Online Library Management System 1.0 – ‘Search’ SQL Injection
# Exploit Title: Online Library Management System 1.0 - 'Search' SQL Injection
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Online Library Management System 1.0 - 'Search' SQL Injection
# Exploit Title: WordPress Plugin Poll, Survey, Questionnaire and Voting system 1.5.2 - 'date_answers' Blind SQL Inje...
# Exploit Title: WordPress Plugin WP Google Maps 8.1.11 - Stored Cross-Site Scripting (XSS)
# Exploit Title: Phone Shop Sales Managements System 1.0 - Insecure Direct Object Reference (IDOR)
# Exploit Title: Responsive Tourism Website 3.1 - Remote Code Execution (RCE) (Unauthenticated)
# Exploit Title: Customer Relationship Management System (CRM) 1.0 - Remote Code Execution
# Exploit Title: Simple CRM 3.0 - 'name' Stored Cross site scripting (XSS)
# Exploit Title: Simple CRM 3.0 - 'Change user information' Cross-Site Request Forgery (CSRF)
# Exploit Title: Websvn 2.6.0 - Remote Code Execution (Unauthenticated)
# Exploit Title: OpenEMR 5.0.1.7 - 'fileName' Path Traversal (Authenticated)
# Exploit Title: Node.JS - 'node-serialize' Remote Code Execution (3)
# Exploit Title: ICE Hrm 29.0.0.OS - 'xml upload' Stored Cross-Site Scripting (XSS)
# Exploit Title: ICE Hrm 29.0.0.OS - 'Account Takeover' Cross-Site Request Forgery (CSRF)
# Exploit Title: Online Shopping Portal 3.1 - Remote Code Execution (Unauthenticated)
# Exploit Title: Zoho ManageEngine ServiceDesk Plus MSP 9.4 - User Enumeration
# Exploit Title: Unified Office Total Connect Now 1.0 – 'data' SQL Injection
# Exploit Title: CKEditor 3 - Server-Side Request Forgery (SSRF)
# Exploit Title: Teachers Record Management System 1.0 – 'email' Stored Cross-site Scripting (XSS)
# Exploit Title: Teachers Record Management System 1.0 – Multiple SQL Injection (Authenticated)
# Exploit Title: OpenEMR 5.0.1.3 - '/portal/account/register.php' Authentication Bypass
# Exploit Title: Cotonti Siena 0.9.19 - 'maintitle' Stored Cross-Site Scripting
# Exploit Title: Client Management System 1.1 - 'Search' SQL Injection
# Exploit Title: Client Management System 1.1 - 'username' Stored Cross-Site Scripting (XSS)
# Exploit Title: OpenEMR 5.0.1.3 - 'manage_site_files' Remote Code Execution (Authenticated)
# Exploit Title : TextPattern CMS 4.8.7 - Remote Command Execution (Authenticated)
# Exploit Title: Small CRM 3.0 - 'Authentication Bypass' SQL Injection
# Exploit Title: Stock Management System 1.0 - 'user_id' Blind SQL injection (Authenticated)
# Exploit Title: COVID19 Testing Management System 1.0 - 'State' Stored Cross-Site-Scripting (XSS)
# Exploit Title: GLPI 9.4.5 - Remote Code Execution (RCE)
# Exploit Title: Accela Civic Platform 21.1 - 'contactSeqNumber' Insecure Direct Object References (IDOR)
# Exploit Title: Accela Civic Platform 21.1 - 'successURL' Cross-Site-Scripting (XSS)
# Exploit Title: WoWonder Social Network Platform 3.1 - Authentication Bypass
# Exploit Title: Zenario CMS 8.8.52729 - 'cID' Blind & Error based SQL injection (Authenticated)
# Exploit Title: Solar-Log 500 2.8.2 - Unprotected Storage of Credentials
# Exploit Title: Solar-Log 500 2.8.2 - Incorrect Access Control
# Exploit Title: Grocery crud 1.6.4 - 'order_by' SQL Injection
# Exploit Title: WordPress Plugin Database Backups 1.2.2.6 - 'Database Backup Download' CSRF
# Exploit Title: OpenEMR 5.0.0 - Remote Code Execution (Authenticated)
# Exploit Title: Microsoft SharePoint Server 16.0.10372.20060 - 'GetXmlDataFromDataSource' Server-Side Request Forger...
# Exploit Title: Cerberus FTP web Service 11 - 'svg' Stored Cross-Site Scripting (XSS)
# Exploit Title: Accela Civic Platform 21.1 - 'servProvCode' Cross-Site-Scripting (XSS)
# Exploit Title: TextPattern CMS 4.8.7 - Stored Cross-Site Scripting (XSS)
# Exploit Title: Student Result Management System 1.0 - 'class' SQL Injection
# Exploit Title: GravCMS 1.10.7 - Arbitrary YAML Write/Update (Unauthenticated) (2)
# Exploit Title: WordPress Plugin visitors-app 0.3 - 'user-agent' Stored Cross-Site Scripting (XSS)
# Exploit Title: OpenCart 3.0.3.6 - 'subject' Stored Cross-Site Scripting
# Exploit Title : OpenCart 3.0.3.7 - 'Change Password' Cross-Site Request Forgery (CSRF)
# Exploit Title: Intelbras Router RF 301K - 'DNS Hijacking' Cross-Site Request Forgery (CSRF)
# Exploit Title: WordPress Plugin wpDiscuz 7.0.4 - Remote Code Execution (Unauthenticated)
# Exploit Title: Wordpress Plugin wpDiscuz 7.0.4 - Arbitrary File Upload (Unauthenticated)