WordPress Theme Zoner Real Estate – 4.1.1 Persistent Cross-Site Scripting
# Exploit Title: WordPress Theme Zoner Real Estate - 4.1.1 Persistent Cross-Site Scripting
php 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: WordPress Theme Zoner Real Estate - 4.1.1 Persistent Cross-Site Scripting
# Exploit Title: thesystem App 1.0 - 'username' SQL Injection
# Exploit Title: thesystem App 1.0 - Persistent Cross-Site Scripting
# Exploit Title: thesystem 1.0 - 'server_name' SQL Injection
# Exploit Title: InoERP 0.7.2 - Persistent Cross-Site Scripting
# Exploit Title: citecodecrashers Pic-A-Point 1.1 - 'Consignment' SQL Injection
# Exploit Title: inoERP 4.15 - 'download' SQL Injection
# Exploit Title: all-in-one-seo-pack 3.2.7 - Persistent Cross-Site Scripting
# Exploit Title: Duplicate-Post 3.2.3 - Persistent Cross-Site Scripting
# Exploit Title: Chamillo LMS 1.11.8 - Arbitrary File Upload
# Exploit Title: YzmCMS 5.3 - 'Host' Header Injection
# Exploit Title: WP Server Log Viewer 1.0 - 'logfile' Persistent Cross-Site Scripting
# Exploit Title: Pfsense 2.3.4 / 2.4.4-p3 - Remote Code Injection
# Exploit Title: LayerBB 1.1.3 - Multiple CSRF
# Exploit Title: GOautodial 4.0 - 'CreateEvent' Persistent Cross-Site Scripting
# Exploit Title: DIGIT CENTRIS 4 ERP - 'datum1' SQL Injection
# Exploit Title: Hospital-Management 1.26 - 'fname' SQL Injection
# Exploit Title: CollegeManagementSystem-CMS 1.3 - 'batch' SQL Injection
# Exploit Title: College-Management-System 1.2 - Authentication Bypass
# Exploit Title: Ticket-Booking 1.4 - Authentication Bypass
SEC Consult Vulnerability Lab Security Advisory < 20190912-0 >
=============================================
# Exploit Title: Dolibarr ERP/CRM 10.0.1 - User-Agent Http Header Cross
# Exploit Title: WordPress Plugin Photo Gallery by 10Web
# Exploit Title: WordPress Plugin Photo Gallery by 10Web
# Exploit Title: WordPress Plugin Photo Gallery by 10Web Add new and in add galleries / Gallery groups. GET request ...
# Exploit Title: Dolibarr ERP/CRM - Multiple Sql Injection
# Exploit Title: WordPress Plugin Sell Downloads 1.0.86 - Cross Site Scripting
# Exploit Title: Online Appointment SQL Injection
# Exploit Title: Dolibarr ERP/CRM - elemid Sql Injection
#!/usr/bin/perl -w
#####################################################################################
# Exploit Title: Inventory Webapp SQL injection
CVE:CVE-2019-15889
# Exploit Title: FileThingie 2.5.7 - Arbitrary File Upload
# Exploit Title : CraftCms Users information disclosure From uploaded File
# Exploit Title: WordPress Plugin Event Tickets >= 4.10.7.1 - CSV Injection
# Exploit Title: Opencart 3.x.x Authenticated Stored XSS
# Exploit Title: WordPress Plugin WooCommerce Product Feed
# Exploit Title: YouPHPTube
# Exploit Title: DomainMod
# Exploit Title: Sentrifugo 3.2 - Persistent Cross-Site Scripting
# Exploit Title: Sentrifugo 3.2 - File Upload Restriction Bypass
# Exploit Title: PilusCart
#!/bin/bash
# Exploit Title: Jobberbase 2.0 CMS - 'jobs-in' SQL Injection
# Exploit Title: openITCOCKPIT 3.6.1-2 - CSRF 2 RCE