Exploits

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers

共24745Exploits
日期 标题 类型 平台 作者
2018-11-16

DomainMOD 4.11.01 – ‘raid’ Cross-Site Scripting

  • webapps
  • php
  • Dawood Ansar
    2018-11-16

    Helpdezk 1.1.1 – Arbitrary File Upload

  • webapps
  • php
  • Ihsan Sencan
    2018-11-16

    Warranty Tracking System 11.06.3 – ‘txtCustomerCode’ SQL Injection

  • webapps
  • php
  • Ihsan Sencan
    2018-11-15

    Precurio Intranet Portal 2.0 – Cross-Site Request Forgery (Add Admin)

  • webapps
  • php
  • Ihsan Sencan
    2018-11-15

    WordPress Plugin Ninja Forms 3.3.17 – Cross-Site Scripting

  • webapps
  • php
  • MTK
    2018-11-15

    PHP Mass Mail 1.0 – Arbitrary File Upload

  • webapps
  • php
  • Ihsan Sencan
    2018-11-15

    2-Plan Team 1.0.4 – Arbitrary File Upload

  • webapps
  • php
  • Ihsan Sencan
    2018-11-15

    Simple E-Document 1.31 – ‘username’ SQL Injection

  • webapps
  • php
  • Ihsan Sencan
    2018-11-15

    Kordil EDMS 2.2.60rc3 – Arbitrary File Upload

  • webapps
  • php
  • Ihsan Sencan
    2018-11-15

    Meneame English Pligg 5.8 – ‘search’ SQL Injection

  • webapps
  • php
  • Ihsan Sencan
    2018-11-15

    Notepad3 1.0.2.350 – Denial of Service (PoC)

  • dos
  • windows_x86-64
  • Ihsan Sencan
    2018-11-15

    EverSync 0.5 – Arbitrary File Download

  • webapps
  • php
  • Ihsan Sencan
    2018-11-15

    Galaxy Forces MMORPG 0.5.8 – ‘type’ SQL Injection

  • webapps
  • php
  • Ihsan Sencan
    2018-11-15

    Net-Billetterie 2.9 – ‘login’ SQL Injection

  • webapps
  • php
  • Ihsan Sencan
    2018-11-15

    BitZoom 1.0 – ‘rollno’ SQL Injection

  • webapps
  • php
  • Ihsan Sencan
    2018-11-15

    PHP-Proxy 5.1.0 – Local File Inclusion

  • webapps
  • php
  • Ameer Pornillos
    2018-11-14

    Electricks eCommerce 1.0 – Cross-Site Request Forgery (Change Admin Password)

  • webapps
  • php
  • Nawaf Alkeraithe
    2018-11-14

    Helpdezk 1.1.1 – ‘query’ SQL Injection

  • webapps
  • php
  • Ihsan Sencan
    2018-11-14

    ntpd 4.2.8p10 – Out-of-Bounds Read (PoC)

  • local
  • linux
  • Magnus Klaaborg Stubman
    2018-11-14

    iServiceOnline 1.0 – ‘r’ SQL Injection

  • webapps
  • php
  • Ihsan Sencan
    2018-11-14

    PHP 5.2.3 imap (Debian Based) – ‘imap_open’ disable_functions Bypass

  • local
  • linux
  • Anton Lopanitsyn
    2018-11-14

    Bosch Video Management System 8.0 – Configuration Client Denial of Service (PoC)

  • dos
  • windows
  • Daniel
    2018-11-14

    DoceboLMS 1.2 – SQL Injection / Arbitrary File Upload

  • webapps
  • php
  • Ihsan Sencan
    2018-11-14

    Electricks eCommerce 1.0 – Persistent Cross-Site Scripting

  • webapps
  • php
  • Nawaf Alkeraithe
    2018-11-14

    Pedidos 1.0 – SQL Injection

  • webapps
  • php
  • Ihsan Sencan
    2018-11-14

    Rmedia SMS 1.0 – SQL Injection

  • webapps
  • php
  • Ihsan Sencan
    2018-11-14

    SwitchVPN for macOS 2.1012.03 – Privilege Escalation

  • local
  • macos
  • Bernd Leitner
    2018-11-14

    Advanced Comment System 1.0 – SQL Injection

  • webapps
  • php
  • Rafael Pedrero
    2018-11-14

    Dell OpenManage Network Manager 6.2.0.51 SP3 – Multiple Vulnerabilities

  • webapps
  • linux
  • KoreLogic
    2018-11-14

    Atlassian Jira – (Authenticated) Upload Code Execution (Metasploit)

  • remote
  • java
  • Metasploit
    2018-11-14

    AMPPS 2.7 – Denial of Service (PoC)

  • dos
  • windows_x86-64
  • Ihsan Sencan
    2018-11-14

    EdTv 2 – ‘id’ SQL Injection

  • webapps
  • php
  • Ihsan Sencan
    2018-11-13

    Maitra Mail Tracking System 1.7.2 – SQL Injection / Database File Download

  • webapps
  • php
  • Ihsan Sencan
    2018-11-13

    Surreal ToDo 0.6.1.2 – SQL Injection

  • webapps
  • php
  • Ihsan Sencan
    2018-11-13

    Alive Parish 2.0.4 – SQL Injection / Arbitrary File Upload

  • webapps
  • php
  • Ihsan Sencan
    2018-11-13

    Evince 3.24.0 – Command Injection

  • dos
  • linux
  • Matlink
    2018-11-13

    ClipperCMS 1.3.3 – Cross-Site Request Forgery (File Upload)

  • webapps
  • php
  • Ameer Pornillos
    2018-11-13

    CuteFTP Mac 3.1 – Denial of Service (PoC)

  • dos
  • macos
  • Yair Rodríguez Aparicio
    2018-11-13

    Silurus Classifieds Script 2.0 – ‘wcategory’ SQL Injection

  • webapps
  • php
  • Ihsan Sencan
    2018-11-13

    CentOS Web Panel 0.9.8.740 – Cross-Site Request Forgery / Cross-Site Scripting

  • webapps
  • php
  • InfinitumIT
    2018-11-13

    Gumbo CMS 0.99 – SQL Injection

  • webapps
  • php
  • Ihsan Sencan
    2018-11-13

    ABC ERP 0.6.4 – Cross-Site Request Forgery (Update Admin)

  • webapps
  • php
  • Ihsan Sencan
    2018-11-13

    Easyndexer 1.0 – Arbitrary File Download

  • webapps
  • php
  • Ihsan Sencan
    2018-11-13

    Tina4 Stack 1.0.3 – Cross-Site Request Forgery (Update Admin)

  • webapps
  • php
  • Ihsan Sencan
    2018-11-13

    Tina4 Stack 1.0.3 – SQL Injection / Database File Download

  • webapps
  • php
  • Ihsan Sencan
    2018-11-13

    xorg-x11-server < 1.20.1 - Local Privilege Escalation

  • local
  • linux
  • bolonobolo
    2018-11-13

    Data Center Audit 2.6.2 – Cross-Site Request Forgery (Update Admin)

  • webapps
  • php
  • Ihsan Sencan
    2018-11-13

    Musicco 2.0.0 – Arbitrary Directory Download

  • webapps
  • php
  • Ihsan Sencan
    2018-11-13

    Cisco Immunet < 6.2.0 / Cisco AMP For Endpoints 6.2.0 - Denial of Service

  • dos
  • windows
  • hyp3rlinx
    2018-11-13

    SIPve 0.0.2-R19 – SQL Injection

  • webapps
  • php
  • Ihsan Sencan