PrestaShop Winbiz Payment module – Improper Limitation of a Pathname to a Restricted Directory
# Exploit Title: PrestaShop Winbiz Payment module - Improper Limitation of a Pathname to a Restricted Directory
php 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: PrestaShop Winbiz Payment module - Improper Limitation of a Pathname to a Restricted Directory
# -*- coding: utf-8 -*-
#!/usr/bin/env python3
# Exploit Title: Super Socializer 7.13.52 - Reflected XSS
# Exploit Title: WP Sticky Social 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting (XSS)
# Exploit Title: WordPress Theme Medic v1.0.0 - Weak Password Recovery Mechanism for Forgotten Password
# Exploit Title: Diafan CMS 6.0 - Reflected Cross-Site Scripting (XSS)
# Exploit Title: Student Study Center Management System v1.0 - Stored Cross-Site Scripting (XSS)
# Exploit Title: Jobpilot v2.61 - SQL Injection
# Exploit Title: Groomify v1.0 - SQL Injection
# Exploit Title: The Shop v2.5 - SQL Injection
# Exploit Title: Online Art gallery project 1.0 - Arbitrary File Upload (Unauthenticated)
# Exploit Title: Textpattern CMS v4.8.8 - Stored Cross-Site Scripting (XSS) (Authenticated)
## Exploit Title: Online Thesis Archiving System v1.0 - Multiple-SQLi
# Exploit Title: Xoops CMS 2.5.10 - Stored Cross-Site Scripting (XSS) (Authenticated)
# Exploit Title: Monstra 3.0.4 - Stored Cross-Site Scripting (XSS)
Exploit Title: projectSend r1605 - Stored XSS
Exploit Title: projectSend r1605 - CSV injection
Exploit Title: Sales Tracker Management System v1.0 – Multiple Vulnerabilities
Exploit Title: Teachers Record Management System 1.0 – File Upload Type Validation
# Exploit Title: Online Examination System Project 1.0 - Cross-site request forgery (CSRF)
# Exploit Title: WordPress Theme Workreap 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
# Exploit Title: Tree Page View Plugin 1.6.7 - Cross Site Scripting (XSS)
# Exploit Title: File Manager Advanced Shortcode 2.3.2 - Unauthenticated Remote Code Execution (RCE)
# Title: MotoCMS Version 3.4.3 - SQL Injection
# Exploit Title: Barebones CMS v2.0.2 - Stored Cross-Site Scripting (XSS) (Authenticated)
# Exploit Title: Enrollment System Project v1.0 - SQL Injection Authentication Bypass (SQLI)
# Exploit Title: Total CMS 1.7.4 - Remote Code Execution (RCE)
# Exploit Title: Faculty Evaluation System 1.0 - Unauthenticated File Upload
#Exploit Title: Online Security Guards Hiring System 1.0 – REFLECTED XSS
Exploit Title: - unilogies/bumsys v1.0.3-beta - Unrestricted File Upload
## Exploit Title: SCRMS 2023-05-27 1.0 - Multiple SQLi
Exploit Title: Rukovoditel 3.3.1 - CSV injection
#Exploit Title: Ulicms 2023.1 - create admin user via mass assignment
Exploit Title: Zenphoto 1.6 - Multiple stored XSS
Exploit Title: WBCE CMS 1.6.1 - Multiple Stored Cross-Site Scripting (XSS)
# Exploit Title: Service Provider Management System v1.0 - SQL Injection
# Exploit Title: CiviCRM 5.59.alpha1 - Stored XSS (Cross-Site Scripting)
# Exploit Title: ChurchCRM v4.5.4 - Reflected XSS via Image (Authenticated)
# Exploit Title: Bludit CMS v3.14.1 - Stored Cross-Site Scripting (XSS) (Authenticated)
# Exploit Title: GetSimple CMS v3.3.16 - Remote Code Execution (RCE)
# Exploit Title: Quicklancer v1.0 - SQL Injection
# Exploit Title: Stackposts Social Marketing Tool v1.0 - SQL Injection
# Exploit Title: Smart School v1.0 - SQL Injection
# Exploit Title: LeadPro CRM v1.0 - SQL Injection
[#] Exploit Title: Affiliate Me Version 5.0.1 - SQL Injection
# Exploit Title: Webkul Qloapps 1.5.2 - Cross-Site Scripting (XSS)
#Exploit Title: SitemagicCMS 4.4.3 Remote Code Execution (RCE)
Exploit Title: Prestashop 8.0.4 - CSV injection
# Exploit Title: Best POS Management System v1.0 - Unauthenticated Remote Code Execution