ModbusPal 1.6b – XML External Entity Injection
[+] Exploit Title: ModbusPal XXE Injection
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
[+] Exploit Title: ModbusPal XXE Injection
# Exploit Title: MyBB Latest Posts on Profile Plugin v1.1 - Cross-Site Scripting
Title: Dell Touchpad - ApMsgFwd.exe Denial Of Service
# Exploit Title: Microsoft Windows FxCop 10/12 - XML External Entity Injection
###########################################################################################
# -*- coding: utf-8 -*-
# Exploit Title: 2345 Security Guard 3.7 - Denial of Service
# Exploit Title: CSP MySQL User Manager 2.3.1 - Authentication Bypass
# Exploit Title: DeviceLock Plug and Play Auditor 5.72 - Unicode Buffer Overflow (SEH)
#!/usr/bin/python
GNU Wget Cookie Injection [CVE-2018-0494]
There's an integer overflow in computing the required allocation size when instantiating a new javascript object.
# Exploit Title: WF Cookie Consent - Authenticated Persistent Cross-Site Scripting
Vendor: IceWarp (http://www.icewarp.com)
TIBCO’s JasperReports ( file = new File(/home/rhino/jasperreports...mcat/webapps/jasperserver,"/WEB-INF/jsp/modules/a...
#!/usr/bin/python
#!/usr/bin/python
# SSRF(Server Side Request Forgery) in Cockpit 0.4.4-0.5.5 (CVE-2018-9302)
#!/usr/bin/python
What do you need to know? Tenable Research has discovered a critical remote code execution vulnerability in Schneider...
% a PDF file using an XFA
# PoC command injection in BLE service of Norton Core Secure WiFi Router (CVE-2018-5234)
# -*- coding: utf-8 -*-
A few years ago, I became aware of a security issue in most Call of Duty games.
# Exploit Title: Wordpress Responsive Cookie Consent 1.7 / 1.6 / 1.5 - Authenticated Persistent Cross-Site Scripting
#!/usr/bin/python
# Exploit Title: Wordpress Plugin Form Maker version 1.12.20 vulnerable to to Formula Injection (CSV Injection)
# Exploit Title: Nagios XI 5.2.[6-9], 5.3, 5.4 Chained Remote Root
Here's a kextd method exposed via MIG (com.apple.KernelExtensionServer)
ReportCrash is the daemon responsible for making crash dumps of crashing userspace processes.
#define _GNU_SOURCE
# Exploit Title: Jfrog Artifactory < 4.16 - Unauthenticated Arbitrary File Upload / Remote Command Execution
# Exploit Title: WordPress Plugin WP with Spritz 1.0 - Remote File Inclusion
# Exploit Title: SickRage < v2018.03.09 - Clear-Text Credentials HTTP Response
# Exploit Title: October CMS User Plugin v1.4.5 - Persistent Cross-Site Scripting
# Exploit Title: MyBB Threads to Link Plugin v1.3 - Persistent XSS
#######################################################