Point of Sale System 1.0 – Multiple Stored XSS
# Exploit Title: Point of Sale System 1.0 - Multiple Stored XSS
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Point of Sale System 1.0 - Multiple Stored XSS
# Exploit Title: Flexmonster Pivot Table & Charts 2.7.17 - 'Remote JSON' Reflected XSS
# Exploit Title: Flexmonster Pivot Table & Charts 2.7.17 - 'To remote CSV' Reflected XSS
# Exploit Title: Flexmonster Pivot Table & Charts 2.7.17 - 'To OLAP' Reflected XSS
# Exploit Title: Flexmonster Pivot Table & Charts 2.7.17 - 'Remote Report' Reflected XSS
# Exploit Title: SCO Openserver 5.0.7 - 'outputform' Command Injection
# Exploit Title: SCO Openserver 5.0.7 - 'section' Reflected XSS
# Exploit Title: Spiceworks 7.5 - HTTP Header Injection
# Exploit Title: Academy-LMS 4.3 - Stored XSS
# Exploit Title: Spotweb 1.4.9 - 'search' SQL Injection
# Exploit Title: Queue Management System 4.0.0 - "Add User" Stored XSS
# Exploit Title: Xeroneit Library Management System 3.1 - "Add Book Category " Stored XSS
# Exploit Title: SyncBreeze 10.0.28 - 'login' Denial of Service (Poc)
# Exploit Title: Smart Hospital 3.1 - "Add Patient" Stored XSS
# Exploit Title: Alumni Management System 1.0 - 'id' SQL Injection
# Exploit Title: Alumni Management System 1.0 - "Course Form" Stored XSS
# Exploit Title: Alumni Management System 1.0 - Unrestricted File Upload To RCE
# Exploit Title: Point of Sale System 1.0 - Authentication Bypass
# Exploit Title: Victor CMS 1.0 - Multiple SQL Injection (Authenticated)
# Exploit Title: PHPJabbers Appointment Scheduler 2.3 - Reflected XSS (Cross-Site Scripting)
# Exploit Title: Employee Record System 1.0 - Multiple Stored XSS
# Exploit Title: Interview Management System 1.0 - 'id' SQL Injection
# Exploit Title: Interview Management System 1.0 - Stored XSS in Add New Question
# Exploit Title: Online Tours & Travels Management System 1.0 - "id" SQL Injection
# Exploit Title: Customer Support System 1.0 - 'id' SQL Injection
# Exploit Title: Customer Support System 1.0 - "First Name" & "Last Name" Stored XSS
# Exploit Title: Medical Center Portal Management System 1.0 - 'id' SQL Injection
# Exploit Title: Content Management System 1.0 - 'id' SQL Injection
# Exploit Title: Content Management System 1.0 - 'email' SQL Injection
# Exploit Title:Content Management System 1.0 - 'First Name' Stored XSS
# Exploit Title: Linksys RE6500 1.0.11.001 - Unauthenticated RCE
# Exploit Title: Dolibarr ERP-CRM 12.0.3 - Remote Code Execution (Authenticated)
const OFFSET_ELEMENT_REFCOUNT = 0x10;
# Exploit Title: Seotoaster 3.2.0 - Stored XSS on Edit page properties
# Exploit Title: PrestaShop ProductComments 4.2.0 - 'id_products' Time Based Blind SQL Injection
# Exploit Title: Magic Home Pro 1.5.1 - Authentication Bypass
# Exploit Title: Raysync 3.3.3.8 - RCE
# Exploit Title: Grav CMS 1.6.30 Admin Plugin 1.9.18 - 'Page Title' Persistent Cross-Site Scripting
# Exploit Title: Cisco ASA 9.14.1.10 and FTD 6.6.0.1 - Path Traversal (2)
# Exploit Title: Online Marriage Registration System (OMRS) 1.0 - Remote Code Execution (Authenticated)
# Exploit Title: Task Management System 1.0 - 'page' Local File Inclusion
# Exploit Title: Gitlab 11.4.7 - Remote Code Execution
# Exploit Title: Macally WIFISD2-2A82 2.000.010 - Guest to Root Privilege Escalation
# Exploit Title: Rumble Mail Server 0.51.3135 - 'username' Stored XSS
# Exploit Title: Rumble Mail Server 0.51.3135 - 'domain and path' Stored XSS
# Exploit Title: Rumble Mail Server 0.51.3135 - 'servername' Stored XSS
# Exploit Title: WordPress Plugin Total Upkeep 1.14.9 - Database and Files Backup Download
# Exploit Title: Seacms 11.1 - 'checkuser' Stored XSS
# Exploit Title: Seacms 11.1 - 'file' Local File Inclusion