Nikto 2.1.6 – CSV Injection
# Exploit Title: Nikto 2.1.6 - CSV Injection
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Nikto 2.1.6 - CSV Injection
# Exploit Title: Pale Moon Browser < 27.9.3 - Use After Free (PoC)
# Exploit Title: Joomla!Component jomres 9.11.2 - Cross site request forgery
# Exploit Title: RabbitMQ Web Management < 3.7.6 - Cross-Site Request Forgery
# Exploit Title: Audiograbber 1.83 - Local Buffer Overflow (SEH)
# Exploit Title: Redis-cli < 5.0 - Buffer Overflow (PoC)
# Exploit Title: Redatam Web Server < 7 - Directory Traversal
Writeup: https://codewhitesec.blogspot.com/2018/06/cve-2018-0624.html
# Title: OEcms 3.1 - Cross-Site Scripting
# Exploit Title: Soroush IM Desktop app 0.15 - Authentication Bypass
# Title: Dimofinf CMS 3.0.0 - Cross-Site Scripting
# Title: SQL Injection Joomla Component Ek rishta 2.10 - SQL Injection
# Exploit Title: rtorrent 0.9.6 - Denial of Service
# Exploit Title: MACCMS_V10 CSRF vulnerability add admin account
Windows: Child Process Restriction Mitigation Bypass
# Exploit Title: Redaxo CMS Mediapool Addon < 5.5.1 - Arbitrary File Upload
# Title: RSLinx Classic and FactoryTalk Linx Gateway - Privilege Escalation
# Exploit Title: Joomla! Component EkRishta 2.10 - 'username' SQL Injection
Product: OX App Suite
# Title: Canon PrintMe EFI - Cross-Site Scripting
# Title: WordPress Google Map Plugin < 4.0.4 - SQL Injection
# Title: WordPress Ultimate Form Builder Lite Plugin < 1.3.7 - SQL Injection
# Exploit Title: Schools Alert Management Script - SQL Injection
# Title: WordPress Plugin Pie Register < 3.0.9 - Blind SQL Injection
# Exploit Title: Event Manager PHP Script Admin panel - 'events_new.php' SQL injection
# Exploit Title: Schools Alert Management Script - Arbitrary File Deletion
# Exploit Title: userSpice 4.3.24 - 'X-Forwarded-For' Cross-Site Scripting
# Exploit Title: userSpice 4.3.24 - Username Enumeration
# Exploit Title: Schools Alert Management Script - 'get_sec.php' SQL Injection
# Exploit Title: Schools Alert Management Script - Arbitrary File Read
## Siaberry's Command Injection Vulnerability
# Title: Gnome Web/Epiphany Browser < 3.28.2.1 - DoS App Crash (PoC)
[+] Credits: John Page (aka hyp3rlinx)
When v8 decodes the locals of a function, it performs a check:
There is a missing check in VP9 frame processing that could lead to memory corruption.
There is a missing check in VP9 frame processing that could lead to memory corruption.
# Exploit Title: XiongMai uc-httpd 1.0.0 - Buffer Overflow
# Exploit Title: Splunk < 7.0.1 - Information Disclosure
# Exploit Title: WampServer 3.0.6 - Cross-Site Request Forgery
# Exploit Title: Ftp Server 1.32 - Credential Disclosure
# Title: WordPress Form Maker Plugin 1.12.24 - SQL Injection
# Title: WordPress Contact Form Maker Plugin 1.12.20 - SQL Injection
# Title: Monstra CMS < 3.0.4 - Cross-Site Scripting