SoftX FTP Client 3.3 – Denial of Service (PoC)
# Exploit Title: SoftX FTP Client 3.3 - Denial of Service (PoC)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: SoftX FTP Client 3.3 - Denial of Service (PoC)
# Exploit Title: Joomla! Component Auction Factory 4.5.5 - 'filter_order' SQL Injection
# Exploit Title: Beyond Remote 2.2.5.3 - Denial of Service (PoC)
# Exploit Title: RICOH MP C6003 Printer - Cross-Site Scripting
There is a use-after-free in VP9 processing in WebRTC. In the method RtpFrameReferenceFinder::ManageFrameVp9 the foll...
There is an out-of-bounds read in FEC processing in WebRTC. If a very short RTP packet is received, FEC will assume t...
# Exploit Title: Collectric CMU 1.0 - 'lang' SQL injection
# Exploit Title: NICO-FTP 3.0.1.19 - Buffer Overflow (SEH)
Windows: CiSetFileCache TOCTOU CVE-2017-11830 Variant WDAC Security Feature Bypass
Windows: Double Dereference in NtEnumerateKey Elevation of Privilege
# Exploit Title: Roundcube rcfilters plugin 2.1.6 - Cross-Site Scripting
# Exploit Title: WordPress Plugin Wechat Broadcast 1.2.0 - Local File Inclusion
# Exploit Title: WordPress Plugin Localize My Post 1.0 - Local File Inclusion
# Exploit Title: LG SuperSign EZ CMS 2.5 - Local File Inclusion
# Exploit Title: NUUO NVRMini2 3.8 - 'cgi_system' Buffer Overflow (Enable Telnet)
# Exploit Title: Ubisoft Uplay Desktop Client 63.0.5699.0 - Remote Code Execution
Here's a snippet of PathTypeHandlerBase::SetAttributesHelper.
A call to the String.prototype.localeCompare method can be inlineed when it only takes one argument. There are two ve...
Title: Blind SQL injection and multiple reflected XSS vulnerabilities in Wordpress Plugin Arigato Autoresponder and N...
# Exploit Title: XAMPP Control Panel 3.2.2 - Denial of Service (PoC)
# Exploit Title : Notebook Pro 2.0 - Denial Of Service (PoC)
# Exploit Title: Oracle VirtualBox Manager 5.2.18 r124319 - 'Name Attribute' Denial of Service (PoC)
# Exploit Title: Netis ADSL Router DL4322D RTK 2.1.1 - Cross-Site Scripting
# Title: Joomla Component JCK Editor 6.4.4 - 'parent' SQL Injection
# Exploit Title: Netis ADSL Router DL4322D RTK 2.1.1 - Denial of Service (PoC)
# Exploit Title: CA Release Automation NiMi 6.5 - Remote Command Execution
3y3t3m th!s - Ivan Ivanovic Ivanov Иван-дурак
# Exploit Title: CdBurnerXP 4.5.8.6795 - 'File Name' Denial of Service (PoC)
# Exploit Title: Wordpress Plugin Survey & Poll 1.5.7.3 - 'sss_params' SQL Injection
# Exploit Title: Free MP3 CD Ripper 2.6 - '.wma' Buffer Overflow (SEH)
# Exploit Title: InfraRecorder 0.53 - '.txt' Denial of Service (PoC)
# Exploit Title: Faleemi Plus 1.0.2 - Denial of Service (PoC)
# Exploit Title: InduSoft Web Studio 8.1 SP1 - 'Tag Name' Buffer Overflow (SEH)
# Exploit Title: Apache Portals Pluto 3.0.0 - Remote Code Execution
# Exploit Title: Clone2Go Video to iPod Converter 2.5.0 - Denial of Service (PoC)
# Exploit Title: MediaTek Wirless Utility rt2870 - Denial of Service (PoC)
# Exploit Title: Apache Syncope 2.0.7 - Remote Code Execution
# Exploit Title: STOPzilla AntiMalware 6.5.2.59 - Privilege Escalation
# Exploit Title: Faleemi Desktop Software 1.8.2 - 'SavePath for ScreenShots' Buffer Overflow (SEH)
# Exploit Title: Free MP3 CD Ripper 2.6 - '.mp3' Buffer Overflow (SEH)
# Exploit Title: TeamViewer App 13.0.100.0 - Denial of Service (PoC)
There is a missing address check in both show_opcodes() callers.
# Exploit Title: Socusoft Photo to Video Converter 8.07 - 'Registration Name' Buffer Overflow
======================= BUG DESCRIPTION =======================
# Exploit Title: jiNa OCR Image to Text 1.0 - Denial of Service (PoC)
# Exploit Title: PixGPS 1.1.8 - Denial of Service (PoC)
# Exploit Title: RoboImport 1.2.0.72 - Denial of Service (PoC)
# Exploit Title: PicaJet FX 2.6.5 - Denial of Service (PoC)