Rocket.Chat 2.1.0 – Cross-Site Scripting
# Title: Rocket.Chat 2.1.0 - Cross-Site Scripting
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Title: Rocket.Chat 2.1.0 - Cross-Site Scripting
# Exploit Title: Joomla! 3.4.6 - Remote Code Execution
# Exploit Title: Restaurant Management System 1.0 - Remote Code Execution
# Exploit Title: Wordpress Popup Builder 3.49 - Persistent Cross-Site Scripting
# Exploit Title: Wordpress Soliloquy Lite 2.5.6 - Persistent Cross-Site Scripting
# Exploit Title: Wordpress FooGallery 1.8.12 - Persistent Cross-Site Scripting
# Exploit Title: Express Accounts Accounting 7.02 - Persistent Cross-Site Scripting
# Exploit Title: Bolt CMS 3.6.10 - Cross-Site Request Forgery
So far we know that adding `?static=1` to a wordpress URL should leak its secret content
Normal URLs like http://redirect.local/test will be forwared to https://redirect.local/test. But by using newlines (C...
The trick is to use a vertical tab (`%09`) and then place another URL in the tag. So once a victim clicks the link on...
# Exploit Title: Kirona-DRS 5.5.3.5 - Information Disclosure
# Title: Ajenti 2.1.31 - Remote Code Execution
# Exploit Title: Express Invoice 7.12 - 'Customer' Persistent Cross-Site Scripting
# Exploit Title: WordPress Arforms 3.7.1 - Directory Traversal
# Exploit Title: Intelbras Router WRN150 1.0.18 - Persistent Cross-Site Scripting
# Exploit Title: TP-Link TL-WR1043ND 2 - Authentication Bypass
# Exploit Title: SMA Solar Technology AG Sunny WebBox device - 1.6 - Cross-Site Request Forgery
# Exploit Title: Zabbix 4.4 - Authentication Bypass
# Exploit Title: IBM Bigfix Platform 9.5.9.62 - Arbitrary File Upload
# Title: Subrion 4.2.1 - 'Email' Persistant Cross-Site Scripting
# Exploit Title: Zabbix 4.2 - Authentication Bypass
# Exploit Title: Joomla 3.4.6 - 'configuration.php' Remote Code Execution
# Exploit Title: LabCollector (Laboratory Information System) 5.423 - Multiples SQL Injection
# Exploit Title: Information disclosure (MySQL password) in error log
# Exploit Title: mintinstall (aka Software Manager) object injection
#!/usr/bin/php
Exploit Title: "Display Name" Stored Unauthenticated XSS in DNN v9.3.2
# Exploit Title: Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0
#!/usr/bin/env ruby
# Exploit Title: thesystem Command Injection
# Exploit Title: thesystem Persistent XSS
#!/usr/bin/env python3
# Exploit Title: WordPress Theme Zoner Real Estate - 4.1.1 Persistent Cross-Site Scripting
# Exploit Title: V-SOL GPON/EPON OLT Platform 2.03 - Remote Privilege Escalation
# Exploit Title: V-SOL GPON/EPON OLT Platform 2.03 - Cross-Site Request Forgery
# Title: V-SOL GPON/EPON OLT Platform 2.03 - Unauthenticated Configuration Download
# Exploit Title: thesystem App 1.0 - 'username' SQL Injection
# Exploit Title: thesystem App 1.0 - Persistent Cross-Site Scripting
# Exploit Title: thesystem 1.0 - 'server_name' SQL Injection
# Exploit Title: InoERP 0.7.2 - Persistent Cross-Site Scripting
# Exploit Title: citecodecrashers Pic-A-Point 1.1 - 'Consignment' SQL Injection
# Exploit Title: inoERP 4.15 - 'download' SQL Injection
# Exploit Title: all-in-one-seo-pack 3.2.7 - Persistent Cross-Site Scripting
# Exploit Title: Duplicate-Post 3.2.3 - Persistent Cross-Site Scripting
# Exploit Title: Chamillo LMS 1.11.8 - Arbitrary File Upload