Joomla JS Jobs plugin 1.4.2 – SQL injection
# Exploit Title: Joomla JS Jobs plugin 1.4.2 - SQL injection
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Joomla JS Jobs plugin 1.4.2 - SQL injection
# Exploit Title: Pie Register WordPress Plugin 3.7.1.4 - Authentication Bypass to RCE
# Exploit Title: Simple File List WordPress Plugin 4.2.2 - File Upload to RCE
# Exploit Title: WP Publications WordPress Plugin 1.2 - Stored XSS
# Exploit Title: White Star Software Protop 4.4.2-2024-11-27 - Local File Inclusion (LFI)
# Exploit Title : SugarCRM 14.0.0 - SSRF/Code Injection
#!/usr/bin/env python3
# Exploit Title: PivotX v3.0.0 RC3 - Stored XSS to Remote Code Execution (RCE)
#!/usr/bin/env python3
# Exploit Title: Stacks Mobile App Builder 5.2.3 - Authentication Bypass via Account Takeover
# Exploit Title: Moodle 4.4.0 - Authenticated Remote Code Execution
#!/usr/bin/env python3
# Exploit Title: Sitecore 10.4 - Remote Code Execution (RCE)
# Exploit Title: Pterodactyl Panel 1.11.11 - Remote Code Execution (RCE)
# Exploit Title: Skyvern 0.1.85 - Remote Code Execution (RCE) via SSTI
#!/usr/bin/env python3
# Exploit Title: Litespeed Cache WordPress Plugin 6.3.0.1 - Privilege Escalation
# Exploit Title: Anchor CMS 0.12.7 - Stored Cross Site Scripting (XSS)
#!/usr/bin/env python3
# Exploit Title: CloudClassroom PHP Project 1.0 - SQL Injection
# Exploit Title: WordPress Digits Plugin 8.4.6.1 - Authentication Bypass via OTP Bruteforcing
# Exploit Title: Campcodes Online Hospital Management System 1.0 - SQL Injection
# Exploit Title: Java-springboot-codebase 1.1 - Arbitrary File Read
#!/usr/bin/env python3
# Exploit Title: Kentico Xperience 13.0.178 - Cross Site Scripting (XSS)
# Exploit Title: WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege Escalation
# Exploit Title: SureTriggers OttoKit Plugin 1.0.82 - Privilege Escalation
# Exploit Title: WordPress Depicter Plugin 3.6.1 - SQL Injection
# Exploit Title: ERPNext 14.82.1 - Account Takeover via Cross-Site Request Forgery (CSRF)
# Exploit Title: Grokability Snipe-IT 8.0.4 - Insecure Direct Object Reference (IDOR)
# Exploit Title: Casdoor 1.901.0 - Cross-Site Request Forgery (CSRF)
# Exploit Title: WordPress Core 6.2 - Directory Traversal
# Date: 2025-04-17
#!/usr/bin/env python
# Exploit Title: KiviCare Clinic & Patient Management System (EHR) 3.6.4 - Unauthenticated SQL Injection
# Exploit Title: UJCMS 9.6.3 User Enumeration via IDOR
# Exploit Title: Inventio Lite 4 - SQL Injection
# Exploit Title: Apache Commons Text 1.10.0 - Remote Code Execution
# Exploit Title:Tatsu 3.3.11 - Unauthenticated RCE
# Exploit Title: Hunk Companion Plugin 1.9.0 - Unauthenticated Plugin Installation
# Exploit Title: compop.ca 3.5.3 - Arbitrary code Execution
#Exploit Title: Blood Bank & Donor Management System 2.4 - CSRF Improper
# Exploit Title: Usermin 2.100 - Username Enumeration
# Exploit Title: Angular-Base64-Upload Library 0.1.21 - Unauthenticated Remote Code Execution (RCE)
# Exploit Title: Smart Manager 8.27.0 - Post-Authenticated SQL Injection
# Exploit Title: KodExplorer 4.52 - Open Redirect
# Exploit Title: Car Rental Project 1.0 - Remote Code Execution
# Exploit Title: Ethercreative Logs 3.0.3 - Path Traversal
# Exploit Title: FLIR AX8 1.46.16 - Remote Command Injection