GL-iNet MT6000 4.5.5 – Arbitrary File Download
# Exploit Title: GL-iNet MT6000 4.5.5 - Arbitrary File Download
remote 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: GL-iNet MT6000 4.5.5 - Arbitrary File Download
################################################################################################
# Exploit Title: Siklu MultiHaul TG series - unauthenticated credential disclosure
# Exploit Title: Asterisk AMI - Partial File Content & Path Disclosure (Authenticated)
#!/usr/bin/perl
# Exploit Title: Hitachi NAS (HNAS) System Management Unit (SMU) 14.8.7825 - Information Disclosure
TELSAT marKoni FM Transmitter 1.9.5 Insecure Access Control Change Password
TELSAT marKoni FM Transmitter 1.9.5 Backdoor Account
#!/usr/bin/env python
# Exploit Title: GitLab CE/EE < 16.7.2 - Password Reset
#- Exploit Title: Ruijie Switch PSG-5124 26293 - Remote Code Execution (RCE)
#- Exploit Title: Viessmann Vitogate 300
#- Exploit Title: SolarView Compact 6.00 - Command Injection
#- Exploit Title: Honeywell PM43 < P10.19.050004 - Remote Code Execution (RCE)
#- Exploit Title: JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE)
# Exploit Title: [VMware Cloud Director | Bypass identity verification]
R Radio Network FM Transmitter 1.07 system.cgi Password Disclosure
#!/usr/bin/env python3
#!/usr/bin/env python
#!/usr/bin/env python3
#!/usr/bin/env python3
# Exploit Title: Maxima Max Pro Power - BLE Traffic Replay (Unauthenticated)
# Exploit Title: Enrollment System v1.0 - SQL Injection
# Exploit Title: AC Repair and Services System v1.0 - Multiple SQL Injection
# Exploit Title: Simple Student Attendance System v1.0 - 'classid' Time Based Blind & Union Based SQL Injection
# Exploit Title: Simple Student Attendance System - Time Based Blind SQL Injection
# Exploit Title: Real Estate Management System v1.0 - Remote Code Execution via File Upload
# Exploit Title: Petrol Pump Management Software v1.0 - Remote Code Execution via File Upload
# Exploit Title: Petrol Pump Management Software v.1.0 - SQL Injection
# Exploit Title: Petrol Pump Management Software v.1.0 - Stored Cross Site Scripting via SVG file
# Exploit Title: Petrol Pump Management Software v1.0 - 'Address' Stored Cross Site Scripting
CSRF Change Forward Power:
TEM Opera Plus FM Family Transmitter 35.45 Remote Code Execution
# Exploit Title: Executables Created with perl2exe malicious.pl
[+] Credits: John Page (aka hyp3rlinx)
[+] Credits: John Page (aka hyp3rlinx)
[+] Credits: John Page (aka hyp3rlinx)
# Exploit Title: FAQ Management System v1.0 - 'faq' SQL Injection
# Exploit Title: Flashcard Quiz App v1.0 - 'card' SQL Injection
# Exploit Title: Simple Inventory Management System v1.0 - 'email' SQL Injection
#!/usr/bin/expect -f
# Exploit Title: PCMan FTP Server 2.0 - 'pwd' Remote Buffer Overflow
# Exploit Title: WebCatalog 48.4 - Arbitrary Protocol Execution
RoyalTSX 6.0.1 RTSZ File Handling Heap Memory Corruption PoC
# Exploit Title: Proxmox VE TOTP Brute Force
#Exploit Title: Ricoh Printer Directory and File Exposure
# Exploit Title: Blood Bank & Donor Management System using v2.2 - Stored XSS