FileRun 2019.05.21 – Reflected Cross-Site Scripting
# Exploit Title: FileRun 2019.05.21 - Reflected Cross-Site Scripting
multiple 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: FileRun 2019.05.21 - Reflected Cross-Site Scripting
# Exploit Title: OpenCTI 3.3.1 - Directory Traversal
# Exploit Title: SOS JobScheduler 1.13.3 - Stored Password Decryption
# Exploit Title: Sysax MultiServer 6.90 - Reflected Cross Site Scripting
# Exploit Title: Avaya IP Office 11 - Password Disclosure
# Exploit Title: SmarterMail 16 - Arbitrary File Upload
# Exploit Title: HFS Http File Server 2.3m Build 300 - Buffer Overflow (PoC)
# Title: Cayin Digital Signage System xPost 2.5 - Remote Command Injection
# Title: Cayin Signage Media Player 3.0 - Remote Command Injection (root)
# Title: Cayin Content Management Server 11.0 - Remote Command Injection (root)
# Exploit Title: VMware vCenter Server 6.7 - Authentication Bypass
# Exploit Title : Crystal Shard http-protection 0.2.0 - IP Spoofing Bypass
# Exploit Title: NOKIA VitalSuite SPM 2020 - 'UserName' SQL Injection
# Exploit Title: OpenEDX platform Ironwood 2.5 - Remote Code Execution
#!/usr/bin/python
Exploit Title: HP LinuxKI 6.01 - Remote Command Injection
# Exploit Title: LibreNMS 1.46 - 'search' SQL Injection
# Exploit Title: Saltstack 3000.1 - Remote Code Execution
# Exploit Title: EspoCRM 5.8.5 - Privilege Escalation
# Title: WhatsApp Desktop 0.3.9308 - Persistent Cross-Site Scripting
# Exploit Title: FIBARO System Home Center 5.021 - Remote File Include
# Exploit Title: CyberArk PSMP 10.9.1 - Policy Restriction Bypass
# VSCode Python Extension Code Execution
So I’ve been holding onto this neat little gem of a .bsp that has four bytes very close to the end of the file that c...
# Exploit Title: Wing FTP Server 6.2.5 - Privilege Escalation
# Exploit Title: Joplin Desktop 1.0.184 - Cross-Site Scripting
#!/usr/bin/python
#!/usr/bin/env python
While investigating possible shared memory issues in AGXCommandQueue::processSegmentKernelCommand(), I noticed that t...
# Exploit Title: Forcepoint WebSecurity 8.5 - Reflective Cross-Site Scripting
# Exploit Title: Google Invisible RECAPTCHA 3 - Spoof Bypass
#!/usr/bin/python3
#!/usr/bin/python3
The attached tiff image causes a crash in ImageIO on the latest macOS and iOS. To reproduce the issue, the attached c...
# Exploit Title : KeePass 2.44 - Denial of Service (PoC)
# Exploit Title: Citrix Application Delivery Controller (ADC) and Gateway 13.0 - Path Traversal