JFrog Artifactory < 7.25.4 - Blind SQL Injection
# Exploit Title: artifactory low-privileged blind sql injection
php 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: artifactory low-privileged blind sql injection
# Exploit Title: Employee Management System v1 - 'email' SQL Injection
# Exploit Title: Lost and Found Information System v1.0 - idor leads to Account Take over
# Exploit Title: Online Nurse Hiring System 1.0 - 'bookid' Time-Based SQL Injection
# Exploit Title: Rail Pass Management System - 'searchdata' Time-Based SQL Injection
# Exploit Title: Wordpress Seotheme - Remote Code Execution Unauthenticated
# Exploit Title: Wordpress Augmented-Reality - Remote Code Execution Unauthenticated
# Exploit Title: Advanced Page Visit Counter 1.0 - Admin+ Stored Cross-Site
# Exploit Title: MISP 2.4.171 Stored XSS [CVE-2023-37307] (Authenticated)
# Exploit Title: Clinic's Patient Management System 1.0 - Unauthenticated RCE
# Exploit Title: Curfew e-Pass Management System 1.0 - FromDate SQL
# Exploit Title: GYM MS - GYM Management System - Cross Site Scripting (Stored)
# ***************************************************************************************************
# Exploit Title: Grocy
## Title: 101 News-1.0 Multiple-SQLi
# Exploit Title: Academy LMS 6.2 - SQL Injection
## Title: PHP Shopping Cart-4.2 Multiple-SQLi
## Title: Fundraising Script-1.0 SQLi
# Exploit Title: Bank Locker Management System - SQL Injection
# Exploit Title: Blood Bank & Donor Management System using v2.2 - Stored XSS
## Title: Equipment Rental Script-1.0 - SQLi
## Title: Shuttle-Booking-Software v1.0 - Multiple-SQLi
## Title: Limo Booking Software v1.0 - CORS
Exploit Title: Webedition CMS v2.9.8.8 - Blind SSRF
#!/usr/bin/python3
# Exploit Title: Cacti 1.2.24 - Authenticated command injection when using SNMP options
# Exploit Title: Wordpress Sonaar Music Plugin 4.7 - Stored XSS
Exploit Title: coppermine-gallery 1.6.25 RCE
# Exploit Title: Media Library Assistant Wordpress Plugin - RCE and LFI
## Title: WEBIGniter v28.7.23 File Upload - Remote Code Execution
# Exploit Title: Wordpress Plugin Masterstudy LMS - 3.0.17 - Unauthenticated Instructor Account Creation
# Exploit Title: Clcknshop 1.0.0 - SQL Injection
## Title: Online ID Generator 1.0 - Remote Code Execution (RCE)
#!/usr/bin/env python3
## Title: drupal-10.1.2 web-cache-poisoning-External-service-interaction
## Title: soosyze 2.0.0 - File Upload
# Exploit Title: Wp2Fac v1.0 - OS Command Injection
# Exploit Title: Wordpress Plugin Elementor < 3.5.5 - Iframe Injection
## Title: Jorani v1.0.3-(c)2014-2023 - XSS Reflected & Information Disclosure
# Exploit Title: SPA-Cart eCommerce CMS 1.9.0.3 - SQL Injection
# Exploit Title: SPA-Cart eCommerce CMS 1.9.0.3 - Reflected XSS
## Title: Bus Reservation System-1.1 Multiple-SQLi
# Exploit Title: WP Statistics Plugin = 5.0:
## Title: Member Login Script 3.3 - Client-side desync
# Exploit Title: AdminLTE PiHole < 5.18 - Broken Access Control
# Exploit Title: CSZ CMS 1.3.0 - Stored Cross-Site Scripting (Plugin 'Gallery')
# Exploit Title: CSZ CMS 1.3.0 - Stored Cross-Site Scripting ('Photo URL' and 'YouTube URL' )
# Exploit Title: Academy LMS 6.1 - Arbitrary File Upload
# Exploit Title: Credit Lite 1.5.4 - SQL Injection