doorGets CMS 7.0 – Arbitrary File Download
# Exploit Title: doorGets CMS 7.0 - Arbitrary File Download
php 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: doorGets CMS 7.0 - Arbitrary File Download
# Exploit Title: Roxy Fileman 1.4.5 - Arbitrary File Download
# Exploit Title: ownDMS 4.7 - SQL Injection
# Exploit Title: Bigcart - Ecommerce Multivendor System 1.0 - SQL Injection
# Exploit Title: Job Portal 1.0 - SQL Injection
# Exploit Title: Real Estate Custom Script 2.0 - SQL Injection
# Exploit Title: thinkphp 5.X RCE
# Exploit Title: HealthNode Hospital Management System 1.0 - SQL Injection
# Exploit Title: Cleanto 5.0 - SQL Injection
# Exploit Title: Locations CMS 1.5 - SQL Injection
# Exploit Title: Craigs CMS 1.0.2 - SQL Injection
# Exploit Title: Live Call Support 1.5 - Remote Code Execution / SQL Injection
# Exploit Title: Live Call Support 1.5 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: Fax Machine System Application 1.0 - SQL Injection
# Exploit Title: Modern POS 1.3 - SQL Injection
# Exploit Title: Modern POS 1.3 - Arbitrary File Download
# Exploit Title: Horde Imp Unauthenticated Remote Command Execution
# Exploit Title: i-doit CMDB 1.12 - SQL Injection
# Exploit Title: i-doit CMDB 1.12 - Arbitrary File Download
# Exploit Title: Joomla! Component JoomCRM 1.1.1 - SQL Injection
# Exploit Title: Joomla! Component JoomProject 1.1.3.2 - Information Disclosure
# Exploit Title: Adapt Inventory Management System 1.0 - SQL Injection
# Exploit Title: eBrigade ERP 4.5 - SQL Injection
# Exploit Title: Event Locations 1.0.1 - SQL Injection
# Exploit Title: Event Calendar 3.7.4 - SQL Injection
# Exploit Title: Matrix MLM Script 1.0 - SQL Injection
# Exploit Title: Architectural Cms 1.0 - SQL Injection
# Exploit Title: SHIELD - Freelancer Content Management System 2.2 - SQL Injection / CSRF
# Exploit Title: doitX 1.0 - SQL Injection
# Exploit Title: Matrix MLM Script 1.0 - Information Leakage
#!/usr/bin/python
PEAR Archive_Tar < 1.4.4 - PHP Object Injection
# Title: Dolibarr ERP-CRM 8.0.4 - 'rowid' SQL Injection
#!/usr/bin/env python
======================================================================
# Exploit Title: MyT-PM 1.5.1 - 'Charge[group_total]' SQL Injection
# Exploit Title: Wordpress Plugin UserPro < 4.9.21 User Registration With Administrator Role
#####################################################################################################################...
# Exploit Title: MyBB OUGC Awards Plugin v1.8.3 - Cross-Site Scripting
# Exploit Title: LayerBB 1.1.1 - Cross-Site Scripting
# Exploit Title: All in One Video Downloader 1.2 - SQL Injection
# Exploit Title: Embed Video Scripts - Cross-site Script (stored)
# Exploit Title: Frog CMS 0.9.5 - Cross-Site Scripting
# Exploit Title: WordPress Plugin Adicon Server 1.2 - 'selectedPlace' SQL Injection
# Exploit Title: Vtiger CRM 7.1.0 - Remote Code Execution
# Exploit Title: WordPress Plugin Baggage Freight Shipping Australia 0.1.0 - Arbitrary File Upload
# Exploit Title: bludit Pages Editor 3.0.0 - Arbitrary File Upload
# Exploit Title: WordPress Plugin Audio Record 1.0 - Arbitrary File Upload
# Exploit Title: Craft CMS 3.0.25 - Cross-Site Scripting