Rest – Cafe and Restaurant Website CMS – ‘slug’ SQL Injection
# Exploit Title: Rest - Cafe and Restaurant Website CMS - SQL Injection
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Rest - Cafe and Restaurant Website CMS - SQL Injection
# Exploit Title: sar2html Remote Code Execution
# Product : Catalyst 3850 Series Device Manager
# Exploit Title: WebIncorp ERP - SQL injection
# Exploit Title:Web Studio Ultimate Loan Manager V2.0 - Persistent Cross Site Scripting
- Exploit Title: XXE Injection Oracle Hyperion
# Exploit Title: GigToDo - Freelance Marketplace Script v1.3 Persistent XSS Injection
# Exploit Title: Real Estate 7 - Real Estate WordPress Theme v2.8.9
# Exploit Title: Cross Site Request Forgery in Wordpress Simple Membership plugin
# Unauthenticated XML External Entity (XXE) in Ahsay Backup v7.x - v8.1.0.50.
# Exploit Title: Authenticated insecure file upload and code execution flaw in Ahsay Backup v7.x - v8.1.1.50. (Metasp...
# Exploit Title: Ahsay Backup 8.1.1.50 - Insecure File Upload and Code Execution (Authenticated)
# Exploit Title: Server Side Request Forgery in Moodle Filepicker
# Exploit Title: MyBB < 1.8.21 Authenticated RCE
#-------------------------------------------------------
#-------------------------------------------------------
# Exploit Title: Wordpress Hybrid Composer
# Product : Cisco Wireless Controller
# Exploit Title: NoviSmart CMS SQL injection
# Title: Axway SecureTransport 5 - Unauthenticated XML Injection
# Exploit Title: REDCap < 9.1.2 - Cross-Site Scripting
# Exploit Title: Web Ofisi Firma 13 - 'oz' SQL Injection
# Exploit Title: Web Ofisi Rent a Car 3 - 'klima' SQL Injection
# Exploit Title: Web Ofisi Firma Rehberi 1 - 'il' SQL Injection
# Exploit Title: Web Ofisi Emlak 3 - 'emlak_durumu' SQL Injection
# Exploit Title: Web Ofisi Emlak 2 - 'ara' SQL Injection
# Exploit Title: Web Ofisi Platinum E-Ticaret 5 - 'q' SQL Injection
# Exploit Title: Web Ofisi E-Ticaret 3 - 'a' SQL Injection
# Exploit Title: fuel CMS 1.4.1 - Remote Code Execution (1)
# Exploit Title: WordPress Plugin OneSignal 1.17.5 - Persistent Cross-Site Scripting
# Exploit Title: Oracle Siebel CRM 19.0 - Persistent Cross-Site Scripting
# Exploit Title: CWP (CentOS Control Web Panel) < 0.9.8.848 User Enumeration via HTTP Response Message
//====================================================================\\
# Exploit Title: CWP (CentOS Control Web Panel) < 0.9.8.847 Bypass Login
# Exploit Title: FlightPath < 4.8.2 & < 5.0-rc2 - Local File Inclusion
# Exploit Title: CISCO Small Business 200, 300, 500 Switches Multiple Vulnerabilities.
# Exploit Title: NETGEAR WiFi Router R6080 - Security Questions Answers Disclosure
# Exploit Title: Citrix SD-WAN Appliance 10.2.2 Auth Bypass and Remote Command Execution
# Exploit Title: Persistent XSS - Dependency Graph View Plugin(v0.13)
# Exploit Title: Sahi Pro V8.0.0 - Unauthenticated Remote Command Execution
# Exploit Title: MyT Project Management - User[username] Stored Cross Site
# Exploit Title: tenda D301 v2 modem router stored xss CVE-2019-13492
# Exploit Title: Stored Cross Site Scripting (XSS) in Sitecore 9.0 rev 171002
Exploit Title: WP Like Button 1.6.0 - Auth Bypass
===========================================================================================
===========================================================================================
# Exploit Title: Persistent XSS on Symantec DLP
#!/usr/bin/python
#!/usr/bin/env python