Zendesk App SweetHawk Survey 1.6 – Persistent Cross-Site Scripting
# Exploit Title: Zendesk App SweetHawk Survey 1.6 - Persistent Cross-Site Scripting
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Zendesk App SweetHawk Survey 1.6 - Persistent Cross-Site Scripting
# Exploit Title: D-Link DIR-615 - Privilege Escalation
# Exploit Title: Roxy Fileman 1.4.5 - Directory Traversal
# Exploit Title: D-Link DIR-615 Wireless Router - Persistent Cross-Site Scripting
# Title: NVMS-1000 - Directory Traversal
# Title: Bullwark Momentum Series JAWS 1.0 - Directory Traversal
class MetasploitModule < Msf::Exploit::Remote
#############################################################
# Exploit Title: Inim Electronics Smartliving SmartLAN 6.x - Remote Command Execution
# Exploit Title: Inim Electronics Smartliving SmartLAN 6.x - Unauthenticated Server-Side Request Forgery
# Exploit Title : Oracle Siebel Sales 8.1 - Persistent Cross-Site Scripting
# Exploit Title: Alcatel-Lucent Omnivista 8770 - Remote Code Execution
# Exploit Title: Yachtcontrol Webapplication 1.0 - Unauthenticated Remote Code Execution
# Exploit Title: PRO-7070 Hazır Profesyonel Web Sitesi 1.0 - Authentication Bypass
# Exploit Title: Snipe-IT Open Source Asset Management 4.7.5 - Persistent Cross-Site Scripting
# Exploit Title: Verot 2.0.3 - Remote Code Execution
# Title: Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution
# Exploit Title: OwnCloud 8.1.8 - Username Disclosure
# Exploit Title: Online Clinic Management System 2.2 - HTML Injection
# Exploit Title: Revive Adserver 4.2 - Remote Code Execution
# Exploit Title: Intelbras Router RF1200 1.1.3 - Cross-Site Request Forgery
# Exploit Title: Online Invoicing System 2.6 - 'description' Persistent Cross-Site Scripting
# Exploit Title: Dokuwiki 2018-04-22b - Username Enumeration
# Exploit Title: SmartHouse Webapp 6.5.33 - Cross-Site Request Forgery
# Exploit Title: Online Inventory Manager 3.2 - Persistent Cross-Site Scripting
# Exploit Title: Mersive Solstice 2.8.0 - Remote Code Execution
# Exploit Title : Wordpress 5.3 - User Disclosure
# Exploit Title: Network Management Card 6.2.0 - Host Header Injection
# Exploit Title: TestLink 1.9.19 - Persistent Cross-Site Scripting
# Exploit Title: OpenNetAdmin 18.1.1 - Remote Code Execution
# Exploit Title: TemaTres 3.0 - 'value' Persistent Cross-site Scripting
# Exploit Title: TemaTres 3.0 — Cross-Site Request Forgery (Add Admin)
# Exploit Title: Centova Cast 3.2.11 - Arbitrary File Download
# Title: Crystal Live HTTP Server 6.01 - Directory Traversal
# Exploit Title: Lexmark Services Monitor 2.27.4.0.39 - Directory Traversal
# Exploit Title: Xfilesharing 2.5.1 - Arbitrary File Upload
# Exploit Title: Fastweb Fastgate 0.00.81 - Remote Code Execution
# Title: gSOAP 2.8 - Directory Traversal
# Exploit Title: Technicolor TC7300.B0 - 'hostname' Persistent Cross-Site Scripting
# Exploit Title: Technicolor TD5130.2 - Remote Command Execution
# Exploit Title : FUDForum 3.0.9 - Remote Code Execution
# Title: Linear eMerge E3 1.00-06 - Remote Code Execution
# Exploit Title: FlexAir Access Control 2.3.35 - Authentication Bypass
# Exploit Title: Adrenalin Core HCM 5.4.0 - 'ReportID' Reflected Cross-Site Scripting
# Title: Optergy 2.3.0a - Remote Code Execution
# Title: Optergy 2.3.0a - Username Disclosure
# Title: Optergy 2.3.0a - Cross-Site Request Forgery (Add Admin)
# Exploit Title: FlexAir Access Control 2.4.9api3 - Remote Code Execution
# Title: Optergy 2.3.0a - Remote Code Execution