WSO2 3.1.0 – Arbitrary File Delete
# Title: WSO2 3.1.0 - Arbitrary File Delete
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Title: WSO2 3.1.0 - Arbitrary File Delete
# Exploit Title: Webtateas 2.0 - Arbitrary File Read
# Exploit Title: TVT NVMS 1000 - Directory Traversal
# Title: Huawei HG630 2 Router - Authentication Bypass
# Exploit Title: Zen Load Balancer 3.10.1 - 'index.cgi' Directory Traversal
Title: Helpful 2.4.11 Sql Injection - Wordpress Plugin
# Exploit Title: Django 3.0 - Cross-Site Request Forgery Token Bypass
# Exploit Title: pfSense 2.4.4-P3 - 'User Manager' Persistent Cross-Site Scripting
# Exploit Title: LimeSurvey 4.1.11 - 'File Manager' Path Traversal
# Exploit Title: Bolt CMS 3.7.0 - Authenticated Remote Code Execution
# Title: WhatsApp Desktop 0.3.9308 - Persistent Cross-Site Scripting
# Exploit Title: LimeSurvey 4.1.11 - 'Survey Groups' Persistent Cross-Site Scripting
# Exploit Title: Pandora FMS 7.0NG - 'net_tools.php' Remote Code Execution
# Exploit Title: PHP-Fusion 9.03.50 - 'panels.php' Multiple vulnerability
# Exploit Title: Grandstream UCM6200 Series WebSocket 1.0.20.20 - 'user_password' SQL Injection
# Exploit Title: Grandstream UCM6200 Series CTI Interface - 'user_password' SQL Injection
# Exploit Title: Zen Load Balancer 3.10.1 - Remote Code Execution
# Exploit Title: Joomla! com_fabrik 3.9.11 - Directory Traversal
# Exploit Title: rConfig 3.9.4 - 'searchField' Unauthenticated Root Remote Code Execution
# Exploit Title: Jinfornet Jreport 15.6 - Unauthenticated Directory Traversal
# Exploit Title : ECK Hotel 1.0 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: Centreo 19.10.8 - 'DisplayServiceStatus' Remote Code Execution
# Exploit Title: LeptonCMS 4.5.0 - Persistent Cross-Site Scripting
# Exploit Title: Joomla! Component GMapFP 3.30 - Arbitrary File Upload
# Exploit Title: UCM6202 1.0.18.13 - Remote Command Injection
# Exploit Title: Wordpress Plugin WPForms 1.5.8.2 - Persistent Cross-Site Scripting
# Exploit Title: UliCMS 2020.1 - Persistent Cross-Site Scripting
# Exploit Title: Joomla! com_hdwplayer 4.2 - 'search.php' SQL Injection
# Exploit Title: rConfig 3.9.4 - 'search.crud.php' Remote Command Injection
# Exploit Title: FIBARO System Home Center 5.021 - Remote File Include
Vulnerable Source:
# Exploit Title: Exagate Sysguard 6001 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: Joomla! ACYMAILING 3.9.0 component - Unauthenticated Arbitrary File Upload
# Exploit Title: Netlink GPON Router 1.0.11 - Remote Code Execution
# Exploit Title: UADMIN Botnet 1.0 - 'link' SQL Injection
# Exploit Title: PHPKB Multi-Language 9 - 'image-upload.php' Authenticated Remote Code Execution
# Exploit Title: PHPKB Multi-Language 9 - Authenticated Directory Traversal
# Exploit Title: PHPKB Multi-Language 9 - Authenticated Remote Code Execution
# Exploit Title: MiladWorkShop VIP System 1.0 - 'lang' SQL Injection
# Exploit Title: Enhanced Multimedia Router 3.0.4.27 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: Wordpress Plugin Custom Searchable Data System -
# Exploit Title: Centos WebPanel 7 - 'term' SQL Injection
# Exploit Title: rConfig 3.9 - 'searchColumn' SQL Injection
# Exploit Title: rConfig 3.93 - 'ajaxAddTemplate.php' Authenticated Remote Code Execution
# Exploit Title: HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: Wordpress Plugin Appointment Booking Calendar 1.3.34 - CSV Injection
# Exploit: WatchGuard Fireware AD Helper Component 5.8.5.10317 - Credential Disclosure
# Exploit Title: Joomla! Component com_newsfeeds 1.0 - 'feedid' SQL Injection
## exploit-phar-loading.py