Sentrifugo 3.2 – Persistent Cross-Site Scripting
# Exploit Title: Sentrifugo 3.2 - Persistent Cross-Site Scripting
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Sentrifugo 3.2 - Persistent Cross-Site Scripting
# Exploit Title: Sentrifugo 3.2 - File Upload Restriction Bypass
# Exploit Title: PilusCart
#!/bin/bash
# Exploit Title: Jobberbase 2.0 CMS - 'jobs-in' SQL Injection
# Exploit Title: Tableau XXE
# Exploit Title: openITCOCKPIT 3.6.1-2 - CSRF 2 RCE
# Exploit Title: UserPro
# Exploit Title: Wordpress Plugin Import Export WordPress Users
# Exploit Title: LSoft ListServ < 16.5 - Cross-Site Scripting (XSS)
# Nimble Streamer 3.0.2-2 to 3.5.4-9 - Path Traversal
# Exploit Title: File disclosure in Pulse Secure SSL VPN (metasploit)
# Exploit Title: CSRF vulnerabilities in WP Add Mime Types Plugin
# Exploit Title: YouPHPTube < 7.3 SQL Injection
#!/bin/sh
# Exploit Title: Neo Billing 3.5 - Stored Cross Site Scripting Vulnerability
# Exploit Title: Fortinet FortiOS Leak file - Reading login/passwords in clear text.
# Exploit Title: Fortinet FortiOS Leak file - Reading login/passwords in clear text.
# Exploit Title: Kimai 2- persistent cross-site scripting (XSS)
# Exploit Title: Web Wiz Forums 12.01 - 'PF' SQL Injection
# Exploit Title: Integria IMS 5.0.86 - Arbitrary File Upload
# Exploit Title: Joomla! component com_jsjobs 1.2.6 - Arbitrary File Deletion
# Exploit Title: EyesOfNetwork 5.1 - Authenticated Remote Command Execution
#!/usr/bin/env python3
Document Title:
# Exploit Title: CSRF vulnerabilities in WordPress Download Manager Plugin 2.5
#Exploit Title: Joomla! component com_jsjobs - 'customfields.php' SQL Injection
# Exploit Title: 0Day UnauthenticatedXSS SugarCRM Enterprise
#Exploit Title: Joomla! component com_jsjobs - SQL Injection
# Exploit Title: osTicket-v1.12 Stored XSS
# Exploit Title: osTicket-v1.12 Formula Injection
# Exploit Title: osTicket-v1.12 Stored XSS via File Upload
#Exploit Title: Joomla! component com_jssupportticket - Authenticated Arbitrary File Deletion
#Exploit Title: Joomla! component com_jssupportticket - Authenticated SQL Injection
# Exploit Title: [UNA - 10.0.0-RC1 stored XSS vuln.]
require 'msf/core'
# Exploit Title:BSI Advance Hotel Booking System Persistent XSS
#Exploit Title: Joomla! component com_jssupportticket - SQL Injection
# Exploit Title: Adive Framework 2.0.7 – Cross-Site Request Forgery (CSRF)
#Exploit Title: Joomla! component com_jssupportticket - Arbitrary File Download
# Exploit Title: Aptana Jaxer Remote Local File inclusion
# Exploit Title: Daily Expense Manager - CSRF (Delete Income)
# Exploit Title: [title]
# Exploit Title: JoomSport 3.3 – for Sports - SQL injection
////////////////////////////////////////////////////////////////////////////////////