Leap Service – Unquoted Service Path Privilege Escalation
Leap service: https://www.leapmotion.com/
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
Leap service: https://www.leapmotion.com/
Wacom Consumer Service: http://www.wacom.com
Foxit Cloud Update Service: https://www.foxitsoftware.com
# Exploit Title : PHP Press Release - Cross-Site Request Forgery (Add Admin - Super User )
# Exploit Title : PHP Press Release* - Stored Cross Site
# Exploit Title: BlueStacks 2.5.55 Unquoted Service Path Privilege Escalation
Waves Audio Service: http://www.maxx.com
[x]==================================================================================================================...
[x]==================================================================================================================...
[x]==================================================================================================================...
[x]==================================================================================================================...
######################
[x]==================================================================================================================...
# Exploit Title: Comodo Dragon Browser Unquoted Service Path Privilege Escalation
# Title : Billion Router 7700NR4 Remote Root Command Execution
# Exploit Title: Comodo Chromodo Browser Unquoted Service Path Privilege Escalation
Document Title:
[-] Title : Picosafe Web Gui - Multiple Vulnerabilities
#!/usr/bin/python
#!/usr/bin/python
#!/usr/bin/python
#!/usr/bin/python
#!/usr/bin/python
# Exploit Title: Abyss Web Server X1 2.11.1 Multiple Local Privilege Escalation
# Exploit Title: Fortitude HTTP 1.0.4.0 Unquoted Service Path Elevation of Privilege
#!/usr/bin/python
KL-001-2016-007 : Cisco Firepower Threat Management Console Remote Command
KL-001-2016-006 : Cisco Firepower Threat Management Console Local File Inclusion
KL-001-2016-005 : Cisco Firepower Threat Management Console Hard-coded MySQL
import socket
Mambo SQL Injection
# Exploit Title: Windows Firewall Control Unquoted Service Path Privilege Escalation
# Exploit Title: DWebPro 8.4.2 Remote Binary Execution
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=860
=============================================
#!/usr/bin/python
# Exploit Title: Netgear Genie 2.4.32 Unquoted Service Path Elevation of Privilege
# Title : KeepNote 0.7.8 Remote Command Execution
# Exploit Title: Grandstream GXV3611_HD Telnet SQL Injection and backdoor command
# Title : Symantec Messaging Gateway
# Title: Glassfish Server - Unquoted Service Path Privilege Escalation
Exploit Title: VLC Media Player 2.2.1 Buffer Overflow
NetMan 204 - Backdoor Account
# Exploit Title: TP-Link Archer CR-700 XSS vulnerability
#Title : Freepbx < 13.0.188 , Remote root exploit
# Exploit Title: NetDrive 2.6.12 Unquoted Service Path Elevation of Privilege