VBScript – VbsErase Reference Leak Use-After-Free
There is an reference leak in Microsoft VBScript that can be turned into an use-after-free given sufficient time. The...
windows 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
There is an reference leak in Microsoft VBScript that can be turned into an use-after-free given sufficient time. The...
#!/usr/bin/env python
#!/usr/bin/env python
# Exploit Title: PDF Explorer SEH Local Exploit
#!/usr/bin/python
# Exploit Title: PassFab RAR Password Recovery SEH Local Exploit
# Exploit Title: Nsauditor Local SEH Buffer Overflow
# Exploit Title: MegaPing
# Exploit Title: Excel Password Recovery Professional
# Exploit Title: AnyBurn
Not only the GET method is vulnerable to BOF (CVE-2004-2271). HEAD and POST
# Exploit Title: UltraISO 9.7.1.3519 - 'Output FileName' Denial of Service (PoC) and Pointer to next SEH and SE handl...
#!/usr/bin/python
#Exploit Title: Zortam MP3 Media Studio Version 24.15 Exploit (SEH)
# Exploit Title: LanSpy 2.0.1.159 - Local BoF (PoC)
# -*- coding: utf-8 -*-
McAfee True Key: Multiple Issues with McAfee.TrueKey.Service Implementation
# Exploit Title: Microsoft Lync for Mac 2011 Injection Forced Browsing/Download
# Exploit Title: Mozilla Firefox 63.0.1 - Denial of Service (PoC)
# Exploit Title: CyberArk 9.7 - Memory Disclosure
# Exploit Title: ELBA5 5.8.0 - Remote Code Execution
Windows: DfMarshal Unsafe Unmarshaling Elevation of Privilege (Master)
Since the patch for CVE-2018-8372, it checks all inputs to native arrays, and if any input equals to the MissingItem ...
# Exploit Title: XMPlay 3.8.3 - '.m3u' Denial of Service (PoC)
# Exploit Title: Bosch Video Management System 8.0-Configuration Client-Denial of Service (Poc)
[+] Credits: John Page (aka hyp3rlinx)
# Exploit Title: XAMPP Control Panel 3.2.2 - Buffer Overflow (SEH) (Unicode)
# Exploit Title: HeidiSQL 9.5.0.5196 - Denial of Service (PoC)
#include "stdafx.h"
# Exploit Title: VSAXESS V2.6.2.70 build20171226_053 - 'organization' Denial of Service (PoC)
# Exloit Title: Microsoft Internet Explorer 11 - Null Pointer Difference
# Exploit Title: Anviz AIM CrossChex Standard 4.3 - CSV Injection
# Exploit Title: QNAP NetBak Replicator 4.5.6.0607 Denial of Service (PoC)
# Exploit Title: Modbus Slave 7.0.0 - Denial of Service (PoC)
SecureAuth - SecureAuth Labs Advisory
Bug description:
# Exploit Title: MGB OpenSource Guestbook 0.7.0.2 - 'id' SQL Injection
# Exploit Title: ServersCheck Monitoring Software 14.3.3 - 'id' SQL Injection
# Exploit Title: ServersCheck Monitoring Software 14.3.3 - Denial of Service (PoC)
#!/usr/bin/env python