VxWorks 6.8 – TCP Urgent Pointer = 0 Integer Underflow
# Exploit Title: VxWorks TCP Urgent pointer = 0 integer underflow vulnerability
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: VxWorks TCP Urgent pointer = 0 integer underflow vulnerability
On NUMA systems, the Linux fair scheduler tracks information related to NUMA
VULNERABILITY DETAILS
$SteamRegKey = "HKLM:\SOFTWARE\WOW6432Node\Valve\Steam\NSIS"
# Exploit Title: [title]
# Exploit Title: Daily Expense Manager - CSRF (Delete Income)
# Exploit Title: Aptana Jaxer Remote Local File inclusion
#Exploit Title: Joomla! component com_jssupportticket - Arbitrary File Download
# Exploit Title: Adive Framework 2.0.7 – Cross-Site Request Forgery (CSRF)
#Exploit Title: Joomla! component com_jssupportticket - SQL Injection
# Exploit Title: JoomSport 3.3 – for Sports - SQL injection
There is a heap overflow in [NSURL initWithCoder:] that can be reached via iMessage and likely other paths. When an N...
import requests
# Exploit Title: sar2html Remote Code Execution
# Exploit Title: Rest - Cafe and Restaurant Website CMS - SQL Injection
////////////////////////////////////////////////////////////////////////////////////
# Exploit Title:Web Studio Ultimate Loan Manager V2.0 - Persistent Cross Site Scripting
# Exploit Title: WebIncorp ERP - SQL injection
# Product : Catalyst 3850 Series Device Manager
- Exploit Title: XXE Injection Oracle Hyperion
When deserializing NSObjects with the NSArchiver API [1], one can supply a whitelist of classes that are allowed to b...
While fuzzing JavaScriptCore, I encountered the following (modified and commented) JavaScript program which crashes j...
While fuzzing JSC, I encountered the following JS program which crashes JSC from current HEAD and release (/System/Li...
When deserializing a class with initWithCoder, subclasses of that class can also be deserialized so long as they do n...
There is a memory corruption vulnerability when decoding an object of class NSKnownKeysDictionary1. This class decod...
The class _NSDataFileBackedFuture can be deserialized even if secure encoding is enabled. This class is a file-backed...
# Exploit Title: Cross Site Request Forgery in Wordpress Simple Membership plugin
# Exploit Title: Real Estate 7 - Real Estate WordPress Theme v2.8.9
# Exploit Title: GigToDo - Freelance Marketplace Script v1.3 Persistent XSS Injection
# Exploit Title: Server Side Request Forgery in Moodle Filepicker
# Exploit Title: pdfresurrect 0.15 Buffer Overflow
# Exploit Title: Ahsay Backup 8.1.1.50 - Insecure File Upload and Code Execution (Authenticated)
# Exploit Title: Authenticated insecure file upload and code execution flaw in Ahsay Backup v7.x - v8.1.1.50. (Metasp...
# Unauthenticated XML External Entity (XXE) in Ahsay Backup v7.x - v8.1.0.50.
#-------------------------------------------------------
#-------------------------------------------------------
# Exploit Title: MyBB < 1.8.21 Authenticated RCE
# Exploit Title: NoviSmart CMS SQL injection