Zilab Remote Console Server 3.2.9 – ‘zrcs’ Unquoted Service Path
# Exploit Title : Zilab Remote Console Server 3.2.9 - 'zrcs' Unquoted Service Path
windows 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title : Zilab Remote Console Server 3.2.9 - 'zrcs' Unquoted Service Path
# Lavasoft 2.3.4.7 - 'LavasoftTcpService' Unquoted Service Path
# Exploit Title : ActiveFax Server 6.92 Build 0316 - 'ActiveFaxServiceNT' Unquoted Service Path
# Exploit Title: ActiveFax Server 6.92 Build 0316 - 'POP3 Server' Denial of Service
# Exploit Title: SpotAuditor 5.3.1.0 - Denial of Service
# Exploit Title: Uplay 92.0.0.6280 - Local Privilege Escalation
# Exploit Title: National Instruments Circuit Design Suite 14.0 - Local Privilege Escalation
We have encountered a Windows kernel crash in memcpy() called by nt!MiRelocateImage while trying to load a malformed ...
We have encountered a Windows kernel crash in CI!HashKComputeFirstPageHash while trying to load a malformed PE image ...
We have encountered a Windows kernel crash in memcpy() called by nt!MiParseImageLoadConfig while trying to load a mal...
We have encountered a Windows kernel crash in CI!CipFixImageType while trying to load a malformed PE image into the p...
We have encountered a Windows kernel crash in nt!MiOffsetToProtos while trying to load a malformed PE image into the ...
We have encountered a Windows kernel crash in the win32k.sys driver while processing a corrupted TTF font file. An ex...
# Exploit Title: Foscam Video Management System 1.1.6.6 - 'UID' Denial of Service (PoC)
# Exploit Title: Sricam DeviceViewer 3.12.0.1 - 'add user' Local Buffer Overflow (DEP Bypass)
# Exploit Title: DeviceViewer 3.12.0.1 - Arbitrary Password Change
# Exploit Title: freeFTP 1.0.8 - Remote Buffer Overflow
# Exploit Title: CheckPoint Endpoint Security Client/ZoneAlarm 15.4.062.17802 - Privilege Escalation
#!/usr/bin/env python
# Title: Mobatek MobaXterm 12.1 - Buffer Overflow (SEH)
# Exploit Title: SpotIE Internet Explorer Password Recovery 2.9.5 - 'Key' Denial of Service
There's a bug in the SymCrypt multi-precision arithmetic routines that can cause an infinite loop when calculating th...
import socket
#!/usr/bin/python
#!/usr/bin/python
// ref : https://medium.com/tenable-techblog/uac-bypass-by-mocking-trusted-directories-24a96675f6e
import struct
#-----------------------------------------------------------------------------#
# Exploit Title: Folder Lock v7.7.9 Denial of Service Exploit
Microsoft DirectWrite is a modern Windows API for high-quality text rendering. A majority of its code resides in the ...
Microsoft DirectWrite is a modern Windows API for high-quality text rendering. A majority of its code resides in the ...
[+] Credits: John Page (aka hyp3rlinx)
#### Fileless UAC bypass (WSReset.exe)
# Exploit Title: Kaseya VSA agent
#!C:\Python27\python.exe
#!C:\Python27\python.exe
#!C:\Python27\python.exe
# Exploit Title: VX Search Enterprise v10.4.16 DoS
#!/usr/bin/python
#!/usr/bin/python
#Exploit Title: SQL Server Password Changer v1.90 Denial of Service Exploit
#Exploit Title: Outlook Password Recovery v2.10 Denial of Service Exploit
Windows: SET_REPARSE_POINT_EX Mount Point Security Feature Bypass
# Exploit Title: LSoft ListServ < 16.5 - Cross-Site Scripting (XSS)
# Exploit Title: RAR Password Recovery v1.80 Denial of Service Exploit