windows
windows 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
Winamp 5.5.8 (in_mod plugin) – Local Stack Overflow (SEH)
#!/usr/bin/python
VeryTools VideoSpirit Pro 1.68 – Local Buffer Overflow
# Exploit Title: VideoSpirit Pro v1.68 Local BoF Exploit
StageTracker 2.5 – Denial of Service
# Exploit Title: StageTracker 2 Local POC
Enzip 3.00 – Local Buffer Overflow
#[+]Exploit Title: Exploit Buffer Overflow Enzip 3.00
Quick Notes Plus 5.0 47 – Multiple DLL Loading Arbitrary Code Executions
// source: https://www.securityfocus.com/bid/45689/info
Xynph FTP Server 1.0 – USER Denial of Service
# Exploit Title: Xynph 1.0 USER Denial of Service Exploit
Music Animation Machine MIDI Player – Local Buffer Overflow (SEH)
# Exploit Title: Music Animation Machine MIDI Player MAMX SEH BOF
Ace Video Workshop 1.2.0.0 – ‘ir50_lcs.dll’ DLL Loading Arbitrary Code Execution
// source: https://www.securityfocus.com/bid/45675/info
Music Animation Machine MIDI Player – Local Crash (PoC)
# Exploit Title: Music Animation Machine MIDI Player Local Crash PoC
CoolPlayer 2.18 – DEP Bypass
# Exploit Title: CoolPlayer 2.18 DEP Bypass
ImgBurn 2.4 – ‘dwmapi.dll’ DLL Loading Arbitrary Code Execution
// source: https://www.securityfocus.com/bid/45657/info
Bywifi 2.8.1 – Local Stack Buffer Overflow
# Exploit Title: [bywifi 2.8.1 stack buffer overflow]
CA ARCserve D2D r15 – Web Service Servlet Code Execution
Computer Associates ARCserve D2D r15 Web Service Apache Axis2 World Accessible Servlet
QuickPHP Web Server – Arbitrary ‘.php’ File Download
# _ ____ __ __ ___
Chilkat Software FTP2 – ActiveX Component Remote Code Execution
original url: http://retrogod.altervista.org/9sg_chilkat.html
QuickPHP Web Server 1.9.1 – Directory Traversal
# ------------------------------------------------------------------------
httpdasm 0.92 – Directory Traversal
# ------------------------------------------------------------------------
TYPSoft FTP Server 1.10 – ‘RETR’ Denial of Service (2)
#!/usr/bin/python
Digital Music Pad 8.2.3.4.8 – ‘.pls’ Local Overflow (SEH)
#Digital Music Pad Version 8.2.3.4.8 SEH overflow
QuickTime Picture Viewer 7.6.6 JP2000 – Denial of Service
# done by BraniX
IrfanView 4.27 – ‘JP2000.dll’ plugin Denial of Service
# done by BraniX
Mongoose 2.11 – ‘Content-Length’ HTTP Header Remote Denial of Service
source: https://www.securityfocus.com/bid/45602/info
Kolibri 2.0 – ‘HEAD’ Remote Buffer Overflow RET (SEH)
#!/usr/bin/env python
HttpBlitz Web Server – Denial of Service
#!/usr/bin/python
Microsoft WMITools – ActiveX Remote Command Execution
Exploit-DB Notes:
Calibre 0.7.34 – Cross-Site Scripting / Directory Traversal
source: https://www.securityfocus.com/bid/45532/info
ecava IntegraXor 3.6.4000.0 – Directory Traversal
Source: http://aluigi.org/adv/integraxor_1-adv.txt
Accmeware MP3 Cut 5.0.9 – Denial of Service (PoC)
# Exploit Title: Accmeware MP3 Cut 5.0.9 DoS PoC
Accmeware MP3 Speed 5.0.9 – Denial of Service (PoC)
# Exploit Title: Accmeware MP3 Speed 5.0.9 DoS PoC
Accmeware MP3 Joiner Pro 5.0.9 – Denial of Service (PoC)
# Exploit Title: Accmeware MP3 Joiner Pro 5.0.9 DoS PoC
MP3 CD Converter Professional – Local Buffer Overflow (SEH)
#!/usr/bin/python
Word Splash Pro 9.5 – Local Buffer Overflow
# Exploit Title: Word Splash Pro Import then click on Word List Builder button
Ecava IntegraXor Remote – ActiveX Buffer Overflow (PoC)
#!/usr/bin/python
Alt-N WebAdmin 3.3.3 – Remote Source Code Information Disclosure
source: https://www.securityfocus.com/bid/45476/info
ESTsoft ALYac Anti-Virus 1.5 < 5.0.1.2 - Local Privilege Escalation
ESTsoft ALYac Anti-Virus 1.5 with AYDrvNT.sys Module[0].Base , strrchr(pmi->Module[0].ImageName , '\\')+1))
NProtect Anti-Virus 2007 < 2010.5.11.1 - Local Privilege Escalation
NProtect Anti-Virus 2007 with TKRgAc2k.sys FsContext for each process to open the device,and save key/key value /...
AhnLab V3 Internet Security 8.0 < 1.2.0.4 - Local Privilege Escalation
AhnLab V3 Internet Security 8.0 with AhnRec2k.sys