Zimbra 8.6.0_GA_1153 – Cross-Site Scripting
# Exploit Title: Xss Zimbra Mail server
php 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Xss Zimbra Mail server
# Exploit Title: Monstra-Dev 3.0.4 - Cross-Site Request Forgery(Account Hijacking)
# Title: OpenEMR 5.0.1.3 - Remote Code Execution (Authenticated)
# Exploit Title: CMS ISWEB 3.5.3 - Directory Traversal
# Exploit Title: Cross-Site Request Forgery (Add Admin)
# Exploit Title: [Subrion CMS- 4.2.1 XSS (Using component with known
# Exploit Title: PHP Template Store Script- 3.0.6 - Stored XSS via Addres ,Bank Name,and A/c Holder Name
# Title : CoSoSys Endpoint Protector - Authenticated Remote Root Command Injection
# Exploit Title: FB Inboxer 1.2 - 'search_field' SQL Injection
# Exploit Title: TI Online Examination System v2 - Arbitrary File Download
Core Security - Corelabs Advisory
# Exploit Title: Kirby CMS 2.5.12 - Cross-Site Scripting
# Exploit Title: MSVOD V10 ¡V SQL Injection
# Exploit Title: MyBB New Threads Plugin - Cross-Site Scripting
# Exploit Title: WordPress Plugin All In One Favicon
# Exploit Title: Modx Revolution < 2.6.4 - Remote Code Execution
# Exploit Title: FTP2FTP 1.0 - Arbitrary File Download
# Exploit Title: Smart SMS & Email Manager v3.3 - SQL Injection
#!/usr/bin/env python3
#!/usr/bin/env python3
# Exploit Title: Wordpress Plugin Job Manager v4.1.0 Stored Cross Site
SEC Consult Vulnerability Lab Security Advisory < 20180712-0 >
SEC Consult Vulnerability Lab Security Advisory < 20180711-0 >
# Exploit Title: Instagram-clone Script 2.0 - Cross-Site Scripting
# Exploit Title: WolfSight CMS 3.2 - SQL Injection
######################
# Exploit Title: SoftExpert Excellence Suite 2.0 - 'cddocument' SQL Injection
# Exploit Title: ShopNx - Angular5 Single Page Shopping Cart Application 1 - Arbitrary File Upload
# Exploit Title: Online Trade 1 - Information Disclosure
# Exploit Title: CMS Made Simple 2.2.5 authenticated Remote Code Execution
# Exploit Title: Unauthenticated Remote Code Evaluation in Dolibarr ERP CRM =
# Exploit Title: hycus Content Management System v1.0.4 Login Page Bypass
# Exploit Title: HongCMS 3.0.0 - SQL Injection
# Exploit Title: A CSRF vulnerability exists in BEESCMS_V4.0: The administrator can be added arbitrarily.
# Exploit Title: Wordpress
# Exploit Title: WordPress Plugin iThemes Security(better-wp-security)
# Exploit Title: Wordpress Plugin Comments Import & Export < 2.0.4 - CSV Injection
# Exploit Title: Wordpress Plugin Advanced Order Export For WooCommerce < 1.5.4 - CSV Injection
# Exploit Title: phpMyAdmin 4.8.1 - Local File Inclusion to Remote Code Execution
#!/usr/bin/perl -w
# Exploit Title: phpLDAPadmin 1.2.2 - 'server_id' LDAP Injection (Username)
# Exploit Title: GreenCMS 2.3.0603 - remote obtain sensitive information
The latest version downloaded from the official website, the file name is phpMyAdmin-4.8.1-all-languages.zip
# Exploit Title: A CSRF vulnerability exists in LFCMS_3.7.0: administrator account can be added arbitrarily.