SCP Client – Multiple Vulnerabilities (SSHtranger Things)
# Exploit Title: SSHtranger Things
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: SSHtranger Things
# Exploit Title: Watchr 1.1.0.0 - Denial of Service (PoC)
# Exploit Title: One Search 1.1.0.0 - Denial of Service (PoC)
# Exploit Title: Eco Search 1.0.2.0 - Denial of Service (PoC)
# Exploit Title: 7 Tik 1.0.1.0 - Denial of Service (PoC)
# Exploit Title: VPN Browser+ 1.1.0.0 - Denial of Service (PoC)
# Exploit Title: FastTube 1.0.1.0 - Denial of Service (PoC)
# Exploit Title: [Joomla Global Configuration Text Filter settings Stored XSS Vulnerability]
In Chakra, if you add a numeric property to an object having inlined properties, it will start transition to a new ty...
NewScObjectNoCtor and InitProto opcodes are treated as having no side effects, but actually they can have via the Set...
Issue description
The JsBuiltInEngineInterfaceExtensionObject::InjectJsBuiltInLibraryCode method is used to execute JsBuiltIn.js which ...
# Exploit Title: Unauthenticated Arbitrary File Upload Vulnerability In Pydio/AjaXplorer 5.0.3 – 3.3.5
# Exploit Title: [Cross-site Scripting (XSS)]
[+] Credits: John Page (aka hyp3rlinx)
# Exploit Title: Check Point ZoneAlarm Local Privilege Escalation
# Exploit Title: Spotify 1.0.96.181 - "Proxy configuration" Denial of Service (PoC)
#/usr/bin/python3
# Exploit Title: Roxy Fileman 1.4.5 - Arbitrary File Download
# Exploit Title: doorGets CMS 7.0 - Arbitrary File Download
# Exploit Title: ShoreTel / Mitel Connect ONSITE ST14.2 Remote Code Execution
#!/usr/bin/env python
#!/usr/bin/env python
#!/usr/bin/env python
#!/usr/bin/env python
# Exploit Title: GL-AR300M-Lite Authenticated Command injection - Arbitrary file download - Directory Traversal
# Exploit Title: Exploit for Blueimp's jQuery File Upload
The doesGC function simply takes a node, and tells if it might cause a garbage collection. This function is used to d...
Windows: RestrictedErrorInfo Unmarshal Section Handle UAF EoP
Windows: XmlDocument Insecure Sharing Elevation of Privilege
############
[+] Credits: John Page (aka hyp3rlinx)
# Exploit Title: ownDMS 4.7 - SQL Injection
#Exploit Title: Across DR-810 ROM-0 Backup - File Disclosure(Sensitive Information)
# Exploit Title: i-doit CMDB 1.12 - Arbitrary File Download
# Exploit Title: i-doit CMDB 1.12 - SQL Injection
# Exploit Title: Horde Imp Unauthenticated Remote Command Execution
# Exploit Title: Modern POS 1.3 - Arbitrary File Download
# Exploit Title: Modern POS 1.3 - SQL Injection
# Exploit Title: Fax Machine System Application 1.0 - SQL Injection
# Exploit Title: Live Call Support 1.5 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: Live Call Support 1.5 - Remote Code Execution / SQL Injection
require 'msf/core'
# Exploit Title: Craigs CMS 1.0.2 - SQL Injection
# Exploit Title: Locations CMS 1.5 - SQL Injection