WordPress Plugin Site Editor 1.1.1 – Local File Inclusion
Product: Site Editor Wordpress Plugin - https://wordpress.org/plugins/site-editor/
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
Product: Site Editor Wordpress Plugin - https://wordpress.org/plugins/site-editor/
Google software updater ships with Chrome on MacOS and installs a root service (com.google.Keystone.Daemon.UpdateEngine)
We have discovered that the nt!NtQueryVirtualMemory system call invoked with the 2 information class (MemoryMappedFil...
We have discovered that the nt!NtQueryInformationThread system call invoked with the 0 information class (ThreadBasic...
We have discovered a new Windows kernel memory disclosure vulnerability in the creation and copying of a EXCEPTION_RE...
We have discovered that the nt!NtWaitForDebugEvent system call discloses portions of uninitialized kernel stack memor...
There is a vulnerability in Internet Explorer that could potentially be used for memory disclosure.
Windows: Windows: Desktop Bridge VFS EoP
Windows: Desktop Bridge Virtual Registry NtLoadKey Arbitrary File Read/Write EoP
# Exploit Title: [INTELBRAS TELEFONE IP TIP200/200 LITE Local File Include]
# Exploit Title: VSMS Multiple Vulnerabilities
######################################################################################
#!/usr/bin/env python3
# OpenSSH 8 else 32
CVE-2016-2819 and ASM.JS JIT-Spray
CVE-2016-1960 and ASM.JS JIT-Spray
# Title : Contec smart home 4.15 Unauthorized Password Reset
# Exploit Title: Unauthenticated root RCE for Unitrends UEB 10.0
# Exploit Title : Duplicator Wordpress Migration Plugin Reflected Cross Site Scripting (XSS)
// Exploit Title: RCE in PATCH requests in Spring Data REST
#!/usr/bin/env python
#!/usr/bin/env python
SEC Consult Vulnerability Lab Security Advisory < 20180312-0 >
===============================================================================
###############################################################################
[+] Credits: John Page (aka hyp3rlinx)
Prisma Industriale Checkweigher PrismaWEB 1.21 Authentication Bypass
=============================================
#!/usr/bin/python2.7
# Exploit Author: Juan Sacco - http://www.exploitpack.com
# Exploit Title: Arbitrary Code Execution
#!/usr/bin/env python3
#!/usr/bin/env python2
function makeid() {
[+] Credits: John Page (aka hyp3rlinx)
[+] Credits: John Page (aka hyp3rlinx)
# Exploit Title: Multiple SQL injection vulnerabilities in Bacula-Web
# Exploit Title: Redaxo CMS Addon MyEvents SQL Injection [ Backend ]
# Exploit Title: antMan
[+] Credits: John Page (aka hyp3rlinx)
Exploit Title: Bravo Tejari Web Portal-CSRF