Symantec Advanced Secure Gateway (ASG) / ProxySG – Unrestricted File Upload
===========Security Intelligence============
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
===========Security Intelligence============
# Exploit Title: Notepad++ all x64 versions before 7.7. Remote memory corruption via .ml file.
import struct
# Exploit Title: CollegeManagementSystem-CMS 1.3 - 'batch' SQL Injection
# Exploit Title: Ticket-Booking 1.4 - Authentication Bypass
# Exploit Title: College-Management-System 1.2 - Authentication Bypass
# Exploit Title: Folder Lock v7.7.9 Denial of Service Exploit
# Exploit Title: Dolibarr ERP/CRM 10.0.1 - User-Agent Http Header Cross
=============================================
SEC Consult Vulnerability Lab Security Advisory < 20190912-0 >
Microsoft DirectWrite is a modern Windows API for high-quality text rendering. A majority of its code resides in the ...
Microsoft DirectWrite is a modern Windows API for high-quality text rendering. A majority of its code resides in the ...
# Exploit Title: AVCON6 systems management platform - OGNL - Remote root command execution
#!/usr/bin/env python
# Exploit Title: WordPress Plugin Photo Gallery by 10Web Add new and in add galleries / Gallery groups. GET request ...
# Exploit Title: WordPress Plugin Photo Gallery by 10Web
# Exploit Title: WordPress Plugin Photo Gallery by 10Web
#!/usr/bin/perl -w
# Exploit Title: Dolibarr ERP/CRM - elemid Sql Injection
#--------------------------------------------------------------------#
#!/usr/bin/python
#--------------------------------------------------------------------#
# Exploit Title: Online Appointment SQL Injection
# Exploit Title: WordPress Plugin Sell Downloads 1.0.86 - Cross Site Scripting
# Exploit Title: Dolibarr ERP/CRM - Multiple Sql Injection
#!/usr/bin/python
# Exploit Title: Inventory Webapp SQL injection
[+] Credits: John Page (aka hyp3rlinx)
#!/usr/bin/python3
#####################################################################################
CVE:CVE-2019-15889
Multiple Cross-Site Scripting (XSS) in the web interface of DASAN Zhone ZNID GPON 2426A EU version S3.1.285 applicati...
# Exploit Title: FileThingie 2.5.7 - Arbitrary File Upload
#!/usr/bin/perl -w
# Exploit Title: Opencart 3.x.x Authenticated Stored XSS
#!C:\Python27\python.exe
#!C:\Python27\python.exe
#!C:\Python27\python.exe