webERP 4.15.1 – Unauthenticated Backup File Access
# Exploit Title: webERP 4.15.1 - Unauthenticated Backup File Access
php 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: webERP 4.15.1 - Unauthenticated Backup File Access
# Exploit Title: Online Scheduling System 1.0 - 'username' SQL Injection
# Title: Fishing Reservation System 7.5 - 'uid' SQL Injection
# Title: addressbook 9.0.0.1 - 'id' SQL Injection
# Title: osTicket 1.14.1 - Persistent Authenticated Cross-Site Scripting
# Exploit Title: BoltWire 6.03 - Local File Inclusion
# Exploit Title: Online Scheduling System 1.0 - Authentication Bypass
# Exploit Title: php-fusion 9.03.50 - Persistent Cross-Site Scripting
# Exploit Title: Online Scheduling System 1.0 - Persistent Cross-Site Scripting
# Exploit Title: ChemInv 1.0 - Authenticated Persistent Cross-Site Scripting
# Exploit Title: hits script 1.0 - 'item_name' SQL Injection
# Exploit Title: School ERP Pro 1.0 - Arbitrary File Read
# Exploit Title: Open-AudIT Professional 3.3.1 - Remote Code Execution
# Exploit Title: School ERP Pro 1.0 - Remote Code Execution
# Exploit Title: School ERP Pro 1.0 - 'es_messagesid' SQL Injection
# Exploit Title: Maian Support Helpdesk 4.3 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: Online Course Registration 2.0 - Authentication Bypass
# Exploit Title: Online shopping system advanced 1.0 - 'p' SQL Injection
# Exploit Title: PHP-Fusion 9.03.50 - 'Edit Profile' Arbitrary File Upload
# Exploit Title: Library CMS Powerful Book Management System 2.2.0 - Session Fixation
# Exploit Title: Complaint Management System 4.2 - Cross-Site Request Forgery (Delete User)
# Exploit Title: Complaint Management System 4.2 - Authentication Bypass
# Exploit Title: Complaint Management System 4.2 - Persistent Cross-Site Scripting
# Exploit Title: User Management System 2.0 - Authentication Bypass
# Exploit Title: User Management System 2.0 - Persistent Cross-Site Scripting
# Exploit Title: jizhi CMS 1.6.7 - Arbitrary File Download
# Exploit Title: CSZ CMS 1.2.7 - 'title' HTML Injection
# Exploit Title: PMB 5.6 - 'logid' SQL Injection
# Exploit Title: CSZ CMS 1.2.7 - Persistent Cross-Site Scripting
# Title: Fork CMS 5.8.0 - Persistent Cross-Site Scripting
This is totally a legit page. Just keep reading this for a minute :)
# Exploit Title: Centreon 19.10.5 - 'id' SQL Injection
# Title: TAO Open Source Assessment Platform 3.3.0 RC02 - HTML Injection
# Exploit Title: Xeroneit Library Management System 3.0 - 'category' SQL Injection
# Title: DedeCMS 7.5 SP2 - Persistent Cross-Site Scripting
# Title: Macs Framework 1.14f CMS - Persistent Cross-Site Scripting
# Title: SeedDMS 5.1.18 - Persistent Cross-Site Scripting
# Title: Pinger 1.0 - Remote Code Execution
# Exploit Title: MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection
# Exploit Title: Wordpress Plugin Media Library Assistant 2.81 - Local File Inclusion
# Exploit Title: Webtateas 2.0 - Arbitrary File Read
Title: Helpful 2.4.11 Sql Injection - Wordpress Plugin
# Exploit Title: Django 3.0 - Cross-Site Request Forgery Token Bypass
# Exploit Title: LimeSurvey 4.1.11 - 'File Manager' Path Traversal
# Exploit Title: Bolt CMS 3.7.0 - Authenticated Remote Code Execution
# Exploit Title: LimeSurvey 4.1.11 - 'Survey Groups' Persistent Cross-Site Scripting
# Exploit Title: Pandora FMS 7.0NG - 'net_tools.php' Remote Code Execution
# Exploit Title: PHP-Fusion 9.03.50 - 'panels.php' Multiple vulnerability
# Exploit Title: Joomla! com_fabrik 3.9.11 - Directory Traversal