JioFi 4G M2S 1.0.2 – ‘mask’ Cross-Site Scripting
# Exploit Title: cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST p...
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST p...
# Exploit Title: cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter
# Exploit Title: osTicket v1.11 - Cross-Site Scripting to Local File
# Exploit Title: AnMing MP3 CD Burner 2.0 Local Dos Exploit
# Exploit Title: Lavavo CD Ripper 4.20 Local Seh Exploit
VirtualBox: COM RPC Interface Code Injection Host EoP
VULNERABILITY DETAILS
Ross Video DashBoard 8.5.1 Insecure Permissions
The Siemens R3964 line discipline code in drivers/tty/n_r3964.c has a few races
Linux: page->_refcount overflow via FUSE with ~140GiB RAM usage
# Exploit Title: Ease Audio Converter 5.30 Audio Cutter Dos Exploit
# Exploit Title: Contact Form Builder [CSRF → LFI]
#!/usr/bin/python
# Exploit Title: 74CMS v5.0.1 has a CSRF vulnerability to add a new admin user
# Exploit Title: Msvod v10 has a CSRF vulnerability to change user information
# Exploit Title: UliCMS - 2019.2 , 2019.1 - Multiple Cross-Site Scripting
# Exploit Title: Directory traversal in Oracle Business Intelligence
# Exploit Title: XXE in Oracle Business Intelligence and XML Publisher
Exploit Title: Code execution via path traversal
# Exploit Title: Netwide Assembler (NASM) 2.14rc15 NULL Pointer Dereference (PoC)
#!/usr/bin/python
# Exploit Title:ASUS HG100 devices denial of service(DOS) via IPv4 packets/SlowHTTPDOS
#Exploit Title: DHCP Server 2.5.2 - Denial of Service (PoC)
A heap corruption was observed in Oracle Java Runtime Environment version 8u202 (latest at the time of this writing) ...
A heap corruption was observed in Oracle Java Runtime Environment version 8u202 (latest at the time of this writing) ...
# Exploit Title: Reflected XSS on Zyxel login pages
# Exploit Title: Zoho ManageEngine ADManager Plus 6.6 (Build < 6659) Privilege Escalation
# -*- coding: utf-8 -*-
# -*- coding: utf-8 -*-
# Exploit Title: Joomla Core (1.5.0 through 3.9.4) - Directory Traversal && Authenticated Arbitrary File Deletion
# -*- coding: utf-8 -*-
Windows: CSRSS SxSSrv Cached Manifest EoP
Windows: LUAFV Delayed Virtualization MAXIMUM_ACCESS DesiredAccess EoP
Windows: LUAFV Delayed Virtualization Cross Process Handle Duplication EoP
Windows: LUAFV LuafvCopyShortName Arbitrary Short Name EoP
Windows: LUAFV NtSetCachedSigningLevel Device Guard Bypass
Windows: LUAFV Delayed Virtualization Cache Manager Poisoning EoP
Windows: LUAFV PostLuafvPostReadWrite SECTION_OBJECT_POINTERS Race Condition EoP
# Title: DirectAdmin Multiple Vulnerabilities to Takeover the Server
#!/usr/bin/python
# Exploit Title: Remote Mouse 3.008 - Failure to Authenticate