Microsoft DirectX SDK 2010 – ‘.PIXrun’ Denial Of Service (PoC)
#Exploit Title: Microsoft DirectX SDK 2010 - '.PIXrun' Denial Of Service (PoC)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
#Exploit Title: Microsoft DirectX SDK 2010 - '.PIXrun' Denial Of Service (PoC)
#Exploit Title: SpotAuditor 5.3.2 - 'Base64' Denial Of Service (PoC)
# Exploit Title: iNetTools for iOS 8.20 - 'Whois' Denial of Service (PoC)
# Exploit Title: InduSoft Web Studio 8.1 SP1 - "Atributos" Denial of Service (PoC)
# Title : SMPlayer 19.5.0 - Denial of Service (PoC)
# Exploit Title: Waves MaxxAudio Drivers 1.1.6.0 - 'WavesSysSvc64' Unquoted Service Path
# Exploit Title: InTouch Machine Edition 8.1 SP1 - 'Atributos' Denial of Service (PoC)
# Exploit Title: Easy-Hide-IP 5.0.0.3 - 'EasyRedirect' Unquoted Service Path
# Exploit Title: Microsoft Windows AppXsvc Deployment Extension - Privilege Escalation
#Exploit Title: ProShow Producer 9.0.3797 - ('ScsiAccess') Unquoted Service Path
# Exploit Title: LiteManager 4.5.0 - Insecure File Permissions
There is a use-after-free issue in JSCript (triggerable via Internet Explorer) where the members of the 'arguments' o...
Tested on macOS Mojave (10.14.6, 18G87) and Catalina Beta (10.15 Beta 19A536g).
# Exploit Title: TestLink 1.9.19 - Persistent Cross-Site Scripting
# Exploit Title: GNU Mailutils 3.7 - Local Privilege Escalation
# Exploit Title: Network Management Card 6.2.0 - Host Header Injection
# Exploit Title: OpenNetAdmin 18.1.1 - Remote Code Execution
Tested on Ubuntu 19.10, kernel "5.3.0-19-generic #20-Ubuntu".
mediaserverd has various media parsing responsibilities; its reachable from various sandboxes
# Exploit Title: ipPulse 1.92 - 'Enter Key' Denial of Service (PoC)
#Exploit Title: BartVPN 1.2.2 - 'BartVPNService' Unquoted Service Path
# Exploit Title: Studio 5000 Logix Designer 30.01.00 - 'FactoryTalk Activation Service' Unquoted Service Path
# Exploit Title: Centova Cast 3.2.12 - Denial of Service (PoC)
# Exploit Title: scadaApp for iOS 1.1.4.0 - 'Servername' Denial of Service (PoC)
#Exploit Title: XMedia Recode 3.4.8.6 - '.m3u' Denial Of Service
# EDB Note: Download ~ https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/47683.zip
# Exploit Title: Emerson PAC Machine Edition 9.70 Build 8595 - 'FxControlRuntime' Unquoted Service Path
# Exploit Title: iSmartViewPro 1.3.34 - Denial of Service (PoC)
# Exploit Title: Lexmark Services Monitor 2.27.4.0.39 - Directory Traversal
# Exploit Title: ASUS HM Com Service 1.00.31 - 'asHMComSvc' Unquoted Service Path
# Exploit Title: Open Proficy HMI-SCADA 5.0.0.25920 - 'Password' Denial of Service (PoC)
# Title: Crystal Live HTTP Server 6.01 - Directory Traversal
# Exploit Title: MobileGo 8.5.0 - Insecure File Permissions
# Exploit Title: NCP_Secure_Entry_Client 9.2 - Unquoted Service Paths
# Exploit Title: Centova Cast 3.2.11 - Arbitrary File Download
# Exploit Title: TemaTres 3.0 — Cross-Site Request Forgery (Add Admin)
# Exploit Title: Foscam Video Management System 1.1.4.9 - 'Username' Denial of Service (PoC)
# Exploit Title: TemaTres 3.0 - 'value' Persistent Cross-site Scripting
# Exploit Title: nipper-ng 0.11.10 - Remote Buffer Overflow (PoC)
# Exploit Title: Shrew Soft VPN Client 2.2.2 - 'iked' Unquoted Service Path
# Title: Siemens Desigo PX 6.00 - Denial of Service (PoC)
# Exploit Title: oXygen XML Editor 21.1.1 - XML External Entity Injection