webapps
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
HBGK DVR 3.0.0 build20161206 – Authentication Bypass
# Exploit Title: HBGK DVR V3.0.0 build20161206 - Authentication Bypass
JitBit HelpDesk < 9.0.2 - Authentication Bypass
# Exploit Title: JitBit HelpDesk
PHP Auction Ecommerce Script 1.6 – SQL Injection
# Exploit Title: PHP Auction Ecommerce Script v1.6 - SQL Injection
Secure E-commerce Script 1.02 – ‘sid’ SQL Injection
# Exploit Title: Secure E-commerce Script v1.02 - SQL Injection
Cash Back Comparison Script 1.0 – SQL Injection
#!/usr/bin/perl -w
Multi Level Marketing – SQL Injection
# # # # #
Stock Photo Selling 1.0 – SQL Injection
#!/usr/bin/perl -w
PHPMyFAQ 2.9.8 – Cross-Site Scripting (1)
# Exploit Title: phpMyFAQ 2.9.8 Stored XSS
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1)
# E-DB Note: https://www.alphabot.com/security/blog/2017/java/Apache-Tomcat-RCE-CVE-2017-12617.html
Apache < 2.2.34 / < 2.4.27 - OPTIONS Memory Leak
#!/usr/bin/env python3
iBall ADSL2+ Home Router – Authentication Bypass
# Exploit Title: iBall ADSL2+ Home Router Authentication Bypass Vulnerability
DigiAffiliate 1.4 – Cross-Site Request Forgery (Update Admin)
#!/usr/local/bin/python
Digileave 1.2 – Cross-Site Request Forgery (Update Admin)
#!/usr/local/bin/python
Digirez 3.4 – Cross-Site Request Forgery (Update Admin)
#!/usr/local/bin/python
WordPress Plugin Content Timeline – SQL Injection
# Exploit Title: Multiple Blind SQL Injections Wordpress Plugin: Content Timeline
iTech Gigs Script 1.20 – ‘cat’ SQL Injection
# Exploit Title: iTech Gigs Script v1.20 - SQL Injection
UTStar WA3002G4 ADSL Broadband Modem – Authentication Bypass
# Exploit Title: UTStar WA3002G4 ADSL Broadband Modem Authentication Bypass Vulnerability
PTCEvolution 5.50 – SQL Injection
# # # # #
Humax Wi-Fi Router HG100R 2.0.6 – Authentication Bypass
# coding: utf-8
Adserver Script 5.6 – SQL Injection
# # # # #
Foodspotting Clone 1.0 – SQL Injection
# Exploit Title: Foodspotting Clone v1.0 - SQL Injection/Reflected XSS
ICSiteBuilder 1.1 – SQL Injection
# # # # #
ICHelpDesk 1.1 – ‘pk’ SQL Injection
# # # # #
ICEstate 1.1 – ‘id’ SQL Injection
# # # # #
ICProjectBidding 1.1 – SQL Injection
# # # # #
ICGrocery 1.1 – ‘key’ SQL Injection
# # # # #
IC-T-Shirt 1.2 – ‘key’ SQL Injection
# # # # #
ICJewelry 1.1 – ‘key’ SQL Injection
# # # # #
ICSurvey 1.1 – SQL Injection
# # # # #
ICStudents 1.2 – ‘key’ SQL Injection
# # # # #
ICClassifieds 1.1 – SQL Injection
# # # # #
ICTraveling 2.2 – Authentication Bypass
# # # # #
ICAutosales 2.2 – SQL Injection
# # # # #
ICDutchAuction 1.2 – SQL Injection
# # # # #