Exploits
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
- 类型
- 漏洞条目
- 总量
- 24,950
- 页码
- 192
Oracle Knowledge Management 12.1.1 < 12.2.5 - XML External Entity Leading To Remote Code Execution
# SSD Advisory – Oracle Knowledge Management XXE Leading to a RCE
Microsoft Windows DVD Maker 6.1.7 – XML External Entity Injection
[+] Credits: John Page AKA hyp3rlinx
Cerberus FTP Server 8.0.10.3 – ‘MLST’ Buffer Overflow (PoC)
[+] Title: Cerberus FTP Server 8.0.10.3 – 'MLST' Remote Buffer Overflow
Microsoft Edge 38.14393.0.0 – JavaScript Engine Use-After-Free
[crayon-6abaab8d2042d345941229/]
Cobbler 2.8.0 – (Authenticated) Remote Code Execution
#!/usr/bin/python
CommVault Edge 11 SP6 – Stack Buffer Overflow (PoC)
import socket
PCAUSA Rawether (ASUS PCE-AC56 WLAN Card Utilities Windows 10 x64) – Local Privilege Escalation
#Exploit Title: PCAUSA Rawether for Windows local privilege escalation
Microsoft Windows – COM Session Moniker Privilege Escalation (MS17-012)
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1021
Adobe Flash – Metadata Parsing Out-of-Bounds Read
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1005
Adobe Flash – MovieClip Attach init Object Use-After-Free
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1006
Adobe Flash – ATF Thumbnailing Heap Overflow
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1015
Adobe Flash – ATF Planar Decompression Heap Overflow
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1016
Adobe Flash – AVC Header Slicing Heap Overflow
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1017
Microsoft Windows – ‘LoadUvsTable()’ Heap Buffer Overflow
# Date: 15-03-2017
GitHub Enterprise 2.8.0 < 2.8.6 - Remote Code Execution
#!/usr/bin/ruby
Sitecore CMS 8.1 Update-3 – Cross-Site Scripting
# Exploit Title: Stored Cross Site Scripting (XSS) in Sitecore Experience Platform 8.1 Update-3
GitHub Enterprise < 2.8.7 - Remote Code Execution
#!/usr/bin/python
APNGDis 2.8 – ‘chunk size descriptor’ Heap Buffer Overflow
# Exploit Title: APNGDis chunk size descriptor Buffer Overflow
APNGDis 2.8 – ‘image width / height chunk’ Heap Buffer Overflow
# Exploit Title: APNGDis image width / height Buffer Overflow
APNGDis 2.8 – ‘filename’ Stack Buffer Overflow (PoC)
# Exploit Title: APNGDis filename Buffer Overflow
Car Workshop System – SQL Injection
# # # # #
Cerberus FTP Server 8.0.10.1 – Denial of Service
# Exploit Title: Cerberus FTP server – Denial of Service
Oracle VM VirtualBox – Cooperating VMs can Escape from Shared Folder
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1037
Steam Profile Integration 2.0.11 – SQL injection
# Exploit Title: IPS Community Suite - Steam Profile Integration 2.0.11 and below SQL injection
Easy MOV Converter 1.4.24 – Local Buffer Overflow (SEH)
#!/usr/bin/python
Nintendo Switch – WebKit Code Execution (PoC)
CVE-2016-4657 Switch PoC
Global In – SQL Injection
# # # # #
Global In – Arbitrary File Upload
# # # # #
Vanelo – SQL Injection
# # # # #
Pet Listing Script 3.0 – SQL Injection
# # # # #
Travel Tours Script 2.0 – SQL Injection
# # # # #
Yacht Listing Script 2.0 – SQL Injection
# # # # #
PHP Forum Script 3.0 – SQL Injection
# # # # #
MobaXterm Personal Edition 9.4 – Directory Traversal
[+] Credits: John Page AKA hyp3rlinx
Mirage – SQL Injection
# # # # #
Fiyo CMS 2.0.6.1 – Privilege Escalation
# Exploit Title: Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter