Free MP3 CD Ripper 2.8 – Stack Buffer Overflow (SEH + Egghunter)
# Exploit Title: Free MP3 CD Ripper 2.8 - Stack Buffer Overflow (SEH + Egghunter)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Free MP3 CD Ripper 2.8 - Stack Buffer Overflow (SEH + Egghunter)
# Exploit Title: Calavera UpLoader 3.5 - 'FTP Logi' Denial of Service (PoC + SEH Overwrite)
# Exploit Title: WordPress Plugin Email Subscribers & Newsletters 4.2.2 - Unauthenticated File Download
# Exploit Title: WordPress Plugin Email Subscribers & Newsletters 4.2.2 - 'hash' SQL Injection (Unauthenticated)
# Exploit Title: PandoraFMS NG747 7.0 - 'filename' Persistent Cross-Site Scripting
# Title: Bludit 3.9.2 - Directory Traversal
# Exploit Title: LibreHealth 2.0.0 - Authenticated Remote Code Execution
# Exploit Title: Online Course Registration 1.0 - Unauthenticated Remote Code Execution
# Exploit Title: elaniin CMS 1.0 - Authentication Bypass
# Exploit Title: Koken CMS 0.22.24 - Arbitrary File Upload (Authenticated)
# Exploit Title: PandoraFMS 7.0 NG 746 - Persistent Cross-Site Scripting
# Exploit Title: Bio Star 2.8.2 - Local File Inclusion
# Exploit Title: Webtareas 2.1p - Arbitrary File Upload (Authenticated)
# Exploit Title: F5 Big-IP 13.1.3 Build 0.0.6 - Local File Inclusion
# Exploit Title: Sickbeard 0.1 - Cross-Site Request Forgery (Disable Authentication)
# Exploit Title: Socket.io-file 2.0.31 - Arbitrary File Upload
# Exploit Title: pfSense 2.4.4-p3 - Cross-Site Request Forgery
# Exploit Title: Virtual Airlines Manager 2.6.2 - Persistent Cross-Site Scripting
# Exploit Title: Rails 5.0.1 - Remote Code Execution
# Title: UBICOD Medivision Digital Signage 1.5.1 - Authorization Bypass
# Exploit Title: FTPDummy 4.80 - Local Buffer Overflow (SEH)
# Exploit Title: Snes9K 0.09z - 'Port Number' Buffer Overflow (SEH)
#!/usr/bin/python3
# Exploit Title: NetPCLinker 1.0.0.0 - Buffer Overflow (SEH Egghunter)
# Exploit Title: Docsify.js 4.11.4 - Reflective Cross-Site Scripting
# Exploit Title: WordPress Theme NexosReal Estate 1.7 - 'search_order' SQL Injection
# Exploit Title: Sophos VPN Web Panel 2020 - Denial of Service (Poc)
# Title: Sonar Qube 8.3.1 - 'SonarQube Service' Unquoted Service Path
# Exploit Title: Simple Startup Manager 1.17 - 'File' Local Buffer Overflow (PoC)
# Exploit Title: CMSUno 1.6 - Cross-Site Request Forgery (Change Admin Password)
# Exploit Title: Wing FTP Server 6.3.8 - Remote Code Execution (Authenticated)
# Exploit Title: SuperMicro IPMI WebInterface 03.40 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: Zyxel Armor X1 WAP6806 - Directory Traversal
# Exploit Title: Joomla! J2 JOBS 1.3.0 - 'sortby' Authenticated SQL Injection
# Exploit Title: Online Polling System 1.0 - Authentication Bypass
# Exploit Title: Web Based Online Hotel Booking System 0.1.0 - Authentication Bypass
# Exploit Title: Online Farm Management System 0.1.0 - Persistent Cross-Site Scripting
# Exploit Title: Infor Storefront B2B 1.0 - 'usr_name' SQL Injection
# Exploit title: BSA Radar 1.6.7234.24750 - Local File Inclusion
# Exploit Title: Park Ticketing Management System 1.0 - 'viewid' SQL Injection
# Exploit Title: Park Ticketing Management System 1.0 - Authentication Bypass
# Exploit Title: HelloWeb 2.0 - Arbitrary File Download
# Exploit Title: Barangay Management System 1.0 - Authentication Bypass
# Exploit Title: Aruba ClearPass Policy Manager 6.7.0 - Unauthenticated Remote Command Execution
# Exploit Title: Wordpress Plugin Powie's WHOIS Domain Check 0.9.31 - Persistent Cross-Site Scripting
# Exploit Title: CompleteFTP Professional < 12.1.3 - Remote Code Execution
# Exploit Title: Savsoft Quiz 5 - Persistent Cross-Site Scripting
# Exploit Title: Qmail SMTP 1.03 - Bash Environment Variable Injection
# Exploit Title: SuperMicro IPMI 03.40 - Cross-Site Request Forgery (Add Admin)