OpenNetAdmin 18.1.1 – Command Injection Exploit (Metasploit)
class MetasploitModule < Msf::Exploit::Remote
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
class MetasploitModule < Msf::Exploit::Remote
# Title: Bullwark Momentum Series JAWS 1.0 - Directory Traversal
# Exploit Title: Product Key Explorer 4.2.0.0 - 'Name' Denial of Service (POC)
# Exploit Title: Product Key Explorer 4.2.0.0 - 'Key' Denial of Service (POC)
# Exploit Title: AppXSvc 17763 - Arbitrary File Overwrite (DoS)
We have observed the following access violation exception in the latest version of Adobe Acrobat Reader DC for Window...
#############################################################
# Exploit Title: Inim Electronics Smartliving SmartLAN 6.x - Hard-coded Credentials
# Exploit Title: Inim Electronics Smartliving SmartLAN 6.x - Unauthenticated Server-Side Request Forgery
# Exploit Title: Inim Electronics Smartliving SmartLAN 6.x - Remote Command Execution
# Exploit Title: Snipe-IT Open Source Asset Management 4.7.5 - Persistent Cross-Site Scripting
# Exploit Title: Omron PLC 1.0.0 - Denial of Service (PoC)
# Exploit Title: PRO-7070 Hazır Profesyonel Web Sitesi 1.0 - Authentication Bypass
# Exploit Title: SpotAuditor 5.3.2 - 'Base64' Local Buffer Overflow (SEH)
# Exploit Title: Yachtcontrol Webapplication 1.0 - Unauthenticated Remote Code Execution
# Exploit Title: Alcatel-Lucent Omnivista 8770 - Remote Code Execution
# Exploit Title : Oracle Siebel Sales 8.1 - Persistent Cross-Site Scripting
Windows 10 UAC bypass for all executable files which are autoelevate true.
// Axel '0vercl0k' Souchet - November 19 2019
# Exploit Title: Verot 2.0.3 - Remote Code Execution
Exploit Title: Integard Pro NoJs 2.2.0.9026 - Remote Buffer Overflow
# Exploit Title: Trend Micro Deep Security Agent 11 - Arbitrary File Overwrite
#Exploit Title: NETGATE Data Backup 3.0.620 - 'NGDatBckpSrv' Unquoted Service Path
#Exploit Title: Amiti Antivirus 25.0.640 - Unquoted Service Path
# Title: Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution
# Exploit Title: Online Clinic Management System 2.2 - HTML Injection
# Exploit Title: Microsoft Visual Basic 2010 Express - XML External Entity Injection
# Exploit Title: Cisco WLC 2504 8.9 - Denial of Service (PoC)
# Exploit Title: OwnCloud 8.1.8 - Username Disclosure
# Exploit Title: Online Invoicing System 2.6 - 'description' Persistent Cross-Site Scripting
# Exploit Title: Intelbras Router RF1200 1.1.3 - Cross-Site Request Forgery
# Exploit Title: Revive Adserver 4.2 - Remote Code Execution
# Exploit Title: Microsoft Windows Media Center 2002 - XML External Entity MotW Bypass
# Exploit Title: Nsauditor 3.1.8.0 - 'Name' Denial of Service (PoC)
# Exploit Title: Visual Studio 2008 - XML External Entity Injection
# Exploit Title: SmartHouse Webapp 6.5.33 - Cross-Site Request Forgery
# Exploit Title: Dokuwiki 2018-04-22b - Username Enumeration
# Exploit Title: Nsauditor 3.1.8.0 - 'Key' Denial of Service (PoC)
# Exploit Title: Max Secure Anti Virus Plus 19.0.4.020 - Insecure File Permissions
# Exploit Title: Anviz CrossChex 4.3.12 - Local Buffer Overflow
# Exploit Title: Microsoft Excel 2016 1901 - XML External Entity Injection
#Exploit Title: SpotAuditor 5.3.2 - 'Key' Denial of Service
# Exploit Title: TexasSoft CyberPlanet 6.4.131 - 'CCSrvProxy' Unquoted Service Path
# Exploit Title: Online Inventory Manager 3.2 - Persistent Cross-Site Scripting
# Exploit Title : Bash 5.0 Patch 11 - SUID Priv Drop Exploit
#Exploit Title: SpotAuditor 5.3.2 - 'Name' Denial Of Service
# Exploit Title : Wordpress 5.3 - User Disclosure
# Exploit Title: GHIA CamIP 1.2 for iOS - 'Password' Denial of Service (PoC)
# Exploit Title: Mersive Solstice 2.8.0 - Remote Code Execution