local
local 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
Arm Whois 3.11 – Buffer Overflow (ASLR)
# Exploit Title: Arm Whois 3.11 - Buffer Overflow (ASLR)
Microsoft Windows – DfMarshal Unsafe Unmarshaling Privilege Escalation
Windows: DfMarshal Unsafe Unmarshaling Elevation of Privilege (Master)
ImageMagick – Memory Leak
#!/bin/bash
HTML Video Player 1.2.5 – Buffer-Overflow (SEH)
# Exploit Title: HTML Video Player 1.2.5 - Buffer-Overflow (SEH)
Linux – Broken uid/gid Mapping for Nested User Namespaces
commit 6397fac4915a ("userns: bump idmap limits to 340") increases the number of
SwitchVPN for macOS 2.1012.03 – Privilege Escalation
=======================================================================
ntpd 4.2.8p10 – Out-of-Bounds Read (PoC)
# Exploit Title: ntpd 4.2.8p10 - Out-of-Bounds Read (PoC)
xorg-x11-server < 1.20.1 - Local Privilege Escalation
# Exploit Title: xorg-x11-server < 1.20.1 - Local Privilege Escalation (RHEL 7)
XAMPP Control Panel 3.2.2 – Buffer Overflow (SEH) (Unicode)
# Exploit Title: XAMPP Control Panel 3.2.2 - Buffer Overflow (SEH) (Unicode)
Microsoft Windows 10 (Build 17134) – Local Privilege Escalation (UAC Bypass)
#include "stdafx.h"
libiec61850 1.3 – Stack Based Buffer Overflow
Exploit Title: libiec61850 1.3 - Stack Based Buffer Overflow
Arm Whois 3.11 – Buffer Overflow (SEH)
# Exploit Title: Arm Whois 3.11 - Buffer Overflow (SEH)
LiquidVPN 1.36 / 1.37 – Privilege Escalation
=======================================================================
Microsoft Internet Explorer 11 – Null Pointer Dereference
# Exloit Title: Microsoft Internet Explorer 11 - Null Pointer Difference
Anviz AIM CrossChex Standard 4.3 – CSV Injection
# Exploit Title: Anviz AIM CrossChex Standard 4.3 - CSV Injection
xorg-x11-server 1.20.3 – Privilege Escalation
# Exploit Title: xorg-x11-server 1.20.3 - Privilege Escalation
R 3.4.4 (Windows 10 x64) – Buffer Overflow (DEP/ASLR Bypass)
#!/usr/bin/python
systemd – ‘chown_one()’ Dereference Symlinks
[I am sending this bug report to Ubuntu, even though it's an upstream
Modbus Slave PLC 7 – ‘.msw’ Buffer Overflow (PoC)
# Exploit Title: Modbus Slave PLC 7 - '.msw' Buffer Overflow (PoC)
School Equipment Monitoring System 1.0 – ‘login’ SQL Injection
# Exploit Title: School Equipment Monitoring System 1.0 - 'login' SQL Injection
xorg-x11-server < 1.20.3 - Local Privilege Escalation
#CVE-2018-14665 - a LPE exploit via http://X.org fits in a tweet
Adult Filter 1.0 – Buffer Overflow (SEH)
# Exploit Title: Adult Filter 1.0 - Buffer Overflow (SEH)
Microsoft Data Sharing – Local Privilege Escalation (PoC)
Bug description:
Keybase keybase-redirector – ‘$PATH’ Local Privilege Escalation
keybase-redirector is a setuid root binary. keybase-redirector calls the fusermount binary using a relative path and ...
Microsoft Windows 10 – Local Privilege Escalation (UAC Bypass)
#!/usr/bin/env python
Any Sound Recorder 2.93 – Buffer Overflow (SEH)
# Exploit Title: Any Sound Recorder 2.93 - Buffer Overflow (SEH)
Git Submodule – Arbitrary Code Execution
# CVE-2018-17456
Snes9K 0.0.9z – Buffer Overflow (SEH)
# Exploit Title: Snes9K 0.0.9z - Buffer Overflow (SEH)
Microsoft SQL Server Management Studio 17.9 – ‘.xmla’ XML External Entity Injection
# Exploit Title: Microsoft SQL Server Management Studio 17.9 - '.xmla' XML External Entity Injection
Microsoft SQL Server Management Studio 17.9 – ‘.xel’ XML External Entity Injection
# Exploit Title: Microsoft SQL Server Management Studio 17.9 - '.xel' XML External Entity Injection
Microsoft SQL Server Management Studio 17.9 – XML External Entity Injection
# Exploit Title: Microsoft SQL Server Management Studio 17.9 - XML External Entity Injection
ghostscript – executeonly Bypass with errorhandler Setup
While documenting bug 1675, I noticed another problem with errordict in ghostscript. Full working exploit that works ...
Seqrite End Point Security 7.4 – Privilege Escalation
# Exploit Title: Seqrite End Point Security 7.4 - Privilege Escalation