Xfilesharing 2.5.1 – Arbitrary File Upload
# Exploit Title: Xfilesharing 2.5.1 - Arbitrary File Upload
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Xfilesharing 2.5.1 - Arbitrary File Upload
# Title: Linear eMerge E3 1.00-06 - Remote Code Execution
# Exploit Title : FUDForum 3.0.9 - Remote Code Execution
# Exploit Title: Technicolor TD5130.2 - Remote Command Execution
# Exploit Title: Technicolor TC7300.B0 - 'hostname' Persistent Cross-Site Scripting
# Title: gSOAP 2.8 - Directory Traversal
# Exploit Title: Fastweb Fastgate 0.00.81 - Remote Code Execution
# Exploit Title: ScanGuard Antivirus 2020 - Insecure Folder Permissions
# Exploit Title: Adrenalin Core HCM 5.4.0 - 'strAction' Reflected Cross-Site Scripting
# Exploit Title: Prima FlexAir Access Control 2.3.38 - Remote Code Execution
# Exploit Title: Adrenalin Core HCM 5.4.0 - 'prntDDLCntrlName' Reflected Cross-Site Scripting
# Exploit Title: Computrols CBAS-Web 19.0.0 - 'username' Reflected Cross-Site Scripting
# Exploit Title: Acronis True Image OEM 19.0.5128 - 'afcdpsrv' Unquoted Service Path
# Exploit Title: eMerge E3 1.00-06 - Unauthenticated Directory Traversal
# Exploit Title: Wondershare Application Framework Service 2.4.3.231 - 'WsAppService' Unquote Service Path
# Exploit Title: eMerge E3 1.00-06 - Privilege Escalation
# Exploit Title: eMerge E3 1.00-06 - Remote Code Execution
# Exploit Title: eMerge E3 1.00-06 - Cross-Site Request Forgery
# Exploit Title: Atlassian Confluence 6.15.1 - Directory Traversal
# Exploit Title: eMerge E3 1.00-06 - Arbitrary File Upload
# Exploit Title: eMerge E3 1.00-06 - 'layout' Reflected Cross-Site Scripting
# Exploit Title: eMerge50P 5000P 4.6.07 - Remote Code Execution
# Exploit Title: eMerge E3 Access Controller 4.6.07 - Remote Code Execution
# Exploit Title: eMerge E3 Access Controller 4.6.07 - Remote Code Execution (Metasploit)
# Exploit Title: CBAS-Web 19.0.0 - Remote Code Execution
# Exploit Title: CBAS-Web 19.0.0 - Cross-Site Request Forgery (Add Super Admin)
# Exploit Title: CBAS-Web 19.0.0 - Information Disclosure
# Exploit Title: CBAS-Web 19.0.0 - Username Enumeration
# Exploit Title: CBAS-Web 19.0.0 - 'id' Boolean-based Blind SQL Injection
# Exploit Title: Prima Access Control 2.3.35 - 'HwName' Persistent Cross-Site Scripting
# Exploit Title: Prima Access Control 2.3.35 - Arbitrary File Upload
# Exploit Title: Atlassian Confluence 6.15.1 - Directory Traversal (Metasploit)
# Title: Optergy 2.3.0a - Remote Code Execution
# Exploit Title: Alps Pointing-device Controller 8.1202.1711.04 - 'ApHidMonitorService' Unquoted Service Path
# Exploit Title: FlexAir Access Control 2.4.9api3 - Remote Code Execution
# Title: Optergy 2.3.0a - Cross-Site Request Forgery (Add Admin)
# Title: Optergy 2.3.0a - Username Disclosure
# Title: Optergy 2.3.0a - Remote Code Execution
# Exploit Title: RTK IIS Codec Service 6.4.10041.133 - 'RtkI2SCodec' Unquote Service Path
# Exploit Title: Adrenalin Core HCM 5.4.0 - 'ReportID' Reflected Cross-Site Scripting
# Exploit Title: FlexAir Access Control 2.3.35 - Authentication Bypass
# Exploit Title: Control Center PRO 6.2.9 - Local Stack Based BufferOverflow (SEH)
# Exploit Title: Wondershare Application Framework Service - "WsAppService" Unquote Service Path
# Exploit Title: Bematech Printer MP-4200 - Denial of Service
# Exploit Title: _GCafé 3.0 - 'gbClienService' Unquoted Service Path
# Exploit Title: Alps HID Monitor Service 8.1.0.10 - 'ApHidMonitorService' Unquote Service Path
# Exploit Title: XML Notepad 2.8.0.4 - XML External Entity Injection
# Exploit Title: iOS IOUSBDeviceFamily 12.4.1 - 'IOInterruptEventSource' Heap Corruption (PoC)
During processing of incoming iMessages, attacker controlled data is deserialized using the