Exploits
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
- 类型
- 漏洞条目
- 总量
- 24,950
- 页码
- 155
PHIMS – Hospital Management Information System – ‘Password’ SQL Injection
# Exploit Title: PHIMS - Hospital Management Information System - 'Password' SQL Injection
PSNews Website 1.0.0 – ‘Keywords’ SQL Injection
# Exploit Title: PSNews Website (Same Backend with Mobile Apps) 1.0.0 - 'Keywords' SQL Injection
Oracle Primavera P6 Enterprise Project Portfolio Management – HTTP Response Splitting
# Exploit Title: Oracle Primavera P6 Enterprise Project Portfolio Management HTTP Response Splitting
Microsoft Edge Chakra JIT – ‘GlobOpt::OptTagChecks’ Must Consider IsLoopPrePass Properly (2)
It seems this is the patch for the bug.
Microsoft Edge Chakra JIT – Memory Corruption
Let's consider the following example code.
Microsoft Edge Chakra JIT – ImplicitCallFlags Checks Bypass
Here's a snippet of ExecuteImplicitCall which is responsible for updating the ImplicitCallFlags flag.
Microsoft Edge Chakra JIT – Array Type Confusion via InitProto Instructions
If a native array is used as a prototype, it is converted to a Var array by the Js::JavascriptNativeFloatArray::SetIs...
Microsoft Edge Chakra JIT – ‘Array.prototype.reverse’ Array Type Confusion
This is simillar to the previous issue 1457. But this time, we use Array.prototype.reverse.
Microsoft Edge Chakra JIT – ‘NewScObjectNoCtor’ Array Type Confusion
This is similar to the previous issues 1457, 1459 (MSRC 42551, MSRC 42552).
Microsoft Edge Chakra JIT – ‘LdThis’ Type Confusion
LdThis instructions' value type is assumed to be "Object". Since "this" can be other objects like an array, it has to...
Pdfium – Pattern Shading Integer Overflows
This vulnerability relies on several minor oversights in the handling of shading patterns in pdfium, I'll try to deta...
Pdfium – Out-of-Bounds Read with Shading Pattern Backed by Pattern Colorspace
Related to issue 1490 .
Chrome V8 – ‘Runtime_RegExpReplace’ Integer Overflow
Here's a snippet of the method.
NAT32 2.2 Build 22284 – Remote Command Execution
[+] Credits: hyp3rlinx
NAT32 2.2 Build 22284 – Cross-Site Request Forgery
[+] Credits: hyp3rlinx
GNU binutils 2.26.1 – Integer Overflow (PoC)
# Exploit Title: Objdump - Integer Overflow Crash POC
Social Oauth Login PHP – Authentication Bypass
# Exploit Title: Social Oauth Login PHP - Authentication Bypass
SOA School Management – ‘access_login’ SQL Injection
# Exploit Title: SOA - School Management Software with Integrated
userSpice 4.3 – Cross-Site Scripting
Application UserSpice PHP user management
Dell EMC Isilon OneFS – Multiple Vulnerabilities
Core Security - Corelabs Advisory
Tenda AC15 Router – Remote Code Execution
#!/usr/bin/env python
CloudMe Sync < 1.11.0 - Buffer Overflow
[+] Credits: John Page (aka hyp3rlinx)
TypeSetter CMS 5.1 – ‘Host’ Header Injection
# Exploit Title: TypeSetter CMS 5.1 Host Header Injection
TypeSetter CMS 5.1 – Cross-Site Request Forgery
# Exploit Title: TypeSetter CMS 5.1 Cross Site Request Forgery
News Website Script 2.0.4 – ‘search’ SQL Injection
##################################################################
Advantech WebAccess 8.3.0 – Remote Code Execution
Vulnerability Title: Advantech WebAccess Node8.3.0 "AspVBObj.dll" - Remote Code Execution
Flash ActiveX 18.0.0.194 – Code Execution
## CVE-2015-5112
LogicalDOC Enterprise 7.7.4 – Directory Traversal
LogicalDOC Enterprise 7.7.4 Multiple Directory Traversal Vulnerabilities
LogicalDOC Enterprise 7.7.4 – User Enumeration
LogicalDOC Enterprise 7.7.4 Username Enumeration Weakness
LogicalDOC Enterprise 7.7.4 – Root Remote Code Execution
LogicalDOC Enterprise 7.7.4 Post-Auth Command Execution Via Binary Path Manipulation
Paypal Clone Script 1.0.9 – ‘id’ / ‘acctype’ SQL Injection
# Exploit Title: Paypal / Money Transfer Clone Script 1.0.9 - SQL Injection
Readymade Video Sharing Script 3.2 – ‘search’ SQL Injection
##################################################################