windows
windows 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
ConQuest DICOM Server 1.4.17d – Stack Buffer (PoC)
#!/usr/bin/env python
OsiriX DICOM Viewer 8.0.1 – Memory Corruption
#!/usr/bin/env python
Orthanc DICOM Server 1.1.0 – Memory Corruption
#!/usr/bin/env python
Adobe Animate 15.2.1.95 – Memory Corruption
[+] Credits: John Page aka hyp3rlinx
Serva 3.0.0 – HTTP Server Denial of Service
#!/usr/bin/env python
EasyPHP Devserver 16.1.1 – Insecure File Permissions Privilege Escalation
Title: EasyPHP Devserver Insecure File Permissions Privilege Escalation
Dual DHCP DNS Server 7.29 – Denial of Service
# Title : Dual DHCP DNS Server 7.29 Buffer Overflow (Dos)
Microsoft Windows 10 (x86/x64) – WLAN AutoConfig Denial of Service (PoC)
#!/usr/bin/python
Microsoft Edge – CBaseScriptable::PrivateQueryInterface Memory Corruption (MS16-068)
Source: http://blog.skylined.nl/20161205001.html
Microsoft Edge – CMarkup::EnsureDeleteCFState Use-After-Free (MS15-125)
Source: http://blog.skylined.nl/20161201001.html
Microsoft PowerShell – XML External Entity Injection
[+] Credits: John Page aka hyp3rlinx
DiskBoss Enterprise 7.4.28 – ‘GET’ Remote Buffer Overflow
#!/usr/bin/python
Dup Scout Enterprise 9.1.14 – Remote Buffer Overflow (SEH)
#!/usr/bin/python
Apache CouchDB 2.0.0 – Local Privilege Escalation
[+] Credits: John Page aka hyp3rlinx
Microsoft MSINFO32.EXE 6.1.7601 – ‘.NFO’ XML External Entity Injection
[+] Credits: John Page aka hyp3rlinx
Microsoft Event Viewer 1.0 – XML External Entity Injection
[+] Credits: John Page aka hyp3rlinx
Alcatel Lucent Omnivista 8770 – Remote Code Execution
import socket
Microsoft Windows Media Center 6.1.7600 – ‘ehshell.exe’ XML External Entity Injection
[+] Credits: John Page aka hyp3rlinx
Microsoft Excel Starter 2010 – XML External Entity Injection
[+] Credits: John Page aka hyp3rlinx
Microsoft Authorization Manager 6.1.7601 – ‘azman’ XML External Entity Injection
[+] Credits: John Page aka hyp3rlinx
Tor (Firefox 41 < 50) - Code Execution
# TOR Browser 0day : JavaScript Exploit !
Disk Savvy Enterprise 9.1.14 – ‘GET’ Remote Buffer Overflow
#!/usr/bin/python
Xitami Web Server 5.0a0 – Denial of Service
#!/usr/bin/env python
WinPower 4.9.0.4 – Local Privilege Escalation
// Exploit Title: WinPower V4.9.0.4 Privilege Escalation
Microsoft Internet Explorer 8/9/10/11 – MSHTML ‘DOMImplementation’ Type Confusion (MS16-009)
Source: http://blog.skylined.nl/20161128001.html
Disk Pulse Enterprise 9.1.16 – ‘Login’ Remote Buffer Overflow
#!/usr/bin/python
Disk Savvy Enterprise 9.1.14 – ‘Login’ Remote Buffer Overflow
#!/usr/bin/python
Disk Sorter Enterprise 9.1.12 – ‘Login’ Remote Buffer Overflow
#!/usr/bin/python
Dup Scout Enterprise 9.1.14 – ‘Login’ Remote Buffer Overflow
#!/usr/bin/python