Laravel Administrator 4 – Unrestricted File Upload (Authenticated)
# Exploit title: Laravel Administrator 4 - Unrestricted File Upload (Authenticated)
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit title: Laravel Administrator 4 - Unrestricted File Upload (Authenticated)
# Product: Ruckus IoT Controller (Ruckus vRIoT)
# Exploit Title: WonderCMS 3.1.3 - 'uploadFile' Stored Cross-Site Scripting
# Exploit Title: Wordpress Theme Wibar 1.1.8 - 'Brand Component' Stored Cross Site Scripting
# Exploit Title: SyncBreeze 10.0.28 - 'password' Remote Buffer Overflow
# Exploit Title: osCommerce 2.3.4.1 - 'title' Persistent Cross-Site Scripting
# Exploit Title: WonderCMS 3.1.3 - 'page' Persistent Cross-Site Scripting
# Exploit Title: OpenCart 3.0.3.6 - 'subject' Stored Cross-Site Scripting
# Exploit Title: OpenCart 3.0.3.6 - 'Profile Image' Stored Cross Site Scripting (Authenticated)
# Exploit Title: Seowon 130-SLC router 1.0.11 - 'ipAddr' RCE (Authenticated)
# Exploit Title: Apache OpenMeetings 5.0.0 - 'hostname' Denial of Service
# Exploit Title: nopCommerce Store 4.30 - 'name' Stored Cross-Site Scripting
# Exploit Title: TP-Link TL-WA855RE V5_200415 - Device Reset Auth Bypass
# Exploit Title: LifeRay 7.2.1 GA2 - Stored XSS
# Exploit Title: VTiger v7.0 CRM - 'To' Persistent XSS
# Exploit Title: WonderCMS 3.1.3 - 'content' Persistent Cross-Site Scripting
# Exploit Title: Nagios Log Server 2.1.7 - 'snapshot_name' Persistent Cross-Site Scripting
# Title: M/Monit 3.7.4 - Password Disclosure
# Title: M/Monit 3.7.4 - Privilege Escalation
# Exploit Title: Gemtek WVRTM-127ACN 01.01.02.141 - Authenticated Arbitrary Command Injection
# Title: TestBox CFML Test Framework 4.1.0 - Directory Traversal
# Title: TestBox CFML Test Framework 4.1.0 - Arbitrary File Write and Remote Code Execution
# Exploit Title: Gitlab 12.9.0 - Arbitrary File Read (Authenticated)
# Exploit Title: Fortinet FortiOS 6.0.4 - Unauthenticated SSL VPN User Password Modification
# Exploit Title: xuucms 3 - 'keywords' SQL Injection
# Exploit Title: PESCMS TEAM 2.3.2 - Multiple Reflected XSS
# Exploit Title: BigBlueButton 2.2.25 - Arbitrary File Disclosure and Server-Side Request Forgery
#Exploit Title : Wordpress Plugin WPForms 1.6.3.1 - Persistent Cross Site Scripting (Authenticated)
# Exploit Title: Joomla Plugin Simple Image Gallery Extended (SIGE) 3.5.3 - Multiple Vulnerabilities
# Exploit Title: Froxlor Froxlor Server Management Panel 0.10.16 - Persistent Cross-Site Scripting
# Exploit Title: WordPress Plugin Buddypress 6.2.0 - Persistent Cross-Site Scripting
# Exploit Title: SugarCRM 6.5.18 - Persistent Cross-Site Scripting
# Exploit Title: Online Doctor Appointment Booking System PHP and Mysql 1.0 - 'q' SQL Injection
# Exploit Title: EgavilanMedia User Registration & Login System with Admin Panel Exploit - SQLi Auth Bypass
# Exploit Title: Car Rental Management System 1.0 - 'car_id' Sql Injection
# Exploit Title: Car Rental Management System 1.0 - Remote Code Execution (Authenticated)
# Exploit Title: PMB 5.6 - 'chemin' Local File Disclosure
# Exploit Title: User Registration & Login and User Management System 2.1 - Login Bypass SQL Injection
# Exploit Title: Water Billing System 1.0 - 'id' SQL Injection (Authenticated)
# Exploit Title: Pandora FMS 7.0 NG 749 - 'CG Items' SQL Injection (Authenticated)
# Exploit Title: October CMS Build 465 - Arbitrary File Read Exploit (Authenticated)
# Exploit Title: OpenCart Theme Journal 3.1.0 - Sensitive Data Exposure
#Exploit Title: Touchbase.io 1.10 - Stored Cross Site Scripting
require "msf/core"
const OFFSET_ELEMENT_REFCOUNT = 0x10;
# Exploit Title: Wordpress Plugin Good LMS 2.1.4 - 'id' Unauthenticated SQL Injection