Exploits
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
- 类型
- 漏洞条目
- 总量
- 24,950
- 页码
- 108
Admin Express 1.2.5.485 – ‘Folder Path’ Local SEH Alphanumeric Encoded Buffer Overflow
# Title: Admin Express v1.2.5.485 'Folder Path' Local SEH Alphanumeric Encoded Buffer Overflow
Easy Chat Server 3.1 – ‘message’ Denial of Service (PoC)
#!/usr/bin/python
ReadyAPI 2.5.0 / 2.6.0 – Remote Code Execution
Create a new xpl
Xitami Web Server 2.5 – Remote Buffer Overflow (SEH + Egghunter)
# Exploit Title: Xitami Web Server 2.5 Remote Buffer Overflow (SEH + Egghunter)
PHPads 2.0 – ‘click.php3?bannerID’ SQL Injection
[+] Sql Injection on PHPads Version 2.0 based on Pixelledads 1.0 by Nile Flores
microASP (Portal+) CMS – ‘pagina.phtml?explode_tree’ SQL Injection
[+] Sql Injection on microASP (Portal+) CMS
NSClient++ 0.5.2.35 – Privilege Escalation
Exploit Author: bzyo
iOS 12.1.3 – ‘cfprefsd’ Memory Corruption
// (c) 2019 ZecOps, Inc. - https://www.zecops.com - Find Attackers' Mistakes
Instagram Auto Follow – Authentication Bypass
# Exploit Title: Instagram Auto Follow - Autobot Instagram - Authentication Bypass
Zotonic < 0.47.0 mod_admin - Cross-Site Scripting
# Exploit Title: Zotonic
Microsoft Windows PowerShell ISE – Remote Code Execution
[+] Credits: John Page (aka hyp3rlinx)
Blue Angel Software Suite – Command Execution
# Exploit Title: Blue Angel Software Suite - Authenticated Command Execution
SolarWinds DameWare Mini Remote Control 10.0 – Denial of Service
#Vendor: Solarwinds
WordPress Plugin Social Warfare < 3.5.3 - Remote Code Execution
# Title: RCE in Social Warfare Plugin Wordpress (
CentOS Web Panel 0.9.8.793 (Free) / v0.9.8.753 (Pro) / 0.9.8.807 (Pro) – Domain Field (Add DNS Zone) Cross-Site Scripting
# Exploit Title: CentOS Web Panel - Domain Field (Add DNS Zone) Cross-Site Scripting Vulnerability
Freefloat FTP Server 1.0 – ‘SIZE’ Remote Buffer Overflow
# Exploit Title: Free Float FTP 1.0 "SIZE" Remote Buffer Overflow
Freefloat FTP Server 1.0 – ‘STOR’ Remote Buffer Overflow
# Exploit Title: Free Float FTP 1.0 "STOR" Remote Buffer Overflow
Veeam ONE Reporter 9.5.0.3201 – Multiple Cross-Site Request Forgery
# Exploit Title: Veeam ONE Reporter - Cross-Site Request Forgery (All Actions/Methods)
Veeam ONE Reporter 9.5.0.3201 – Persistent Cross-Site Scripting
# Exploit Title: Veeam ONE Reporter - Stored Cross-site Scripting (Stored XSS)
Veeam ONE Reporter 9.5.0.3201 – Persistent Cross-site Scripting (Add/Edit Widget)
# Exploit Title: Veeam ONE Reporter - Stored Cross-site Scripting (Add/Edit Widget)
Joomla! Component ARI Quiz 3.7.4 – SQL Injection
# Exploit Title: Joomla! Component ARI Quiz 3.7.4 - SQL Injection
Intelbras IWR 3000N 1.5.0 – Cross-Site Request Forgery
IWR 3000N - CSRF on authenticated administrator
HumHub 1.3.12 – Cross-Site Scripting
# Exploit Title: HumHub 1.3.12 - Cross-Site Scripting
Domoticz 4.10577 – Unauthenticated Remote Command Execution
#!/usr/bin/env python
Joomla! Component JiFile 2.3.1 – Arbitrary File Download
# Exploit Title: Joomla! Component JiFile 2.3.1 - Arbitrary File Download
Hyvikk Fleet Manager – Shell Upload
========================================================================================
Agent Tesla Botnet – Information Disclosure
################################
SpotAuditor 5.2.6 – ‘Name’ Denial of Service (PoC)
#Exploit Title: SpotAuditor 5.2.6 - 'Name' Denial of Service (PoC)
DeviceViewer 3.12.0.1 – ‘user’ SEH Overflow
# Exploit Title: DeviceViewer v3.12.0.1 username field SEH overflow (PoC)
Oracle Weblogic 10.3.6.0.0 / 12.1.3.0.0 – Remote Code Execution
#!/usr/bin/python
Linux – Missing Locking Between ELF coredump code and userfaultfd VMA Modification
elf_core_dump() has a comment back from something like 2.5.43-C3 that says:
NSauditor 3.1.2.0 – ‘Community’ Denial of Service (PoC)
#Exploit Title: NSauditor 3.1.2.0 - 'Community' Denial of Service (PoC)
NSauditor 3.1.2.0 – ‘Name’ Denial of Service (PoC)
#Exploit Title: NSauditor 3.1.2.0 - 'Name' Denial of Service (PoC)
Apache Pluto 3.0.0 / 3.0.1 – Persistent Cross-Site Scripting
Exploit Title: Stored XSS
systemd – DynamicUser can Create setuid Binaries when Assisted by Another Process
This bug report describes a bug in systemd that allows a service with
HeidiSQL 10.1.0.5464 – Denial of Service (PoC)
#Exploit Title: HeidiSQL Portable 10.1.0.5464 - Denial of Service (PoC)
Backup Key Recovery 2.2.4 – Denial of Service (PoC)
#Exploit Title: Backup Key Recovery 2.2.4 - 'Name' Denial of Service (PoC)