YzmCMS 5.3 – ‘Host’ Header Injection
# Exploit Title: YzmCMS 5.3 - 'Host' Header Injection
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: YzmCMS 5.3 - 'Host' Header Injection
# Exploit Title: NPMJS gitlabhook 0.0.17 - 'repository' Remote Command Execution
# Exploit Title: WP Server Log Viewer 1.0 - 'logfile' Persistent Cross-Site Scripting
# Exploit Title: Microsoft SharePoint 2013 SP1 - 'DestinationFolder' Persistent Cross-Site Scripting
# Exploit Title: Pfsense 2.3.4 / 2.4.4-p3 - Remote Code Injection
# Exploit Title: Authenticated Local File Inclusion(LFI) in GilaCMS
# Exploit Title: LayerBB 1.1.3 - Multiple CSRF
# Exploit Title: GOautodial 4.0 - 'CreateEvent' Persistent Cross-Site Scripting
# Exploit Title: DIGIT CENTRIS 4 ERP - 'datum1' SQL Injection
# Exploit Title: Western Digital My Book World II NAS
# Exploit Title: Hospital-Management 1.26 - 'fname' SQL Injection
# Exploit Title: CollegeManagementSystem-CMS 1.3 - 'batch' SQL Injection
===========Security Intelligence============
# Exploit Title: NetGain EM Plus
# Exploit Title: College-Management-System 1.2 - Authentication Bypass
# Exploit Title: Ticket-Booking 1.4 - Authentication Bypass
SEC Consult Vulnerability Lab Security Advisory < 20190912-0 >
=============================================
# Exploit Title: Dolibarr ERP/CRM 10.0.1 - User-Agent Http Header Cross
#!/usr/bin/env python
# Exploit Title: AVCON6 systems management platform - OGNL - Remote root command execution
# Exploit Title: WordPress Plugin Photo Gallery by 10Web
# Exploit Title: WordPress Plugin Photo Gallery by 10Web
# Exploit Title: WordPress Plugin Photo Gallery by 10Web Add new and in add galleries / Gallery groups. GET request ...
# Exploit Title: Dolibarr ERP/CRM - Multiple Sql Injection
# Exploit Title: WordPress Plugin Sell Downloads 1.0.86 - Cross Site Scripting
# Exploit Title: Online Appointment SQL Injection
#--------------------------------------------------------------------#
#!/usr/bin/python
#--------------------------------------------------------------------#
# Exploit Title: Dolibarr ERP/CRM - elemid Sql Injection
#!/usr/bin/perl -w
#####################################################################################
# Exploit Title: Inventory Webapp SQL injection
Multiple Cross-Site Scripting (XSS) in the web interface of DASAN Zhone ZNID GPON 2426A EU version S3.1.285 applicati...
CVE:CVE-2019-15889
# Exploit Title: FileThingie 2.5.7 - Arbitrary File Upload
# Exploit Title : CraftCms Users information disclosure From uploaded File
# Exploit Title: Alkacon OpenCMS 10.5.x - Multiple LFI in Alkacon OpenCms
# Exploit Title: Alkacon OpenCMS 10.5.x - Multiple XSS in Alkacon OpenCms
# Exploit Title: Alkacon OpenCMS 10.5.x - Multiple XSS in Apollo Template
# Exploit Title: WordPress Plugin Event Tickets >= 4.10.7.1 - CSV Injection
# Exploit Title: Opencart 3.x.x Authenticated Stored XSS
# Exploit Title: WordPress Plugin WooCommerce Product Feed
# Exploit Title: YouPHPTube
# Exploit Title: DomainMod