PHP 5.4/5.5/5.6 – SplDoublyLinkedList ‘Unserialize()’ Use-After-Free
Yet Another Use After Free Vulnerability in unserialize() with SplDoublyLinkedList
php 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
Yet Another Use After Free Vulnerability in unserialize() with SplDoublyLinkedList
=============================================================================
# Exploit Title: Wordpress White-Label Framework XSS
Just one of many handfuls of FireEye / Mandiant 0day. Been sitting on this for more than 18 months with no fix from t...
Advisory ID: HTB23269
# Exploit Title: YESWIKI 0.2 - Path Traversal
# Exploit Title: MantisBT 1.2.19 - Host header attack vulnerability
########################################################################################
# Title: phpwiki 1.5.4 - Cross Site Scripting / Local File Inclusion
# Title: Pluck 4.7.3 - Multiple vulnerabilities
# Exploit Title : Wolf CMS 0.8.2 Arbitrary File Upload To Command
# Exploit Title: Wordpress Responsive Thumbnail Slider Arbitrary File Upload
# Exploit Title: IP.Board 4.X Stored XSS
##################################################################################################
##################################################################################
+--------------------------------------------------------+
+------------------------------------------------------------------------+
+--------------------------------------------------------+
+-----------------------------------------------------------------------+
+----------------------------------------------------------------+
+----------------------------------+
+-------------------------------------+
# Exploit Title: WordPress MDC Private Message Persistent XSS
[+] Exploit Title : Wordpress Googmonify Plug-in XSS/CSRF
+-----------------------------------------------------------------+
{php}echo ' Hacked ';
up.time 7.5.0 Upload And Execute File Exploit
up.time 7.5.0 Arbitrary File Disclose And Delete Exploit
up.time 7.5.0 XSS And CSRF Add Admin Exploit
# Exploit Title: Wordpress Plugin wp-symposium Unauthenticated SQL Injection Vulnerability
BigTree CMS 4.2.3: Multiple SQL Injection Vulnerabilities
CodoForum 3.3.1: Multiple SQL Injection Vulnerabilities
[+] Credits: John Page aka hyp3rlinx
[+] Credits: John Page aka hyp3rlinx
[+] Credits: John Page aka hyp3rlinx
vBulletin's memcache setting is vulnerable in certain versions(all
#!/usr/bin/python
# Exploit Title: Joomla com_informations component SQL Injection vulnerability
# Exploit Title: Joomla com_memorix component SQL Injection vulnerability
# Exploit Title: Gkplugins Picasaweb Download File
Title: Remote file download vulnerability in candidate-application-form v1.0 wordpress plugin
Title: Remote file download in simple-image-manipulator v1.0 wordpress plugin