Seagate Personal Cloud SRN21C 4.3.16.0 / 4.3.18.0 – SQL Injection
------------------------------------------------------------------------
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
------------------------------------------------------------------------
The following vulnerabilities were fixed in the version 9.13.4.
CVE-2018-15685 - Electron WebPreferences Remote Code Execution
# Exploit Title: WordPress Plugin Gift Voucher 1.0.5 - 'template_id' SQL Injection
# Exploit Title: ManageEngine ADManager Plus 6.5.7 - Cross-Site Scripting
#!/usr/bin/env python3
# Exploit Title: UltimatePOS 2.5 - Remote Code Execution
# Exploit Title: ManageEngine ADManager Plus 6.5.7 - HTML Injection
#!/usr/bin/python
# Exploit Title: SkypeApp 12.8.487.0 - 'Cuenta de Skype o Microsoft' Denial of Service (PoC)
# Title: Vox TG790 ADSL Router - Cross-Site Request Forgery (Add Admin)
# Exploit Title : CuteFTP 8.3.1 - Denial Of Service (PoC)
# Exploit Title: Twitter-Clone 1 - 'code' SQL Injection
# Exploit Title: PCViewer vt1000 - Directory Traversal
# Exploit Title: Epiphany Web Browser 3.28.1 - Denial of Service (PoC)
# Exploit Title: StyleWriter 4 1.0 - Denial of Service (PoC)
# Exploit Title: Project64 2.3.2 - Local BufferOverflow (SEH)
# Exploit Title: ZyXEL VMG3312-B10B - Cross-Site Scripting
# Exploit Title: KingMedia 4.1 - Remote Code Execution
# Exploit Title: Textpad 7.6.4 - Denial Of Service (PoC)
# Exploit Title : UltraISO 9.7.1.3519 - Denial Of Service (PoC)
# Exploit Title: Geutebrueck re_porter 7.8.974.20 - Credential Disclosure
# Exploit Title: Easyboot 6.6.0 - Denial Of Service (PoC)
# Exploit Title: Geutebrueck re_porter 16 - Cross-Site Scripting
http://seclists.org/oss-sec/2018/q3/142
# Exploit Title: Softdisk 3.0.3 - Denial Of Service (PoC)
# Exploit Title: Project64 2.3.2 - Denial Of Service (PoC).
# Exploit Title: Twitter-Clone 1 - 'userid' SQL Injection
# Exploit title: Hikvision IP Camera 5.4.0 - User Enumeration (Metasploit)
# Exploit Title: Twitter-Clone 1 - Cross-Site Request Forgery (Delete Post)
# Exploit: OpenSSH 7.7 - Username Enumeration
# Exploit Title: Wordpress Plugin Ninja Forms 3.3.13 - CSV Injection
# Title: SEIG Modbus 3.4 - Denial of Service (PoC)
# Title: SEIG Modbus 3.4 - Remote Code Execution
# Exploit Title: WordPress Plugin Chained Quiz 1.0.8 - 'answer' SQL Injection
# Exploit Title: Zortam MP3 Media Studio 23.95 - Denial of Service (PoC)
# Exploit Title: Restorator 1793 - Denial of Service (PoC)
# Exploit Title: MyBB Moderator Log Notes Plugin 1.1 - Cross-Site Request Forgery
# Exploit Title: WordPress Plugin Tagregator 0.6 - Cross-Site Scripting
# Exploit Title: Prime95 29.4b7 - Denial Of Service (PoC)
############################################################################
# Title: SEIG SCADA SYSTEM 9 - Remote Code Execution
# Title: Mikrotik WinBox 6.42 - Credential Disclosure ( golang edition )
# Exploit Title: CEWE Photoshow 6.3.4 - Denial of Service (PoC)
# Title: Asustor ADM 3.1.2RHG1 - Remote Code Execution
If the Intl object hasn't been initialized, access to any property of it will trigger the initialization process whic...