Exploits
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
- 类型
- 漏洞条目
- 总量
- 24,950
- 页码
- 113
Pegasus CMS 1.0 – ‘extra_fields.php’ Plugin Remote Code Execution
# Exploit Title: Pegasus extra_fields.php Plugin Remote Code Execution
FTPGetter Standard 5.97.0.177 – Remote Code Execution
# Exploit Title: FTPGetter Standard - v.5.97.0.177 Remote Code Execution
Microsoft Windows – ‘.reg’ File / Dialog Box Message Spoofing
[+] Credits: John Page (aka hyp3rlinx)
Core FTP Server FTP / SFTP Server v2 Build 674 – ‘MDTM’ Directory Traversal
# Exploit Title: CoreFTP Server FTP / SFTP Server v2 - Build 674 MDTM Directory Traversal
Core FTP Server FTP / SFTP Server v2 Build 674 – ‘SIZE’ Directory Traversal
# Exploit Title: CoreFTP Server FTP / SFTP Server v2 - Build 674 SIZE Directory Traversal
Microsoft Windows MSHTML Engine – ‘Edit’ Remote Code Execution
# Exploit Title: Microsoft Windows (CVE-2019-0541) MSHTML Engine "Edit" Remote Code Execution Vulnerability
WordPress Plugin GraceMedia Media Player 1.0 – Local File Inclusion
=============================================
pfSense 2.4.4-p1 (HAProxy Package 0.59_14) – Persistent Cross-Site Scripting
# Exploit Title: pfSense 2.4.4-p1 (HAProxy Package 0.59_14) - Stored Cross-Site Scripting
Apache Tika-server < 1.18 - Command Injection
######################################################################################################
PilusCart 1.4.1 – Cross-Site Request Forgery (Add Admin)
# Exploit Title: PilusCart 1.4.1 - Cross-Site Request Forgery (Add Admin)
Core FTP 2.0 build 653 – ‘PBSZ’ Denial of Service (PoC)
# Exploit Title: Core FTP 2.0 build 653 - 'PBSZ' - Unauthenticated - Denial of Service (PoC)
Flexpaper PHP Publish Service 2.3.6 – Remote Code Execution
#!/usr/bin/env python
NetSetMan 4.7.1 – Local Buffer Overflow (SEH Unicode)
#Exploit Title: NetSetMan 4.7.1 - Local Buffer Overflow (SEH Unicode)
OrientDB 3.0.17 GA Community Edition – Cross-Site Request Forgery / Cross-Site Scripting
#####################################################################################################################...
McAfee ePO 5.9.1 – Registered Executable Local Access Bypass
# Exploit Title: McAfee ePO 5.9.1 Registered Executable Local Access Bypass
DirectAdmin 1.55 – ‘CMD_ACCOUNT_ADMIN’ Cross-Site Request Forgery
# Exploit title: DirectAdmin v1.55 - CSRF via CMD_ACCOUNT_ADMIN Admin Panel
Sony Playstation 4 (PS4) < 6.20 - WebKit Code Execution (PoC)
PS4 6.20 WebKit Code Execution PoC
Kados R10 GreenBee – Multiple SQL Injection
===========================================================================================
Linux < 4.20.14 - Virtual Address 0 is Mappable via Privileged write() to /proc/*/mem
By following the codepath that Andrea Arcangeli pointed out in his mails
Android – binder Use-After-Free via racy Initialization of ->allow_user_free
The following bug report solely looks at the situation on the upstream master
Android – getpidcon() Usage in Hardware binder ServiceManager Permits ACL Bypass
We already reported four bugs in Android that are caused by the use of
OpenDocMan 1.3.4 – ‘search.php where’ SQL Injection
===========================================================================================
CMSsite 1.0 – Multiple Cross-Site Request Forgery
# Exploit Title: CMSsite 1.0 - Cross-Site Request Forgery (Delete Admin)
elFinder 2.1.47 – ‘PHP connector’ Command Injection
#!/usr/bin/python
OOP CMS BLOG 1.0 – Multiple SQL Injection
# Exploit Title: OOP CMS BLOG 1.0 - SQL Injection
OOP CMS BLOG 1.0 – Multiple Cross-Site Request Forgery
# Exploit Title: OOP CMS BLOG 1.0 - Cross-Site Request Forgery (Delete Admin)
FileZilla 3.40.0 – ‘Local search’ / ‘Local site’ Denial of Service (PoC)
# Exploit Title: FileZilla 3.40.0 - "Local search" Denial of Service (PoC)
zzzphp CMS 1.6.1 – Cross-Site Request Forgery
# Exploit Title: Cross-Site Request Forgery(CSRF) of zzzphp cms 1.6.1
Raisecom XPON ISCOMHT803G-U_2.0.0_140521_R4.1.47.002 – Remote Code Execution
# Exploit Title: Remote code execution in Raisecom xpon
MarcomCentral FusionPro VDP Creator < 10.0 - Directory Traversal
#!/usr/bin/env python
Bolt CMS 3.6.4 – Cross-Site Scripting
# Exploit Title: Bolt CMS - 3.6.4 - Cross-Site Scripting
Craft CMS 3.1.12 Pro – Cross-Site Scripting
# Exploit Title: Craft CMS 3.1.12 Pro - Cross-Site Scripting
WordPress Plugin Cerber Security, Antispam & Malware Scan 8.0 – Multiple Bypass Vulnerabilities
# Exploit Title: WordPress Cerber Security, Antispam & Malware Scan - Multiple Bypass Vulnerabilities
Fiberhome AN5506-04-F RP2669 – Persistent Cross-Site Scripting
# Exploit Title: Fiberhome AN5506-04-F - Stored Cross Site Scripting
Google Chrome < M72 - PaymentRequest Service Use-After-Free
There are several object-lifetime issues in the browser process in the