Wavemaker Studio 6.6 – Server-Side Request Forgery
# Exploit Title: Wavemaker Studio 6.6 - Server-Side Request Forgery (SSRF).
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Wavemaker Studio 6.6 - Server-Side Request Forgery (SSRF).
# Exploit Title: CMS ISWEB 3.5.3 - Directory Traversal
# Exploit Title: Cross-Site Request Forgery (Add Admin)
# Exploit Title: LAMS < 3.1 - Cross-Site Scripting
# Exploit Title: Sitecore.Net 8.1 - Directory Traversal
# Exploit Title: [Subrion CMS- 4.2.1 XSS (Using component with known
There is a directory traversal vulnerability in cgit_clone_objects(), reachable when the configuration flag enable-ht...
Issue: Out-of-Band XXE in Plex Media Server's SSDP Processing
Issue: Out-of-Band XXE in Vuze Bittorrent Client's SSDP Processing
# Exploit Title: PHP Template Store Script- 3.0.6 - Stored XSS via Addres ,Bank Name,and A/c Holder Name
# Exploit Title: Seq 4.2.476 - Authentication Bypass
# Exploit Title: ASUS DSL-N12E_C1 1.1.2.3_345 - Remote Command Execution
Issue: Out-of-Band XXE in Universal Media Server's SSDP Processing
# Title : CoSoSys Endpoint Protector - Authenticated Remote Root Command Injection
# Exploit Title: FB Inboxer 1.2 - 'search_field' SQL Injection
# Exploit Title: TI Online Examination System v2 - Arbitrary File Download
# LG NAS 3718.510.a0 - Remote Command Execution
# Exploit Title: Craft CMS SEOmatic plugin 3.1.4 - Server-Side Template Injection
# Exploit Title: H2 Database 1.4.197 - Information Disclosure
# Exploit Title: Responsive filemanager 9.13.1 - Server-Side Request Forgery
Core Security - Corelabs Advisory
# Exploit Title: Online Trade 1 - Information Disclosure
# Exploit Title: Kirby CMS 2.5.12 - Cross-Site Request Forgery (Delete Page)
# Exploit Title: Trivum Multiroom Setup Tool 8.76 - Corss-Site Request Forgery (Admin Bypass)
# Exploit Title: D-Link DAP-1360 File path traversal and Cross site
# Exploit Title: Tenda Wireless N150 Router 5.07.50 - Cross-Site Request Forgery (Reboot Router)
# Exploit Title: Davolink DVW 3200 Router - Password Disclosure
# Exploit Title: Synology DiskStation Manager 4.1 - Directory Traversal
# Exploit Title: NUUO NVR Unauthenticated Remote Code Execution
# Exploit Title: Kirby CMS 2.5.12 - Cross-Site Scripting
# Exploit Title: GeoVision GV-SNVR0811 Directory Traversal
# Exploit Title: Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 - Unauthorized Authentication Reset
# Exploit Title: MSVOD V10 ¡V SQL Injection
# Exploit Title: MyBB New Threads Plugin - Cross-Site Scripting
# Exploit Title: WordPress Plugin All In One Favicon
# Exploit Title: Modx Revolution < 2.6.4 - Remote Code Execution
# Exploit Title: FTP2FTP 1.0 - Arbitrary File Download
#######################################
# Exploit Title: Smart SMS & Email Manager v3.3 - SQL Injection
Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway Remote Root Exploit
Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway Arbitrary File Attacks
Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway Configuration Download
Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway CSRF Vulnerabilities
#!/usr/bin/env python3
#!/usr/bin/env python3
# Exploit Title: Wordpress Plugin Job Manager v4.1.0 Stored Cross Site
Title: Vulnerability in VelotiSmart Wifi - Directory Traversal