WBCE 1.6.0 – Unauthenticated SQL injection
# Exploit Title: |Unauthenticated SQL injection in WBCE 1.6.0
php 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: |Unauthenticated SQL injection in WBCE 1.6.0
# Exploit Title: Moodle Authenticated Time-Based Blind SQL Injection - "sort" Parameter
# Exploit Title: PopojiCMS Version : 2.0.1 Remote Command Execution
# Exploit Title: Wordpress Plugin Playlist for Youtube - Stored Cross-Site Scripting (XSS)
# Exploit Title: HTMLy Version v2.9.6 - Stored XSS
# Exploit Title: GUnet OpenEclass E-learning platform 3.15 - 'certbadge.php' Unrestricted File Upload
# Exploit Title : Open Source Medicine Ordering System v1.0 - SQLi
# Exploit Title: Daily Expense Manager 1.0 - 'term' SQLi
## Title: Best Student Result Management System v1.0 - Multiple SQLi
## Title: Human Resource Management System v1.0 - Multiple SQLi
# Exploit Title: Wordpress Theme Travelscape v1.0.3 - Arbitrary File Upload
# Exploit Title: Wordpress Plugin Alemha Watermarker 1.3.1 - Stored Cross-Site Scripting (XSS)
# Title: Computer Laboratory Management System v1.0 - Multiple-SQLi
# Exploit Title: Axigen < 10.5.7 - Persistent Cross-Site Scripting
# Exploit Title: Gibbon LMS v26.0.00 - SSTI vulnerability
# Exploit Title: Wordpress Plugin - Membership For WooCommerce < v2.1.7 - Arbitrary File Upload to Shell (Unauthentic...
# Exploit Title: Smart School 6.4.1 - SQL Injection
## Exploit Title: CE Phoenix v1.0.8.20 - Remote Code Execution (RCE) (Authenticated)
#EXPLOIT Elementor Website Builder < 3.12.2 - Admin+ SQLi
# Exploit Title: Blood Bank v1.0 Stored Cross Site Scripting (XSS)
# Exploit Title: Daily Habit Tracker 1.0 - Broken Access Control
# Exploit Title: Daily Habit Tracker 1.0 - SQL Injection
# Exploit Title: Daily Habit Tracker 1.0 - Stored Cross-Site Scripting (XSS)
# Exploit Title: Employee Management System 1.0 - `txtusername` and `txtpassword` SQL Injection (Admin Login)
# Exploit Title: Employee Management System 1.0 - `txtfullname` and `txtphone` SQL Injection
# Exploit Title: LeptonCMS 7.0.0 - Remote Code Execution (RCE) (Authenticated)
Exploit Title: FoF Pretty Mail 1.1.2 - Server Side Template Injection (SSTI)
Exploit Title: FoF Pretty Mail 1.1.2 - Local File Inclusion (LFI)
# Exploit Title: Hospital Management System v1.0 - Stored Cross Site Scripting (XSS)
# Exploit Title: E-INSUARANCE v1.0 - Stored Cross Site Scripting (XSS)
# Exploit Title: Petrol Pump Management Software v1.0 - Remote Code Execution (RCE)
# Exploit Title: OpenCart Core 4.0.2.3 - 'search' SQLi
# Exploit Title: Online Hotel Booking In PHP 1.0 - Blind SQL Injection (Unauthenticated)
# Exploit Title: Simple Backup Plugin < 2.7.10 - Arbitrary File Download via Path Traversal
## Exploit Title: liveSite Version : 2019.1 Campaigns Remote Code Execution
# Exploit Title: Purei CMS 1.0 - SQL Injection
# Exploit Title: Workout Journal App 1.0 - Stored XSS
# Exploit Title: Stored Cross-Site Scripting (XSS) in LimeSurvey Community
# Exploit Title: Wallos - File Upload RCE (Authenticated)
# Exploit Title: Tourism Management System v2.0 - Arbitrary File Upload
+ Exploit Title: MobileShop master v1.0 - SQL Injection Vuln.
# Exploit Title:Insurance Management System PHP and MySQL 1.0 - Multiple
# Exploit Title: SPA-CART CMS - Stored XSS
#!/usr/bin/env python3
# Title: CSZCMS v1.3.0 - SQL Injection (Authenticated)
# Exploit Title: Teacher Subject Allocation Management System 1.0 - 'searchdata' SQLi
# Exploit Title: Simple Task List 1.0 - 'status' SQLi
# Exploit Title: Blood Bank 1.0 - 'bid' SQLi
# Exploit Title: Employee Management System 1.0 - 'admin_id' SQLi
# Exploit Title: Quick.CMS 6.7 SQL Injection Login Bypass