multiple
multiple 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
Oracle Hyperion Planning 11.1.2.3 – XML External Entity
- Exploit Title: XXE Injection Oracle Hyperion
iMessage – NSKeyedUnarchiver Deserialization Allows file Backed NSData Objects
The class _NSDataFileBackedFuture can be deserialized even if secure encoding is enabled. This class is a file-backed...
iMessage – Memory Corruption when Decoding NSKnownKeysDictionary1
There is a memory corruption vulnerability when decoding an object of class NSKnownKeysDictionary1. This class decod...
iMessage – NSArray Deserialization can Invoke Subclass that does not Retain References
When deserializing a class with initWithCoder, subclasses of that class can also be deserialized so long as they do n...
macOS / iOS JavaScriptCore – JSValue Use-After-Free in ValueProfiles
While fuzzing JSC, I encountered the following JS program which crashes JSC from current HEAD and release (/System/Li...
macOS / iOS JavaScriptCore – Loop-Invariant Code Motion (LICM) Leaves Object Property Access Unguarded
While fuzzing JavaScriptCore, I encountered the following (modified and commented) JavaScript program which crashes j...
macOS / iOS NSKeyedUnarchiver – Use-After-Free of ObjC Objects when Unarchiving OITSUIntDictionary Instances
When deserializing NSObjects with the NSArchiver API [1], one can supply a whitelist of classes that are allowed to b...
Trend Micro Deep Discovery Inspector IDS – Security Bypass
[+] Credits: John Page (aka hyp3rlinx)
Mozilla Spidermonkey – Unboxed Objects Uninitialized Memory Access
For constructors, Spidermonkey implements a "definite property analysis" [1] to compute which properties will definit...
Firefox 67.0.4 – Denial of Service
Loading please wait
Symantec DLP 15.5 MP1 – Cross-Site Scripting
# Exploit Title: Persistent XSS on Symantec DLP
CyberPanel 1.8.4 – Cross-Site Request Forgery
# Title: CyberPanel Administrator Account Takeover
Sahi pro 8.x – Directory Traversal
# Exploit Title: Sahi pro (8.x) Directory traversal
SAP Crystal Reports – Information Disclosure
# Exploit Title: [Sensitive Information Disclosure in SAP Crystal Reports]
Varient 1.6.1 – SQL Injection
===========================================================================================
Mozilla Spidermonkey – IonMonkey ‘Array.prototype.pop’ Type Confusion
The following program (found through fuzzing and manually modified) crashes Spidermonkey built from the current beta ...
SuperDoctor5 – ‘NRPE’ Remote Code Execution
# SuperMicro implemented a Remote Command Execution plugin in their implementation of
GrandNode 4.40 – Path Traversal / Arbitrary File Download
# Exploit Title: GrandNode Path Traversal & Arbitrary File Download (Unauthenticated)
Sahi pro 8.x – Cross-Site Scripting
# Exploit Title: Sahi pro (
Sahi pro 8.x – SQL Injection
# Exploit Title: Sahi pro (
Sahi pro 7.x/8.x – Directory Traversal
# Exploit Title: Sahi pro (
Thunderbird ESR < 60.7.XXX - 'icalrecur_add_bydayrules' Stack-Based Buffer Overflow
X41 D-Sec GmbH Security Advisory: X41-2019-003
Thunderbird ESR < 60.7.XXX - 'parser_get_next_char' Heap-Based Buffer Overflow
X41 D-Sec GmbH Security Advisory: X41-2019-002
Thunderbird ESR < 60.7.XXX - 'icalmemorystrdupanddequote' Heap-Based Buffer Overflow
X41 D-Sec GmbH Security Advisory: X41-2019-001
Thunderbird ESR < 60.7.XXX - Type Confusion
-----BEGIN PGP SIGNED MESSAGE-----
RedwoodHQ 2.5.5 – Authentication Bypass
# -*- encoding: utf-8 -*-
Spidermonkey – IonMonkey Unexpected ObjectGroup in ObjectGroupDispatch Operation
While fuzzing Spidermonkey, I encountered the following (commented and modified) JavaScript program which crashes deb...
Spidermonkey – IonMonkey Leaks JS_OPTIMIZED_OUT Magic Value to Script
IonMonkey can, during a bailout, leak an internal JS_OPTIMIZED_OUT magic value to the running script. This magic valu...
Phraseanet < 4.0.7 - Cross-Site Scripting
# Exploit title: Stored XSS vulnerability in Phraseanet DAM Open Source software
Deltek Maconomy 2.2.5 – Local File Inclusion
# Exploit Title: Maconomy Erp local file include
Zoho ManageEngine ServiceDesk Plus 9.3 – Cross-Site Scripting
# Exploit Title: Zoho ManageEngine ServiceDesk Plus 9.3 Cross-Site Scripting
Zoho ManageEngine ServiceDesk Plus < 10.5 - Improper Access Restrictions
# Exploit Title: Zoho ManageEngine ServiceDesk Plus < 10.5 Incorrect Access Control
Apple macOS < 10.14.5 / iOS < 12.3 JavaScriptCore - AIR Optimization Incorrectly Removes Assignment to Register
While fuzzing JavaScriptCore, I encountered the following JavaScript program which crashes jsc from current HEAD (git...
Apple macOS < 10.14.5 / iOS < 12.3 JavaScriptCore - Loop-Invariant Code Motion (LICM) in DFG JIT Leaves Stack Variable Uninitialized
While fuzzing JavaScriptCore, I encountered the following (modified and commented) JavaScript program which crashes j...
Apple macOS < 10.14.5 / iOS < 12.3 DFG JIT Compiler - 'HasIndexedProperty' Use-After-Free
See also https://bugs.chromium.org/p/project-zero/issues/detail?id=1699 for a similar issue.
Deluge 1.3.15 – ‘URL’ Denial of Service (PoC)
#Exploit Title: Deluge 1.3.15 - 'URL' Denial of Service (PoC)
CyberArk Enterprise Password Vault 10.7 – XML External Entity Injection
# Exploit Title: CyberArk XML External Entity (XXE) Injection in SAML
Cortex Unshortenlink Analyzer < 1.1 - Server-Side Request Forgery
# Exploit Title: Cortex Unshortenlink Analyzer < 1.1 - Server-Side Request Forgery
ReadyAPI 2.5.0 / 2.6.0 – Remote Code Execution
Create a new xpl
Zotonic < 0.47.0 mod_admin - Cross-Site Scripting
# Exploit Title: Zotonic