htmlLawed 1.2.5 – Remote Code Execution (RCE)
# Exploit Title: htmlLawed 1.2.5 - Remote Code Execution (RCE)
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: htmlLawed 1.2.5 - Remote Code Execution (RCE)
# Exploit Title: PopojiCMS 2.0.1 - Remote Command Execution
# Exploit Title: Backdrop CMS 1.27.1 - Authenticated Remote Command Execution (RCE)
# Exploit Title: Apache OFBiz 18.12.12 - Directory Traversal
# Exploit Title: Wordpress Theme XStore 9.3.8 - SQLi
# Title: Rocket LMS 1.9 - Persistent Cross Site Scripting (XSS)
# Exploit : Prison Management System Using PHP -SQL Injection Authentication Bypass
# Exploit Title: PyroCMS v3.0.1 - Stored XSS
# Exploit Title: CE Phoenix Version 1.0.8.20 - Stored XSS
# Leafpub 1.1.9 - Stored Cross-Site Scripting (XSS)
# Chyrp 2.5.2 - Stored Cross-Site Scripting (XSS)
import requests
# Exploit Title: iboss Secure Web Gateway - Stored Cross-Site Scripting (XSS)
# Exploit Title: Clinic Queuing System 1.0 RCE
Elber Reble610 M/ODU XPIC IP-ASI-SDH Microwave Link Device Config
Elber Reble610 M/ODU XPIC IP-ASI-SDH Microwave Link Authentication Bypass
Elber Cleber/3 Broadcast Multi-Purpose Platform 1.0.0 Device Config
Elber Cleber/3 Broadcast Multi-Purpose Platform 1.0.0 Authentication Bypass
Elber Signum DVB-S/S2 IRD For Radio Networks 1.999 Device Config
Elber Signum DVB-S/S2 IRD For Radio Networks 1.999 Authentication Bypass
# Exploit Title: Flowise 1.6.5 - Authentication Bypass
# Exploit Title: Laravel Framework 11 - Credential Leakage
# Exploit Title: SofaWiki 3.9.2 - Remote Command Execution (RCE) (Authenticated)
# Exploit Title: Wordpress Plugin Background Image Cropper v1.2 - Remote Code Execution
# Exploit Title: FlatPress v1.3 - Remote Command Execution
# Exploit Title: OpenClinic GA 5.247.01 - Path Traversal (Authenticated)
# Exploit Title: OpenClinic GA 5.247.01 - Information Disclosure
# Exploit Title: Jenkins 2.441 - Local File Inclusion
# Exploit Title: djangorestframework-simplejwt 5.3.1 - Information Disclosure
#!/usr/bin/env python3
# Exploit Title: Stock Management System v1.0 - Unauthenticated SQL Injection
# Exploit Title: Online Fire Reporting System SQL Injection Authentication Bypass
# Exploit Title: Savsoft Quiz v6.0 Enterprise - Persistent Cross-Site
# Exploit Title: Wordpress Plugin WP Video Playlist 1.1.1 - Stored Cross-Site Scripting (XSS)
# Exploit Title: WBCE CMS Version : 1.6.1 Remote Command Execution
# Exploit Title: |Unauthenticated SQL injection in WBCE 1.6.0
# Exploit Title: Moodle Authenticated Time-Based Blind SQL Injection - "sort" Parameter
# Exploit Title: PopojiCMS Version : 2.0.1 Remote Command Execution
# Exploit Title: Wordpress Plugin Playlist for Youtube - Stored Cross-Site Scripting (XSS)
# Exploit Title: HTMLy Version v2.9.6 - Stored XSS
# Exploit Title: Ray OS v2.6.3 - Command Injection RCE(Unauthorized)
# Exploit Title: GUnet OpenEclass E-learning platform 3.15 - 'certbadge.php' Unrestricted File Upload
# Exploit Title : Open Source Medicine Ordering System v1.0 - SQLi
# Exploit Title: Daily Expense Manager 1.0 - 'term' SQLi
## Title: Best Student Result Management System v1.0 - Multiple SQLi
## Title: Human Resource Management System v1.0 - Multiple SQLi
# Exploit Title: Wordpress Theme Travelscape v1.0.3 - Arbitrary File Upload
# Exploit Title: Wordpress Plugin Alemha Watermarker 1.3.1 - Stored Cross-Site Scripting (XSS)
# Title: Computer Laboratory Management System v1.0 - Multiple-SQLi
# Exploit Title: Axigen < 10.5.7 - Persistent Cross-Site Scripting