IcoFX 2.6 – ‘.ico’ Buffer Overflow SEH + DEP Bypass using JOP
# Exploit Title: IcoFX 2.6 - '.ico' Buffer Overflow SEH + DEP Bypass using JOP
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: IcoFX 2.6 - '.ico' Buffer Overflow SEH + DEP Bypass using JOP
# Title: Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated)
# Title: Grav CMS 1.7.10 - Server-Side Template Injection (SSTI) (Authenticated)
# Exploit Title: Wordpress Plugin wpDiscuz 7.0.4 - Arbitrary File Upload (Unauthenticated)
# Exploit Title: Monstra CMS 3.0.4 - Remote Code Execution (Authenticated)
# Exploit Title: Gitlab 13.10.2 - Remote Code Execution (Authenticated)
# Exploit Title: Color Notes 1.4 - Denial of Service (PoC)
# Exploit Title: Macaron Notes great notebook 5.5 - Denial of Service (PoC)
# Exploit Title: My Notes Safe 5.3 - Denial of Service (PoC)
# Exploit Title: PHP 8.1.0-dev - 'User-Agentt' Remote Code Execution
# Exploit Title: Seo Panel 4.8.0 - 'from_time' Reflected XSS
# Exploit Title: CHIYU IoT Devices - 'Telnet' Authentication Bypass
# Exploit Title: CHIYU IoT Devices - Denial of Service (DoS)
# Exploit Title: FUDForum 3.1.0 - 'srch' Reflected XSS
# Exploit Title: FUDForum 3.1.0 - 'author' Reflected XSS
# Exploit Title: Gitlab 13.9.3 - Remote Code Execution (Authenticated)
# Exploit Title: 4Images 1.8 - 'redirect' Reflected XSS
# Exploit Title: Thecus N4800Eco Nas Server Control Panel - Comand Injection
# Exploit Title: Apache Airflow 1.10.10 - 'Example Dag' Remote Code Execution
# Exploit Title: GetSimple CMS 3.3.4 - Information Disclosure
# Exploit Title: Intel(R) Audio Service x64 01.00.1080.0 - 'IntelAudioService' Unquoted Service Path
# Exploit Title: Products.PluggableAuthService 2.6.0 - Open Redirect
# Exploit Title: Seo Panel 4.8.0 - 'search_name' Reflected XSS
# Exploit Title: Seo Panel 4.8.0 - 'category' Reflected XSS
# Exploit Title: DupTerminator 1.4.5639.37199 - Denial of Service (PoC)
# Exploit Title: LogonTracer 1.2.0 - Remote Code Execution (Unauthenticated)
# Exploit Title: ProjeQtOr Project Management 9.1.4 - Remote Code Execution
# Exploit Title: Ubee EVW327 - 'Enable Remote Access' Cross-Site Request Forgery (CSRF)
# Exploit Title: WordPress Plugin WP Prayer version 1.6.1 - 'prayer_messages' Stored Cross-Site Scripting (XSS) (Auth...
# Exploit Title: CHIYU IoT devices - 'Multiple' Cross-Site Scripting (XSS)
# Exploit Title: CHIYU TCP/IP Converter devices - CRLF injection
# Exploit Title: Atlassian Jira 8.15.0 - Information Disclosure (Username Enumeration)
# Exploit Title: Veyon 4.4.1 - 'VeyonService' Unquoted Service Path
# Exploit Title: PHPFusion 9.03.50 - Remote Code Execution
# Exploit Title: WordPress Plugin LifterLMS 4.21.0 - Stored Cross-Site Scripting (XSS)
# Exploit Title: Trixbox 2.8.0.4 - 'lang' Remote Code Execution (Unauthenticated)
# Exploit Title: Trixbox 2.8.0.4 - 'lang' Path Traversal
# Exploit Title: Selenium 3.141.59 - Remote Code Execution (Firefox/geckodriver)
# Exploit Title: Postbird 0.8.4 - Javascript Injection
# Exploit Title: RarmaRadio 2.72.8 - Denial of Service (PoC)
# Exploit Title: Codiad 2.8.4 - Remote Code Execution (Authenticated) (3)
# Exploit Title: ProFTPd 1.3.5 - 'mod_copy' Remote Command Execution (2)
# Exploit Title: Pluck CMS 4.7.13 - File Upload Remote Code Execution (Authenticated)
# Exploit Title: Gadget Works Online Ordering System 1.0 - 'Category' Persistent Cross-Site Scripting (XSS)
# Exploit Title: WordPress Plugin Cookie Law Bar 1.2.1 - 'clb_bar_msg' Stored Cross-Site Scripting (XSS)
# Exploit Title: Schlix CMS 2.2.6-6 - Arbitary File Upload And Directory Traversal Leads To RCE (Authenticated)
# Exploit Title: iDailyDiary 4.30 - Denial of Service (PoC)
# Exploit Title: DiskBoss Service 12.2.18 - 'diskbsa.exe' Unquoted Service Path
# Exploit Title: ePowerSvc 6.0.3008.0 - 'ePowerSvc.exe' Unquoted Service Path
# Exploit Title: Shopizer 2.16.0 - 'Multiple' Cross-Site Scripting (XSS)