Microsoft Windows – DSSVC CheckFilePermission Arbitrary File Deletion
Windows: DSSVC CheckFilePermission Arbitrary File Delete EoP
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
Windows: DSSVC CheckFilePermission Arbitrary File Delete EoP
When a (non-root) user attempts to e.g. control systemd units in the system
XML External Entity Injection Vulnerability in BlogEngine 3.3
#!/usr/bin/env python
# Title: Dolibarr ERP-CRM 8.0.4 - 'rowid' SQL Injection
The following crash due to a heap-based out-of-bounds memory read can be observed in an ASAN build of Wireshark, by f...
# Exploit Title: Embed Video Scripts - Cross-site Script (stored)
# Exploit Title: All in One Video Downloader 1.2 - SQL Injection
# Exploit Title: LayerBB 1.1.1 - Cross-Site Scripting
# Exploit Title: MyBB OUGC Awards Plugin v1.8.3 - Cross-Site Scripting
# Exploit Title: PLC Wireless Router GPN2.4P21-C-CN -Reflected XSS
#####################################################################################################################...
# Exploit Title: Wordpress Plugin UserPro < 4.9.21 User Registration With Administrator Role
# Exploit Title: MyT-PM 1.5.1 - 'Charge[group_total]' SQL Injection
======================================================================
# Exploit Title: Ajera Timesheets
# Exploit Title: BlueAuditor 1.7.2.0 - 'Key' Denial of Service (PoC)
# Exploit Title: SpotFTP Password Recover 2.4.2 - 'Name' Denial of Service (PoC)
# Exploit Title: Foscam Video Management System 1.1.4.9 - 'Username' Denial of Service (PoC)
# Exploit Title: Huawei E5330 Cross-Site Request Forgery (Send SMS)
# Exploit Title : KioWare Server Version 4.9.6 - Weak Folder Permissions Privilege Escalation
# Exploit Title: NBMonitor Network Bandwidth Monitor 1.6.5.0 - 'Name' Denial of Service (PoC)
# Exploit Title: Vtiger CRM 7.1.0 - Remote Code Execution
# Exploit Title: WordPress Plugin Adicon Server 1.2 - 'selectedPlace' SQL Injection
# Exploit Title: Frog CMS 0.9.5 - Cross-Site Scripting
# Exploit Title: EZ CD Audio Converter 8.0.7 - Denial of Service (PoC)
# Exploit Title: NetworkSleuth 3.0.0.0 - 'Key' Denial of Service (PoC)
# Exploit Title: Ayukov NFTP FTP Client 2.0 - Buffer Overflow
// ./jsc --useConcurrentJIT=false ~/test.js
bool JSArray::shiftCountWithArrayStorage(VM& vm, unsigned startIndex, unsigned count, ArrayStorage* storage)
Make sure to copy the file report.wer found in the folder PoC-Files in the same folder as the executable before runni...
// A proof-of-concept local root exploit for CVE-2017-7308.
// A proof-of-concept local root exploit for CVE-2017-1000112.
# Exploit Title: Craft CMS 3.0.25 - Cross-Site Scripting
# Exploit Title: WordPress Plugin Audio Record 1.0 - Arbitrary File Upload
# Exploit Title: MAGIX Music Editor 3.1 - Buffer Overflow (SEH)
# Exploit Title: Product Key Explorer 4.0.9 - Denial of Service (PoC)
# Exploit Title: Terminal Services Manager 3.1 - Buffer Overflow (SEH)
# Exploit Title: Iperius Backup 5.8.1 - Buffer Overflow (SEH)