Exploits

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers

共24745Exploits
日期 标题 类型 平台 作者
2013-10-25

JReport – ‘dealSchedules.jsp’ Cross-Site Request Forgery

  • webapps
  • jsp
  • Poonam Singh
    2013-10-24

    FortKnox Personal Firewall 9.0.305.0/10.0.305.0 – Kernel Driver ‘fortknoxfw.sys’ Memory Corruption

  • dos
  • windows
  • Arash Allebrahim
    2013-10-24

    WordPress Theme SAICO 1.0 < 1.0.2 - Arbitrary File Upload

  • webapps
  • php
  • Byakuya Kouta
    2013-10-23

    WordPress Theme Daily Deal – Arbitrary File Upload

  • webapps
  • php
  • DevilScreaM
    2013-10-23

    ASF Demux for VideoLAN VLC Media Player 2.0.x – Denial of Service (PoC)

  • dos
  • windows
  • Pedro Ribeiro
    2013-10-22

    WebTester 5.x – Command Execution (Metasploit)

  • remote
  • unix
  • Metasploit
    2013-10-22

    ARRIS DG860A – NVRAM Backup Password Disclosure

  • webapps
  • hardware
  • Justin Oberdorf
    2013-10-22

    Interactive Graphical SCADA System – Remote Command Injection (Metasploit)

  • remote
  • windows
  • Metasploit
    2013-10-22

    HP Intelligent Management Center BIms UploadServlet – Directory Traversal (Metasploit)

  • remote
  • windows
  • Metasploit
    2013-10-22

    D-Link DIR-605L – Captcha Handling Buffer Overflow (Metasploit)

  • remote
  • hardware
  • Metasploit
    2013-10-22

    Avira Internet Security – ‘avipbb.sys’ Filter Bypass / Privilege Escalation

  • local
  • windows
  • Ahmad Moghimi
    2013-10-21

    Course Registration Management System – Cross-Site Scripting / SQL Injection

  • webapps
  • php
  • Omar Kurt
    2013-10-21

    Apache Shindig – XML External Entity Information Disclosure

  • remote
  • multiple
  • Kousuke Ebihara
    2013-10-20

    Joomla! Component Maian15 – ‘name’ Arbitrary File Upload

  • webapps
  • php
  • SultanHaikal
    2013-10-20

    ZonPHP 2.25 – Remote Code Execution

  • webapps
  • php
  • Halim Cruzito
    2013-10-19

    WHMCompleteSolution (WHMCS) 5.2.8 – SQL Injection

  • webapps
  • php
  • g00n
    2013-10-19

    WordPress Theme Area53 – Arbitrary File Upload

  • webapps
  • php
  • Byakuya Kouta
    2013-10-18

    SikaBoom – Remote Buffer Overflow (Metasploit)

  • remote
  • windows
  • Asesino04
    2013-10-18

    Elite Graphix ElitCMS 1.01 / PRO – Multiple Web Vulnerabilities

  • webapps
  • multiple
  • Vulnerability-Lab
    2013-10-18

    PHP Point Of Sale – ‘ofc_upload_image.php’ Remote Code Execution

  • remote
  • php
  • Gabby
    2013-10-17

    Woltlab Burning Board Regenbogenwiese 2007 Addon – SQL Injection

  • webapps
  • php
  • Easy Laster
    2013-10-17

    WordPress Plugin Realty – Blind SQL Injection

  • webapps
  • php
  • Napsterakos
    2013-10-17

    Zikula CMS 1.3.5 – Multiple Vulnerabilities

  • webapps
  • php
  • Vulnerability-Lab
    2013-10-17

    WordPress Plugin Quick Paypal Payments 3.0 – Presistant Cross-Site Scripting

  • webapps
  • php
  • Zy0d0x
    2013-10-16

    WebTester 5.x – Multiple Vulnerabilities

  • webapps
  • php
  • X-Cisadane
    2013-10-15

    UbiDisk File Manager 2.0 iOS – Multiple Web Vulnerabilities

  • webapps
  • ios
  • Vulnerability-Lab
    2013-10-15

    OliveOffice Mobile Suite 2.0.3 iOS – Local File Inclusion

  • webapps
  • ios
  • Vulnerability-Lab
    2013-10-15

    My File Explorer 1.3.1 iOS – Multiple Web Vulnerabilities

  • webapps
  • ios
  • Vulnerability-Lab
    2013-10-15

    Microsoft Internet Explorer – CDisplayPointer Use-After-Free (MS13-080) (Metasploit)

  • remote
  • windows
  • Metasploit
    2013-10-15

    HP Data Protector – Cell Request Service Buffer Overflow (Metasploit)

  • remote
  • windows
  • Metasploit
    2013-10-15

    Zabbix 2.0.8 – SQL Injection / Remote Code Execution (Metasploit)

  • webapps
  • unix
  • Jason Kratzer
    2013-10-15

    Dolibarr ERP/CRM 3.4.0 – ‘exportcsv.php?sondage’ SQL Injection

  • webapps
  • php
  • drone
    2013-10-15

    WordPress Plugin Dexs PM System – (Authenticated) Persistent Cross-Site Scripting

  • webapps
  • php
  • TheXero
    2013-10-15

    Beetel Connection Manager PCW_BTLINDV1.0.0B04 – Local Buffer Overflow (SEH)

  • local
  • windows
  • metacom
    2013-10-15

    Aladdin Knowledge Systems Ltd. PrivAgent – ActiveX Control Overflow

  • remote
  • windows
  • blake
    2013-10-15

    Level One Enterprise Access Point (Multiple Devices) – ‘backupCfg.cgi’ Security Bypass

  • remote
  • hardware
  • Richard Weinberger
    2013-10-15

    Oracle GlassFish Server 2.1.1/3.0.1 – Multiple Subcomponent Resource Identifier Traversal Arbitrary File Access

  • remote
  • multiple
  • Alex Kouzemtchenko
    2013-10-15

    DornCMS Application 1.4 – Multiple Web Vulnerabilities

  • webapps
  • linux
  • Vulnerability-Lab
    2013-10-15

    Apple iOS 7.0.2 – Sim Lock Screen Display Bypass

  • webapps
  • ios
  • Vulnerability-Lab
    2013-10-14

    D-Link / PLANEX COMMUNICATIONS – ‘RuntimeDiagnosticPing()’ Remote Stack Buffer Overflow

  • remote
  • hardware
  • Craig Heffner
    2013-10-14

    aMSN 0.98.9 Web App – Multiple Vulnerabilities

  • webapps
  • php
  • drone
    2013-10-14

    VMware Hyperic HQ Groovy Script-Console – Java Execution (Metasploit)

  • remote
  • multiple
  • Metasploit
    2013-10-14

    WordPress Plugin Cart66 1.5.1.14 – Multiple Vulnerabilities

  • webapps
  • php
  • absane
    2013-10-14

    Android Zygote – Socket and Fork Bomb (Denial of Service)

  • dos
  • android
  • Luca Verderame
    2013-10-14

    StatusNet/Laconica 0.7.4/0.8.2/0.9.0beta3 – Arbitrary File Reading

  • webapps
  • php
  • spiderboy
    2013-10-14

    Internet Haut Debit Mobile PCW_MATMARV1.0.0B03 – Local Buffer Overflow (SEH)

  • local
  • windows
  • metacom
    2013-10-13

    vBulletin 4.1.x – ‘/install/upgrade.php’ Security Bypass

  • webapps
  • php
  • Joshua Rogers
    2013-10-12

    Fortinet FortiAnalyzer – Cross-Site Request Forgery

  • remote
  • hardware
  • William Costa
    2013-10-11

    IBM Cognos Business Intelligence – XML External Entity Information Disclosure

  • remote
  • multiple
  • IBM
    2013-10-11

    Bilboplanet – ‘auth.php’ SQL Injection

  • webapps
  • php
  • Omar Kurt