SuperDoctor5 – ‘NRPE’ Remote Code Execution
# SuperMicro implemented a Remote Command Execution plugin in their implementation of
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# SuperMicro implemented a Remote Command Execution plugin in their implementation of
# Exploit Title: SAPIDO RB-1732 command line execution
# Exploit Title: FCM-MB40 Remote Command Execution as Root via CSRF
[+] Sql Injection on AZADMIN CMS of HIDEA v1.0
# Exploit Title: Directory Traversal on BlogEngine.NET
# Exploit Title: iLive - Intelligent WordPress Live Chat Support
# Exploit Title: Live Chat Unlimited v2.8.3 Stored XSS Injection
# Exploit Title: dotProject 2.1.9 - Multiple Sql Injection (Poc)
# Exploit Title: [Remote Command Execution through Unvalidated File Upload in SeedDMS versions
# Exploit Title: [Persistent Cross-Site Scripting or Stored XSS in out/out.UsrMgr.php in SeedDMS before 5.1.11]
# Exploit Title: [Persistent Cross-Site Scripting or Stored XSS in out/out.GroupMgr.php in SeedDMS before 5.1.11]
# Exploit Title: GSearch v1.0.1.0 - Denial of Service (PoC)
# Exploit Title: GrandNode Path Traversal & Arbitrary File Download (Unauthenticated)
Windows: CmpAddRemoveContainerToCLFSLog Arbitrary File/Directory Creation EoP
Windows: Windows Font Cache Service Insecure Sections EoP
# Exploit Title: EA Origin
# Exploit Title: TuneClone Local Seh Exploit
# Exploit Title: Blind SQL injection in WebERP.
# Exploit Title: Out-of-band XML External Entity Injection on BlogEngine.NET
When a #BR exception is raised because of an MPX bounds violation, Linux parses
# Exploit Title: Directory Traversal + RCE on BlogEngine.NET
# Exploit Title: Directory Traversal + RCE on BlogEngine.NET
# Exploit Title: Sahi pro (
# Exploit Title: Sahi pro (
# Exploit Title: Sahi pro (
CVE-2019-12181 Serv-U 15.1.6 Privilege Escalation
# -*- encoding: utf-8 -*-
1. Advisory Information
[+] Credits: John Page (aka hyp3rlinx)
#!/bin/bash
# Exploit Author: Juan Sacco - http://exploitpack.com
# Exploit Title: Open Redirector in spring-security-oauth2
-----BEGIN PGP SIGNED MESSAGE-----
X41 D-Sec GmbH Security Advisory: X41-2019-001
X41 D-Sec GmbH Security Advisory: X41-2019-002
X41 D-Sec GmbH Security Advisory: X41-2019-003
#!/usr/bin/env bash
#!/usr/bin/python
# Exploit Title: Sitecore v 8.x Deserialization RCE
# Exploit Title: FusionPBX
#!/usr/bin/python
# Exploit Title: Authenticated code execution in `insert-or-embed-articulate-content-into-wordpress` Wordpress plugin
# Exploit Title: Cross Site Request Forgery (CSRF)
# Exploit Title: Liferay Portal < 7.1 CE GA4 / SimpleCaptcha API XSS