php
php 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
CMS Auditor Website 1.0 – SQL Injection
# # # # #
FS Quibids Clone 1.0 – SQL Injection
# # # # #
OpenEMR 5.0.0 – OS Command Injection / Cross-Site Scripting
SEC Consult Vulnerability Lab Security Advisory < 20171130-1 >
FS Facebook Clone – ‘token’ SQL Injection
# Exploit Title: FS Facebook Clone - 'token' SQL Injection
FS IMDB Clone – ‘id’ SQL Injection
# Exploit Title: FS IMDB Clone - 'id' SQL Injection
FS Shaadi Clone – ‘token’ SQL Injection
# Exploit Title: FS Shaadi Clone - SQL Injection
WinduCMS 3.1 – Local File Disclosure
#!/usr/bin/python
FS Makemytrip Clone – ‘id’ SQL Injection
# Exploit Title: FS Makemytrip Clone - SQL Injection
Artica Web Proxy 3.06 – Remote Code Execution
[+] Credits: John Page (aka Hyp3rlinX)
Jobs2Careers / Coroflot Clone – SQL Injection
# Exploit Title: Jobs2Careers / Coroflot Clone - SQL Injection
WordPress Plugin WooCommerce 2.0/3.0 – Directory Traversal
# Exploit Title: WordPress woocommerce directory traversal
Zeta Components Mail 1.8.1 – Remote Code Execution
Vendor: Zeta Components
Kirby CMS < 2.5.7 - Cross-Site Scripting
# Exploit Title: KirbyCMS
Web Viewer 1.0.0.193 (Samsung SRN-1670D) – Unrestricted File Upload
# Exploit Title: Unrestricted file upload vulnerability - Web Viewer 1.0.0.193 on Samsung SRN-1670D
osCommerce 2.3.4.1 – Arbitrary File Upload
# Exploit Title: osCommerce 2.3.4.1 Authenticated Arbitrary File Upload
MyBB 1.8.13 – Cross-Site Scripting
# Exploit Title: XSS in MyBB up to 1.8.13 via installer
MyBB 1.8.13 – Remote Code Execution
# Exploit Title: RCE in MyBB up to 1.8.13 via installer
Ametys CMS 4.0.2 – Password Reset
## Vulnerability Summary
pfSense 2.3.1_1 – Command Execution
# Exploit Title: pfSense Groups) in the handling of the members[] parameter. This allows an authenticated WebGUI use...
WordPress Plugin Userpro < 4.9.17.1 - Authentication Bypass
# Exploit Title: Userpro – WordPress Plugin – Authentication Bypass
WordPress Plugin JTRT Responsive Tables 4.1 – SQL Injection
# Exploit Title: JTRT Responsive Tables 4.1 – WordPress Plugin – Sql Injection
Ingenious School Management System 2.3.0 – ‘friend_index’ SQL injection
# Exploit Title: Ingenious School Management System 2.3.0 - SQL injection
OctoberCMS 1.0.426 (Build 426) – Cross-Site Request Forgery
# Exploit Title: OctoberCMS 1.0.426 - CSRF to Admin Account Takover
Ingenious 2.3.0 – Arbitrary File Upload
# # # # #
D-Park Pro 1.0 – SQL Injection
Username: