Exploits
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
- 类型
- 漏洞条目
- 总量
- 24,950
- 页码
- 248
vBulletin < 4.2.2 - Memcache Remote Code Execution
vBulletin's memcache setting is vulnerable in certain versions(all
Cisco Unified Communications Manager – Multiple Vulnerabilities
Vantage Point Security Advisory 2015-001
PHPfileNavigator 2.3.3 – Cross-Site Scripting
[+] Credits: John Page aka hyp3rlinx
PHPfileNavigator 2.3.3 – Cross-Site Request Forgery
[+] Credits: John Page aka hyp3rlinx
PHPfileNavigator 2.3.3 – Privilege Escalation
[+] Credits: John Page aka hyp3rlinx
CodoForum 3.3.1 – Multiple SQL Injections
CodoForum 3.3.1: Multiple SQL Injection Vulnerabilities
BigTree CMS 4.2.3 – (Authenticated) SQL Injection
BigTree CMS 4.2.3: Multiple SQL Injection Vulnerabilities
WordPress Plugin WP Symposium 15.1 – ‘get_album_item.php’ SQL Injection
# Exploit Title: Wordpress Plugin wp-symposium Unauthenticated SQL Injection Vulnerability
Apple Mac OSX 10.10.5 – ‘XNU’ Local Privilege Escalation
Source: https://github.com/kpwn/tpwn
XMPlay 3.8.1.12 – ‘.pls’ Local Crash (PoC)
#!/usr/bin/env python
Sagemcom F@ST 3864 V2 – Get Admin Password
#!/bin/bash
Apache ActiveMQ 5.11.1/5.13.2 – Directory Traversal / Command Execution
I have recently been playing with Apache ActiveMQ, and came across a simple but interesting directory traversal flaw ...
Gkplugins Picasaweb – Download File
# Exploit Title: Gkplugins Picasaweb Download File
TOTOLINK Routers – Backdoor / Remote Code Execution
# Exploit Title: TOTOLINK backdoor and RCE exploit POC
Microsoft HTML Help Compiler 4.74.8702.0 – Local Overflow (SEH)
#!/usr/bin/env python
Mozilla Firefox < 39.03 - 'pdf.js' Same Origin Policy
# Exploit Title: Firefox < 39.03 pdf.js same origin policy exploit
Joomla! Component com_memorix – SQL Injection
# Exploit Title: Joomla com_memorix component SQL Injection vulnerability
Joomla! Component com_informations – SQL Injection
# Exploit Title: Joomla com_informations component SQL Injection vulnerability
Ability FTP Server 2.1.4 – ‘afsmain.exe’ ‘USER’ Remote Denial of Service
#!/usr/bin/env python
Ability FTP Server 2.1.4 – Admin Panel ‘AUTHCODE’ Remote Denial of Service
#!/usr/bin/env python
Security IP Camera Star Vision DVR – Authentication Bypass
# Exploit Title: Security IP Camera Star Vision DVR Authentication Bypass
Zend Framework 2.4.2 – PHP FPM XML eXternal Entity Injection
=============================================
Google Chrome 43.0 – Certificate MIME Handling Integer Overflow
#!/usr/bin/python2
Joomla! Component com_jem 2.1.4 – Multiple Vulnerabilities
# Exploit Title: Joomla Event Manager 2.1.4 - Multiple Vulnerabilities
Microsoft Windows 8.1 – DCOM DCE/RPC Local NTLM Reflection Privilege Escalation (MS15-076)
Source: https://github.com/monoxgas/Trebuchet
Microsoft Windows Server 2003 SP2 – TCP/IP IOCTL Privilege Escalation (MS14-070)
################################################################
Geoserver < 2.7.1.1 / < 2.6.4 / < 2.5.5.1 - XML External Entity
# Exploit Title : GeoServer XXE
NeuroServer 0.7.4 – EEG TCP/IP Transceiver Remote Denial of Service
#!/usr/bin/env python
Printer Pro 5.4.3 IOS – Persistent Cross-Site Scripting
Document Title:
NetServe FTP Client 1.0 – Local Denial of Service
# Exploit Title: NetServe FTP Client 1.0 DOS (Overflow).
Havij Pro – Crash (PoC)
#!/usr/bin/env python
WDS CMS – SQL Injection
# ( In The Name Of ALLAH )
WordPress Plugin WPTF Image Gallery 1.03 – Arbitrary File Download
Title: Remote file download vulnerability in wptf-image-gallery v1.03
WordPress Plugin Recent Backups 0.7 – Arbitrary File Download
Title: Remote file download vulnerability in recent-backups v0.7 wordpress plugin
WordPress Plugin Simple Image Manipulator 1.0 – Arbitrary File Download
Title: Remote file download in simple-image-manipulator v1.0 wordpress plugin
WordPress Plugin Candidate Application Form 1.0 – Arbitrary File Download
Title: Remote file download vulnerability in candidate-application-form v1.0 wordpress plugin
WordPress Plugin Video Gallery 2.7 – SQL Injection
# Exploit Title: WordPress Video Gallery 2.7 SQL Injection
Netsparker 2.3.x – Remote Code Execution
#!/usr/bin/python
Apple Mac OSX Keychain – EXC_BAD_ACCESS Denial of Service
# Exploit Title: OSX Keychain - EXC_BAD_ACCESS
Brasero – Crash (PoC)
#!/usr/bin/perl -w
Linux Kernel (x86) – Memory Sinkhole Privilege Escalation
; memory sinkhole proof of concept
Froxlor Server Management Panel 0.9.33.1 – MySQL Login Information Disclosure
#------------------------------------------------------------------------------------------#