Angry IP Scanner 3.5.3 – Denial of Service (PoC)
#!/usr/bin/python
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
#!/usr/bin/python
# Exploit Title: Facebook And Google Reviews System For Businesses 1.1 - SQL Injection
# Exploit Title: Facebook And Google Reviews System For Businesses 1.1 - Remote Code Execution
# Exploit Title: UltraISO 9.7.1.3519 - 'Output FileName' Denial of Service (PoC) and Pointer to next SEH and SE handl...
# Exploit Title: Double Your Bitcoin Script Automatic 2018 for $50 - Authentication Bypass
Using the userfaultfd API, it is possible to first register a
// All greets goes to RIPS Tech
When the mmap() syscall is invoked on a POSIX shared memory segment
McAfee True Key: Multiple Issues with McAfee.TrueKey.Service Implementation
# Exploit Title: Tourism Website Blog - Remote Code Execution / SQL Injection
# Exploit Title: Alumni Tracer SMS Notification - SQL Injection / Cross-Site Request Forgery (Add/Update Admin)
# -*- coding: utf-8 -*-
# Exploit Title: DomainMOD 4.11.01 - Cross-Site Scripting
# Exploit Title: LanSpy 2.0.1.159 - Local BoF (PoC)
# Exploit Author: bzyo
[+] Unauthenticated
#Product Family: LTE
[*] POC: (CVE-2018-7357 and CVE-2018-7358)
# Exploit Title: Apache OFBiz v16.11.05 - Stored Cross-Site Scripting Vulnerability
# Exploit Title: SQL Injection in HotelDruid version 2.3
# Exploit Title: WP AutoSuggest 0.24 - SQL Injection
# Exploit Title: ThinkPHP 5.x < v5.0.23,v5.1.31 Remote Code Execution
# Exploit Title: Unrestricted file upload in Adobe ColdFusion 2018
#!/usr/bin/env python3
#!/usr/bin/env python3
# Exploit Title: Textpad 8.1.2 - Denial Of Service (PoC)
# Exploit Title: i-doit CMDB 1.11.2 - Remote Code Execution
# Exploit Title: Adiscon LogAnalyzer 4.1.7 - Cross-Site Scripting
# Exploit Title: DomainMOD 4.11.01 - Cross-Site Scripting
# Exploit Title: HasanMWB 1.0 - SQL Injection
# Exploit Title: Microsoft Lync for Mac 2011 Injection Forced Browsing/Download
# Exploit Title: Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control
# Exploit Title: AIX Xorg X11 Server - Local Privilege Escalation
#!/usr/bin/env python2
# Exploit Title: DomainMOD 4.11.01 - Cross-Site Scripting
################################
# Exploit Title: Dolibarr ERP/CRM
# Exploit Title: DomainMOD 4.11.01 - Cross-Site Scripting
# Exploit Title: DomainMOD 4.11.01 - Cross-Site Scripting
# Exploit Title: NUUO NVRMini2 Authenticated Command Injection
# Exploit Title: DomainMOD 4.11.01 - Cross-Site Scripting
The following crash due to a stack-based out-of-bounds memory access can be observed in an ASAN build of Wireshark (c...
The following crash due to a heap-based out-of-bounds read can be observed in an ASAN build of Wireshark (current git...