Express Invoice 7.12 – ‘Customer’ Persistent Cross-Site Scripting
# Exploit Title: Express Invoice 7.12 - 'Customer' Persistent Cross-Site Scripting
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Express Invoice 7.12 - 'Customer' Persistent Cross-Site Scripting
# Title: Ajenti 2.1.31 - Remote Code Execution
# Exploit Title: Kirona-DRS 5.5.3.5 - Information Disclosure
The trick is to use a vertical tab (`%09`) and then place another URL in the tag. So once a victim clicks the link on...
Normal URLs like http://redirect.local/test will be forwared to https://redirect.local/test. But by using newlines (C...
So far we know that adding `?static=1` to a wordpress URL should leak its secret content
# Exploit Title: National Instruments Circuit Design Suite 14.0 - Local Privilege Escalation
# Exploit Title: Intelbras Router WRN150 1.0.18 - Persistent Cross-Site Scripting
# Exploit Title: WordPress Arforms 3.7.1 - Directory Traversal
# Exploit Title: SMA Solar Technology AG Sunny WebBox device - 1.6 - Cross-Site Request Forgery
# Exploit Title: TP-Link TL-WR1043ND 2 - Authentication Bypass
We have encountered a Windows kernel crash in the win32k.sys driver while processing a corrupted TTF font file. An ex...
We have encountered a Windows kernel crash in nt!MiOffsetToProtos while trying to load a malformed PE image into the ...
We have encountered a Windows kernel crash in CI!CipFixImageType while trying to load a malformed PE image into the p...
We have encountered a Windows kernel crash in memcpy() called by nt!MiParseImageLoadConfig while trying to load a mal...
We have encountered a Windows kernel crash in CI!HashKComputeFirstPageHash while trying to load a malformed PE image ...
We have encountered a Windows kernel crash in memcpy() called by nt!MiRelocateImage while trying to load a malformed ...
# Exploit Title: DeviceViewer 3.12.0.1 - Arbitrary Password Change
# Exploit Title: Sricam DeviceViewer 3.12.0.1 - 'add user' Local Buffer Overflow (DEP Bypass)
# Exploit Title: Foscam Video Management System 1.1.6.6 - 'UID' Denial of Service (PoC)
=== Summary ===
# Exploit Title: Zabbix 4.4 - Authentication Bypass
# Exploit Title: Joomla 3.4.6 - 'configuration.php' Remote Code Execution
# Exploit Title: logrotten 3.15.1 - Privilege Escalation
# Exploit Title: Zabbix 4.2 - Authentication Bypass
# Exploit Title: ASX to MP3 converter 3.1.3.7 - '.asx' Local Stack Overflow (DEP)
# Title: Subrion 4.2.1 - 'Email' Persistant Cross-Site Scripting
# Exploit Title: IBM Bigfix Platform 9.5.9.62 - Arbitrary File Upload
# Exploit Title: CheckPoint Endpoint Security Client/ZoneAlarm 15.4.062.17802 - Privilege Escalation
# Exploit Title: freeFTP 1.0.8 - Remote Buffer Overflow
# Exploit Title: LabCollector (Laboratory Information System) 5.423 - Multiples SQL Injection
The following issue exists in the android-msm-wahoo-4.4-pie branch of https://android.googlesource.com/kernel/msm (an...
# Exploit Title: mintinstall (aka Software Manager) object injection
# Exploit Title: Information disclosure (MySQL password) in error log
#!/usr/bin/php
#!/usr/bin/env python
# Exploit Title: Ciftokic 2.4a - DoS Buffer Overflow
# Exploit Title: Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0
Exploit Title: "Display Name" Stored Unauthenticated XSS in DNN v9.3.2
VULNERABILITY DETAILS
VULNERABILITY DETAILS
#!/usr/bin/env python3
# Exploit Title: GoAhead Web server HTTP Header Injection.