rConfig 3.9.4 – ‘searchField’ Unauthenticated Root Remote Code Execution
# Exploit Title: rConfig 3.9.4 - 'searchField' Unauthenticated Root Remote Code Execution
php 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: rConfig 3.9.4 - 'searchField' Unauthenticated Root Remote Code Execution
# Exploit Title : ECK Hotel 1.0 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: Centreo 19.10.8 - 'DisplayServiceStatus' Remote Code Execution
# Exploit Title: LeptonCMS 4.5.0 - Persistent Cross-Site Scripting
# Exploit Title: Joomla! Component GMapFP 3.30 - Arbitrary File Upload
# Exploit Title: Wordpress Plugin WPForms 1.5.8.2 - Persistent Cross-Site Scripting
# Exploit Title: UliCMS 2020.1 - Persistent Cross-Site Scripting
# Exploit Title: Joomla! com_hdwplayer 4.2 - 'search.php' SQL Injection
# Exploit Title: rConfig 3.9.4 - 'search.crud.php' Remote Command Injection
Vulnerable Source:
# Exploit Title: Exagate Sysguard 6001 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: Joomla! ACYMAILING 3.9.0 component - Unauthenticated Arbitrary File Upload
# Exploit Title: UADMIN Botnet 1.0 - 'link' SQL Injection
# Exploit Title: PHPKB Multi-Language 9 - 'image-upload.php' Authenticated Remote Code Execution
# Exploit Title: PHPKB Multi-Language 9 - Authenticated Directory Traversal
# Exploit Title: PHPKB Multi-Language 9 - Authenticated Remote Code Execution
# Exploit Title: MiladWorkShop VIP System 1.0 - 'lang' SQL Injection
# Exploit Title: Wordpress Plugin Custom Searchable Data System -
# Exploit Title: rConfig 3.9 - 'searchColumn' SQL Injection
# Exploit Title: rConfig 3.93 - 'ajaxAddTemplate.php' Authenticated Remote Code Execution
# Exploit Title: HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: Wordpress Plugin Appointment Booking Calendar 1.3.34 - CSV Injection
# Exploit Title: Joomla! Component com_newsfeeds 1.0 - 'feedid' SQL Injection
## exploit-phar-loading.py
## exploit-inc-inclusion.py
# Exploit Title: TeamCity Agent XML-RPC 10.0 - Remote Code Execution
# Exploit Title: Wing FTP Server 6.2.3 - Privilege Escalation
#!/usr/bin/python3
# Exploit Title: Wordpress Plugin Search Meter 2.13.2 - CSV Injection
# Exploit Title: Persian VIP Download Script 1.0 - 'active' SQL Injection
# Exploit Title: YzmCMS 5.5 - 'url' Persistent Cross-Site Scripting
# Exploit Title: Sentrifugo HRMS 3.2 - 'id' SQL Injection
# Exploit Title: 60CycleCMS - 'news.php' Multiple vulnerability
# Exploit Title: UniSharp Laravel File Manager 2.0.0 - Arbitrary File Read
# Exploit Title: GUnet OpenEclass 1.7.3 E-learning platform - 'month' SQL Injection
# Exploit Title: Alfresco 5.2.4 - Persistent Cross-Site Scripting
# Exploit Title: Cacti v1.2.8 - Unauthenticated Remote Code Execution (Metasploit)
# Exploit Title: Wordpress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery (Add User)
# Exploit Title: Business Live Chat Software 1.0 - Cross-Site Request Forgery (Add Admin)
# Title: PhpIX 2012 Professional - 'id' SQL Injection
# Exploit Title: Magento WooCommerce CardGate Payment Gateway 2.0.30 - Payment Process Bypass
# Exploit Title: WordPress Plugin WooCommerce CardGate Payment Gateway 3.1.15 - Payment Process Bypass
# Exploit Title: Cacti 1.2.8 - Remote Code Execution
# Title: eLection 2.0 - 'id' SQL Injection
# Exploit Title: ATutor 2.2.4 - 'id' SQL Injection
# Title: AMSS++ 4.7 - Backdoor Admin Account