Seacms 11.1 – ‘ip and weburl’ Remote Command Execution
# Exploit Title: Seacms 11.1 - 'ip and weburl' Remote Command Execution
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Seacms 11.1 - 'ip and weburl' Remote Command Execution
# Exploit Title: MiniWeb HTTP Server 0.8.19 - Buffer Overflow (PoC)
# Exploit Title: LibreNMS 1.46 - MAC Accounting Graph Authenticated SQL Injection
# Exploit Title: Rukovoditel 2.6.1 - Cross-Site Request Forgery (Change
# Exploit Title: Jenkins 2.235.3 - 'X-Forwarded-For' Stored XSS
# Exploit Title: Courier Management System 1.0 - 'ref_no' SQL Injection
# Exploit Title: Courier Management System 1.0 - 'MULTIPART street ' SQL Injection
# Exploit Title: Courier Management System 1.0 - 'First Name' Stored XSS
# Exploit Title: Dolibarr 12.0.3 - SQLi to RCE
# Exploit Title: Supply Chain Management System - Auth Bypass SQL Injection
# Exploit Title: Rukovoditel 2.6.1 - RCE
# Exploit Title: Jenkins 2.235.3 - 'Description' Stored XSS
# Exploit Title: Medical Center Portal Management System 1.0 - Multiple Stored XSS
# Exploit Title: Openfire 4.6.0 - 'sql' Stored XSS
# Exploit Title: Openfire 4.6.0 - 'users' Stored XSS
# Exploit Title: Openfire 4.6.0 - 'groupchatJID' Stored XSS
# Exploit Title: Jenkins 2.235.3 - 'tooltip' Stored Cross-Site Scripting
# Exploit Title: WordPress Plugin Popup Builder 3.69.6 - Multiple Stored Cross Site Scripting
# Exploit Title: Library Management System 2.0 - Auth Bypass SQL Injection
# Exploit Title: Openfire 4.6.0 - 'path' Stored XSS
# Exploit Title: OpenCart 3.0.3.6 - Cross Site Request Forgery
# Exploit Title: Barcodes generator 1.0 - 'name' Stored Cross Site Scripting
# Exploit Title: Task Management System 1.0 - 'id' SQL Injection
# Exploit Title: Task Management System 1.0 - Unrestricted File Upload to Remote Code Execution
# Exploit Title: Task Management System 1.0 - 'First Name and Last Name' Stored XSS
# Exploit Title: VestaCP 0.9.8-26 - 'backup' Information Disclosure
# Exploit Title: VestaCP 0.9.8-26 - 'LoginAs' Insufficient Session Validation
# Exploit Title: Employee Performance Evaluation System 1.0 - ' Task and Description' Persistent Cross Site Scripting
# Exploit Title: Online Bus Ticket Reservation 1.0 - SQL Injection
# Exploit Title: vBulletin 5.6.3 - 'group' Cross Site Scripting
# Exploit Title: Savsoft Quiz 5 - 'Skype ID' Stored XSS
# Exploit Title: Cyber Cafe Management System Project (CCMS) 1.0 - Persistent Cross-Site Scripting
# Exploit Title: Zabbix 5.0.0 - Stored XSS via URL Widget Iframe
# Exploit Title: CMS Made Simple 2.2.15 - Stored Cross-Site Scripting via SVG File Upload (Authenticated)
# Exploit Title: Laravel Nova 3.7.0 - 'range' DoS
# Exploit Title: Forma LMS 2.3 - 'First & Last Name' Stored Cross-Site Scripting
# Exploit Title: Savsoft Quiz 5 - 'field_title' Stored Cross-Site Scripting
# Exploit Title: Testa Online Test Management System 3.4.7 - 'q' SQL Injection
# Exploit Title: MiniCMS 1.10 - 'content box' Stored XSS
# Exploit Title: Phpscript-sgh 0.1.0 - Time Based Blind SQL Injection
# Exploit Title: Composr CMS 10.0.34 - 'banners' Persistent Cross Site Scripting
# Exploit Title: Wordpress Plugin Canto 1.3.0 - Blind SSRF (Unauthenticated)
# Exploit Title: Invision Community 4.5.4 - 'Field Name' Stored Cross-Site Scripting
# Exploit Title: Sony BRAVIA Digital Signage 1.7.8 - System API Information Disclosure
# Exploit Title: Sony BRAVIA Digital Signage 1.7.8 - Unauthenticated Remote File Inclusion
# Exploit Title: mojoPortal forums 2.7.0.0 - 'Title' Persistent Cross-Site Scripting
# Exploit Title: Online Matrimonial Project 1.0 - Authenticated Remote Code Execution
# Exploit Title: EgavilanMedia Address Book 1.0 Exploit - SQLi Auth Bypass
# Exploit Title: Coastercms 5.8.18 - Stored XSS
# Exploit Title: User Registration & Login and User Management System 2.1 - Cross Site Request Forgery