Web Interface for DNSmasq / Mikrotik – SQL Injection
[+] Credits: hyp3rlinx
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
[+] Credits: hyp3rlinx
[+] Credits: John Page aka hyp3rlinx
=============================================
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=775
# Exploit Title: WordPress plugin Image Gallery Full Path Disclosure and SQL Injection
# Exploit Title: WordPress Q and A (Focus Plus) FAQ Full Path Disclosure and SQL Injection
ZeewaysCMS Multiple Vulnerabilities
Ajaxel CMS 8.0 Multiple Vulnerabilities
[SPSA-2016-02/ManageEngine ApplicationsManager]------------------------------
# Exploit Title: DotNetNuke 07.04.00 Administration Authentication Bypass
# Exploit Title: PHP Imagick disable_functions Bypass
######################################################################################
=============================================
# Exploit Title: Alibaba Clone B2B Script Admin Authentication Bypass
# Exploit Title: WordPress Export to Ghost Unrestricted Export Download
Advisory ID: HTB23301
_ _ _ _ _ _ _ _ _ _
# Exploit title: Observium Commercial - Authenticated RCE
Change admin password
# Title: Misfortune Cookie Exploit (RomPager
=============================================
#1 Stored XSS in 'signup[note]' POST parameter
Document Title:
#!/usr/bin/python
# Exploit Title: Symantec Brightmail ldap credential Grabber
#####################################################################################################################...
[+] Credits: hyp3rlinx
# Title: Blind Injection modified eCommerce 2.0.0.0 rev 9678
Dear OffSec,
I would like to disclose CSRF and stored XSS vulnerability in Kento post view counter plugin version 2.8 .
I would like to disclose CSRF and stored XSS vulnerability in Wordpress
EDB-Note Source: https://hackerone.com/reports/73480
#####################################################################################################################...
# Exploit Title: pfSense Firewall
# Exploit Title: Oracle Application Testing Suite Authentication Bypass and Arbitrary File Upload Remote Exploit
# Title: Ovidentia Module troubletickets 7.6 GLOBALS[babInstallPath] Remote File Inclusion Vulnerability
>> Multiple vulnerabilities in Novell Service Desk 7.1.0, 7.0.3 and 6.5
#####################################################################################################################...
OpenCart json_decode function Remote PHP Code Execution