SG ERP 1.0 – ‘info’ SQL Injection
# Exploit Title: SG ERP 1.0 - 'info' SQL Injection
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: SG ERP 1.0 - 'info' SQL Injection
# Exploit Title: Fifa Master XLS 2.3.2 - 'usw' SQL Injection
# Exploit Title: Axioscloud Sissiweb Registro Elettronico 7.0.0 - 'Error_desc' Cross-Site Scripting
# Exploit Title: ADULT FILTER 1.0 - Denial of Service (PoC)
# Exploit Title: exim 4.90 - Remote Code Execution
# Exploit Title: LANGO Codeigniter Multilingual Script 1.0 - Cross-Site Scripting
# Exploit Title: Apache OFBiz 16.11.04 - XML External Entity Injection
# Exploit Title: Appsource School Management System 1.0 - 'student_id' SQL Injection
# Exploit Title: ServersCheck Monitoring Software 14.3.3 - Denial of Service (PoC)
# Exploit Title: SIM-PKH 2.4.1 - Arbitrary File Upload
# Exploit Title: ServersCheck Monitoring Software 14.3.3 - 'id' SQL Injection
# Exploit Title: School ERP Pro+Responsive 1.0 - Arbitrary File Download
# Exploit Title: School ERP Pro+Responsive 1.0 - 'fid' SQL Injection
# Exploit Title: SIM-PKH 2.4.1 - 'id' SQL Injection
# Exploit Title: MGB OpenSource Guestbook 0.7.0.2 - 'id' SQL Injection
Bug description:
# Exploit Title: MySQL Edit Table 1.0 - 'id' SQL Injection
# Exploit Title: Modbus Poll 7.2.2 - Denial of Service (PoC)
# Exploit Title: School ERP Ultimate 2018 - Arbitrary File Download
# Exploit Title: Oracle Siebel CRM 8.1.1 - CSV Injection
# Exploit Title: AudaCity 2.3 - Denial of Service (PoC)
# Exploit Title: The Open ISES Project 3.30A - 'tick_lat' SQL Injection
# Exploit Title: School ERP Ultimate 2018 - 'fid' SQL Injection
This PoC file might look familiar; this bug is a trivial variant of CVE-2016-1744 (Apple bug id 635599405.)
io_hideventsystem is a MIG service which provides proxy access to various HID devices for untrusted
Here's a code snippet from sleh.c with the second level exception handler for undefined instruction exceptions:
io_hideventsystem sets up a shared memory event queue; at the end of this shared memory buffer it puts
IOHIDResourceQueue inherits from IOSharedDataQueue and adds its own ::enqueueReport method,
There was recently some cleanup in the persona code to fix some race conditions there, I don't think it was sufficient:
# Exploit Title: eNdonesia Portal 8.7 - 'artid' SQL Injection
# Exploit Title: The Open ISES Project 3.30A - Arbitrary File Download
# Exploit Title: Viva Visitor & Volunteer ID Tracking 0.95.1 - 'fname' SQL Injection
#!/usr/bin/env python
keybase-redirector is a setuid root binary. keybase-redirector calls the fusermount binary using a relative path and ...
#!/usr/bin/env python3
# Exploit Title: Learning with Texts 1.6.2 - 'start' SQL Injection
# Exploit Title: PHP-SHOP master 1.0 - Cross-Site Request Forgery (Add admin)
# Exploit Title: OwnTicket 1.0 - 'TicketID' SQL Injection
#!/usr/bin/env python3
# Exploit Title: Any Sound Recorder 2.93 - Buffer Overflow (SEH)
# Exploit Title: BigTree CMS 4.2.23 - Cross-Site Scripting
# Exploit Title: FLIR AX8 Thermal Camera 1.32.16 - Hard-Coded Credentials
# Exploit Title: Time and Expense Management System 3.0 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: TP-Link TL-SC3130 1.6.18 - RTSP Stream Disclosure
# Exploit Title: Time and Expense Management System 3.0 - 'table' SQL Injection
# Exploit Title: HotelDruid 2.2.4 - 'anno' SQL Injection
# Exploit Title: Navigate CMS 2.8.5 - Arbitrary File Download
# Exploit Title: Library CMS 2.1.1 - Cross-Site Scripting
# Exploit Title: Kados R10 GreenBee - 'release_id' SQL Injection