Garage Management System 1.0 (categoriesName) – Stored XSS
# Exploit Title: Garage Management System 1.0 (categoriesName) - Stored XSS
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Garage Management System 1.0 (categoriesName) - Stored XSS
# Exploit Title: phpMyFAQ v3.2.10 - Unintended File Download Triggered by Embedded Frames
# Exploit Title: Zabbix 7.0.0 - SQL Injection
# Exploit Title: NagVis 1.9.33 - Arbitrary File Read
# Exploit Title: phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS)
# Exploit Title: ProConf 6.0 - Insecure Direct Object Reference (IDOR)
# Exploit Title: Teedy 1.11 - Account Takeover via Stored Cross-Site Scripting (XSS)
# Exploit Title: WooCommerce Customers Manager 29.4 - Post-Authenticated SQL Injection
# Exploit Title: Cacti 1.2.26 - Remote Code Execution (RCE) (Authenticated)
ABB Cylon Aspect 3.08.03 Hard-coded Secrets
ABB Cylon Aspect 3.08.03 (MapServicesHandler) - Authenticated Reflected XSS
# Author Title: John Page (aka hyp3rlinx)
# Exploit Title: Plane - Server side request forgery (SSRF)
# Author Title: John Page (aka hyp3rlinx)
# Exploit Title: OpenCMS 17.0 - Stored Cross Site Scripting (XSS)
# Exploit Title: Adapt Authoring Tool 0.11.3 - Remote Command Execution (RCE)
#!/usr/bin/env python3
# Exploit Title: Unrestricted File Upload
# Exploit Title: SilverStripe 5.3.8 - Stored Cross Site Scripting (XSS) (Authenticated)
# Exploit Title: OpenPanel Copy and View functions in the File Manager 0.3.4 - Directory Traversal
# Exploit Title: OpenPanel 0.3.4 - OS Command Injection
# Exploit Title: OpenPanel 0.3.4 - Incorrect Access Control
# Exploit Title: OpenPanel 0.3.4 - Directory Traversal
# Exploit Title: Pimcore customer-data-framework 4.2.0 - SQL injection
# Exploit Title: Xinet Elegant 6 Asset Lib Web UI 6.1.655 - SQL Injection
# Exploit Title: Authenticated Stored Cross-Site Scripting (XSS) Via Search
# Exploit Title: Broken Access Control in GeoVision GV-ASManager
# Exploit Title: GeoVision GV-ASManager 6.1.1.0 - CSRF
# Exploit Tile: CMU CERT/CC VINCE 2.0.6 - Stored XSS
# Exploit Title: WebFileSys 2.31.0 - Directory Path Traversal in relPath Parameter
# Exploit Title: Nagios Log Server 2024R1.3.1 - API Key Exposure
# Exploit Title: phpIPAM 1.6 - Reflected Cross Site Scripting (XSS)
# Exploit Title: MiniCMS 1.1 - Cross Site Scripting (XSS)
# Exploit Title: NEWS-BUZZ News Management System 1.0 - SQL Injection
# Exploit Title: Roundcube Webmail 1.6.6 - Stored Cross Site Scripting (XSS)
# Exploit Title: CyberPanel 2.3.6 - Remote Code Execution (RCE)
# Exploit Title: LearnPress WordPress LMS Plugin 4.2.7 - SQL Injection
# Exploit Title: MagnusSolution magnusbilling 7.3.0 - Command Injection
# Exploit Title: RosarioSIS 7.6 - SQL Injection
# Exploit Title: GetSimpleCMS 3.3.16 - Remote Code Execution (RCE)
# Exploit Title: flatCore 1.5 - Cross Site Request Forgery (CSRF)
# Exploit Title: flatCore 1.5.5 - Arbitrary File Upload
# Exploit Title: AquilaCMS 1.409.20 - Remote Command Execution (RCE)
# Exploit Title: Typecho 1.3.0 - Stored Cross-Site Scripting (XSS)
# Exploit Title: Typecho 1.3.0 - Race Condition
# Exploit Title: CodeAstro Online Railway Reservation System 1.0 - Cross Site Scripting (XSS)
# Exploit Title: PandoraFMS 7.0NG.772 - SQL Injection
# Exploit Title : Centron 19.04 - Remote Code Execution (RCE)
# Exploit Title: Cisco Smart Software Manager On-Prem 8-202206 - Account Takeover
# Exploit Title: Feng Office 3.11.1.2 - SQL Injection