Exploits
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
- 类型
- 漏洞条目
- 总量
- 24,950
- 页码
- 110
MailCarrier 2.51 – POP3 ‘USER’ Buffer Overflow
#!/usr/bin/python
MailCarrier 2.51 – POP3 ‘LIST’ SEH Buffer Overflow
#!/usr/bin/python
MailCarrier 2.51 – POP3 ‘TOP’ SEH Buffer Overflow
#!/usr/bin/python
UltraVNC Viewer 1.2.2.4 – ‘VNC Server’ Denial of Service (PoC)
#Exploit Title: UltraVNC Viewer 1.2.2.4 - Denial of Service (PoC)
UltraVNC Launcher 1.2.2.4 – ‘Path’ Denial of Service (PoC)
#Exploit Title: UltraVNC Launcher 1.2.2.4 - Denial of Service (PoC)
CyberArk EPM 10.2.1.603 – Security Restrictions Bypass
# Exploit Title: CyberArk Endpoint bypass
Microsoft Internet Explorer 11 – XML External Entity Injection
[+] Credits: John Page (aka hyp3rlinx)
FTPShell Server 6.83 – ‘Account name to ban’ Local Buffer
#!/usr/bin/python
FTPShell Server 6.83 – ‘Virtual Path Mapping’ Local Buffer
#!/usr/bin/python
D-Link DI-524 V2.06RU – Multiple Cross-Site Scripting
# Exploit Title: Multiple Stored and Reflected XSS vulnerabilities in D-Link DI-524
TP-LINK TL-WR940N / TL-WR941ND – Buffer Overflow
#Author Grzegorz Wypych - h0rac
Ashop Shopping Cart Software – ‘bannedcustomers.php?blacklistitemid’ SQL Injection
# Exploit Title: Ashop Shopping Cart Software - SQL Injection
Apache Axis 1.4 – Remote Code Execution
#+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++#
Microsoft Windows – AppX Deployment Service Privilege Escalation
This vulnerability allows low privileged users to hijack file that are owned by NT AUTHORITY\SYSTEM by overwriting pe...
Jobgator – ‘experience’ SQL Injection
# Exploit Title: NCrypted Jobgator - SQL Injection
FlexHEX 2.71 – SEH Buffer Overflow (Unicode)
#!/usr/bin/python -w
ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilities
# Exploit Title: Shoretel Connect Multiple Vulnerability
SaLICru -SLC-20-cube3(5) – HTML Injection
# Exploit Title: Reflected HTML Injection
AllPlayer 7.4 – SEH Buffer Overflow (Unicode)
#!/usr/bin/python -w
CentOS Web Panel 0.9.8.793 (Free) / 0.9.8.753 (Pro) – Cross-Site Scripting
# Exploit Title: CentOS Web Panel v0.9.8.793 (Free) and v0.9.8.753 (Pro) - Email Field Stored Cross-Site Scripting Vu...
River Past Cam Do 3.7.6 – ‘Activation Code’ Local Buffer Overflow
#!/usr/bin/python -w
Tradebox CryptoCurrency – ‘symbol’ SQL Injection
# Title: Tradebox - CryptoCurrency Buy Sell and Trading
WordPress Plugin Limit Login Attempts Reloaded 2.7.4 – Login Limit Bypass
#!/usr/bin/env node
Download Accelerator Plus (DAP) 10.0.6.0 – SEH Buffer Overflow
#!/usr/bin/python #
ManageEngine ServiceDesk Plus 9.3 – User Enumeration
# Exploit Title: ManageEngine ServiceDesk Plus - 9.3 User enumeration vulnerability
Manage Engine ServiceDesk Plus 10.0 – Privilege Escalation
#!/usr/bin/python
AIDA64 Extreme 5.99.4900 – ‘Logging’ SEH Buffer Overflow
#!/usr/bin/python #
WordPress Plugin Contact Form Maker 1.13.1 – Cross-Site Request Forgery
# Exploit Title: Contact Form by WD [CSRF → LFI]
Magic ISO Maker 5.5(build 281) – ‘Serial Code’ Denial of Service (PoC)
# -*- coding: utf-8 -*-
AIDA64 Engineer 5.99.4900 – ‘Load from file’ Field Buffer Overflow (SEH)
#!/usr/bin/python
FreeSMS 2.1.2 – SQL Injection (Authentication Bypass)
# Exploit Title: FreeSMS 2.1.2 - Authentication Bypass
AIDA64 Business 5.99.4900 – SEH Buffer Overflow (EggHunter)
#!/usr/bin/python #
iScripts ReserveLogic – SQL Injection
# Exploit Title: iScripts ReserveLogic - SQL Injection
Clinic Pro v4 – ‘month’ SQL Injection
# Title: Clinic Pro - Clinic Management Software
Ashop Shopping Cart Software – SQL Injection
# Exploit Title: Ashop Shopping Cart Software - SQL Injection
PhreeBooks ERP 5.2.3 – Arbitrary File Upload
PhreeBooks ERP v5.2.3 - Arbitrary File Upload
PhreeBooks ERP 5.2.3 – Remote Command Execution (1)
# Exploit Title: PhreeBooks ERP 5.2.3 - Remote Command Execution
SpiderMonkey – IonMonkey Compiled Code Fails to Update Inferred Property Types (Type Confusion)
A bug in IonMonkey leaves type inference information inconsistent, which in turn allows the compilation of JITed func...