Jorani v1.0.3-(c)2014-2023 – XSS Reflected & Information Disclosure
## Title: Jorani v1.0.3-(c)2014-2023 - XSS Reflected & Information Disclosure
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
## Title: Jorani v1.0.3-(c)2014-2023 - XSS Reflected & Information Disclosure
# Exploit Title: SPA-Cart eCommerce CMS 1.9.0.3 - SQL Injection
# Exploit Title: SPA-Cart eCommerce CMS 1.9.0.3 - Reflected XSS
## Title: Bus Reservation System-1.1 Multiple-SQLi
# Exploit Title: WP Statistics Plugin = 5.0:
## Title: Member Login Script 3.3 - Client-side desync
# Exploit Title : DLINK DPH-400SE - Exposure of Sensitive Information
# Exploit Title: FileMage Gateway 1.10.9 - Local File Inclusion
# Exploit Title: AdminLTE PiHole < 5.18 - Broken Access Control
# Exploit Title: CSZ CMS 1.3.0 - Stored Cross-Site Scripting (Plugin 'Gallery')
# Exploit Title: CSZ CMS 1.3.0 - Stored Cross-Site Scripting ('Photo URL' and 'YouTube URL' )
# Exploit Title: Academy LMS 6.1 - Arbitrary File Upload
# Exploit Title: Credit Lite 1.5.4 - SQL Injection
# Exploit Title: Hyip Rio 2.1 - Arbitrary File Upload
# Exploit Title: Blood Donor Management System v1.0 - Stored XSS
# Exploit Title: Uvdesk 1.1.4 - Stored XSS (Authenticated)
# Exploit Title: User Registration & Login and User Management System v3.0 - SQL Injection (Unauthenticated)
# Exploit Title: User Registration & Login and User Management System v3.0 - Stored Cross-Site Scripting (XSS)
# Exploit Title: Taskhub CRM Tool 2.8.6 - SQL Injection
# Exploit Title: OVOO Movie Portal CMS v3.3.3 - SQL Injection
# Exploit Title: Global - Multi School Management System Express v1.0- SQL Injection
# Exploit Title: Color Prediction Game v1.0 - SQL Injection
# Exploit Title: Crypto Currency Tracker (CCT) 9.5 - Admin Account Creation (Unauthenticated)
# Exploit Title: PHPJabbers Business Directory Script v3.2 - Multiple Vulnerabilities
# Exploit Title: Dolibarr Version 17.0.1 - Stored XSS
# Exploit Title: PHPJabbers Vacation Rental Script 4.0 - CSRF
# Exploit Title: Social-Commerce 3.1.6 - Reflected XSS
# Exploit Title: mooSocial 3.1.8 - Reflected XSS
# Exploit Title: Pyro CMS 3.9 - Server-Side Template Injection (SSTI) (Authenticated)
# Exploit Title: Lucee 5.4.2.17 - Authenticated Reflected XSS
# Exploit Title: Adlisting Classified Ads 2.14.0 - WebPage Content Information Disclosure
# Exploit Title: WordPress Plugin Forminator 1.24.6 - Unauthenticated Remote Command Execution
# Exploit Title: WordPress adivaha Travel Plugin 2.3 - Reflected XSS
Exploit Title: Webedition CMS v2.9.8.8 - Stored XSS
Exploit Title: Webedition CMS v2.9.8.8 - Remote Code Execution (RCE)
Exploit Title: Webutler v3.2 - Remote Code Execution (RCE)
# Exploit Title: Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Post Access via IDOR
# Exploit Title: Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Event Access
# Exploit Title: Online Matrimonial Website System v3.3 - Code Execution via malicious SVG file upload
# Exploit Title: WordPress adivaha Travel Plugin 2.3 - SQL Injection
# Exploit Title: Academy LMS 6.0 - Reflected XSS
# Exploit Title: PHPJabbers Rental Property Booking 2.0 - Reflected XSS
# Exploit Title: PHPJabbers Taxi Booking 2.0 - Reflected XSS
# Exploit Title: PHPJabbers Cleaning Business 1.0 - Reflected XSS
# Exploit Title: PHPJabbers Night Club Booking 1.0 - Reflected XSS
# Exploit Title: PHPJabbers Service Booking Script 1.0 - Reflected XSS
# Exploit Title: PHPJabbers Shuttle Booking Software 1.0 - Reflected XSS
# Exploit Title: JLex GuestBook 1.6.4 - Reflected XSS
# Exploit Title: Ozeki 10 SMS Gateway 10.3.208 - Arbitrary File Read (Unauthenticated)