Exploits
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
- 类型
- 漏洞条目
- 总量
- 24,950
- 页码
- 137
Microsoft Edge Chakra JIT – ‘InlineArrayPush’ Type Confusion
This is similar to issue 1531 . The patch seems to prevent type confusion triggered from StElemI_A instructions. But...
Microsoft Edge Chakra JIT – InitializeNumberFormat and InitializeDateTimeFormat Type Confusion
The InitializeNumberFormat function in Intl.js is used to initialize an Intl.NumberFormat object, and InitializeDateT...
OpenEMR 5.0.1.3 – (Authenticated) Arbitrary File Actions
# Exploit Title: OpenEMR 5.0.1.3 - Arbitrary File Actions
TP-Link WR840N 0.9.1 3.16 – Denial of Service (PoC)
# Exploit Title: TP-Link WR840N 0.9.1 3.16 - Denial of Service (PoC)
ObserverIP Scan Tool 1.4.0.1 – Denial of Service (PoC)
# Exploit Title: ObserverIP Scan Tool 1.4.0.1 - Denial of Service (PoC)
WebkitGTK+ 2.20.3 – ‘ImageBufferCairo::getImageData()’ Buffer Overflow (PoC)
# Exploit Title: WebkitGTK+ 2.20.3 - 'ImageBufferCairo::getImageData()' Buffer Overflow (PoC)
WordPress Plugin Export Users to CSV 1.1.1 – CSV Injection
# Exploit Title: Wordpress Plugin Export Users to CSV 1.1.1 - CSV Injection
Central Management Software 1.4.13 – Denial of Service (PoC)
# Exploit Title: Central Management Software v1.4.13 - Denial of Service (PoC)
Pimcore 5.2.3 – SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
SEC Consult Vulnerability Lab Security Advisory < 20180813-0 >
OpenSSH 2.3 < 7.7 - Username Enumeration (PoC)
#!/usr/bin/env python
JioFi 4G M2S 1.0.2 – Denial of Service (PoC)
# Exploit Title: JioFi 4G M2S 1.0.2 - Denial of Service (PoC)
ASUSTOR ADM 3.1.0.RFQ3 – Remote Command Execution / SQL Injection
Product - ASUSTOR ADM - 3.1.0.RFQ3 and all previous builds
ASUS-DSL N10 1.1.2.2_17 – Authentication Bypass
# Title: ASUS-DSL N10 1.1.2.2_17 - Authentication Bypass
Wansview 1.0.2 – Denial of Service (PoC)
# Exploit Title: Wansview 1.0.2 - Denial of Service (PoC)
cgit 1.2.1 – Directory Traversal (Metasploit)
# Title: cgit 1.2.1 - Directory Traversal (Metasploit)
Cloudme 1.9 – Buffer Overflow (DEP) (Metasploit)
# Exploit Title: Cloudme 1.9 - Buffer Overflow (DEP) (Metasploit)
Oracle Glassfish OSE 4.1 – Path Traversal (Metasploit)
# Exploit title: Oracle Glassfish OSE 4.1 - Path Traversal (Metasploit)
Microsoft DirectX SDK – ‘Xact.exe’ Remote Code Execution
[+] Credits: John Page (aka hyp3rlinx)
Monitoring software iSmartViewPro 1.5 – ‘SavePath for ScreenShots’ Buffer Overflow
# Exploit Title: iSmartViewPro 1.5 - 'SavePath for ScreenShots' Local Buffer Overflow
IP Finder 1.5 – Denial of Service (PoC)
# Exploit Title: IP Finder 1.5 - Denial of Service (PoC)
PostgreSQL 9.4-0.5.3 – Privilege Escalation
# Exploit Title: PostgreSQL 9.4-0.5.3 - Privilege Escalation
Acunetix WVS 10.0 Build 20150623 – Denial of Service (PoC)
# Exploit Title : Acunetix Web Vulnerability Scanner 10.0 Build 20150623 - Denial of Service (PoC)
PLC Wireless Router GPN2.4P21-C-CN – Denial of Service
# Exploit Title: PLC Wireless Router GPN2.4P21-C-CN Unauthenticated Remote Reboot
IBM Sterling B2B Integrator 5.2.0.1/5.2.6.3 – Cross-Site Scripting
# Exploit Title: [IBM Sterling B2B Integrator persistent cross-site scripting]
Switch Port Mapping Tool 2.81.2 – ‘Name Field’ Denial of Service (PoC)
# Exploit Title: Switch Port Mapping Tool 2.81.2 - 'Name Field' Denial of Service (PoC)
Android – Directory Traversal over USB via Injection in blkid Output
When a USB mass storage device is inserted into an Android phone (even if the
iSmartViewPro 1.5 – ‘Password’ Buffer Overflow
# Exploit Title: iSmartViewPro 1.5 - 'Password' Buffer Overflow
Zimbra 8.6.0_GA_1153 – Cross-Site Scripting
# Exploit Title: Xss Zimbra Mail server
MyBB Thank You/Like Plugin 3.0.0 – Cross-Site Scripting
# Exploit Title: MyBB Thank You/Like Plugin 3.0.0 - Cross-Site Scripting
MyBB Like Plugin 3.0.0 – Cross-Site Scripting
# Exploit Title: MyBB Like Plugin 3.0.0 - Cross-Site Scripting
Mikrotik WinBox 6.42 – Credential Disclosure (Metasploit)
# Exploit Title: Mikrotik WinBox 6.42 - Credential Disclosure (Metasploit)
Soroush IM Desktop App 0.17.0 – Authentication Bypass
# Exploit Title: Soroush IM Desktop App 0.17.0 - Authentication Bypass
TP-Link C50 Wireless Router 3 – Cross-Site Request Forgery (Remote Reboot)
# Exploit Title: TP-Link C50 Wireless Router 3 - Cross-Site Request Forgery (Remote Reboot)
TP-Link C50 Wireless Router 3 – Cross-Site Request Forgery (Information Disclosure)
# Exploit Title: TP-Link C50 Wireless Router 3 - Cross-Site Request Forgery (Information Disclosure)
Linux Kernel 4.14.7 (Ubuntu 16.04 / CentOS 7) – (KASLR & SMEP Bypass) Arbitrary File Read
// A proof-of-concept exploit for CVE-2017-18344.
iSmartViewPro 1.5 – ‘Device Alias’ Buffer Overflow
# Exploit Title: iSmartViewPro 1.5 - 'Device Alias' Buffer Overflow
iSmartViewPro 1.5 – ‘Account’ Buffer Overflow
# Exploit Title: iSmartViewPro 1.5 - 'Account' Buffer Overflow
LG-Ericsson iPECS NMS 30M – Directory Traversal
# Exploit Title: LG-Ericsson iPECS NMS 30M - Directory Traversal
TP-Link Wireless N Router WR840N – Denial of Service (PoC)
# Exploit Title:- TP-Link Wireless N Router WR840N - Denial of Service (PoC)
osTicket 1.10.1 – Arbitrary File Upload
# Exploit Title: osTicket 1.10.1 - Arbitrary File Upload
OpenEMR 5.0.1.3 – Remote Code Execution (Authenticated)
# Title: OpenEMR 5.0.1.3 - Remote Code Execution (Authenticated)
QNap QVR Client 5.0.3.23100 – Denial of Service (PoC)
# Exploit Title : QNap QVR Client 5.0.3.23100 - Denial of Service (PoC)
Monstra-Dev 3.0.4 – Cross-Site Request Forgery (Account Hijacking)
# Exploit Title: Monstra-Dev 3.0.4 - Cross-Site Request Forgery(Account Hijacking)
Subrion CMS 4.2.1 – Cross-Site Scripting
# Exploit Title: [Subrion CMS- 4.2.1 XSS (Using component with known