ClipperCMS 1.3.3 – Cross-Site Scripting
# Exploit Title: ClipperCMS 1.3.3 Persistent XSS on 'Site name' field
php 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: ClipperCMS 1.3.3 Persistent XSS on 'Site name' field
# Exploit Title: Listing Hub CMS 1.0 - Multiple SQL Injection
# Exploit Title: BookingWizz Booking System 5.5 - 'bs-services-add.php' SQL Injection
# Exploit Title: Lyrist - Music Lyrics Script - SQL Injection
# Exploit Title: Sharetronix CMS XSRF Vulnerability
# Exploit Title: Ingenious School Management System - SQL Injection
# Exploit Title: Wordpress Plugin Booking Calendar 3.0.0 - SQL Injection / Cross-Site Scripting
The PDOSessionHandler class allows to store sessions on a PDO connection. Under some configurations (see below) and w...
# Exploit Title: easyLetters 1.0 - 'id' SQL Injection
# Exploit Title: mySurvey 1.0 - 'statistic.php' SQL Injection
# Exploit Title: Ajax Full Featured Calendar 2.0 - 'search' SQL Injection
# Exploit Title: EWS 5.9 - 'search' SQL Injection
# Exploit Title: MyBB Moderator Log Notes Plugin 1.1 - Cross-Site Scripting
# Exploit Title: KomSeo Cart 1.3 - 'edit.php' SQL Injection
# Exploit Title: Timber - Ultimate Freelancer Platform 1.1 - Cross site request forgery
# Exploit Title: PaulNews 1.0 - 'keyword' SQL Injection / Cross-Site Scripting
# Exploit Title: Wordpress Plugin Peugeot Music - Arbitrary File Upload
# Exploit Title: # Exploit Title: Mcard Mobile Card Selling Platform 1 - SQL Injection
# Exploit Title: eWallet - Online Payment Gateway 2 - Cross-Site Request Forgery
# Exploit Title: Wecodex Restaurant CMS 1.0 - 'Login' SQL Injection
# Exploit Title: Wecodex Hotel CMS 1.0 - 'Admin Login' SQL Injection
# Exploit Title: Library CMS 1.0 - SQL Injection
# Exploit Title: School Management System CMS 1.0 - Admin Login SQL
# Exploit Title: SAT CFDI 3.3 - SQL Injection
# Exploit Title: Wecodex Store Paypal 1.0 - SQL Injection
# Exploit Title: Shipping System CMS 1.0 - SQL Injection
# Exploit Title: GPSTracker v1.0 - Login Page SQL Injection
# Exploit Title: Online Store System CMS 1.0 - SQL Injection
# Exploit Title: Gigs v2.0 - Login Page SQL Injection
# Exploit Title: Mcard - Mobile Card Selling Platform 1 - Cross-Site Request Forgery
# Exploit Title: PHP Dashboards 4.5 - SQL Injection
# Exploit Title: PHP Dashboards v4.5 - Registration Page SQL Injection
# Exploit Title: MySQL Blob Uploader 1.7 - 'home-filet-edit.php' SQL Injection
# Exploit Title: MySQL Blob Uploader 1.7 - 'home-filet-edit.php' SQL Injection / Cross-Site Scripting
# Exploit Title: MySQL Blob Uploader 1.7 - 'home-file-edit.php' SQL Injection / Cross-Site Scripting
# Exploit Title: MySQL Blob Uploader 1.7 - 'download.php' SQL Injection / Cross-Site Scripting
# Exploit Title: MySQL Smart Reports 1.0 - SQL Injection / Cross-Site Scripting
# Exploit Title: EasyService Billing 1.0 - 'customer-new-s.php' SQL
# Exploit Title: EasyService Billing 1.0 - 'template_().php' SQL Injection / Cross-Site Scripting
# Exploit Title: Easy File Uploader 1.7 - SQL Injection / Cross-Site
# Exploit Title: NewsBee CMS 1.4 - 'download.php' SQL Injection
# Exploit Title: Feedy RSS News Ticker 2.0 - 'cat' SQL Injection
# Exploit Title: NewsBee CMS 1.4 - 'home-text-edit.php' SQL Injection
# Exploit Title: Auto car 1.2 - 'car_title' SQL Injection / Cross-Site Scripting
# Exploit Title: iSocial 1.2.0 - Cross-Site Scripting / Cross-Site Request Forgery
# Exploit Title: PaulPrinting CMS Printing 1.0 - SQL Injection
# Exploit Title: WebSocket Live Chat - Cross-Site Scripting