ECK Hotel 1.0 – Cross-Site Request Forgery (Add Admin)
# Exploit Title : ECK Hotel 1.0 - Cross-Site Request Forgery (Add Admin)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title : ECK Hotel 1.0 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: Everest 5.50.2100 - 'Open File' Denial of Service (PoC)
# Exploit Title: Jinfornet Jreport 15.6 - Unauthenticated Directory Traversal
# Exploit Title: rConfig 3.9.4 - 'searchField' Unauthenticated Root Remote Code Execution
# Exploit Title: TP-Link Archer C50 3 - Denial of Service (PoC)
# Exploit Title: Centreo 19.10.8 - 'DisplayServiceStatus' Remote Code Execution
# Exploit Title: Joomla! Component GMapFP 3.30 - Arbitrary File Upload
# Exploit Title: AVAST SecureLine 5.5.522.0 - 'SecureLine' Unquoted Service Path
# Exploit Title: LeptonCMS 4.5.0 - Persistent Cross-Site Scripting
# Exploit Title: 10-Strike Network Inventory Explorer - 'srvInventoryWebServer' Unquoted Service Path
# Exploit Title: 10-Strike Network Inventory Explorer 8.54 - 'Add' Local Buffer Overflow (SEH)
# Exploit Title: UliCMS 2020.1 - Persistent Cross-Site Scripting
# Exploit Title: Wordpress Plugin WPForms 1.5.8.2 - Persistent Cross-Site Scripting
# Exploit Title: Veyon 4.3.4 - 'VeyonService' Unquoted Service Path
# Exploit Title: UCM6202 1.0.18.13 - Remote Command Injection
# Exploit Title: ProficySCADA for iOS 5.0.25920 - 'Password' Denial of Service (PoC)
# Exploit Title: Google Chrome 80.0.3987.87 - Heap-Corruption Remote Denial of Service (PoC)
Vulnerable Source:
# Exploit Title: CyberArk PSMP 10.9.1 - Policy Restriction Bypass
# Exploit Title: FIBARO System Home Center 5.021 - Remote File Include
# Exploit Title: rConfig 3.9.4 - 'search.crud.php' Remote Command Injection
# Exploit Title: Joomla! com_hdwplayer 4.2 - 'search.php' SQL Injection
FreeBSD 12.0-RELEASE x64 Kernel Exploit
# Exploit Title: Exagate Sysguard 6001 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: VMware Fusion 11.5.2 - Privilege Escalation
# Exploit Title: Netlink GPON Router 1.0.11 - Remote Code Execution
# Exploit Title: NetBackup 7.0 - 'NetBackup INET Daemon' Unquoted Service Path
# Excploit Title: Microtik SSH Daemon 6.44.3 - Denial of Service (PoC)
# Exploit Title: Joomla! ACYMAILING 3.9.0 component - Unauthenticated Arbitrary File Upload
# Exploit Title: UADMIN Botnet 1.0 - 'link' SQL Injection
# VSCode Python Extension Code Execution
Local Privilege Escalation via VMWare Fusion
# Exploit Title: Enhanced Multimedia Router 3.0.4.27 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: MiladWorkShop VIP System 1.0 - 'lang' SQL Injection
# Exploit Title: PHPKB Multi-Language 9 - Authenticated Remote Code Execution
# Exploit Title: PHPKB Multi-Language 9 - Authenticated Directory Traversal
# Exploit Title: PHPKB Multi-Language 9 - 'image-upload.php' Authenticated Remote Code Execution
# CVE-2020-0796 PoC aka CoronaBlue aka SMBGhost
# Exploit Title: AnyBurn 4.8 - Buffer Overflow (SEH)
# Exploit Title: Centos WebPanel 7 - 'term' SQL Injection
# Exploit Title: Wordpress Plugin Custom Searchable Data System -
# Exploit Title: Drobo 5N2 4.1.1 - Remote Command Injection
# Exploit Title: Joomla! Component com_newsfeeds 1.0 - 'feedid' SQL Injection
# Exploit: WatchGuard Fireware AD Helper Component 5.8.5.10317 - Credential Disclosure
# Exploit Title: Wordpress Plugin Appointment Booking Calendar 1.3.34 - CSV Injection
# Exploit Title: HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: ASUS AAHM 1.00.22 - 'asHmComSvc' Unquoted Service Path