php
php 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
Event Manager 1.0 – SQL Injection
# # # # #
Advance Loan Management System – ‘id’ SQL Injection
# Exploit Title: Advance Loan Management System - 'id' SQL Injection
Real Estate Custom Script – ‘route’ SQL Injection
# Exploit Title: Real Estate Custom Script - 'route' SQL Injection
Fancy Clone Script – ‘search_browse_product’ SQL Injection
# Exploit Title: Fancy Clone Script - 'search_browse_product' SQL Injection
Buddy Zone 2.9.9 – SQL Injection
# # # # #
TSiteBuilder 1.0 – SQL Injection
# # # # #
Gnew 2018.1 – Cross-Site Request Forgery
# Exploit Title: Gnew 2018.1 - Cross-Site Request Forgery
PACSOne Server 6.6.2 DICOM Web Viewer – SQL Injection
# Exploit Title: PACSOne Server 6.6.2 DICOM Web Viewer SQL Injection
PACSOne Server 6.6.2 DICOM Web Viewer – Directory Trasversal
# Exploit Title: PACSOne Server 6.6.2 DICOM Web Viewer Directory Trasversal / Local File Inclusion
WordPress Plugin Learning Management System – ‘course_id’ SQL Injection
# Exploit Title: Good LMS - Learning Management System WP Plugin SQL
WordPress Plugin Email Subscribers & Newsletters 3.4.7 – Information Disclosure
# Exploit Title: WordPress Plugin Email Subscribers & Newsletters 3.4.7 - Information Disclosure
Flexible Poll 1.2 – SQL Injection
# # # # #
Quickad 4.0 – SQL Injection
# # # # #
Tumder 2.1 – SQL Injection
# # # # #
Zechat 1.5 – SQL Injection
# # # # #
Wchat 1.5 – SQL Injection
# # # # #
Easy Car Script 2014 – SQL Injection
# # # # #
Affiligator 2.1.0 – SQL Injection
# # # # #
LiveCRM SaaS Cloud 1.0 – SQL Injection
# # # # #
CentOS Web Panel 0.9.8.12 – ‘row_id’ / ‘domain’ SQL Injection
Document Title:
PHPFreeChat 1.7 – Denial of Service
# Exploit Title: phpFreeChat 1.7 and earlier - Denial of Service
CentOS Web Panel 0.9.8.12 – Multiple Vulnerabilities
Document Title:
GitStack 2.3.10 – Remote Code Execution
# Exploit: GitStack 2.3.10 Unauthenticated Remote Code Execution
SugarCRM 3.5.1 – Cross-Site Scripting
# Exploit Title: sugarCRM 3.5.1 XSS refeclted
Reservo Image Hosting Script 1.5 – Cross-Site Scripting
# Exploit Title: Reservo Image Hosting Script 1.5 - Cross Site Scripting
GitStack – Remote Code Execution
## Vulnerability Summary
D-Link DNS-325 ShareCenter < 1.05B03 - Multiple Vulnerabilities
D-Link DNS-325 ShareCenter Multiple Vulnerabilities
D-Link DNS-343 ShareCenter < 1.05 - Command Injection
D-Link DNS-343 ShareCenter Remote Root
Flash Operator Panel 2.31.03 – Command Execution
Document Title:
ILIAS < 5.2.4 - Cross-Site Scripting
# Exploit Title: Cross Site Scripting in ILIAS CMS 5.2.3
Adminer 4.3.1 – Server-Side Request Forgery
[+] Credits: John Page (aka hyp3rlinx)
RISE 1.9 – ‘search’ SQL Injection
# Exploit Title: RISE Ultimate Project Manager 1.9 - SQL Injection