Expense Tracker 1.0 – ‘Expense Name’ Stored Cross-Site Scripting
# Exploit Title: Expense Tracker 1.0 - 'Expense Name' Stored Cross-Site Scripting
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Expense Tracker 1.0 - 'Expense Name' Stored Cross-Site Scripting
# Exploit Title: IPeakCMS 3.5 - Boolean-based blind SQLi
# Exploit Title: Advanced Webhost Billing System 3.7.0 - Cross-Site Request Forgery (CSRF)
# Exploit Title: Online Movie Streaming 1.0 - Authentication Bypass
# Exploit Title: WordPress Plugin WP-Paginate 2.1.3 - 'preset' Stored XSS
# Exploit Title: WordPress Plugin Stripe Payments 2.0.39 - 'AcceptStripePayments-settings[currency_code]' Stored XSS
# Exploit Title: Resumes Management and Job Application Website 1.0 - Authentication Bypass (Sql Injection)
# Exploit Title: IncomCMS 2.0 - Insecure File Upload
# Exploit Title: EgavilanMedia User Registration & Login System with Admin Panel 1.0 - Multiple Stored Cross-Site Scr...
# Exploit Title: Klog Server 2.4.1 - Command Injection (Unauthenticated)
# Exploit Title: Online Learning Management System 1.0 - RCE (Authenticated)
# Exploit Title: CSZ CMS 1.2.9 - Multiple Cross-Site Scripting
# Exploit Title: Cassandra Web 0.5.0 - Remote File Read
# Exploit Title: HPE Edgeline Infrastructure Manager 1.0 - Multiple Remote Vulnerabilities
# Exploit Title: Zoom Meeting Connector 4.6.239.20200613 - Remote Root Exploit (Authenticated)
# Exploit Title: Responsive FileManager 9.13.4 - 'path' Path Traversal
# Exploit Title: Baby Care System 1.0 - 'Post title' Stored XSS
# Exploit Title: Responsive E-Learning System 1.0 – 'id' Sql Injection
# Exploit Title: Arteco Web Client DVR/NVR - 'SessionId' Brute Force
# Exploit Title: Click2Magic 1.1.5 - Stored Cross-Site Scripting
# Exploit Title: Subrion CMS 4.2.1 - 'avatar[path]' XSS
# Exploit Title: CMS Made Simple 2.2.15 - RCE (Authenticated)
# Exploit Title: sar2html 3.2.1 - 'plot' Remote Code Execution
# Exploit Title: Advanced Comment System 1.0 - 'ACS_path' Path Traversal
# Exploit Title: Mantis Bug Tracker 2.24.3 - 'access' SQL Injection
# Exploit Title: 4images v1.7.11 - 'Profile Image' Stored Cross-Site Scripting
# Exploit Title: Wordpress Core 5.2.2 - 'post previews' XSS
# Exploit Title: Apartment Visitors Management System 1.0 - Authentication Bypass
# Exploit Title: GitLab 11.4.7 RCE (POC)
# Exploit Title: WordPress Plugin Adning Advertising 1.5.5 - Arbitrary File Upload
# Exploit Title: WordPress Plugin WP-PostRatings 1.86 - 'postratings_image' Cross-Site Scripting
# Exploit Title: Baby Care System 1.0 - 'roleid' SQL Injection
# Exploit Title: Sales and Inventory System for Grocery Store 1.0 - Multiple Stored XSS
# Exploit Title: Wordpress Epsilon Framework Multiple Themes - Unauthenticated Function Injection
# Exploit Title: Online Learning Management System 1.0 - 'id' SQL Injection
# Exploit Title: Online Learning Management System 1.0 - Multiple Stored XSS
# Exploit Title: Online Learning Management System 1.0 - Authentication Bypass
# Exploit Title: Class Scheduling System 1.0 - Multiple Stored XSS
# Exploit Title: TerraMaster TOS 4.2.06 - RCE (Unauthenticated)
# Exploit Title: Faculty Evaluation System 1.0 - Stored XSS
# Exploit Title: Artworks Gallery Management System 1.0 - 'id' SQL Injection
# Exploit Title: Multi Branch School Management System 3.5 - "Create Branch" Stored XSS
# Exploit Title: Library Management System 3.0 - "Add Category" Stored XSS
# Exploit Title : CSE Bookstore 1.0 - Multiple SQL Injection
# Exploit Title: Pandora FMS 7.0 NG 750 - 'Network Scan' SQL Injection (Authenticated)
# Exploit Title: Victor CMS 1.0 - File Upload To RCE
# Exploit Title: Online Marriage Registration System 1.0 - 'searchdata' SQL Injection