Easy File Uploader – Arbitrary File Upload
# Exploit Title: Easy File Uploader - Arbitrary File Upload
php 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Easy File Uploader - Arbitrary File Upload
# Exploit Title: Simple File Uploader - Arbitrary File Download
# Exploit Title: TYPO3 News Module SQL Injection
---------------------------------------------------------------
October CMS v1.0.412 several vulnerabilities
# Exploit Title: Wow Forms v2.1 WordPress Plugin SQL Injection
# Exploit Title: Wow Viral Signups v2.1 WordPress Plugin SQL Injection
# Exploit Title: Car Rental System v2.5
# Exploit Title: KittyCatfish 2.2 Plugin for WordPress - SQL Injection
# Exploit Title: XSRF Stored FlySpray 1.0-rc4 (XSS2CSRF add admin account)
# Exploit Title: Joomla Component Myportfolio 3.0.2 - SQL Injection
[+] Credits: John Page a.k.a hyp3rlinx
[+] Credits: John Page a.k.a hyp3rlinx
Source: https://blogs.securiteam.com/index.php/archives/3107
Description:
=============================================
# # # # #
----------------
# # # # #
# # # # #
# Exploit: Moodle SQL Injection via Object Injection Through User Preferences
# Exploit Title: CSRF / Privilege Escalation (Manipulation of Role Agent to Admin) on Faveo version Community 1.9.3
# Exploit Title: Multiple CSRF Remote Code Execution Vulnerability on HelpDEZK 1.1.1
# # # # #
# # # # #
# Exploit Title: GeoMoose
# Exploit Title: File Extension Filter Bypass in File Manager Pixie 1.0.4 With Low Privilege # Google Dork: no
# Exploit Title: EyesOfNetwork (EON) 5.1 Unauthenticated SQL Injection in eonweb leading to remote root