rConfig 3.93 – ‘ajaxAddTemplate.php’ Authenticated Remote Code Execution
# Exploit Title: rConfig 3.93 - 'ajaxAddTemplate.php' Authenticated Remote Code Execution
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: rConfig 3.93 - 'ajaxAddTemplate.php' Authenticated Remote Code Execution
# Exploit Title: rConfig 3.9 - 'searchColumn' SQL Injection
# Exploit Title: ASUS AXSP 1.02.00 - 'asComSvc' Unquoted Service Path
class MetasploitModule < Msf::Auxiliary
class MetasploitModule < Msf::Auxiliary
# Exploit Title: Wordpress Plugin Search Meter 2.13.2 - CSV Injection
#!/usr/bin/python3
# Exploit Title: Wing FTP Server 6.2.3 - Privilege Escalation
# Exploit Title: TeamCity Agent XML-RPC 10.0 - Remote Code Execution
## exploit-inc-inclusion.py
## exploit-phar-loading.py
# Exploit Title: Sysaid 20.1.11 b26 - Remote Command Execution
# Exploit Title: YzmCMS 5.5 - 'url' Persistent Cross-Site Scripting
# Exploit Title: Persian VIP Download Script 1.0 - 'active' SQL Injection
# Exploit Title: 60CycleCMS - 'news.php' Multiple vulnerability
# Exploit Title: Sentrifugo HRMS 3.2 - 'id' SQL Injection
So I’ve been holding onto this neat little gem of a .bsp that has four bytes very close to the end of the file that c...
# Exploit Title: Iskysoft Application Framework Service 2.4.3.241 - 'IsAppService' Unquoted Service Path
# Exploit Title: SpyHunter 4 - 'SpyHunter 4 Service' Unquoted Service Path
# Exploit Title: ASUS GiftBox Desktop 1.1.1.127 - 'ASUSGiftBoxDesktop' Unquoted Service Path
# Exploit Title: Deep Instinct Windows Agent 1.2.29.0 - 'DeepMgmtService' Unquoted Service Path
# Exploit Title: UniSharp Laravel File Manager 2.0.0 - Arbitrary File Read
# Exploit Title: RICOH Aficio SP 5200S Printer - 'entryNameIn' HTML Injection
# Exploit Title: Alfresco 5.2.4 - Persistent Cross-Site Scripting
# Exploit Title: GUnet OpenEclass 1.7.3 E-learning platform - 'month' SQL Injection
# Exploit Title: RICOH Aficio SP 5210SF Printer - 'entryNameIn' HTML Injection
# Exploit Title: Joplin Desktop 1.0.184 - Cross-Site Scripting
# Exploit Title: Cyberoam Authentication Client 2.1.2.7 - Buffer Overflow (SEH)
# Exploit Title: Netis WF2419 2.2.36123 - Remote Code Execution
# Exploit Title: Wordpress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery (Add User)
# Exploit Title: TL-WR849N 0.9.1 4.16 - Authentication Bypass (Upload Firmware)
# Exploit Title: Microsoft Exchange 2019 15.2.221.12 - Authenticated Remote Code Execution
# Exploit Title: Wing FTP Server 6.2.5 - Privilege Escalation
# Exploit Title: TP LINK TL-WR849N - Remote Code Execution
# Exploit Title: CA Unified Infrastructure Management Nimsoft 7.80 - Remote Buffer Overflow
# Exploit Title: Intelbras Wireless N 150Mbps WRN240 - Authentication Bypass (Config Upload)