WordPress Plugin Caldera Forms 1.5.9.1 – Cross-Site Scripting
# Exploit Title: CalderaForms 1.5.9.1 - multiple XSS
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: CalderaForms 1.5.9.1 - multiple XSS
# Exploit Title: PDFunite Malformed pdf buffer overflow
# Exploit Title: Buffer-overflow in RSVG while converting a malformed svg
#######################################
# Exploit Author: bzyo
#!/usr/bin/python
#######################################
# Exploit Title: Ultra MiniHTTPd 1.2 - 'GET' Remote Stack Buffer Overflow
######################################################################################
# Exploit Title:Brave Browser < 0.13.0 Denial of Service (resource consumption) via a long alert() argument.
# Exploit Title:Brave Browser < 0.13.0 Denial of Service (resource consumption) via a window.close(self) js code.
# Exploit Title: Reaper 5.78 - Local Buffer Overflow
# Exploit Title: Cobub Razor 0.8.0 SQL injection Vulnerability
#!/usr/bin/python
#!/usr/bin/python
We have discovered that the nt!NtQueryFullAttributesFile system call invoked with paths of certain kernel objects dis...
We have discovered that the nt!NtQueryAttributesFile system call invoked with paths of certain kernel objects disclos...
We have discovered that the nt!NtQueryVolumeInformationFile system call invoked against certain kernel objects disclo...
We have discovered that the nt!NtQuerySystemInformation system call invoked with the SystemPageFileInformation (0x12)...
We have discovered that the nt!NtQueryInformationTransactionManager system call invoked with the TransactionManagerRe...
We have discovered that the nt!NtQueryInformationProcess system call invoked with the ProcessImageFileName (0x1B) inf...
We have discovered that the nt!NtQueryVirtualMemory system call invoked with the MemoryBasicInformation (0x0) and Mem...
We have discovered that the nt!NtQueryVirtualMemory system call invoked with the MemoryImageInformation (0x6) informa...
Windows: CiSetFileCache TOCTOU CVE-2017-11830 Incomplete Fix
Each Edge Content process (MicrosoftEdgeCP.exe) needs to call SetProcessMitigationPolicy() on itself to enable ACG. T...
#!/usr/bin/python
# Exploit Title: Sophos Cyberoam UTM - Privilege Escalation
#######################################################
########################################################################
################
# Exploit Title: Joomla Extension Convert Forms version 2.0.3 is vulnerable to Formula Injection (CSV Injection)
# Exploit Title: iScripts Easycreate 3.2.1 - Stored Cross-Site Scripting
# Exploit Title : Activity Log Wordpress Plugin Stored Cross Site Scripting (XSS)
######################################################
# Exploit Title: WUZHI CMS 4.1.0 CSRF vulnerability add admin account
# Exploit Title: WUZHI CMS 4.1.0 CSRF vulnerability add user account
# Exploit Title: [Dell EMC Avamar and Integrated Data Protection Appliance Installation Manager Missing Access Contro...
I think this commit has introduced the bug: https://chromium.googlesource.com/v8/v8.git/+/9884bc5dee488bf206655f07b8a...
# Exploit Title: WordPress Plugin WordPress File Upload 4.3.2 - Stored XSS
# Exploit Title: WordPress Plugin WordPress File Upload 4.3.3 - Stored XSS
# Exploit Title: WP Background Takeover, Directory Traversal
#######################################
# Exploit Title: [Cobub Razor 0.7.2 Add New Superuser User]
# Exploit Title: MyBB Recent threads
#######################################