webapps
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
ICAuction 2.2 – ‘id’ SQL Injection
# # # # #
ICMLM 2.1 – ‘key’ SQL Injection
# # # # #
ICLowBidAuction 3.3 – SQL Injection
# # # # #
D-Link DIR-8xx Routers – Local Firmware Upload
#!/bin/bash
D-Link DIR-8xx Routers – Root Remote Code Execution
# Due to error in hnap protocol implementation we can overflow stack and execute any sh commands under root priviliges.
D-Link DIR-8xx Routers – Leak Credentials
# phpcgi is responsible for processing requests to .php, .asp and .txt pages. Also, it checks whether a user is autho...
Consumer Review Script 1.0 – SQL Injection
# Exploit Title: Consumer Review Script v1.0 - SQL Injection
XYZ Auto Classifieds 1.0 – SQL Injection
# Exploit Title: XYZ Auto Classifieds v1.0 - SQL Injection
inClick Cloud Server 5.0 – SQL Injection
# # # # #
FoodStar 1.0 – SQL Injection
# # # # #
osTicket 1.10 – SQL Injection (PoC)
1. ADVISORY INFORMATION
Hanbanggaoke IP Camera – Arbitrary Password Change
## Vulnerability summary
AirStar Airbnb Clone Script 1.0 – SQL Injection
# Exploit Title: AirStar Airbnb Clone Script v1.0 - SQL Injection
EduStar Udemy Clone Script 1.0 – SQL Injection
# Exploit Title: EduStar Udemy Clone Script v1.0 - SQL Injection
iTech StockPhoto Script 2.02 – SQL Injection
# Exploit Title: iTech StockPhoto Script v2.02 - SQL Injection
iTech Book Store Script 2.02 – SQL Injection
# Exploit Title: iTech Book Store Script v2.02 - SQL Injection / Reflected XSS
JobStar Monster Clone Script 1.0 – SQL Injection
# Exploit Title: JobStar Monster Clone Script v1.0 - SQL Injection
PHP Dashboards NEW 4.4 – SQL Injection
# # # # #
WiseGiga NAS – Multiple Vulnerabilities
Source: https://blogs.securiteam.com/index.php/archives/3402
Law Firm 1.0 – SQL Injection
# # # # #
Job Board Software 1.0 – SQL Injection
# # # # #
Escort Marketplace 1.0 – SQL Injection
# # # # #
McAfee LiveSafe 16.0.3 – Man In The Middle Registry Modification Leading to Remote Command Execution
## Vulnerabilities Summary
Huawei HG255s – Directory Traversal
# Exploit Title: [Server Directory Traversal at Huawei HG255s]
Roteador Wireless Intelbras WRN150 – Cross-Site Scripting
# Exploit Title: XSS persistent on intelbras router with firmware WRN 250
EzInvoice 6.02 – SQL Injection
# # # # #
EzBan 5.3 – ‘id’ SQL Injection
# # # # #
Cory Support – ‘pr’ SQL Injection
# Exploit : Cory Support (pr) SQL Injection Vulnerability
Ultimate HR System < 1.2 - Directory Traversal / Cross-Site Scripting
# Exploit Title: HRM - Workable Zone : Ultimate HR System Last Name
The Car Project 1.0 – SQL Injection
# # # # #
A2billing 2.x – SQL Injection
# Title : A2billing 2.x , Sql injection vulnerability
iGreeting Cards 1.0 – SQL Injection
# # # # #