Exploits
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
- 类型
- 漏洞条目
- 总量
- 24,950
- 页码
- 190
Bluecoat ASG 6.6/CAS 1.3 – OS Command Injection (Metasploit)
# Exploit Title: OS Command Injection Vulnerability in BlueCoat ASG and CAS
Bluecoat ASG 6.6/CAS 1.3 – Local Privilege Escalation (Metasploit)
# Exploit Title: OS Command Injection Vulnerability in BlueCoat ASG and CAS
GeoMoose < 2.9.2 - Directory Traversal
# Exploit Title: GeoMoose
Moxa AWK-3131A 1.4 < 1.7 - 'Username' OS Command Injection
#!/usr/bin/env python2
BackBox OS – Denial of Service
//Exploited By Hosein Askari
Zyxel, EMG2926 < V1.00(AAQT.4)b8 - OS Command Injection
# Exploit Title: Zyxel, EMG2926 < V1.00(AAQT.4)b8 - OS Command Injection
Pixie 1.0.4 – Arbitrary File Upload
# Exploit Title: File Extension Filter Bypass in File Manager Pixie 1.0.4 With Low Privilege # Google Dork: no
Splunk Enterprise – Information Disclosure
[+] Credits: John Page AKA hyp3rlinx
Microsoft Xbox One 10.0.14393.2152 – Code Execution (PoC)
For Xbox-SystemOS version: 10.0.14393.2152 (rs1_xbox_rel_1610 161208-1218) fre, 12/14/2016
Apple macOS/IOS 10.12.2 (16C67) – ‘mach_msg’ Heap Overflow
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1083
Disk Sorter Enterprise 9.5.12 – ‘Import Command’ Local Buffer Overflow
#!/usr/bin/env python
DiskBoss Enterprise 7.8.16 – ‘Import Command’ Local Buffer Overflow
#!/usr/bin/env python
Sync Breeze Enterprise 9.5.16 – ‘Import Command’ Local Buffer Overflow
#!/usr/bin/env python
EyesOfNetwork (EON) 5.1 – SQL Injection
# Exploit Title: EyesOfNetwork (EON) 5.1 Unauthenticated SQL Injection in eonweb leading to remote root
Sync Breeze Enterprise 9.5.16 – ‘GET’ Remote Buffer Overflow (SEH)
#!/usr/bin/env python
DzSoft PHP Editor 4.2.7 – File Enumeration
[+] Credits: John Page AKA hyp3rlinx
MikroTik RouterBoard 6.38.5 – Denial of Service
#!/usr/local/bin/perl
Intermec PM43 Industrial Printer – Local Privilege Escalation
# TITLE: Intermec Industrial Printers Local root with Busybox jailbreak
Microsoft Outlook – HTML Email Denial of Service
Source: https://justhaifei1.blogspot.ca/2017/03/an-interesting-outlook-bug.html
CouponPHP CMS 3.1 – ‘code’ SQL Injection
# # # # #
Disk Sorter Enterprise 9.5.12 – Local Buffer Overflow
[+] Title: Disk Sorter Server v9.5.12 - Local Stack-based buffer overflow
Samba 4.5.2 – Symlink Race Permits Opening Files Outside Share Directory
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1039
QNAP QTS < 4.2.4 - Domain Privilege Escalation
QNAP QTS Domain Privilege Escalation Vulnerability
EyesOfNetwork (EON) 5.0 – Remote Code Execution
# [CVE-2017-6087] EON 5.0 Remote Code Execution
EyesOfNetwork (EON) 5.0 – SQL Injection
# [CVE-2017-6088] EON 5.0 Multiple SQL Injection
inoERP 0.6.1 – Cross-Site Scripting / Cross-Site Request Forgery / SQL Injection / Session Fixation
=== FOXMOLE - Security Advisory 2017-01-25 ===
Alibaba Clone Script – SQL Injection
# # # # #
Hotel Booking Script 1.0 – SQL Injection
# # # # #
Tour Package Booking 1.0 – SQL Injection
# # # # #
Microsoft Visual Studio 2015 update 3 – Denial of Service
# Exploit Title: Microsoft Visual Studio 2015 update 3 – Stack overflow
D-Link DCS-936L Network Camera – Cross-Site Request Forgery
# Exploit Title: [D-Link DCS-936L network camera incomplete/weak CSRF protection vulnerability]