Advantech WebAccess 8.3.0 – Remote Code Execution
Vulnerability Title: Advantech WebAccess Node8.3.0 "AspVBObj.dll" - Remote Code Execution
windows 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
Vulnerability Title: Advantech WebAccess Node8.3.0 "AspVBObj.dll" - Remote Code Execution
[+] Credits: John Page (aka hyp3rlinx)
# Exploit Title: Adobe Coldfusion BlazeDS Java Object Deserialization RCE
Title: MalwareFox AntiMalware 2.74.0.150 - Local Privilege Escalation
Title : MalwareFox AntiMalware 2.74.0.150 - Local Privilege Escalation
#define _GNU_SOURCE
# Exploit Title: Sync Breeze Enterprise v10.4.18 Server - Unauthenticated Remote Buffer Overflow SEH
## Vulnerability Summary
# Exploit Title: BMC BladeLogic RSCD agent get Windows users
#!/usr/bin/python
Exploit Title - System Shield AntiVirus & AntiSpyware Arbitrary Write Privilege Escalation
#!/usr/bin/python2.7
# Exploit Title: HPE iMC 7.3 Java RMI Registry Deserialization RCE Vulnerability
All blizzard games are installed alongside a shared tool called "Blizzard Update Agent", investor.activision.com clai...
#Tested on HP Connected Backup version 8.8.2.0 on Windows 7 x64
#!/usr/bin/python
If variables don't escape the scope, the variables can be allocated to the stack. However, there are some situations,...
AsmJSByteCodeGenerator::EmitCall which is used to emit call insturctions doesn't check if an array identifier is used...
// Here's the PoC demonstrating OOB write.
Since the PoC is only triggerable when the "DeferParse" flag enabled and requires a with statement, I think this is s...
Here's a snippet of the method.
Let's start with comments in the "GlobOpt::TrackIntSpecializedAddSubConstant" method.
author = '''
# Exploit Title: Disk Pulse Enterprise Server v10.1.18 - Buffer Overflow
# Exploit Title: SysGauge Server 3.6.18 - Buffer Overflow
=============================================
Document Title:
#!/usr/bin/python
Here's a snippet of AppendLeftOverItemsFromEndSegment in JavascriptArray.inl.
Windows: SMB Server (v1 and v2) Mount Point Arbitrary Device Open EoP
Windows: NtImpersonateAnonymousToken LPAC to Non-LPAC EoP
Windows: NtImpersonateAnonymousToken AC to Non-AC EoP
Windows: NTFS Owner/Mandatory Label Privilege Bypass EoP
// ConsoleApplication1.cpp : Defines the entry point for the console application.
The method "Lowerer::LowerSetConcatStrMultiItem" is used to generate machine code to concatenate strings.
# Exploit Title: DiskBoss
We have discovered that the nt!NtQuerySystemInformation system call invoked with the 138 information class discloses ...
We have discovered that the nt!NtQueryInformationProcess system call invoked with the 76 information class discloses ...
Escape analysis: https://en.wikipedia.org/wiki/Escape_analysis
Here's a snippet of AsmJSByteCodeGenerator::EmitAsmJsFunctionBody.
The optimizations for memory operations may leave empty loops as follows: