XMLBlueprint 16.191112 – XML External Entity Injection
# Exploit Title: XMLBlueprint 16.191112 - XML External Entity Injection
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: XMLBlueprint 16.191112 - XML External Entity Injection
# Exploit Title: Microsoft Windows 10 - Theme API 'ThemePack' File Parsing
# Exploit Title: Satellian 1.12 - Remote Code Execution
# Exploit Title: Centreon 19.10.5 - 'Pollers' Remote Command Execution
# Exploit Title: Centreon 19.10.5 - 'centreontrapd' Remote Command Execution
# Exploit Title: Fifthplay S.A.M.I 2019.2_HP - Persistent Cross-Site Scripting
# Exploit Title: Adive Framework 2.0.8 - Cross-Site Request Forgery (Change Admin Password)
# Exploit Title: Octeth Oempro 4.8 - 'CampaignID' SQL Injection
# Exploit Title: Centreon 19.10.5 - Database Credentials Disclosure
# Exploit Title: Centreon 19.10.5 - Remote Command Execution
The attached tiff image causes a crash in ImageIO on the latest macOS and iOS. To reproduce the issue, the attached c...
# Exploit Title: Torrent 3GP Converter 1.51 - Stack Overflow (SEH)
# PoC for the SWAPGS attack ([CVE-2019-1125](https://nvd.nist.gov/vuln/detail/CVE-2019-1125))
# Exploit Title: TP-Link TP-SG105E 1.0.0 - Unauthenticated Remote Reboot
# Exploit Title: Webtareas 2.0 - 'id' SQL Injection
# Exploit Title: OLK Web Store 2020 - Cross-Site Request Forgery
# Exploit Title: Genexis Platinum-4410 2.1 - Authentication Bypass
# Exploit Title: qdPM 9.1 - Remote Code Execution
# Exploit Title: BOOTP Turbo 2.0 - Denial of Service (SEH)(PoC)
# Exploit Title: Pachev FTP Server 1.0 - Path Traversal
#include "BlueGate.h"
#include "BlueGate.h"
# Exploit Title: Citrix XenMobile Server 10.8 - XML External Entity Injection
# Exploit Title : KeePass 2.44 - Denial of Service (PoC)
This proof of concept code monitors file changes on Ricoh's driver DLL files and overwrites
# Exploit Title: ManageEngine Network Configuration Manager 12.2 - 'apiKey' SQL Injection
# Exploit Title: NEOWISE CARBONFTP 1.4 - Weak Password Encryption
#!/usr/bin/env python3
# Exploit Title: Easy XML Editor 1.7.8 - XML External Entity Injection
# Exploit Title: Adive Framework 2.0.8 - Persistent Cross-Site Scripting
# Exploit Title: Sysax Multi Server 5.50 - Denial of Service (PoC)
####################################################################
# Exploit Title: APKF Product Key Finder 2.5.8.0 - 'Name' Denial of Service (PoC)
# Exploit Title: Torrent FLV Converter 1.51 Build 117 - Stack Oveflow (SEH partial overwrite)
# Exploit Title: Wordpress Plugin InfiniteWP Client 1.9.4.5 - Authentication Bypass
# Exploit Title: Trend Micro Maximum Security 2019 - Arbitrary Code Execution
# Exploit Title: Wordpress Time Capsule Plugin 1.21.16 - Authentication Bypass
# Exploit Title: GTalk Password Finder 2.2.1 - 'Key' Denial of Service (PoC)
# Exploit Title: Trend Micro Maximum Security 2019 - Privilege Escalation
# Exploit Title: WordPress Plugin Postie 1.9.40 - Persistent Cross-Site Scripting
# Exploit Title: Rukovoditel Project Management CRM 2.5.2 - 'reports_id' SQL Injection
# Exploit Title: Jenkins Gitlab Hook Plugin 1.4.2 - Reflected Cross-Site Scripting
# Exploit Title: Online Book Store 1.0 - Arbitrary File Upload
# Exploit Title: Citrix Application Delivery Controller (ADC) and Gateway 13.0 - Path Traversal
# Exploit Title: Rukovoditel Project Management CRM 2.5.2 - 'entities_id' SQL Injection
# Exploit: SunOS 5.10 Generic_147148-26 - Local Privilege Escalation
# Exploit Title: Rukovoditel Project Management CRM 2.5.2 - 'filters' SQL Injection