Seqrite End Point Security 7.4 – Privilege Escalation
# Exploit Title: Seqrite End Point Security 7.4 - Privilege Escalation
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Seqrite End Point Security 7.4 - Privilege Escalation
# Exploit Title: Wikidforum 2.20 - 'message_id' SQL Injection
The BailOutOnInvalidatedArrayHeadSegment check uses the JavascriptArray::GetArrayForArrayOrObjectWithArray method to ...
The switch statement only handles Js::TypeIds_Array but not Js::TypeIds_NativeIntArray and Js::TypeIds_NativeFloatArr...
While documenting bug 1675, I noticed another problem with errordict in ghostscript. Full working exploit that works ...
# Title: FLIR Thermal Traffic Cameras 1.01-0bb5b27 - Information Disclosure
# Title: Imperva SecureSphere 13 - Remote Command Execution
# Exploit Title: net-snmp 5.7.3 - Unauthenticated Denial of Service (PoC)
Commit 82abbf8d2fc46d79611ab58daa7c608df14bb3ee ("bpf: do not allow root to mangle valid pointers", first in v4.15) i...
Tested on a Pixel 2 (walleye):
# Exploit Title: Chamilo LMS 1.11.8 - 'firstname' Cross-Site Scripting
# Exploit Title: FLIR Thermal Traffic Cameras 1.01-0bb5b27 - RTSP Stream Disclosure
# Exploit Title: Netis ADSL Router DL4322D RTK 2.1.1 - Cross-Site Request Forgery (Add Admin)
Core Security - Corelabs Advisory
# Title: ISPConfig < 3.1.13 - Remote Command Execution
# Exploit Title: Chamilo LMS 1.11.8 - Cross-Site Scripting
These releases fix a security flaw (CVE-2018-17456), which allowed an
# Exploit Title: virtualenv 16.0.0 - Sandbox Escape
# Exploit Title: LayerBB Forum 1.1.1 - 'search_query' SQL Injection
# Title: NICO-FTP 3.0.1.19 - Buffer Overflow (SEH)(ASLR)
# Exploit Title: Zechat 1.5 - 'uname' SQL Injection
# Exploit Title: Joomla! Component Jimtawl 2.2.7 - 'id' SQL Injection
# Exploit Title: Airties AIR5342 1.0.0.18 - Cross-Site Scripting
# Exploit Title: RICOH MP C1803 JPN Printer - Cross-Site Scripting
# Exploit Title: FTP Voyager 16.2.0 - Denial of Service (PoC)
# Exploit Title: OPAC EasyWeb Five 5.7 - 'biblio' SQL Injection
# Exploit Title: Coaster CMS 5.5.0 - Cross-Site Scripting
# Exploit Title: OPAC EasyWeb Five 5.7 - 'nome' SQL Injection
# Exploit Title: Snes9K 0.0.9z - Denial of Service (PoC)
# Exploit Title: Zahir Enterprise Plus 6 build 10b - Buffer Overflow (SEH)
# Exploit Title: H2 Database 1.4.196 - Remote Code Execution
# Exploit Title: ManageEngine AssetExplorer 6.2.0 - Cross-Site Scripting
# Exploit Title: Fork CMS 5.4.0 - Cross-Site Scripting
# Exploit Title: Hotel Booking Engine 1.0 - 'h_room_type' SQL Injection
# Exploit Title: Education Website 1.0 - 'subject' SQL Injection
# Exploit Title: Singleleg MLM Software 1.0 - 'msg_id' SQL Injection
# Exploit Title: Binary MLM Software 1.0 - 'pid' SQL Injection
# Exploit Title: Flippa Marketplace Clone 1.0 - 'date_started' SQL Injection
# Title: WUZHICMS 2.0 - Cross-Site Scripting
# Exploit Title: Billion ADSL Router 400G 20151105641 - Cross-Site Scripting
# Exploit Title: PCProtect 4.8.35 - Privilege Escalation