InoERP 0.7.2 – Remote Code Execution (Unauthenticated)
#!/usr/bin/python
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
#!/usr/bin/python
# Exploit Title: Online Health Care System 1.0 - Multiple Cross Site Scripting (Stored)
# Exploit Title: CMS Made Simple 2.1.6 - 'cntnt01detailtemplate' Server-Side Template Injection
#!/usr/bin/python3
#!/usr/bin/python3
# Exploit Title: Gym Management System 1.0 - Stored Cross Site Scripting
# Exploit Title: Gym Management System 1.0 - Authentication Bypass
# Exploit Title: School Faculty Scheduling System 1.0 - 'username' SQL Injection
# Exploit Title: School Faculty Scheduling System 1.0 - 'id' SQL Injection
# Exploit Title: Point of Sales 1.0 - 'username' SQL Injection
# Exploit Title: Gym Management System 1.0 - 'id' SQL Injection
#Exploit Title: lot reservation management system 1.0 - Stored Cross Site Scripting
#Exploit Title: lot reservation management system 1.0 - Authentication Bypass
#Exploit Title: Point of Sales 1.0 - SQL Injection
# Exploit Title: User Registration & Login and User Management System 2.1 - SQL Injection
# Exploit Title: Car Rental Management System 1.0 - Arbitrary File Upload
# Exploit Title: Stock Management System 1.0 - SQL Injection
#!/usr/bin/python3
# Exploit Title: Online Library Management System 1.0 - Arbitrary File Upload
# Exploit Title: Tiki Wiki CMS Groupware 21.1 - Authentication Bypass
# Exploit Title: Stock Management System 1.0 - Persistent Cross-Site Scripting (Brand Name)
# Exploit Title: Stock Management System 1.0 - Persistent Cross-Site Scripting (Categories Name)
# Exploit Title: Stock Management System 1.0 - Persistent Cross-Site Scripting (Product Name)
# Exploit Title: GOautodial 4.0 - Authenticated Shell Upload
# Exploit Title: School Faculty Scheduling System 1.0 - Authentication Bypass
# Exploit Title: School Faculty Scheduling System 1.0 - Stored Cross Site Scripting
# Exploit Title: Hrsale 2.0.0 - Local File Inclusion
# Exploit Title: WordPress Plugin Colorbox Lightbox v1.1.1 - Persistent Cross-Site Scripting Vulnerability (Authentic...
# Exploit Title: WordPress Rest Google Maps Plugin SQL Injection
# Exploit Title: Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution
# Title: Mobile Shop System v1.0 - SQLi lead to authentication bypass
# Exploit Title: RiteCMS 2.2.1 - Authenticated Remote Code Execution
# Exploit Title: User Registration & Login and User Management System With admin panel 2.1 - Persistent XSS
# Exploit Title: WordPress Plugin HS Brand Logo Slider 2.1 - 'logoupload' File Upload
# Exploit Title: Ultimate Project Manager CRM PRO 2.0.5 - SQLi Credentials Leakage
# Title: Visitor Management System in PHP 1.0 - Authenticated SQL Injection
# Exploit Title: WP Courses < 2.0.29 - Broken Access Controls leading to
# Exploit Title: Loan Management System 1.0 - Multiple Cross Site Scripting (Stored)
#!/usr/bin/env python3
# Exploit Title: Textpattern CMS 4.6.2 - Cross-site Request Forgery
# Exploit Title: Typesetter CMS 5.1 - Arbitrary Code Execution
# Exploit Title: PHPGurukul hostel-management-system 2.1 allows XSS via
# Exploit Title: Jenkins 2.63 - Sandbox bypass in pipeline: Groovy plug-in
#!/usr/bin/env bash
#!/usr/bin/env bash
#!/usr/bin/env bash
#!/usr/bin/env bash
#!/usr/bin/env bash
# Exploit Title: Online Job Portal 1.0 Cross Site Scripting (Stored)
# Exploit Title: Online Discussion Forum Site 1.0 - XSS in Messaging System