Commit graph

2829 commits

Author SHA1 Message Date
Exploit-DB
e791587e41 DB: 2024-03-29
10 changes to exploits/shellcodes/ghdb

RouterOS 6.40.5 - 6.44 and 6.48.1 - 6.49.10 - Denial of Service

Siklu MultiHaul TG series < 2.0.0 - unauthenticated credential disclosure

Dell Security Management Server <1.9.0 - Local Privilege Escalation

Asterisk AMI - Partial File Content & Path Disclosure (Authenticated)

Broken Access Control - on NodeBB v3.6.7

liveSite Version 2019.1 - Remote Code Execution

Purei CMS 1.0 - SQL Injection

Workout Journal App 1.0 - Stored XSS

WinRAR version 6.22 - Remote Code Execution via ZIP archive
2024-03-29 00:16:30 +00:00
Exploit-DB
c9576b1787 DB: 2024-03-26
11 changes to exploits/shellcodes/ghdb

LBT-T300-mini1 - Remote Buffer Overflow

Nagios XI Version 2024R1.01 - SQL Injection

Craft CMS 4.4.14 - Unauthenticated Remote Code Execution

Insurance Management System PHP and MySQL 1.0 - Multiple Stored XSS

LimeSurvey Community 5.3.32 - Stored XSS

MobileShop master v1.0 - SQL Injection Vuln.

SPA-CART CMS - Stored XSS

Tourism Management System v2.0 - Arbitrary File Upload

Wallos < 1.11.2 - File Upload RCE
2024-03-26 00:16:32 +00:00
Exploit-DB
26a991fc28 DB: 2024-03-23
2 changes to exploits/shellcodes/ghdb

minaliC 2.0.0 - Denied of Service
2024-03-23 00:16:33 +00:00
Exploit-DB
a24ba3c94b DB: 2024-03-21
7 changes to exploits/shellcodes/ghdb

HNAS SMU 14.8.7825 - Information Disclosure

Blood Bank 1.0 - 'bid' SQLi

CSZCMS v1.3.0 - SQL Injection (Authenticated)

Employee Management System 1.0 - 'admin_id' SQLi

Simple Task List 1.0 - 'status' SQLi

Teacher Subject Allocation Management System 1.0 - 'searchdata' SQLi
2024-03-21 00:16:27 +00:00
Exploit-DB
bbffa273d4 DB: 2024-03-19
13 changes to exploits/shellcodes/ghdb

TELSAT marKoni FM Transmitter 1.9.5 - Backdoor Account Information Disclosure
TELSAT marKoni FM Transmitter 1.9.5 - Insecure Access Control Change Password
TELSAT marKoni FM Transmitter 1.9.5 - Root Command Injection

Atlassian Confluence < 8.5.3 - Remote Code Execution

Backdrop CMS 1.23.0 - Stored XSS

Gibbon LMS < v26.0.00 - Authenticated RCE

Quick.CMS 6.7 - SQL Injection Login Bypass

TYPO3 11.5.24 - Path Traversal (Authenticated)

WEBIGniter v28.7.23 - Stored XSS

WordPress File Upload Plugin < 4.23.3 - Stored XSS

xbtitFM 4.1.18 - Multiple Vulnerabilities

ZoneMinder Snapshots < 1.37.33 - Unauthenticated RCE
2024-03-19 00:16:26 +00:00
Exploit-DB
8c78d80c78 DB: 2024-03-17
7 changes to exploits/shellcodes/ghdb

Karaf v4.4.3 Console - RCE

Nokia BMC Log Scanner - Remote Code Execution

vm2 - sandbox escape

UPS Network Management Card 4 - Path Traversal

Winter CMS 1.2.3 - Server-Side Template Injection (SSTI) (Authenticated)

LaborOfficeFree 19.10 - MySQL Root Password Calculator
2024-03-17 00:16:40 +00:00
Exploit-DB
2af1700331 DB: 2024-03-15
10 changes to exploits/shellcodes/ghdb

Honeywell PM43 < P10.19.050004 - Remote Code Execution (RCE)

Ruijie Switch PSG-5124 26293 - Remote Code Execution (RCE)

SolarView Compact 6.00 - Command Injection

Viessmann Vitogate 300 2.1.3.0 - Remote Code Execution (RCE)

GitLab CE/EE < 16.7.2 - Password Reset

JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE)
KiTTY 0.76.1.13 - 'Start Duplicated Session Hostname' Buffer Overflow
KiTTY 0.76.1.13 - 'Start Duplicated Session Username' Buffer Overflow
KiTTY 0.76.1.13 - Command Injection
2024-03-15 00:16:19 +00:00
Exploit-DB
98f7ce18e2 DB: 2024-03-13
8 changes to exploits/shellcodes/ghdb

Cisco Firepower Management Center < 6.6.7.1 - Authenticated RCE

VMware Cloud Director 10.5 - Bypass identity verification
OSGi v3.7.2 (and below) Console - RCE
OSGi v3.8-3.18 Console - RCE

SnipeIT 6.2.1 - Stored Cross Site Scripting

Client Details System 1.0 - SQL Injection

Human Resource Management System 1.0 - 'employeeid' SQL Injection
2024-03-13 00:16:28 +00:00
Exploit-DB
ce58678266 DB: 2024-03-12
7 changes to exploits/shellcodes/ghdb

Sitecore - Remote Code Execution v8.2

Hitachi NAS (HNAS) System Management Unit (SMU) Backup & Restore < 14.8.7825.01 - IDOR

Adobe ColdFusion versions 2018_15 (and earlier) and 2021_5 and earlier - Arbitrary File Read

WordPress Plugin Duplicator < 1.5.7.1 - Unauthenticated Sensitive Data Exposure to Account Takeover

Microsoft Windows Defender / Trojan.Win32/Powessere.G - Detection Mitigation Bypass
2024-03-12 00:16:25 +00:00
Exploit-DB
60a90afc8d DB: 2024-03-11
7 changes to exploits/shellcodes/ghdb

Ladder v0.0.21 - Server-side request forgery (SSRF)

TP-Link TL-WR740N - Buffer Overflow 'DOS'

Numbas < v7.3 - Remote Code Execution

Akaunting < 3.1.3 - RCE

DataCube3 v1.0 - Unrestricted file upload 'RCE'

Hide My WP < 6.2.9 - Unauthenticated SQLi
2024-03-11 00:16:24 +00:00
Exploit-DB
0af7c5d561 DB: 2024-03-09
1 changes to exploits/shellcodes/ghdb
2024-03-09 00:16:22 +00:00
Exploit-DB
7528fc1c5b DB: 2024-03-07
8 changes to exploits/shellcodes/ghdb

GLiNet - Router Authentication Bypass

CSZ CMS Version 1.3.0 - Authenticated Remote Command Execution

CVE-2023-50071 - Multiple SQL Injection

elFinder Web file manager Version - 2.1.53 Remote Command Execution
Lot Reservation Management System - Unauthenticated File Disclosure
Lot Reservation Management System - Unauthenticated File Upload and Remote Code Execution
2024-03-07 00:16:27 +00:00
Exploit-DB
42e75482b6 DB: 2024-03-06
4 changes to exploits/shellcodes/ghdb

Solar-Log 200 PM+ 3.6.0 Build 99 - 15.10.2019 - Stored XSS

kk Star Ratings < 5.4.6 - Rating Tampering via Race Condition

Neontext Wordpress Plugin - Stored XSS
2024-03-06 00:16:30 +00:00
Exploit-DB
7ef8e488d8 DB: 2024-03-04
22 changes to exploits/shellcodes/ghdb

GL.iNet AR300M v3.216 Remote Code Execution - CVE-2023-46456 Exploit
GL.iNet AR300M v4.3.7 Arbitrary File Read - CVE-2023-46455 Exploit
GL.iNet AR300M v4.3.7 Remote Code Execution - CVE-2023-46454 Exploit

Maxima Max Pro Power - BLE Traffic Replay (Unauthenticated)

R Radio Network FM Transmitter 1.07 system.cgi - Password Disclosure

TitanNit Web Control 2.01 / Atemio 7600 - Root Remote Code Execution

TPC-110W - Missing Authentication for Critical Function

A-PDF All to MP3 Converter 2.0.0 - DEP Bypass via HeapCreate + HeapAlloc

Easywall 0.3.1 - Authenticated Remote Command Execution

Magento ver. 2.4.6 - XSLT Server Side Injection

AC Repair and Services System v1.0 - Multiple SQL Injection

Enrollment System v1.0 - SQL Injection
Petrol Pump Management Software v.1.0 - SQL Injection
Petrol Pump Management Software v.1.0 - Stored Cross Site Scripting via SVG file
Petrol Pump Management Software v1.0 - 'Address' Stored Cross Site Scripting
Petrol Pump Management Software v1.0 - Remote Code Execution via File Upload

Real Estate Management System v1.0 - Remote Code Execution via File Upload
Simple Student Attendance System v1.0 -  'classid' Time Based Blind & Union Based SQL Injection
Simple Student Attendance System v1.0 - Time Based Blind SQL Injection

Boss Mini 1.4.0 - local file inclusion

Windows PowerShell - Event Log Bypass Single Quote Code Execution
2024-03-04 00:16:34 +00:00
Exploit-DB
d0ee8ba723 DB: 2024-03-01
5 changes to exploits/shellcodes/ghdb

mooSocial 3.1.8 - Cross-Site Scripting (XSS) on User Login Page

Wordpress 'simple urls' Plugin < 115 - XSS
2024-03-01 00:16:37 +00:00
Exploit-DB
59f10b7f45 DB: 2024-02-29
13 changes to exploits/shellcodes/ghdb

Saflok - Key Derication Function Exploit

(shellcode) Linux-x64 - create a shell with execve() sending argument using XOR (/bin//sh) [55 bytes]

Academy LMS 6.2 - Reflected XSS

Blood Bank v1.0 - Multiple SQL Injection

Moodle 4.3 - Reflected XSS

TASKHUB-2.8.8 - XSS-Reflected

WordPress Plugin Admin Bar & Dashboard Access Control Version: 1.2.8 - _Dashboard Redirect_ field Stored Cross-Site Scripting (XSS)
WP Fastest Cache 1.2.2 - Unauthenticated SQL Injection
WP Rocket < 2.10.3 - Local File Inclusion (LFI)
2024-02-29 00:16:26 +00:00
Exploit-DB
c1bcfc6347 DB: 2024-02-28
13 changes to exploits/shellcodes/ghdb

TEM Opera Plus FM Family Transmitter 35.45 - Remote Code Execution
TEM Opera Plus FM Family Transmitter 35.45 - XSRF

Executables Created with perl2exe < V30.10C - Arbitrary Code Execution

Atlassian Confluence Data Center and Server - Authentication Bypass (Metasploit)
Automatic-Systems SOC FL9600 FastLine - Directory Transversal
Automatic-Systems SOC FL9600 FastLine - The device contains hardcoded login and password for super admin

dawa-pharma 1.0-2022 - Multiple-SQLi
Moodle 4.3 - Insecure Direct Object Reference
Moodle 4.3 - Reflected XSS

SuperStoreFinder - Multiple Vulnerabilities

Wordpress Plugin Canto < 3.0.5 - Remote File Inclusion (RFI) and Remote Code Execution (RCE)

Zoo Management System 1.0 - Unauthenticated RCE
2024-02-28 00:16:32 +00:00
Exploit-DB
9734fcef1e DB: 2024-02-27
12 changes to exploits/shellcodes/ghdb

Wyrestorm Apollo VX20  < 1.3.58 - Incorrect Access Control 'DoS'
Wyrestorm Apollo VX20 < 1.3.58 - Account Enumeration
Wyrestorm Apollo VX20 < 1.3.58 - Incorrect Access Control 'Credentials Disclosure'
FAQ Management System v1.0 - 'faq' SQL Injection
Flashcard Quiz App v1.0 - 'card' SQL Injection

Simple Inventory Management System v1.0 - 'email' SQL Injection

comments-like-dislike < 1.2.0 - Authenticated (Subscriber+) Plugin Setting Reset

Online Shopping System Advanced - Sql Injection

taskhub 2.8.7 - SQL Injection

IBM i Access Client Solutions v1.1.2 - 1.1.4_ v1.1.4.3 - 1.1.9.4 - Remote Credential Theft
2024-02-27 00:16:33 +00:00
Exploit-DB
624b24bca9 DB: 2024-02-22
2 changes to exploits/shellcodes/ghdb

WEBIGniter v28.7.23 - Stored Cross Site Scripting (XSS)
2024-02-22 00:16:28 +00:00
Exploit-DB
ba28fce174 DB: 2024-02-20
9 changes to exploits/shellcodes/ghdb

SureMDM On-premise < 6.31 - CAPTCHA Bypass User Enumeration

Wondercms 4.3.2 - XSS to RCE

Employee Management System v1 - 'email' SQL Injection

JFrog Artifactory < 7.25.4 - Blind SQL Injection

phpFox < 4.8.13 - (redirect) PHP Object Injection Exploit

XAMPP - Buffer Overflow POC
Microsoft Windows Defender - VBScript Detection Bypass
Microsoft Windows Defender Bypass - Detection Mitigation Bypass
2024-02-20 00:16:25 +00:00
Exploit-DB
411b6755b3 DB: 2024-02-17
1 changes to exploits/shellcodes/ghdb
2024-02-17 00:16:52 +00:00
Exploit-DB
bdcc81a451 DB: 2024-02-16
4 changes to exploits/shellcodes/ghdb

DS Wireless Communication - Remote Code Execution

Metabase 0.46.6 - Pre-Auth Remote Code Execution

SISQUALWFM 7.1.319.103 - Host Header Injection
2024-02-16 00:16:25 +00:00
Exploit-DB
5c0c152cec DB: 2024-02-14
6 changes to exploits/shellcodes/ghdb

VIMESA VHF/FM Transmitter Blue Plus 9.7.1 (doreboot) - Remote Denial Of Service

Splunk 9.0.4 - Information Disclosure

Lost and Found Information System v1.0 - ( IDOR ) leads to Account Take over

ManageEngine ADManager Plus Build < 7183 - Recovery Password Disclosure
2024-02-14 00:16:18 +00:00
Exploit-DB
a846c2fd3a DB: 2024-02-10
8 changes to exploits/shellcodes/ghdb

Zyxel zysh - Format string

Elasticsearch - StackOverflow DoS

Advanced Page Visit Counter 1.0 - Admin+ Stored Cross-Site Scripting (XSS) (Authenticated)

Online Nurse Hiring System 1.0 - Time-Based SQL Injection

Rail Pass Management System 1.0 - Time-Based SQL Injection

Wordpress Augmented-Reality - Remote Code Execution Unauthenticated

Wordpress Seotheme - Remote Code Execution Unauthenticated
2024-02-10 00:16:32 +00:00
Exploit-DB
3876052878 DB: 2024-02-07
1 changes to exploits/shellcodes/ghdb
2024-02-07 00:16:30 +00:00
Exploit-DB
0c65b881ba DB: 2024-02-06
10 changes to exploits/shellcodes/ghdb

Milesight Routers UR5X_ UR32L_ UR32_ UR35_ UR41 - Credential Leakage Through Unprotected System Logs and Weak Password Encryption

WhatsUp Gold 2022 (22.1.0 Build 39) - XSS

Clinic's Patient Management System 1.0 - Unauthenticated RCE

Curfew e-Pass Management System 1.0 - FromDate SQL Injection

GYM MS - GYM Management System - Cross Site Scripting (Stored)

MISP 2.4.171 - Stored XSS

TASKHUB-2.8.8 - XSS-Reflected

Wordpress 'simple urls' Plugin < 115 - XSS
2024-02-06 00:16:29 +00:00
Exploit-DB
81ae91fdae DB: 2024-02-03
14 changes to exploits/shellcodes/ghdb

Electrolink FM/DAB/TV Transmitter - Unauthenticated Remote DoS
Electrolink FM/DAB/TV Transmitter (controlloLogin.js) - Credentials Disclosure
Electrolink FM/DAB/TV Transmitter (Login Cookie) - Authentication Bypass
Electrolink FM/DAB/TV Transmitter (login.htm/mail.htm) - Credentials Disclosure
Electrolink FM/DAB/TV Transmitter - Pre-Auth MPFS Image Remote Code Execution
Electrolink FM/DAB/TV Transmitter - Remote Authentication Removal
TP-LINK TL-WR740N - Multiple HTML Injection
TP-Link TL-WR740N - UnAuthenticated Directory Transversal

Juniper-SRX-Firewalls&EX-switches - (PreAuth-RCE) (PoC)

mooSocial 3.1.8 - Cross-Site Scripting (XSS) on User Login Page

PCMan FTP Server 2.0 - 'pwd' Remote Buffer Overflow

WebCatalog 48.4 - Arbitrary Protocol Execution
2024-02-03 00:16:34 +00:00
Exploit-DB
2aed99237c DB: 2024-02-01
8 changes to exploits/shellcodes/ghdb

Proxmox VE - TOTP Brute Force

RoyalTSX 6.0.1 - RTSZ File Handling Heap Memory Corruption PoC

GoAhead Web Server 2.5 - 'goform/formTest' Multiple HTML Injection Vulnerabilities

101 News 1.0 - Multiple-SQLi
Academy LMS 6.2 - Reflected XSS
Academy LMS 6.2 - SQL Injection

Grocy <=4.0.2 - CSRF
2024-02-01 00:16:32 +00:00
Exploit-DB
a5920da7af DB: 2024-01-30
10 changes to exploits/shellcodes/ghdb

Ricoh Printer - Directory and File Exposure

Blood Bank & Donor Management System using v2.2 - Stored XSS

Equipment Rental Script-1.0 - SQLi

Bank Locker Management System - SQL Injection

Fundraising Script 1.0 - SQLi

PHP Shopping Cart 4.2 - Multiple-SQLi

7 Sticky Notes v1.9 - OS Command Injection

Typora v1.7.4 - OS Command Injection
2024-01-30 00:16:26 +00:00
Exploit-DB
967f9d17d6 DB: 2024-01-24
1 changes to exploits/shellcodes/ghdb
2024-01-24 00:16:25 +00:00
Exploit-DB
cb7ba0c503 DB: 2023-12-22
1 changes to exploits/shellcodes/ghdb
2023-12-22 00:16:27 +00:00
Exploit-DB
82c4f0ab51 DB: 2023-12-19
1 changes to exploits/shellcodes/ghdb
2023-12-19 00:16:22 +00:00
Exploit-DB
d6ac341475 DB: 2023-12-16
1 changes to exploits/shellcodes/ghdb
2023-12-16 00:16:30 +00:00
Exploit-DB
5ae67f58b9 DB: 2023-12-15
1 changes to exploits/shellcodes/ghdb
2023-12-15 00:16:26 +00:00
Exploit-DB
07b04761c2 DB: 2023-12-13
1 changes to exploits/shellcodes/ghdb
2023-12-13 00:16:53 +00:00
Exploit-DB
4b91641d83 DB: 2023-12-12
1 changes to exploits/shellcodes/ghdb
2023-12-12 00:16:31 +00:00
Exploit-DB
baedefe44c DB: 2023-12-07
1 changes to exploits/shellcodes/ghdb
2023-12-07 00:16:31 +00:00
Exploit-DB
3ed9fc9688 DB: 2023-12-05
1 changes to exploits/shellcodes/ghdb
2023-12-05 00:16:21 +00:00
Exploit-DB
066333e56d DB: 2023-12-02
1 changes to exploits/shellcodes/ghdb
2023-12-02 00:16:24 +00:00
Exploit-DB
7e32166ebc DB: 2023-12-01
1 changes to exploits/shellcodes/ghdb
2023-12-01 00:16:26 +00:00
Exploit-DB
057c2f886a DB: 2023-11-30
1 changes to exploits/shellcodes/ghdb
2023-11-30 00:16:31 +00:00
Exploit-DB
bde3836027 DB: 2023-11-28
1 changes to exploits/shellcodes/ghdb
2023-11-28 00:16:33 +00:00
Exploit-DB
617a6b4036 DB: 2023-11-25
1 changes to exploits/shellcodes/ghdb
2023-11-25 00:16:32 +00:00
Exploit-DB
8a972c9a3f DB: 2023-11-24
1 changes to exploits/shellcodes/ghdb
2023-11-24 00:16:42 +00:00
Exploit-DB
d66aada84d DB: 2023-11-21
1 changes to exploits/shellcodes/ghdb
2023-11-21 00:16:23 +00:00
Exploit-DB
034fa97b3e DB: 2023-11-18
1 changes to exploits/shellcodes/ghdb
2023-11-18 00:16:41 +00:00
Exploit-DB
e7b3c09fd9 DB: 2023-11-11
1 changes to exploits/shellcodes/ghdb
2023-11-11 00:16:32 +00:00
Exploit-DB
937420d384 DB: 2023-11-10
1 changes to exploits/shellcodes/ghdb
2023-11-10 00:16:27 +00:00
Exploit-DB
43a5e18260 DB: 2023-11-09
1 changes to exploits/shellcodes/ghdb
2023-11-09 00:16:27 +00:00
Exploit-DB
7b7a9c9ea4 DB: 2023-11-08
1 changes to exploits/shellcodes/ghdb
2023-11-08 00:17:10 +00:00