Exploits
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
- 类型
- 漏洞条目
- 总量
- 24,950
- 页码
- 177
Microsoft Edge Chakra – Uninitialized Arguments (1)
function f() {
Microsoft Edge Chakra – Uninitialized Arguments (2)
function f() {
Microsoft Edge Chakra – ‘EmitNew’ Integer Overflow
let args = new Array(0x10000);
Adobe Flash – Invoke Accesses Trait Out-of-Bounds
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1320
Microsoft Edge – Out-of-Bounds Access when Fetching Source
// The attached JavaScript file causes an out-of-bounds access of the source buffer when fetching the source for one ...
Food Ordering Script 1.0 – SQL Injection
# # # # #
MyDoomScanner 1.00 – Local Buffer Overflow (PoC)
#!/usr/bin/python
ALLPlayer 7.4 – Local Buffer Overflow (SEH Unicode)
#!/usr/bin/python
ClipBucket 2.8.3 – Multiple Vulnerabilities
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Quali CloudShell 7.1.0.6508 (Patch 6) – Persistent Cross-Site Scripting
# Vulnerability type: Multiple Stored Cross Site Scripting
Xamarin Studio for Mac 6.2.1 (build 3) / 6.3 (build 863) – Local Privilege Escalation
Source: https://www.securify.nl/advisory/SFY20170403/xamarin-studio-for-mac-api-documentation-update-affected-by-loca...
Tomabo MP4 Converter 3.19.15 – Denial of Service
#!/usr/bin/python
Linux Kernel < 4.4.0-83 / < 4.8.0-58 (Ubuntu 14.04/16.04) - Local Privilege Escalation (KASLR / SMEP)
// A proof-of-concept local root exploit for CVE-2017-1000112.
DeWorkshop 1.0 – SQL Injection
# # # # #
De-Journal 1.0 – SQL Injection
# # # # #
De-Tutor 1.0 – SQL Injection
# # # # #
ImageBay 1.0 – SQL Injection
# # # # #
GIF Collection 2.0 – SQL Injection
# # # # #
Piwigo Plugin User Tag 0.9.0 – Cross-Site Scripting
# Exploit Title: Piwigo plugin User Tag , Persistent XSS
Red-Gate SQL Monitor < 3.10 / 4.2 - Authentication Bypass
# Exploit Title: Red-Gate SQL Monitor authentication bypass
DALIM SOFTWARE ES Core 5.0 build 7184.1 – User Enumeration
#!/usr/bin/env python
DALIM SOFTWARE ES Core 5.0 build 7184.1 – Directory Traversal
DALIM SOFTWARE ES Core 5.0 build 7184.1 Multiple Remote File Disclosures
DALIM SOFTWARE ES Core 5.0 build 7184.1 – Server-Side Request Forgery
DALIM SOFTWARE ES Core 5.0 build 7184.1 Server-Side Request Forgery
Symantec Messaging Gateway < 10.6.3-267 - Cross-Site Request Forgery
# Exploit Title: CSRF
Android Bluetooth – ‘Blueborne’ Information Leak (1)
from pwn import *
WildMIDI 0.4.2 – Multiple Vulnerabilities
wildmidi multiple vulnerabilities
Unitrends UEB 9.1 – ‘Unitrends bpserverd’ Remote Command Execution
# Exploit Title: Unauthenticated root RCE for Unitrends UEB 9.1
Unitrends UEB 9.1 – Authentication Bypass / Remote Command Execution
# Exploit Title: Unauthenticated root RCE for Unitrends UEB 9.1
Unitrends UEB 9.1 – Privilege Escalation
# Exploit Title: Authenticated lowpriv RCE for Unitrends UEB 9.1
VMware WorkStation 12.5.5 – Virtual Machine Escape
# VMware Escape Exploit
WordPress Plugin Easy Modal 2.0.17 – SQL Injection
DefenseCode ThunderScan SAST Advisory
Microsoft Windows – ‘.LNK’ Shortcut File Code Execution
#!/usr/bin/python