multiple
multiple 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
nostromo 1.9.6 – Remote Code Execution
# Exploit Title: nostromo 1.9.6 - Remote Code Execution
iMessage – Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
During processing of incoming iMessages, attacker controlled data is deserialized using the
WebKit – Universal XSS in JSObject::putInlineSlow and JSValue::putToPrimitive
VULNERABILITY DETAILS
JavaScriptCore – Type Confusion During Bailout when Reconstructing Arguments Objects
The following sample was found by Fuzzilli and then slightly modified. It crashes JSC in debug builds:
JavaScriptCore – GetterSetter Type Confusion During DFG Compilation
The following JavaScript program, found by Fuzzilli and slightly modified, crashes JavaScriptCore built from HEAD and...
WebKit – Universal XSS in HTMLFrameElementBase::isURLAllowed
VULNERABILITY DETAILS
WordPress Core < 5.2.3 - Viewing Unauthenticated/Password/Private Posts
So far we know that adding `?static=1` to a wordpress URL should leak its secret content
Apache Httpd mod_rewrite – Open Redirects
Normal URLs like http://redirect.local/test will be forwared to https://redirect.local/test. But by using newlines (C...
Apache Httpd mod_proxy – Error Page Cross-Site Scripting
The trick is to use a vertical tab (`%09`) and then place another URL in the tag. So once a victim clicks the link on...
AnchorCMS < 0.12.3a - Information Disclosure
# Exploit Title: Information disclosure (MySQL password) in error log
WebKit – Universal XSS Using Cached Pages
VULNERABILITY DETAILS
WebKit – UXSS Using JavaScript: URI and Synchronous Page Loads
VULNERABILITY DETAILS
DotNetNuke 9.3.2 – Cross-Site Scripting
Exploit Title: "Display Name" Stored Unauthenticated XSS in DNN v9.3.2
DotNetNuke < 9.4.0 - Cross-Site Scripting
# Exploit Title: Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0
GoAhead 2.5.0 – Host Header Injection
# Exploit Title: GoAhead Web server HTTP Header Injection.
Gila CMS < 1.11.1 - Local File Inclusion
# Exploit Title: Authenticated Local File Inclusion(LFI) in GilaCMS
Enigma NMS 65.0.0 – SQL Injection
#--------------------------------------------------------------------#
Enigma NMS 65.0.0 – OS Command Injection
#!/usr/bin/python
Enigma NMS 65.0.0 – Cross-Site Request Forgery
#--------------------------------------------------------------------#
Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN – Remote Code Execution
#!/usr/bin/python
Alkacon OpenCMS 10.5.x – Local File inclusion
# Exploit Title: Alkacon OpenCMS 10.5.x - Multiple LFI in Alkacon OpenCms
Alkacon OpenCMS 10.5.x – Cross-Site Scripting (2)
# Exploit Title: Alkacon OpenCMS 10.5.x - Multiple XSS in Alkacon OpenCms
Alkacon OpenCMS 10.5.x – Cross-Site Scripting
# Exploit Title: Alkacon OpenCMS 10.5.x - Multiple XSS in Apollo Template
Webkit JSC: JIT – Uninitialized Variable Access in ArgumentsEliminationPhase::transform
https://github.com/WebKit/webkit/blob/94e868c940d46c5745869192d07255331d00102b/Source/JavaScriptCore/dfg/DFGArguments...
Tableau – XML External Entity
# Exploit Title: Tableau XXE
Nimble Streamer 3.0.2-2 < 3.5.4-9 - Directory Traversal
# Nimble Streamer 3.0.2-2 to 3.5.4-9 - Path Traversal
Cisco UCS Director, Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data – Multiple Vulnerabilities
>> Multiple critical vulnerabilities in Cisco UCS Director, Cisco Integrated Management Controller Supervisor and Cis...
Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN – Arbitrary File Disclosure (Metasploit)
# Exploit Title: File disclosure in Pulse Secure SSL VPN (metasploit)
NSKeyedUnarchiver – Info Leak in Decoding SGBigUTF8String
There is an info leak when decoding the SGBigUTF8String class using [SGBigUTF8String initWithCoder:]. This class init...
WebKit – UXSS via XSLT and Nested Document Replacements
VULNERABILITY DETAILS
Aptana Jaxer 1.0.3.4547 – Local File inclusion
# Exploit Title: Aptana Jaxer Remote Local File inclusion
ARMBot Botnet – Arbitrary Code Execution
import requests
Ultimate Loan Manager 2.0 – Cross-Site Scripting
# Exploit Title:Web Studio Ultimate Loan Manager V2.0 - Persistent Cross Site Scripting