UliCMS 2019.1 ‘Spitting Lama’ – Persistent Cross-Site Scripting
# Exploit Title: UliCMS 2019.1 "Spitting Lama" - Stored Cross-Site Scripting
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: UliCMS 2019.1 "Spitting Lama" - Stored Cross-Site Scripting
#!/usr/bin/env bash
CVE-2019-0841 BYPASS #2
Exploit Title: Remote file inclusion
# VMware Escape Exploit
Qualys Security Advisory
# Exploit Title: IceWarp
#!/usr/bin/python
#!/usr/bin/python
# Exploit Title: DVDXPlayer 5.5 Pro Local Buffer Overflow with SEH
# Exploit Title: Zoho ManageEngine ServiceDesk Plus 9.3 Cross-Site Scripting via SiteLookup.do
# Exploit Title: Zoho ManageEngine ServiceDesk Plus 9.3 Cross-Site Scripting via SolutionSearch.do
# Exploit Title: Zoho ManageEngine ServiceDesk Plus 9.3 Cross-Site Scripting via SearchN.do
# Exploit Title: Zoho ManageEngine ServiceDesk Plus 9.3 Cross-Site Scripting via PurchaseRequest.do
Vim/Neovim Arbitrary Code Execution via Modelines
# Exploit Title: [Dell Kace Appliance Multiple Vulnerabilities]
# Exploit Title: AUO Solar Data Recorder - Incorrect Access Control
# -*- coding: utf-8 -*-
Press CTRL+V+Enter
import socket, sys, struct
# Exploit Title: pfSense 2.4.4-p3 (ACMEPackage 0.5.7_1) - Stored Cross-Site Scripting
#Exploit Title: Free SMTP Server - Local Denial of Service Crash (PoC)
IonMonkey can, during a bailout, leak an internal JS_OPTIMIZED_OUT magic value to the running script. This magic valu...
While fuzzing Spidermonkey, I encountered the following (commented and modified) JavaScript program which crashes deb...
The following issue exists in the android-msm-wahoo-4.4-pie branch of
#Exploit title: EquityPandit v1.0 - Insecure Logging
# Exploit Title: Petraware pTransformer ADC before 2.1.7.22827 allows SQL
# Exploit title: Stored XSS vulnerability in Phraseanet DAM Open Source software
# -*- coding: utf-8 -*-
# Exploit Title: Maconomy Erp local file include
# Exploit Title: Code execution via path traversal
# Title: Axessh 4.2 - 'Log file name' Local Stack-based Buffer Overflow
#Exploit Title: Cyberoam SSLVPN Client 1.3.1.30 - 'Connect To Server' Denial of Service (PoC)
#Exploit Title: Cyberoam SSLVPN Client 1.3.1.30 - 'HTTP Proxy' Denial of Service (PoC)
#Exploit Title: Cyberoam Transparent Authentication Suite 2.1.2.5 - 'Fully Qualified Domain Name' Denial of Service (...
#Exploit Title: Cyberoam Transparent Authentication Suite 2.1.2.5 - 'NetBIOS Name' Denial of Service (PoC)
#Exploit Title: Cyberoam General Authentication Client 2.1.2.7 - Denial of Service (PoC)
# Exploit Title: Microsoft Internet Explorer Windows 10 1809 17763.316 - Scripting Engine Memory Corruption
# Exploit Title: Fast AVI MPEG Joiner Dos Exploit
# -*- coding: utf-8 -*-
# -*- coding: utf-8 -*-
# Exploit Title: Nagiosxi username sql injection
# -*- coding: utf-8 -*-
Windows: CmKeyBodyRemapToVirtualForEnum Arbitrary Key Enumeration EoP