Grundig Smart Inter@ctive 3.0 – Cross-Site Request Forgery
# Exploit Title: Grundig Smart Inter@ctive 3.0 - Cross-Site Request Forgery
webapps 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Grundig Smart Inter@ctive 3.0 - Cross-Site Request Forgery
# Exploit Title: Cela Link CLR-M20 2.7.1.6 - Arbitrary File Upload
SEC Consult Vulnerability Lab Security Advisory < 20180712-0 >
Core Security - Corelabs Advisory
SEC Consult Vulnerability Lab Security Advisory < 20180711-0 >
# Exploit Title: Dicoogle PACS 2.5.0 - Directory Traversal
# Exploit Title: Instagram-clone Script 2.0 - Cross-Site Scripting
# Exploit title: D-Link DIR601 2.02NA - Credential disclosure
# Title: Elektronischer Leitz-Ordner 10 - SQL Injection
# Exploit Title: WolfSight CMS 3.2 - SQL Injection
######################
# Exploit Title: Airties AIR5444TT - Cross-Site Scripting
SEC Consult Vulnerability Lab Security Advisory < 20180704-1 >
# Exploit Title: SoftExpert Excellence Suite 2.0 - 'cddocument' SQL Injection
# pip install PyJWT requests
# Exploit Title: ShopNx - Angular5 Single Page Shopping Cart Application 1 - Arbitrary File Upload
# Exploit Title: Online Trade 1 - Information Disclosure
# Exploit Title: CMS Made Simple 2.2.5 authenticated Remote Code Execution
# Exploit Title: ManageEngine Exchange Reporter Plus
# Exploit Title: Unauthenticated Remote Code Evaluation in Dolibarr ERP CRM =
#!/usr/bin/env python
# Exploit Title: DIGISOL DG-HR3400 Wireless Router - Cross-Site Scripting
# Exploit Title: hycus Content Management System v1.0.4 Login Page Bypass
# Exploit Title: HongCMS 3.0.0 - SQL Injection
# Exploit Title: A CSRF vulnerability exists in BEESCMS_V4.0: The administrator can be added arbitrarily.
# Exploit Title: Wordpress
1. ADVISORY INFORMATION
# Exploit Title: WordPress Plugin iThemes Security(better-wp-security)
# Exploit Title: Wordpress Plugin Comments Import & Export < 2.0.4 - CSV Injection
# Exploit Title: Intex Router N-150 - Arbitrary File Upload
# Exploit Title: Ecessa ShieldLink SL175EHQ 10.7.4 - Cross-Site Request Forgery (Add Superuser)
# Exploit Title: AsusWRT RT-AC750GF - Cross-Site Request Forgery (Change Admin Password)
# Exploit title: Ecessa WANWorx WVR-30 < 10.7.4 - Cross-Site Request Forgery (Add Superuser)
# Exploit Title: DIGISOL DG-BR4000NG - Cross-Site Scripting
# Exploit Title: Intex Router N-150 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: Ecessa Edge EV150 10.7.4 - Cross-Site Request Forgery (Add Superuser)
# Exploit Title: Wordpress Plugin Advanced Order Export For WooCommerce < 1.5.4 - CSV Injection
# Exploit Title: phpMyAdmin 4.8.1 - Local File Inclusion to Remote Code Execution
# Exploit Title: phpLDAPadmin 1.2.2 - 'server_id' LDAP Injection (Username)
# Exploit Title: GreenCMS 2.3.0603 - remote obtain sensitive information
The latest version downloaded from the official website, the file name is phpMyAdmin-4.8.1-all-languages.zip
# Exploit Title: A CSRF vulnerability exists in LFCMS_3.7.0: administrator account can be added arbitrarily.
# Exploit Title: A CSRF vulnerability exists in LFCMS_3.7.0: users can be added arbitrarily.
# Title: VideoInsight WebClient 5 - SQL Injection