Microsoft Edge Chakra – ‘InlineArrayPush’ Type Confusion
In Chakra, if you add a numeric property to an object having inlined properties, it will start transition to a new ty...
windows 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
In Chakra, if you add a numeric property to an object having inlined properties, it will start transition to a new ty...
# Exploit Title: FastTube 1.0.1.0 - Denial of Service (PoC)
# Exploit Title: VPN Browser+ 1.1.0.0 - Denial of Service (PoC)
# Exploit Title: 7 Tik 1.0.1.0 - Denial of Service (PoC)
# Exploit Title: Eco Search 1.0.2.0 - Denial of Service (PoC)
# Exploit Title: One Search 1.1.0.0 - Denial of Service (PoC)
# Exploit Title: Watchr 1.1.0.0 - Denial of Service (PoC)
# Exploit Title: Check Point ZoneAlarm Local Privilege Escalation
[+] Credits: John Page (aka hyp3rlinx)
Windows: XmlDocument Insecure Sharing Elevation of Privilege
Windows: RestrictedErrorInfo Unmarshal Section Handle UAF EoP
# Exploit Title: Spotify 1.0.96.181 - "Proxy configuration" Denial of Service (PoC)
[+] Credits: John Page (aka hyp3rlinx)
-----BEGIN PGP SIGNED MESSAGE-----
Windows: COM Desktop Broker Elevation of Privilege
Windows: Browser Broker Cross Session EoP
Windows: DSSVC MoveFileInheritSecurity Multiple Issues EoP
Windows: DSSVC CanonicalAndValidateFilePath Security Feature Bypass
Windows: DSSVC DSOpenSharedFile Arbitrary File Delete EoP
Windows: DSSVC DSOpenSharedFile Arbitrary File Open EoP
Windows: SSPI Network Authentication Session 0 EoP
Exploit Title - Dokany Stack-based Buffer Overflow Privilege Escalation
# Exploit Title: Luminance Studio 2.17 - Denial of Service (PoC)
# Exploit Title: Blob Studio 2.17 - Denial of Service (PoC)
# Exploit Title: Liquid Studio 2.17 - Denial of Service (PoC)
# Exploit Title: Pixel Studio 2.17 - Denial of Service (PoC)
# Exploit Title: Paint Studio 2.17 - Denial of Service (PoC)
# Exploit Title: Tree Studio 2.17 - Denial of Service (PoC)
# Exploit Title: Selfie Studio 2.17 - Denial of Service (PoC)
#!/usr/bin/python
#!/usr/bin/python
XML External Entity Injection Vulnerability in BlogEngine 3.3
Windows: DSSVC CheckFilePermission Arbitrary File Delete EoP
# Exploit Title : KioWare Server Version 4.9.6 - Weak Folder Permissions Privilege Escalation
# Exploit Title: Foscam Video Management System 1.1.4.9 - 'Username' Denial of Service (PoC)
# Exploit Title: SpotFTP Password Recover 2.4.2 - 'Name' Denial of Service (PoC)
# Exploit Title: BlueAuditor 1.7.2.0 - 'Key' Denial of Service (PoC)
# Exploit Title: Ajera Timesheets
Make sure to copy the file report.wer found in the folder PoC-Files in the same folder as the executable before runni...
Download: https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/46051.zip
# Exploit Title: McAfee Foundstone SQLScan - Denial of Service (PoC) and EIP record overwrite
The bug is in “MsiAdvertiseProduct”
# Exploit Title: Microsoft Edge edgehtml.dll!Tree::ANode::DocumentLayout. Denial of Service (PoC)
#!/usr/bin/env python
The bug is in “MsiAdvertiseProduct”
According to https://blogs.windows.com/msedgedev/2017/07/07/update-disabling-vbscript-internet-explorer-11/, Starting...