Exploits
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
- 类型
- 漏洞条目
- 总量
- 24,950
- 页码
- 204
WordPress Plugin Slider Templatic Tevolution < 2.3.6 - Arbitrary File Upload
# Exploit Title: WordPress Templatic
Dell SonicWALL Global Management System GMS 8.1 – Blind SQL Injection
Dell SonicWALL Global Management System GMS 8.1 Blind SQL Injection
Dell SonicWALL Secure Mobile Access SMA 8.1 – Cross-Site Scripting / Cross-Site Request Forgery
Dell SonicWALL Secure Mobile Access SMA 8.1 XSS And WAF CSRF
b2evolution 6.8.2 – Arbitrary File Upload
# Exploit Title: b2evolution6.8.2stable – Upload
WordPress Plugin Simply Poll 1.4.1 – SQL Injection
# Exploit Title: Simply Poll 1.4.1 Plugin for WordPress SQL Injection
Joomla! Component aWeb Cart Watching System for Virtuemart 2.6.0 – SQL Injection
# Exploit Title: Sqli Blind Timebased on Joomla + Viertuemart + aweb-cartwatching-system/aweb-cartwatching
SapLPD 7.40 – Denial of Service
# Exploit Title: SAPlpd 7.40 Denial of Service
PHPMailer < 5.2.20 - Remote Code Execution
#!/usr/bin/python
FTPShell Server 6.36 – ‘.csv’ Local Denial of Service
#Exploit FTPShell server 6.36 '.csv' Crash(PoC)
Joomla! Component Blog Calendar – SQL Injection
==========================================================================================
Wampserver 3.0.6 – Insecure File Permissions Privilege Escalation
=====================================================
PHPMailer < 5.2.18 - Remote Code Execution
#!/bin/bash
Shutter 0.93.1 – Code Execution
# Exploit Title: Shutter user-assisted remote code execution
Sonicwall 8.1.0.2-14sv – ‘extensionsettings.cgi’ Remote Command Injection (Metasploit)
# Exploit Title: Sonicwall extensionsettings scriptname Remote Command Injection Vulnerablity
Sonicwall 8.1.0.2-14sv – ‘viewcert.cgi’ Remote Command Injection (Metasploit)
# Exploit Title: Sonicwall viewcert.cgi CGI Remote Command Injection Vulnerablity
OpenSSH < 7.4 - 'UsePrivilegeSeparation Disabled' Forwarded Unix Domain Sockets Privilege Escalation
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1010
OpenSSH < 7.4 - agent Protocol Arbitrary Library Loading
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1009
Freepbx < 2.11.1.5 - Remote Code Execution
Exploit Title: Freepbx coockie recordings injection
Apple macOS 10.12.1 Kernel – Writable Privileged IOKit Registry Properties Code Execution
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=974
Apple macOS 10.12 – Double vm_deallocate in Userspace MIG Code Use-After-Free
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=954
Apple macOS < 10.12.2 / iOS < 10.2 Kernel - ipc_port_t Reference Count Leak Due to Incorrect externalMethod Overrides Use-After-Free
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=926
Apple macOS < 10.12.2 / iOS < 10.2 - '_kernelrpc_mach_port_insert_right_trap' Kernel Reference Count Leak / Use-After-Free
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=941
Apple macOS < 10.12.2 / iOS < 10.2 - Broken Kernel Mach Port Name uref Handling Privileged Port Name Replacement Privilege Escalation
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=959
Apple macOS 10.12.1 / iOS < 10.2 - powerd Arbitrary Port Replacement
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=976
Apple macOS 10.12.1 / iOS < 10.2 - syslogd Arbitrary Port Replacement
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=977
Google Android – WifiNative::setHotlist Stack Overflow
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=958
Java Debug Wire Protocol (JDWP) – Remote Code Execution
#!/usr/bin/python
WordPress Plugin 404 Redirection Manager 1.0 – SQL Injection
# Exploit Title: Unauthenticated SQL injeciton in 404 plugin for Wordpress v1.0
RedStar 3.0 Server – ‘Shellshock’ ‘BEAM’ / ‘RSSMON’ Command Injection
#!/usr/bin/env python
Orthanc DICOM Server 1.1.0 – Memory Corruption
#!/usr/bin/env python
OsiriX DICOM Viewer 8.0.1 – Memory Corruption
#!/usr/bin/env python
ConQuest DICOM Server 1.4.17d – Stack Buffer (PoC)
#!/usr/bin/env python
DCMTK 3.6.0 storescp – Stack Buffer Overflow
#!/usr/bin/env python