exploit Title: Interview Management System 1.0 - 'id' SQL Injection
# Exploit Title: Interview Management System 1.0 - Stored XSS in Add New Question
# Exploit Title: Online Tours & Travels Management System 1.0 - "id" SQL Injection
# Exploit Title: Customer Support System 1.0 - 'id' SQL Injection
# Exploit Title: Customer Support System 1.0 - "First Name" & "Last Name" Stored XSS
# Exploit Title: Medical Center Portal Management System 1.0 - 'id' SQL Injection
# Exploit Title: Content Management System 1.0 - 'id' SQL Injection
# Exploit Title: Content Management System 1.0 - 'email' SQL Injection
# Exploit Title:Content Management System 1.0 - 'First Name' Stored XSS
# Exploit Title: Dolibarr ERP-CRM 12.0.3 - Remote Code Execution (Authenticated)
# Exploit Title: Seotoaster 3.2.0 - Stored XSS on Edit page properties
# Exploit Title: PrestaShop ProductComments 4.2.0 - 'id_products' Time Based Blind SQL Injection
# Exploit Title: Grav CMS 1.6.30 Admin Plugin 1.9.18 - 'Page Title' Persistent Cross-Site Scripting
# Exploit Title: Online Marriage Registration System (OMRS) 1.0 - Remote Code Execution (Authenticated)
# Exploit Title: Task Management System 1.0 - 'page' Local File Inclusion
# Exploit Title: Rukovoditel 2.6.1 - Cross-Site Request Forgery (Change
# Exploit Title: Courier Management System 1.0 - 'ref_no' SQL Injection
# Exploit Title: Courier Management System 1.0 - 'MULTIPART street ' SQL Injection
# Exploit Title: Courier Management System 1.0 - 'First Name' Stored XSS
# Exploit Title: Dolibarr 12.0.3 - SQLi to RCE
# Exploit Title: Supply Chain Management System - Auth Bypass SQL Injection
# Exploit Title: Rukovoditel 2.6.1 - RCE
# Exploit Title: Medical Center Portal Management System 1.0 - Multiple Stored XSS
# Exploit Title: WordPress Plugin Popup Builder 3.69.6 - Multiple Stored Cross Site Scripting
# Exploit Title: Library Management System 2.0 - Auth Bypass SQL Injection
# Exploit Title: OpenCart 3.0.3.6 - Cross Site Request Forgery
# Exploit Title: Barcodes generator 1.0 - 'name' Stored Cross Site Scripting
# Exploit Title: Task Management System 1.0 - 'id' SQL Injection
# Exploit Title: Task Management System 1.0 - Unrestricted File Upload to Remote Code Execution
# Exploit Title: Task Management System 1.0 - 'First Name and Last Name' Stored XSS
# Exploit Title: Employee Performance Evaluation System 1.0 - ' Task and Description' Persistent Cross Site Scripting
# Exploit Title: Online Bus Ticket Reservation 1.0 - SQL Injection
# Exploit Title: vBulletin 5.6.3 - 'group' Cross Site Scripting
# Exploit Title: Savsoft Quiz 5 - 'Skype ID' Stored XSS
# Exploit Title: Cyber Cafe Management System Project (CCMS) 1.0 - Persistent Cross-Site Scripting
# Exploit Title: Zabbix 5.0.0 - Stored XSS via URL Widget Iframe
# Exploit Title: CMS Made Simple 2.2.15 - Stored Cross-Site Scripting via SVG File Upload (Authenticated)
# Exploit Title: Laravel Nova 3.7.0 - 'range' DoS
# Exploit Title: Forma LMS 2.3 - 'First & Last Name' Stored Cross-Site Scripting