Exploits
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
- 类型
- 漏洞条目
- 总量
- 24,950
- 页码
- 174
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Pool Overflow / Local Privilege Escalation (1)
# -*- coding: utf-8 -*-
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Out-of-Bounds Write Privilege Escalation
# -*- coding: utf-8 -*-
Tor (Linux) – X11 Linux Sandbox Breakout
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1293&desc=2
Apache Struts 2.5 < 2.5.12 - REST Plugin XStream Remote Code Execution
# Exploit Title: Struts 2.5 - 2.5.12 REST Plugin XStream RCE
A2billing 2.x – SQL Injection
# Title : A2billing 2.x , Sql injection vulnerability
The Car Project 1.0 – SQL Injection
# # # # #
Ultimate HR System < 1.2 - Directory Traversal / Cross-Site Scripting
# Exploit Title: HRM - Workable Zone : Ultimate HR System Last Name
Wireless Repeater BE126 – Remote Code Execution
# Exploit Title: WIFI Repeater BE126 – Remote Code Execution
CodeMeter 6.50 – Cross-Site Scripting
Document Title:
RubyGems < 2.6.13 - Arbitrary File Overwrite
There is no check for name field in metadata.gz. By assigning a maliciously crafted string like ../../../../../any/wh...
Dup Scout Enterprise 9.9.14 – ‘Input Directory’ Local Buffer Overflow
#!/usr/bin/python
Mongoose Web Server 6.5 – Cross-Site Request Forgery / Remote Code Execution
[+] Credits: John Page AKA hyp3rlinx
A2billing 2.x – Backup File Download / Remote Code Execution
# Title : A2billing 2.x , Unauthenticated Backup dump / RCE flaw
iGreeting Cards 1.0 – SQL Injection
# # # # #
IBM Notes 8.5.x/9.0.x – Denial of Service
# Exploit Title: IBM Notes is affected by a denial of service vulnerability
Lotus Notes Diagnostic Tool 8.5/9.0 – Local Privilege Escalation
# Exploit Title: Lotus Notes Diagnostic Tool (nsd.exe) Privelege Escalation
OpenJPEG – ‘mqc.c’ Heap Buffer Overflow
DESCRIPTION
WordPress Plugin Participants Database < 1.7.5.10 - Cross-Site Scripting
# Exploit Title: Wordpress Plugin Participants Database < 1.7.5.10 - XSS
Joomla! Component Huge-IT Video Gallery 1.0.9 – SQL Injection
# Exploit Title Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla
Joomla! Component Huge-IT Portfolio Gallery Plugin 1.0.6 – SQL Injection
# Exploit Title Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
Joomla! Component Huge-IT Portfolio Gallery Plugin 1.0.7 – SQL Injection
# Exploit Title Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla
IBM Notes 8.5.x/9.0.x – Denial of Service (2)
# Exploit Title: IBM Notes is affected by a denial of service vulnerability
Sitefinity CMS 9.2 – Cross-Site Scripting
# Exploit Title: Stored Cross Site Scripting (XSS) in Progress Sitefinity CMS 9.2
Invoice Manager 3.1 – Cross-Site Request Forgery (Add Admin)
# # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # #
PHP-SecureArea < 2.7 - Multiple Vulnerabilities
# Exploit Title: PHP-SecureArea
Metasploit Web UI < 4.14.1-20170828 - Cross-Site Request Forgery
# Exploit Title: CSRF
Oracle Java JDK/JRE < 1.8.0.131 / Apache Xerces 2.11.0 - 'PDF/Docx' Server Side Denial of Service
## Vulnerabilities Summary
D-Link DIR-600 – Authentication Bypass
# Exploit Title: D-Link DIR-600 - Authentication Bypass (Absolute Path Traversal Attack)
User Login and Management – Multiple Vulnerabilities
-----------------------------------------------------------------------------------
Brickcom IP Camera – Credentials Disclosure
1. Advisory Information
FineCMS 1.0 – Multiple Vulnerabilities
# # # # #
Easy WMV/ASF/ASX to DVD Burner 2.3.11 – Local Buffer Overflow (SEH)
#!/usr/bin/python
Easy RM RMVB to DVD Burner 1.8.11 – Local Buffer Overflow (SEH)
#!/usr/bin/python
Smart Chat 1.0.0 – SQL Injection
# # # # #
FTP Made Easy PRO 1.2 – SQL Injection
# # # # #
Easy Web Search 4.0 – SQL Injection
# # # # #
PHP Search Engine 1.0 – SQL Injection
# # # # #
Flash Poker 2.0 – ‘game’ SQL Injection
# # # # #