TufinOS 2.17 Build 1193 – XML External Entity Injection
# Exploit Title: TufinOS 2.17 Build 1193 - XML External Entity Injection
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: TufinOS 2.17 Build 1193 - XML External Entity Injection
# Exploit Title: Data Center Audit 2.6.2 - 'username' SQL Injection
# Exploit Title: PlayJoom 0.10.1 - 'catid' SQL Injection
# Exploit Title: LibreHealth 2.0.0 - Arbitrary File Actions
# Exploit Title: OpenBiz Cubi Lite 3.0.8 - 'username' SQL Injection
# Exploit Title: OOP CMS BLOG 1.0 - 'search' SQL Injection
# Exploit Title: Grocery crud 1.6.1 - 'search_field' SQL Injection
# Exploit Title: OOP CMS BLOG 1.0 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: CMS Made Simple 2.2.7 - Remote Code Execution
Exploit Title: Voovi Social Networking Script 1.0 - 'user' SQL Injection
RoyalTS/X Exploit
# Exploit Title: PHP-Proxy 3.0.3 - Local File Inclusion
# Exploit Title: Mongo Web Admin 6.0 - Information Disclosure
# Exploit Title: Poppy Web Interface Generator 0.8 - Arbitrary File Upload
# Exploit Title: WebVet 0.1a - 'id' SQL Injection
# Exploit Title: Advantech WebAccess SCADA 8.3.2 - Remote Code Execution
# Exploit Title: SiAdmin 1.1 - 'id' SQL Injection
# Exploit Title: Yot CMS 3.3.1 - 'aid' SQL Injection
# Exploit Title: qdPM 9.1 - 'filter_by' SQL Injection
# Exploit Title: Gate Pass Management System 2.1 - 'login' SQL Injection
# Exploit Title: Jelastic 5.4 - 'host' SQL injection
# Exploit Title: Fantastic Blog CMS 1.0 - 'id' SQL Injection
# Exploit Title: Loadbalancer.org Enterprise VA MAX 8.3.2 - Remote Code Execution
# Exploit Title: CI User Login and Management 1.0 - Arbitrary File Upload
# Exploit Title: Simple PHP Shopping Cart 0.9 - Arbitrary File Upload
# Exploit Title: Instagram Clone 1.0 - Arbitrary File Upload
# Exploit Title: Notes Manager 1.0 - Arbitrary File Upload
# Exploit Title: University Application System 1.0 - SQL Injection / Cross-Site Request Forgery (Add Admin)
# Exploit Title: Expense Management 1.0 - Arbitrary File Upload
# Exploit Title: MyBB Downloads 2.0.3 - SQL Injection
# Exploit Title: NETGEAR WiFi Router R6120 - Credential Disclosure
# Exploit Title: Webiness Inventory 2.9 - Arbitrary File Upload
# Exploit Title: phptpoint Pharmacy Management System 1.0 - 'username' SQL injection
# Exploit Title: Electricks eCommerce 1.0 - 'prodid' SQL Injection
# Exploit Title: South Gate Inn Online Reservation System 1.0 - 'q' SQL Injection
# Exploit Title: K-iwi Framework 1775 - SQL Injection
# Exploit Title: SaltOS Erp, Crm 3.1 r8126 - Database File Download
# Exploit Title: SaltOS Erp, Crm 3.1 r8126 - SQL Injection
# Exploit Title: SaltOS Erp, Crm 3.1 r8126 - SQL Injection
# Exploit Title: E-Negosyo System 1.0 - SQL Injection
# Exploit Title: RhinOS CMS 3.x - Arbitrary File Download
# Exploit Title: PayPal/Credit Card/Debit Card Payment 1.0 - SQL Injection
# Exploit Title: School Attendance Monitoring System 1.0 - SQL Injection
# Exploit Title: School Attendance Monitoring System 1.0 - Arbitrary File Upload
# Exploit Title: School Attendance Monitoring System 1.0 - Cross-Site Request Forgery (Update Admin)
# Exploit Title: School Event Management System 1.0 - Cross-Site Request Forgery (Update Admin)
# Exploit Title: School Event Management System 1.0 - Arbitrary File Upload
# Exploit Title: School Event Management System 1.0 - SQL Injection