Nanometrics Centaur 4.3.23 – Unauthenticated Remote Memory Leak
# Exploit Title: Nanometrics Centaur 4.3.23 - Unauthenticated Remote Memory Leak
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Nanometrics Centaur 4.3.23 - Unauthenticated Remote Memory Leak
# Exploit Title: DBPower C300 HD Camera - Remote Configuration Disclosure
# Exploit title : Virtual Freer 1.58 - Remote Command Execution
# Exploit Title: WordPress Plugin WP Sitemap Page 1.6.2 - Persistent Cross-Site Scripting
# Exploit Title: LabVantage 8.3 - Information Disclosure
# Exploit Title: SOPlanning 1.45 - 'users' SQL Injection
# Exploit Title: Wordpress Plugin WOOF Products Filter for WooCommerce 1.2.3 - Persistent Cross-Site Scripting
# Exploit Title: SOPlanning 1.45 - Cross-Site Request Forgery (Add User)
# Exploit Title: WordPress Theme Fruitful 3.8 - Persistent Cross-Site Scripting
# Exploit Title: Ice HRM 26.2.0 - Cross-Site Request Forgery (Add User)
# Exploit Title: Avaya Aura Communication Manager 5.2 - Remote Code Execution
# Exploit Title: Wordpress Plugin Strong Testimonials 2.40.0 - Persistent Cross-Site Scripting
# Exploit Title: SOPlanning 1.45 - 'by' SQL Injection
# Title: phpMyChat Plus 1.98 - 'pmc_username' SQL Injection
# Title : WordPress Plugin ultimate-member 2.1.3 - Local File Inclusion
# Exploit Title: PANDORAFMS 7.0 - Authenticated Remote Code Execution
# Tile: Wordpress Plugin contact-form-7 5.1.6 - Remote File Upload
# Tile: Wordpress Plugin wordfence.7.4.5 - Local File Disclosure
# Tile: Wordpress Plugin tutor.1.5.3 - Persistent Cross-Site Scripting
# Tile: Wordpress Plugin tutor.1.5.3 - Local File Inclusion
# Exploit Title: Vanilla Forums 2.6.3 - Persistent Cross-Site Scripting
# Exploit Title: CHIYU BF430 TCP IP Converter - Stored Cross-Site Scripting
# Exploit Title: LearnDash WordPress LMS Plugin 3.1.2 - Reflective Cross-Site Scripting
# Exploit Title: Forcepoint WebSecurity 8.5 - Reflective Cross-Site Scripting
# Exploit Title: Google Invisible RECAPTCHA 3 - Spoof Bypass
[+] Exploit Title: ExpertGPS 6.38 - XML External Entity Injection
# Exploit Title: EyesOfNetwork 5.3 - Remote Code Execution
# Exploit Title: PackWeb Formap E-learning 1.0 - 'NumCours' SQL Injection
# Exploit Title: VehicleWorkshop 1.0 - 'bookingid' SQL Injection
# Exploit Title: QuickDate 1.3.2 - SQL Injection
#!/usr/bin/python
#!/usr/bin/python
# Exploit Title: Ecommerce Systempay 1.0 - Production KEY Brute Force
# Exploit Title: Online Job Portal 1.0 - Cross Site Request Forgery (Add User)
# Exploit Title: Online Job Portal 1.0 - Remote Code Execution
# Exploit Title: Online Job Portal 1.0 - 'user_email' SQL Injection
# Exploit Title: AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset)
# Exploit Title: Verodin Director Web Console 3.5.4.0 - Remote Authenticated Password Disclosure (PoC)
# Exploit Title: Kronos WebTA 4.0 - Authenticated Remote Privilege Escalation
# Exploit Title: Wago PFC200 - Authenticated Remote Code Execution (Metasploit)
# Exploit Title: AVideo Platform 8.1 - Information Disclosure (User Enumeration)
# Title: F-Secure Internet Gatekeeper 5.40 - Heap Overflow (PoC)
#!/usr/bin/python3
#!/usr/bin/python3
# Title: School ERP System 1.0 - Cross Site Request Forgery (Add Admin)
# Exploit Title: Schneider Electric U.Motion Builder 1.3.4 - Authenticated Command Injection
# Exploit Title: Jira 8.3.4 - Information Disclosure (Username Enumeration)