Metabase 0.46.6 – Pre-Auth Remote Code Execution
# Exploit Title: metabase 0.46.6 - Pre-Auth Remote Code Execution
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: metabase 0.46.6 - Pre-Auth Remote Code Execution
# Exploit Title: SISQUALWFM 7.1.319.103 Host Header Injection
# Exploit Title: Lost and Found Information System v1.0 - idor leads to Account Take over
# Exploit Title: ManageEngine ADManager Plus Build < 7183 - Recovery Password Disclosure
# Exploit Title: Splunk 9.0.4 - Information Disclosure
# Exploit Title: Online Nurse Hiring System 1.0 - 'bookid' Time-Based SQL Injection
# Exploit Title: Rail Pass Management System - 'searchdata' Time-Based SQL Injection
# Exploit Title: Wordpress Seotheme - Remote Code Execution Unauthenticated
# Exploit Title: Wordpress Augmented-Reality - Remote Code Execution Unauthenticated
# Exploit Title: Advanced Page Visit Counter 1.0 - Admin+ Stored Cross-Site
# Exploit Title: WhatsUpGold 22.1.0 - Stored Cross-Site Scripting (XSS)
# Exploit Title: MISP 2.4.171 Stored XSS [CVE-2023-37307] (Authenticated)
# Exploit Title: Clinic's Patient Management System 1.0 - Unauthenticated RCE
# Exploit Title: Curfew e-Pass Management System 1.0 - FromDate SQL
# Exploit Title: GYM MS - GYM Management System - Cross Site Scripting (Stored)
# ***************************************************************************************************
Electrolink FM/DAB/TV Transmitter Pre-Auth MPFS Image Remote Code Execution
#!/usr/bin/env python
Electrolink FM/DAB/TV Transmitter (Login Cookie) Authentication Bypass
Electrolink FM/DAB/TV Transmitter (controlloLogin.js) Credentials Disclosure
Electrolink FM/DAB/TV Transmitter (login.htm/mail.htm) Credentials Disclosure
# Exploit Title: TP-LINK TL-WR740N - Multiple HTML Injection Vulnerabilities
# Exploit Title: TP-Link TL-WR740N UnAuthenticated Directory Transversal
# Exploit Title: GoAhead Web Server 2.5 - 'goform/formTest' Multiple HTML Injection Vulnerabilities
# Exploit Title: Grocy
## Title: 101 News-1.0 Multiple-SQLi
# Exploit Title: Academy LMS 6.2 - SQL Injection
## Title: PHP Shopping Cart-4.2 Multiple-SQLi
## Title: Fundraising Script-1.0 SQLi
# Exploit Title: Bank Locker Management System - SQL Injection
#!/usr/bin/env python3
## Title: Shuttle-Booking-Software v1.0 - Multiple-SQLi
## Title: Limo Booking Software v1.0 - CORS
Exploit Title: Webedition CMS v2.9.8.8 - Blind SSRF
#!/usr/bin/python3
# Exploit Title: Cacti 1.2.24 - Authenticated command injection when using SNMP options
# Exploit Title: Wordpress Sonaar Music Plugin 4.7 - Stored XSS
Exploit Title: coppermine-gallery 1.6.25 RCE
# Exploit Title: Media Library Assistant Wordpress Plugin - RCE and LFI
## Title: WEBIGniter v28.7.23 File Upload - Remote Code Execution
# Exploit Title: Wordpress Plugin Masterstudy LMS - 3.0.17 - Unauthenticated Instructor Account Creation
# Exploit Title: Minio 2022-07-29T19-40-48Z - Path traversal
# Exploit Title: Clcknshop 1.0.0 - SQL Injection
## Title: Online ID Generator 1.0 - Remote Code Execution (RCE)
#!/usr/bin/env python3
## Title: drupal-10.1.2 web-cache-poisoning-External-service-interaction
# Exploit Title: Axigen < 10.3.3.47, 10.2.3.12 - Reflected XSS
## Title: soosyze 2.0.0 - File Upload
# Exploit Title: Wp2Fac v1.0 - OS Command Injection
# Exploit Title: Wordpress Plugin Elementor < 3.5.5 - Iframe Injection