Microsoft Windows Server 2012 – ‘Group Policy’ Remote Code Execution (MS15-011)
# Exploit Title: Microsoft Windows Server 2012 - 'Group Policy' Remote Code Execution
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Microsoft Windows Server 2012 - 'Group Policy' Remote Code Execution
# Exploit Title: Microsoft Windows Server 2012 - 'Group Policy' Security Feature Bypass
Exploit Title: Intelbras Router WRN150 1.0.18 - Cross-Site Request Forgery
Exploit Title: waldronmatt FullCalendar-BS4-PHP-MySQL-JSON 1.21 - 'start' SQL Injection
# Exploit Title: Part-DB 0.4 - Authentication Bypass
Exploit Title: waldronmatt FullCalendar-BS4-PHP-MySQL-JSON 1.21 - 'description' Cross-Site Scripting
# Exploit Title: JumpStart 0.6.0.0 - 'jswpbapi' Unquoted Service Path
Exploit Title: delpino73 Blue-Smiley-Organizer 1.32 - 'datetime' SQL Injection
# Exploit Title: ChaosPro 2.0 - Buffer Overflow (SEH)
VULNERABILITY DETAILS
# PHuiP-FPizdaM
# Exploit Title: ClonOs WEB UI 19.09 - Improper Access Control
# Exploit Title: Wordpress Sliced Invoices 3.8.2 - 'post' SQL Injection
# Exploit Title: AUO SunVeillance Monitoring System 1.1.9e - Incorrect Access Control
# Exploit Title: AUO SunVeillance Monitoring System 1.1.9e - 'MailAdd' SQL Injection
# Title: Rocket.Chat 2.1.0 - Cross-Site Scripting
# Title: IObit Uninstaller 9.1.0.8 - 'IObitUnSvr' Unquoted Service Path
# Exploit Title: Joomla! 3.4.6 - Remote Code Execution (Metasploit)
During an engagement for a client, RandoriSec found 2 vulnerabilities on Moxa EDR-810 Series Secure Routers. The firs...
# Exploit Title: winrar 5.80 64bit - Denial of Service
# Exploit Title: winrar 5.80 - XML External Entity Injection
# Exploit Title: Trend Micro Anti-Threat Toolkit 1.62.0.1218 - Remote Code Execution
We have observed the following access violation exception in the latest version of Adobe Acrobat Reader DC for Window...
@Mediaservice.net Security Advisory #2019-02 (last updated on 2019-10-16)
# Exploit Title: Joomla! 3.4.6 - Remote Code Execution
# Exploit Title: Wordpress FooGallery 1.8.12 - Persistent Cross-Site Scripting
# Exploit Title: Wordpress Soliloquy Lite 2.5.6 - Persistent Cross-Site Scripting
# Exploit Title: Wordpress Popup Builder 3.49 - Persistent Cross-Site Scripting
# Exploit Title: ThinVNC 1.0b1 - Authentication Bypass
# Exploit Title: Restaurant Management System 1.0 - Remote Code Execution
# Exploit Title: BlackMoon FTP Server 3.1.2.1731 - 'BMFTP-RELEASE' Unquoted Serive Path
# Exploit Title: Web Companion versions 5.1.1035.1047 - 'WCAssistantService' Unquoted Service Path
# Exploit Title : WorkgroupMail 7.5.1 - 'WorkgroupMail' Unquoted Service Path
# Lavasoft 2.3.4.7 - 'LavasoftTcpService' Unquoted Service Path
# Exploit Title: Express Accounts Accounting 7.02 - Persistent Cross-Site Scripting
# Exploit Title : Zilab Remote Console Server 3.2.9 - 'zrcs' Unquoted Service Path
# Exploit Title: X.Org X Server 1.20.4 - Local Stack Overflow
# Exploit Title : LiteManager 4.5.0 - 'romservice' Unquoted Serive Path
# Exploit Title: Solaris xscreensaver 11.4 - Privilege Escalation
# Exploit Title : Mikogo 5.2.2.150317 - 'Mikogo-Service' Unquoted Serive Path
# Exploit Title: Whatsapp 2.19.216 - Remote Code Execution
# Exploit Title: Podman & Varlink 1.5.1 - Remote Code Execution
# Exploit Title: Bolt CMS 3.6.10 - Cross-Site Request Forgery
# Exploit Title : sudo 1.8.27 - Security Bypass
# Exploit Title : ActiveFax Server 6.92 Build 0316 - 'ActiveFaxServiceNT' Unquoted Service Path
# Exploit Title: Uplay 92.0.0.6280 - Local Privilege Escalation
# Exploit Title: SpotAuditor 5.3.1.0 - Denial of Service
# Exploit Title: ActiveFax Server 6.92 Build 0316 - 'POP3 Server' Denial of Service