windows
windows 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
LiquidXML Studio 2010 – ActiveX Code Execution
LiquidXML Studio 2010 ActiveX Insecure Method Executable File Creation 0-day
LiquidXML Studio 2012 – ActiveX Insecure Method Executable File Creation
LiquidXML Studio 2012 ActiveX Insecure Method Executable File Creation 0-day
IconCool MP3 WAV Converter 3.00 Build 120518 – Stack Buffer Overflow
# Exploit Title: IconCool MP3 WAV Converter Stack Buffer Overflow Vulnerability
Photodex ProShow Gold/Producer 5.0.3310/6.0.3410 – ‘ScsiAccess.exe’ Local Privilege Escalation
## Exploit-DB Note: Vuln still in 6.0.3410 as well as 'Photodex ProShow Gold'
EastFTP 4.6.02 – ActiveX Control
#################################################################
BlazeVideo HDTV Player Standard – ‘.plf’ File Remote Buffer Overflow
source: https://www.securityfocus.com/bid/58624/info
aktiv-player 2.9.0 – Crash (PoC)
# !/usr/bin/python
Nitro Pro 8.0.3.1 – Crash (PoC)
#!C:\Python27\python.exe
QlikView – ‘.qvw’ File Remote Integer Overflow
source: https://www.securityfocus.com/bid/58463/info
Cam2pc 4.6.2 – ‘.BMP’ Image Processing Integer Overflow
Application: Cam2pc BMP Image Processing Integer Overflow Vulnerability
Kaspersky Internet Security 2013 – Denial of Service
I usually do not write security advisories unless absolutely necessary.
Sami FTP Server 2.0.1 – ‘LIST’ Buffer Overflow
#!/usr/bin/env python
Hanso Player 2.1.0 – ‘.m3u’ Buffer Overflow
#!/usr/bin/python
Photodex ProShow Producer – Multiple DLL Loading Arbitrary Code Execution Vulnerabilities
source: https://www.securityfocus.com/bid/58131/info
Alt-N MDaemon WorldClient 13.0.3 – Multiple Vulnerabilities
======================================================================
Alt-N MDaemon 12.5.6/13.0.3 – Email Body HTML/JS Injection
==============================================================
Microsoft Office 2010 – Download Execute
#!/usr/bin/python
Alt-N MDaemon WorldClient And WebAdmin – Cross-Site Request Forgery
source: https://www.securityfocus.com/bid/58076/info
SAP NetWeaver Message Server – Multiple Vulnerabilities
1. *Advisory Information*
Photodex ProShow Producer 5.0.3297 – ‘.pxs’ Memory Corruption
#!/usr/bin/python
Microsoft Windows – HWND_BROADCAST (PoC) (MS13-005)
ms13-005-funz-poc.cpp - Drive a Medium IL cmd.exe via a Low IL
Freefloat FTP Server 1.0 – ‘Raw’ Remote Buffer Overflow
#!/usr/bin/env python
Schneider Electric Accutech Manager – Heap Overflow (PoC)
#Schneider Electric
KMPlayer – Denial of Service
Title : KMPlayer (PlayList M3U) Denial Of Service PoC All Versions
Cool PDF Reader 3.0.2.256 – Buffer Overflow
# Exploit Title: Cool PDF Reader 3.0.2.256 buffer overflow
Apple Quick Time Player (Windows) 7.7.3 – Out of Bound Read
# Title: Apple Quick Time Player (Windows)Version 7.7.3 Out of Bound Read
Microsoft Internet Explorer 8/9 – Steal Any Cookie
# Exploit Title: Internet Explorer 8 & Internet Explorer 9 steal any Cookie