multiple
multiple 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
Nexpose < 6.4.66 - Cross-Site Request Forgery
# Exploit Title: [Cross Site Request Forgery at Nexpose Automated Actions]
Werkzeug – ‘Debug Shell’ Command Execution
#!/usr/bin/env python
Artifex MuJS 1.0.2 – Integer Overflow
# Exploit Title: DoS caused by the interactive call between two functions
BMC BladeLogic 8.3.00.64 – Remote Command Execution
# Exploit Title: BMC BladeLogic RSCD agent remote exec - XMLRPC version
Oracle VirtualBox < 5.1.30 / < 5.2-rc1 - Guest to Host Escape
# SSD Advisory – Oracle VirtualBox Multiple Guest to Host Escape Vulnerabilities
NEC Univerge SV9100/SV8100 WebPro 10.0 – Configuration Download
NEC Univerge SV9100/SV8100 WebPro 10.0 Remote Configuration Download
DarkComet (C2 Server) – File Upload
#!/usr/bin/env python3
Transmission – RPC DNS Rebinding
The transmission bittorrent client uses a client/server architecture, the user interface is the client and a daemon r...
SAP NetWeaver J2EE Engine 7.40 – SQL Injection
#!/usr/bin/env python
Oracle WebLogic < 10.3.6 - 'wls-wsat' Component Deserialisation Remote Command Execution
#!/usr/bin/env python
EMC xPression 4.5SP1 Patch 13 – ‘model.jobHistoryId’ SQL Injection
Title: EMC xDashboard - SQL Injection Vulnerability
SAP BusinessObjects launch pad – Server-Side Request Forgery
# Exploit Title: SAP BusinessObjects launch pad SSRF
Ability Mail Server 3.3.2 – Cross-Site Scripting
# Exploit Title: Ability Mail Server 3.3.2 Persistent Cross Site Scripting (XSS)
Conarc iChannel – Improper Access Restrictions
# Exploit Title: Conarc iChannel - Unauthenticated Access/Default Webserver Misconfiguration allows for compromise of...
Trend Micro Smart Protection Server – Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control
# Trend Micro Smart Protection Server Multiple Vulnerabilities
vBulletin 5.x – ‘cacheTemplates’ Remote Arbitrary File Deletion
# SSD Advisory – vBulletin cacheTemplates Unauthenticated Remote Arbitrary File Deletion
vBulletin 5.x – ‘routestring’ Remote Code Execution
# SSD Advisory – vBulletin routestring Unauthenticated Remote Code Execution
Apple macOS/iOS – Kernel Double Free due to Incorrect API Usage in Flow Divert Socket Option Handling
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1373
Apple macOS/iOS – Multiple Kernel Use-After-Frees due to Incorrect IOKit Object Lifetime Management in IOTimeSyncClockManagerUserClient
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1377
Apple XNU Kernel – Memory Corruption due to Integer Overflow in __offsetof Usage in posix_spawn on 32-bit Platforms
posix_spawn is a complex syscall which takes a lot of arguments from userspace. The third argument
Apple macOS/iOS – Kernel Double Free due to IOSurfaceRootUserClient not Respecting MIG Ownership Rules
I have previously detailed the lifetime management paradigms in MIG in the writeups for:
MistServer 2.12 – Cross-Site Scripting
[+] Credits: John Page (aka Hyp3rlinX)
Exim 4.89 – ‘BDAT’ Denial of Service
While parsing BDAT data header, exim still scans for '.' and consider it the end of mail.
WebKit – ‘WebCore::SVGPatternElement::collectPatternAttributes’ Out-of-Bounds Read
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1350
WebKit – ‘WebCore::SimpleLineLayout::RunResolver::runForPoint’ Out-of-Bounds Read
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1349
WebKit – ‘WebCore::RenderText::localCaretRect’ Out-of-Bounds Read
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1348
WebKit – ‘WebCore::AXObjectCache::performDeferredCacheUpdate’ Use-After-Free
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1347
WebKit – ‘WebCore::PositionIterator::decrement’ Use-After-Free
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1346
WebKit – ‘WebCore::InputType::element’ Use-After-Free (2)
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1345
WebKit – ‘WebCore::TreeScope::documentScope’ Use-After-Free
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1344
CommuniGatePro 6.1.16 – Cross-Site Scripting
# Exploit Title: CommuniGatePro webmails Multiple Stored XSS
PHP 7.1.8 – Heap Buffer Overflow
Description:
Logitech Media Server 7.9.0 – ‘Radio URL’ Cross-Site Scripting
# Exploit Title: Logitech Media Server : HTML code injection and execution.
Logitech Media Server 7.9.0 – ‘favorites’ Cross-Site Scripting
# Exploit Title: Logitech Media Server : Persistent Cross Site Scripting(XSS)