Exploits
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
- 类型
- 漏洞条目
- 总量
- 24,950
- 页码
- 173
Microsoft Windows .NET Framework – Remote Code Execution
Source: https://github.com/Voulnet/CVE-2017-8759-Exploit-sample
Astaro Security Gateway 7 – Remote Code Execution
#!/usr/bin/python
Foodspotting Clone 1.0 – SQL Injection
# Exploit Title: Foodspotting Clone v1.0 - SQL Injection/Reflected XSS
osTicket 1.10 – SQL Injection (PoC)
1. ADVISORY INFORMATION
FoodStar 1.0 – SQL Injection
# # # # #
inClick Cloud Server 5.0 – SQL Injection
# # # # #
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Pool Overflow / Local Privilege Escalation (2)
# -*- coding: utf-8 -*-
WebKit JSC – ‘BytecodeGenerator::emitGetByVal’ Incorrect Optimization (1)
Let's start with JS code.
XYZ Auto Classifieds 1.0 – SQL Injection
# Exploit Title: XYZ Auto Classifieds v1.0 - SQL Injection
Consumer Review Script 1.0 – SQL Injection
# Exploit Title: Consumer Review Script v1.0 - SQL Injection
D-Link DIR-8xx Routers – Leak Credentials
# phpcgi is responsible for processing requests to .php, .asp and .txt pages. Also, it checks whether a user is autho...
D-Link DIR-8xx Routers – Root Remote Code Execution
# Due to error in hnap protocol implementation we can overflow stack and execute any sh commands under root priviliges.
D-Link DIR-8xx Routers – Local Firmware Upload
#!/bin/bash
WiseGiga NAS – Multiple Vulnerabilities
Source: https://blogs.securiteam.com/index.php/archives/3402
tcprewrite – Heap Buffer Overflow
################
PHP Dashboards NEW 4.4 – SQL Injection
# # # # #
JobStar Monster Clone Script 1.0 – SQL Injection
# Exploit Title: JobStar Monster Clone Script v1.0 - SQL Injection
iTech Book Store Script 2.02 – SQL Injection
# Exploit Title: iTech Book Store Script v2.02 - SQL Injection / Reflected XSS
iTech StockPhoto Script 2.02 – SQL Injection
# Exploit Title: iTech StockPhoto Script v2.02 - SQL Injection
EduStar Udemy Clone Script 1.0 – SQL Injection
# Exploit Title: EduStar Udemy Clone Script v1.0 - SQL Injection
AirStar Airbnb Clone Script 1.0 – SQL Injection
# Exploit Title: AirStar Airbnb Clone Script v1.0 - SQL Injection
Hanbanggaoke IP Camera – Arbitrary Password Change
## Vulnerability summary
Escort Marketplace 1.0 – SQL Injection
# # # # #
Job Board Software 1.0 – SQL Injection
# # # # #
Law Firm 1.0 – SQL Injection
# # # # #
EzBan 5.3 – ‘id’ SQL Injection
# # # # #
EzInvoice 6.02 – SQL Injection
# # # # #
Roteador Wireless Intelbras WRN150 – Cross-Site Scripting
# Exploit Title: XSS persistent on intelbras router with firmware WRN 250
Huawei HG255s – Directory Traversal
# Exploit Title: [Server Directory Traversal at Huawei HG255s]
HiSilicon DVR Devices – Remote Code Execution
#!/usr/bin/env python2
McAfee LiveSafe 16.0.3 – Man In The Middle Registry Modification Leading to Remote Command Execution
## Vulnerabilities Summary
Cory Support – ‘pr’ SQL Injection
# Exploit : Cory Support (pr) SQL Injection Vulnerability