Exploits
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
- 类型
- 漏洞条目
- 总量
- 24,950
- 页码
- 206
Google Android – ‘IOMXNodeInstance::enableNativeBuffers’ Unchecked Index
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=932
AbanteCart 1.2.7 – Cross-Site Scripting
# Exploit Title: AbanteCart 1.2.7 Stored XSS
Microsoft Edge – CMarkup::EnsureDeleteCFState Use-After-Free (MS15-125)
Source: http://blog.skylined.nl/20161201001.html
Microsoft Edge – CBaseScriptable::PrivateQueryInterface Memory Corruption (MS16-068)
Source: http://blog.skylined.nl/20161205001.html
Edge SkateShop – Authentication bypass
# Exploit Title: Edge SkateShop Authentication Bypass
Microsoft Windows 10 (x86/x64) – WLAN AutoConfig Denial of Service (PoC)
#!/usr/bin/python
Microsoft Event Viewer 1.0 – XML External Entity Injection
[+] Credits: John Page aka hyp3rlinx
Microsoft MSINFO32.EXE 6.1.7601 – ‘.NFO’ XML External Entity Injection
[+] Credits: John Page aka hyp3rlinx
Apache CouchDB 2.0.0 – Local Privilege Escalation
[+] Credits: John Page aka hyp3rlinx
NetCat 0.7.1 – Denial of Service
#/usr/bin/python
Shuttle Tech ADSL Wireless 920 WM – Multiple Vulnerabilities
######################
Dup Scout Enterprise 9.1.14 – Remote Buffer Overflow (SEH)
#!/usr/bin/python
DiskBoss Enterprise 7.4.28 – ‘GET’ Remote Buffer Overflow
#!/usr/bin/python
WordPress Plugin Single Personal Message 1.0.3 – SQL Injection
# Exploit Title: Single Personal Message 1.0.3 – Plugin WordPress – Sql Injection
BlackStratus LOGStorm 4.5.1.35/4.5.1.96 – Remote Code Execution
#!/usr/bin/python
Microsoft Authorization Manager 6.1.7601 – ‘azman’ XML External Entity Injection
[+] Credits: John Page aka hyp3rlinx
Microsoft Excel Starter 2010 – XML External Entity Injection
[+] Credits: John Page aka hyp3rlinx
Microsoft Windows Media Center 6.1.7600 – ‘ehshell.exe’ XML External Entity Injection
[+] Credits: John Page aka hyp3rlinx
Alcatel Lucent Omnivista 8770 – Remote Code Execution
import socket
Smart Guard Network Manager 6.3.2 – SQL Injection
# Exploit Title: SQL Injection In Smart Guard Network Manager Api
Xfinity Gateway – Remote Code Execution
# Exploit Title: Xfinity Gateway: Remote Code Execution
Disk Savvy Enterprise 9.1.14 – ‘GET’ Remote Buffer Overflow
#!/usr/bin/python
Tor (Firefox 41 < 50) - Code Execution
# TOR Browser 0day : JavaScript Exploit !
Broadcom BCM43xx Wi-Fi – ‘BroadPWN’ Denial of Service
This Exploit allows arbitrary memory writes and reads. Running the specified payload within this package will write t...
Xitami Web Server 5.0a0 – Denial of Service
#!/usr/bin/env python
WordPress Plugin WP Vault 0.8.6.6 – Local File Inclusion
# Exploit Title: WP Vault 0.8.6.6 – Plugin WordPress – Local File Inclusion
Xfinity Gateway – Cross-Site Request Forgery
EXPLOIT TITLE: CSRF RCE XFINITY WEB GATEWAY
WinPower 4.9.0.4 – Local Privilege Escalation
// Exploit Title: WinPower V4.9.0.4 Privilege Escalation
VX Search Enterprise 9.1.12 – ‘Login’ Remote Buffer Overflow
#!/usr/bin/python
Sync Breeze Enterprise 9.1.16 – ‘Login’ Remote Buffer Overflow
#!/usr/bin/python
Dup Scout Enterprise 9.1.14 – ‘Login’ Remote Buffer Overflow
#!/usr/bin/python
Disk Sorter Enterprise 9.1.12 – ‘Login’ Remote Buffer Overflow
#!/usr/bin/python
Disk Savvy Enterprise 9.1.14 – ‘Login’ Remote Buffer Overflow
#!/usr/bin/python
Disk Pulse Enterprise 9.1.16 – ‘Login’ Remote Buffer Overflow
#!/usr/bin/python
Tenda/Dlink/Tplink TD-W8961ND – ‘DHCP’ Cross-Site Scripting
Document Title:
NTP 4.2.8p3 – Denial of Service
#!/usr/bin/env python
Red Hat JBoss EAP – Deserialization of Untrusted Data
Security Advisory @ Mediaservice.net Srl
Microsoft Internet Explorer 8/9/10/11 – MSHTML ‘DOMImplementation’ Type Confusion (MS16-009)
Source: http://blog.skylined.nl/20161128001.html
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 – Multiple Vulnerabilities
# Exploit Title: [Trend Micro Interscan Web Security Virtual Appliance (IWSVA) 6.5.x Multiple Vulnerabilities]
Core FTP LE 2.2 – ‘SSH/SFTP’ Remote Buffer Overflow (PoC)
[+] Credits: John Page aka hyp3rlinx
Linux Kernel 2.6.22 < 3.9 - 'Dirty COW /proc/self/mem' Race Condition Privilege Escalation (/etc/passwd Method)
// EDB-Note: Compile: g++ -Wall -pedantic -O2 -std=c++11 -pthread -o dcow 40847.cpp -lutil
Microsoft Windows Kernel – ‘win32k.sys NtSetWindowLongPtr’ Local Privilege Escalation (MS16-135) (1)
Complete Proof of Concept: