OBS Studio 20.1.3 – Local Buffer Overflow
author = '''
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
author = '''
Document Title:
D-Link DNS-343 ShareCenter Remote Root
D-Link DNS-325 ShareCenter Multiple Vulnerabilities
#!/usr/bin/env python3
## Vulnerability Summary
# Exploit Title: Xnami Image Sharing - Persistent XSS Vulnerability
Document Title:
=============================================
This bug is similar to Jann Horn's issue (https://bugs.chromium.org/p/project-zero/issues/detail?id=851) -- credit sh...
Windows: NTFS Owner/Mandatory Label Privilege Bypass EoP
Windows: NtImpersonateAnonymousToken AC to Non-AC EoP
Windows: NtImpersonateAnonymousToken LPAC to Non-LPAC EoP
Windows: SMB Server (v1 and v2) Mount Point Arbitrary Device Open EoP
Here's a snippet of AppendLeftOverItemsFromEndSegment in JavascriptArray.inl.
#!/usr/bin/python
# SSD Advisory – Seagate Personal Cloud Multiple Vulnerabilities
The transmission bittorrent client uses a client/server architecture, the user interface is the client and a daemon r...
# Exploit Title: Worpress Plugin Service Finder Booking < 3.2 - Local File Disclosure
# Exploit Title: Muviko 1.1 - Multiple SQL Injection
# Exploit Title: DiskBoss
# Exploit Title: Wichipi Events Calendar - SQL Injection
# Exploit Title: Joomla Plugin Easydiscuss
== INTRODUCTION ==
The method "Lowerer::LowerSetConcatStrMultiItem" is used to generate machine code to concatenate strings.
// ConsoleApplication1.cpp : Defines the entry point for the console application.
#!/usr/bin/env python
1. Call patterns like "Math.max.apply(Math, [1, 2, 3, 4, 5])" and "Math.max.apply(Math, arr)" can be optimized to dir...
The optimizations for memory operations may leave empty loops as follows:
Here's a snippet of AsmJSByteCodeGenerator::EmitAsmJsFunctionBody.
Escape analysis: https://en.wikipedia.org/wiki/Escape_analysis
We have discovered that the nt!NtQueryInformationProcess system call invoked with the 76 information class discloses ...
We have discovered that the nt!NtQuerySystemInformation system call invoked with the 138 information class discloses ...
# Exploit Title: VX Search Enterprise Server v10.1.12 - Denial of Service