dizqueTV 1.5.3 – Remote Code Execution (RCE)
# Exploit Title: dizqueTV 1.5.3 - Remote Code Execution (RCE)
jsp 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: dizqueTV 1.5.3 - Remote Code Execution (RCE)
#!/usr/bin/env python3
Exploit Title: STARFACE 7.3.0.10 - Authentication with Password Hash Possible
# Exploit Title: Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated)
# Exploit Title: ZKTeco ZEM/ZMM 8.88 - Missing Authentication
# Exploit Title: Desktop Central 9.1.0 - Multiple Vulnerabilities
# Exploit Title: Openfire 4.6.0 - 'sql' Stored XSS
# Exploit Title: Openfire 4.6.0 - 'users' Stored XSS
# Exploit Title: Openfire 4.6.0 - 'groupchatJID' Stored XSS
# Exploit Title: Openfire 4.6.0 - 'path' Stored XSS
# Exploit Title: Atlassian Confluence 6.15.1 - Directory Traversal (Metasploit)
# Exploit Title: Atlassian Confluence 6.15.1 - Directory Traversal
# Exploit Title: NetGain EM Plus
# Unauthenticated XML External Entity (XXE) in Ahsay Backup v7.x - v8.1.0.50.
# Exploit Title: Authenticated insecure file upload and code execution flaw in Ahsay Backup v7.x - v8.1.1.50. (Metasp...
# Exploit Title: Ahsay Backup 8.1.1.50 - Insecure File Upload and Code Execution (Authenticated)
# Exploit Title: Liferay Portal < 7.1 CE GA4 / SimpleCaptcha API XSS
# Exploit Title: dotCMS 5.1.1 - HTML Injection
#!/usr/bin/python
# Exploit Title: Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 - arbitrary file upload
# Exploit Title: Sophos Cyberoam UTM - Privilege Escalation
Core Security - Corelabs Advisory
# Exploit Title: Oracle E-Business suite Open Redirect
# [CVE-2017-7997] Gespage SQL Injection vulnerability
Title: OpenText Document Sciences xPression (formerly EMC Document
Title: OpenText Document Sciences xPression (formerly EMC Document
require 'msf/core'
This is an advisory for CVE-2017-6327 which is an unauthenticated remote
DALIM SOFTWARE ES Core 5.0 build 7184.1 Server-Side Request Forgery
DALIM SOFTWARE ES Core 5.0 build 7184.1 Multiple Remote File Disclosures
#!/usr/bin/env python
#!/usr/bin/env ruby
# Exploit Title: Oracle E-Business Suite - Server Side Request Forgery
Application: Oracle E-Business Suite
##################################################################
# Exploit Title: NetGain Enterprise Manager – “Ping” Command Injection
=====[ Tempest Security Intelligence - ADV-3/2016 CVE-2016-6283 ]==============
ZKTeco ZKBioSecurity 3.0 (visLogin.jsp) Local Authorization Bypass
ZKTeco ZKBioSecurity 3.0 File Path Manipulation Vulnerability