WordPress Plugin Ninja Forms 3.3.17 – Cross-Site Scripting
# Exploit Title: Wordpress Plugin Ninja Forms 3.3.17 - Cross-Site Scripting
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Wordpress Plugin Ninja Forms 3.3.17 - Cross-Site Scripting
# Exploit Title: PHP Mass Mail 1.0 - Arbitrary File Upload
# Exploit Title: 2-Plan Team 1.0.4 - Arbitrary File Upload
# Exploit Title: Simple E-Document 1.31 - 'username' SQL Injection
# Exploit Title: Kordil EDMS 2.2.60rc3 - Arbitrary File Upload
# Exploit Title: Meneame English Pligg 5.8 - 'search' SQL Injection
# Exploit Title: EverSync 0.5 - Arbitrary File Download
# Exploit Title: Galaxy Forces MMORPG 0.5.8 - 'type' SQL Injection
# Exploit Title: Net-Billetterie 2.9 - 'login' SQL Injection
# Exploit Title: BitZoom 1.0 - 'rollno' SQL Injection
# Exploit Title: PHP-Proxy 5.1.0 - Local File Inclusion
# Exploit Title: Precurio Intranet Portal 2.0 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: DoceboLMS 1.2 - SQL Injection
# Exploit Title: Electricks eCommerce 1.0 - Cross-Site Scripting
# Exploit Title: Pedidos 1.0 - SQL Injection
# Exploit Title: Rmedia SMS 1.0 - SQL Injection
# Exploit Title: SQL injection in Advanced comment system v1.0
# Exploit Title: EdTv 2 - 'id' SQL Injection
# Exploit Title: Electricks eCommerce 1.0 - Cross-Site Request Forgery (Change Admin Password)
# Exploit Title: Helpdezk 1.1.1 - 'query' SQL Injection
# Exploit Title: iServiceOnline 1.0 - 'r' SQL Injection
# Exploit Title: SIPve 0.0.2-R19 - SQL Injection
# Exploit Title: Webiness Inventory 2.3 - SQL Injection
# Exploit Title: Webiness Inventory 2.3 - Arbitrary File Upload / Cross-Site Request Forgery Add Admin)
# Exploit Title: Maitra - Mail Tracking System 1.7.2 - SQL Injection / Database File Download
# Exploit Title: Alive Parish 2.0.4 - SQL Injection / Arbitrary File Upload
# Exploit Title: ClipperCMS 1.3.3 File Upload CSRF Vulnerability
# Exploit Title: Silurus Classifieds Script 2.0 - SQL Injection
# Exploit Title: Gumbo CMS 0.99 - SQL Injection
# Exploit Title: ABC ERP 0.6.4 - Cross-Site Request Forgery (Update Admin)
# Exploit Title: Easyndexer 1.0 - Arbitrary File Download
# Exploit Title: Tina4 Stack 1.0.3 - Cross-Site Request Forgery (Update Admin)
# Exploit Title: Tina4 Stack 1.0.3 - SQL Injection / Database File Download
# Exploit Title: Data Center Audit 2.6.2 - Cross-Site Request Forgery (Update Admin)
# Exploit Title: Musicco 2.0.0 - Arbitrary Directory Download
# Exploit Title: Alienor Web Libre 2.0 - SQL Injection
# Exploit Title: Surreal ToDo 0.6.1.2 - Local File Inclusion
# Exploit Title: Surreal ToDo 0.6.1.2 - SQL Injection
# Title: CentOS Web Panel Root Account Takeover + Remote Command Execution
# Exploit Title: Nominas 0.27 - 'username' SQL Injection
# Exploit Title: D-LINK Central WifiManager CWM-100 - Server-Side Request Forgery
# Exploit Title: ServerZilla 1.0 - 'email' SQL Injection
# Exploit Title: GPS Tracking System 2.12 - 'username' SQL Injection
# Exploit Title: Easyndexer 1.0 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: Facturation System 1.0 - 'modid' SQL Injection
# Exploit Title: The Don 1.0.1 - 'login' SQL Injection
# Exploit Title: TP-Link Archer C50 Wireless Router 171227 - Cross-Site Request Forgery (Configuration File Disclosure)
# Exploit Title: Paroiciel 11.20 - 'tRecIdListe' SQL Injection
# Exploit Title: Wordpress Plugin Media File Manager 1.4.2 - Directory Traversal