webapps
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
ManageEngin AMP 4.3.0 – File-path-traversal
## Exploit Title: ManageEngine Access Manager Plus 4.3.0 - File-path-traversal
Active eCommerce CMS 6.5.0 – Stored Cross-Site Scripting (XSS)
# Exploit Title: Active eCommerce CMS 6.5.0 - Stored Cross-Site Scripting (XSS)
ERPGo SaaS 3.9 – CSV Injection
# Exploit Title: ERPGo SaaS 3.9 - CSV Injection
AmazCart CMS 3.4 – Cross-Site-Scripting (XSS)
# Exploit Title: AmazCart CMS 3.4 - Cross-Site-Scripting (XSS)
SQL Monitor 12.1.31.893 – Cross-Site Scripting (XSS)
# Exploit Title: SQL Monitor 12.1.31.893 - Cross-Site Scripting (XSS)
Art Gallery Management System Project v1.0 – SQL Injection (editid) authenticated
# Exploit Title: Art Gallery Management System Project v1.0 - SQL Injection (editid) authenticated
Art Gallery Management System Project v1.0 – SQL Injection (cid) Unauthenticated
# Exploit Title: Art Gallery Management System Project v1.0 - SQL Injection (cid) Unauthenticated
Art Gallery Management System Project v1.0 – Reflected Cross-Site Scripting (XSS)
# Exploit Title: Art Gallery Management System Project v1.0 - Reflected Cross-Site Scripting (XSS)
MyBB 1.8.32 – Remote Code Execution (RCE) (Authenticated)
# Exploit Title: MyBB 1.8.32 - Chained LFI Remote Code Execution (RCE) (Authenticated)
SLIMSV 9.5.2 – Cross-Site Scripting (XSS)
## Exploit Title: SLIMSV 9.5.2 - Cross-Site Scripting (XSS)
Zstore 6.5.4 – Reflected Cross-Site Scripting (XSS)
## Exploit Title: Zstore 6.5.4 - Reflected Cross-Site Scripting (XSS)
Nacos 2.0.3 – Access Control vulnerability
# Exploit Title: Nacos 2.0.3 - Access Control vulnerability
Metform Elementor Contact Form Builder v3.1.2 – Unauthenticated Stored Cross-Site Scripting (XSS)
# Exploit Title: Metform Elementor Contact Form Builder v3.1.2 - Unauthenticated Stored Cross-Site Scripting (XSS)
ChiKoi v1.0 – SQL Injection
## Title: ChiKoi-1.0 SQLi
pimCore v5.4.18-skeleton – Sensitive Cookie with Improper SameSite Attribute
## Exploit Title: pimCore v5.4.18-skeleton - Sensitive Cookie with Improper SameSite Attribute
ELSI Smart Floor V3.3.3 – Stored Cross-Site Scripting (XSS)
# Exploit Title: ELSI Smart Floor V3.3.3 - Stored Cross-Site Scripting (XSS)
Yahoo User Interface library (YUI2) TreeView v2.8.2 – Multiple Reflected Cross Site Scripting (XSS)
# Exploit Title: Yahoo User Interface library (YUI2) TreeView v2.8.2 - Multiple Reflected Cross Site Scripting (XSS)
PMB 7.4.6 – SQL Injection
# Exploit Title: PMB 7.4.6 - SQL Injection
Centos Web Panel 7 v0.9.8.1147 – Unauthenticated Remote Code Execution (RCE)
[+] Exploit Title: Centos Web Panel 7 v0.9.8.1147 - Unauthenticated Remote Code Execution (RCE)
Apache 2.4.x – Buffer Overflow
# Exploit Title: Apache 2.4.x - Buffer Overflow
Reprise Software RLM v14.2BL4 – Cross-Site Scripting (XSS)
# Exploit Title: Reprise Software RLM v14.2BL4 - Cross-Site Scripting (XSS)
SugarCRM 12.2.0 – Remote Code Execution (RCE)
#!/usr/bin/env python
perfSONAR v4.4.5 – Partial Blind CSRF
Exploit Title: perfSONAR v4.4.5 - Partial Blind CSRF
Prizm Content Connect v10.5.1030.8315 – XXE
# Exploit Title: Prizm Content Connect v10.5.1030.8315 - XXE
XCMS v1.83 – Remote Command Execution (RCE)
Exploit Title: XCMS v1.83 - Remote Command Execution (RCE)
GitLab v15.3 – Remote Code Execution (RCE) (Authenticated)
# Exploit Title: GitLab v15.3 - Remote Code Execution (RCE) (Authenticated)
GeoVision Camera GV-ADR2701 – Authentication Bypass
# Exploit Title: GeoVision Camera GV-ADR2701 - Authentication Bypass
Textpattern 4.8.8 – Remote Code Execution (RCE) (Authenticated)
# Exploit Title: Textpattern 4.8.8 - Remote Code Execution (RCE) (Authenticated)
Bangresto 1.0 – SQL Injection
## Exploit Title: Bangresto 1.0 - SQL Injection
Cacti v1.2.22 – Remote Command Execution (RCE)
# Exploit Title: Cacti v1.2.22 - Remote Command Execution (RCE)
Judging Management System v1.0 – Authentication Bypass
# Exploit Title: Judging Management System v1.0 - Authentication Bypass
Judging Management System v1.0 – Remote Code Execution (RCE)
# Exploit Title: Judging Management System v1.0 - Remote Code Execution (RCE)
rconfig 3.9.7 – Sql Injection (Authenticated)
# Exploit Title: rconfig 3.9.7 - Sql Injection (Authenticated)
Spitfire CMS 1.0.475 – PHP Object Injection
# Exploit Title: Spitfire CMS 1.0.475 - PHP Object Injection
Senayan Library Management System v9.0.0 – SQL Injection
## Exploit Title: Senayan Library Management System v9.0.0 - SQL Injection
Bludit 3-14-1 Plugin ‘UploadPlugin’ – Remote Code Execution (RCE) (Authenticated)
# Exploit Title: Bludit 3-14-1 Plugin 'UploadPlugin' - Remote Code Execution (RCE) (Authenticated)
WooCommerce v7.1.0 – Remote Code Execution(RCE)
# Title: Wordpress Plugin WooCommerce v7.1.0 - Remote Code Execution(RCE)
EQ Enterprise management system v2.2.0 – SQL Injection
Exploit Title: EQ Enterprise management system v2.2.0 - SQL Injection
Eve-ng 5.0.1-13 – Stored Cross-Site Scripting (XSS)
# Exploit Title: Eve-ng 5.0.1-13 - Stored Cross-Site Scripting (XSS)
WPForms 1.7.8 – Cross-Site Scripting (XSS)
# Exploit Title: WPForms 1.7.8 - Cross-Site Scripting (XSS)
Shoplazza 1.1 – Stored Cross-Site Scripting (XSS)
# Exploit Title: Shoplazza 1.1 - Stored Cross-Site Scripting (XSS)
LISTSERV 17 – Insecure Direct Object Reference (IDOR)
# Exploit Title: LISTSERV 17 - Insecure Direct Object Reference (IDOR)
LISTSERV 17 – Reflected Cross Site Scripting (XSS)
# Exploit Title: LISTSERV 17 - Reflected Cross Site Scripting (XSS)
4images 1.9 – Remote Command Execution (RCE)
# Exploit Title: 4images 1.9 - Remote Command Execution (RCE)
Device Manager Express 7.8.20002.47752 – Remote Code Execution (RCE)
# Exploit Title: Device Manager Express 7.8.20002.47752 - Remote Code Execution (RCE)
Concrete5 CME v9.1.3 – Xpath injection
## Exploit Title: Concrete5 CME v9.1.3 - Xpath injection
Virtual Reception v1.0 – Web Server Directory Traversal
# Exploit Title: Virtual Reception v1.0 - Web Server Directory Traversal
Covenant v0.5 – Remote Code Execution (RCE)
# Exploit Title: Covenant v0.5 - Remote Code Execution (RCE)
Ecommerse v1.0 – Cross-Site Scripting (XSS)
## Title: Ecommerse v1.0 - Cross-Site Scripting (XSS)