Commit graph

2829 commits

Author SHA1 Message Date
Exploit-DB
3711d1e88d DB: 2023-11-07
1 changes to exploits/shellcodes/ghdb
2023-11-07 00:16:47 +00:00
Exploit-DB
5b9acfe03d DB: 2023-11-03
1 changes to exploits/shellcodes/ghdb
2023-11-03 00:17:00 +00:00
Exploit-DB
ea7fd161a3 DB: 2023-11-02
1 changes to exploits/shellcodes/ghdb
2023-11-02 00:16:33 +00:00
Exploit-DB
e369c91366 DB: 2023-11-01
1 changes to exploits/shellcodes/ghdb
2023-11-01 00:16:42 +00:00
Exploit-DB
75cbb282d9 DB: 2023-10-31
12 changes to exploits/shellcodes/ghdb

systemd 246 - Local Privilege Escalation

ChurchCRM v4.5.3 - Authenticated SQL Injection

Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE) via subprocess_execute

Maltrail v0.53 - Unauthenticated Remote Code Execution (RCE)

Request-Baskets v1.2.1 - Server-side request forgery (SSRF)
2023-10-31 00:17:05 +00:00
Exploit-DB
45020d9cc3 DB: 2023-10-26
1 changes to exploits/shellcodes/ghdb
2023-10-26 00:16:49 +00:00
Exploit-DB
3c68644b7f DB: 2023-10-24
1 changes to exploits/shellcodes/ghdb
2023-10-24 00:16:26 +00:00
Exploit-DB
28233c60a9 DB: 2023-10-21
1 changes to exploits/shellcodes/ghdb
2023-10-21 00:17:11 +00:00
Exploit-DB
8e469af5e4 DB: 2023-10-20
1 changes to exploits/shellcodes/ghdb
2023-10-20 00:16:34 +00:00
Exploit-DB
d769738a1b DB: 2023-10-19
1 changes to exploits/shellcodes/ghdb
2023-10-19 00:16:34 +00:00
Exploit-DB
888e6c1d4c DB: 2023-10-17
1 changes to exploits/shellcodes/ghdb
2023-10-17 00:16:34 +00:00
Exploit-DB
53fc63f69b DB: 2023-10-14
1 changes to exploits/shellcodes/ghdb
2023-10-14 00:16:29 +00:00
Exploit-DB
f3649a641f DB: 2023-10-10
24 changes to exploits/shellcodes/ghdb

Minio 2022-07-29T19-40-48Z - Path traversal

Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Denial Of Service

Atcom 2.7.x.x - Authenticated Command Injection

Ruijie Reyee Mesh Router - MITM Remote Code Execution (RCE)
Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Admin Password Change
Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Credentials Extraction

OpenPLC WebServer 3 - Denial of Service

Splunk 9.0.5 - admin account take over

BoidCMS v2.0.0 - authenticated file upload vulnerability

Cacti 1.2.24 - Authenticated command injection when using SNMP options

Chitor-CMS v1.1.2 - Pre-Auth SQL Injection

Clcknshop 1.0.0 - SQL Injection

Coppermine Gallery 1.6.25 - RCE

Crypto Currency Tracker (CCT) 9.5 - Admin Account Creation (Unauthenticated)

GLPI GZIP(Py3) 9.4.5 - RCE

Limo Booking Software v1.0 - CORS

Media Library Assistant Wordpress Plugin - RCE and LFI

Online ID Generator 1.0 - Remote Code Execution (RCE)

Shuttle-Booking-Software v1.0 - Multiple-SQLi

Webedition CMS v2.9.8.8 - Blind SSRF

WEBIGniter v28.7.23 File Upload - Remote Code Execution

Wordpress Plugin Masterstudy LMS - 3.0.17 - Unauthenticated Instructor Account Creation

Wordpress Sonaar Music Plugin 4.7 - Stored XSS

Microsoft Windows 11 - 'apds.dll' DLL hijacking (Forced)
2023-10-10 00:16:32 +00:00
Exploit-DB
e5f7757184 DB: 2023-10-03
1 changes to exploits/shellcodes/ghdb
2023-10-03 00:16:26 +00:00
g0t mi1k
f88561adfb Merge branch 'nmap-version-parsing' into 'main'
Fix: searchsploit Nmap XML parsing loses software version data.

See merge request exploit-database/exploitdb!3
2023-09-25 16:46:54 +00:00
Michael Monsivais
8298b27c9c Fix: searchsploit Nmap parsing loses version data.
Modified searchsploit's Nmap XML parsing to correctly extract software
versions. Also, these versions are no longer split on '.'.
2023-09-15 20:29:25 -04:00
Exploit-DB
3cde8c39d6 DB: 2023-09-13
1 changes to exploits/shellcodes/ghdb
2023-09-13 00:16:29 +00:00
Exploit-DB
db6fc602bf DB: 2023-09-12
1 changes to exploits/shellcodes/ghdb
2023-09-12 00:16:26 +00:00
Exploit-DB
cbe784b087 DB: 2023-09-09
16 changes to exploits/shellcodes/ghdb

Techview LA-5570 Wireless Gateway Home Automation Controller - Multiple Vulnerabilities

Axigen < 10.3.3.47_ 10.2.3.12 - Reflected XSS

Drupal 10.1.2 - web-cache-poisoning-External-service-interaction

Jorani v1.0.3-(c)2014-2023 - XSS Reflected & Information Disclosure

soosyze 2.0.0 - File Upload

SPA-Cart eCommerce CMS 1.9.0.3 - SQL Injection

Wordpress Plugin Elementor 3.5.5 - Iframe Injection

Wp2Fac - OS Command Injection

Maltrail v0.53 - Unauthenticated Remote Code Execution (RCE)

SyncBreeze 15.2.24 - 'login' Denial of Service

GOM Player 2.3.90.5360 - Buffer Overflow (PoC)

GOM Player 2.3.90.5360 - Remote Code Execution (RCE)

Windows/x64 - PIC Null-Free TCP Reverse Shell Shellcode (476 Bytes)
2023-09-09 00:16:33 +00:00
Exploit-DB
54971d143b DB: 2023-09-08
1 changes to exploits/shellcodes/ghdb
2023-09-08 00:16:30 +00:00
Exploit-DB
fdcaa2b976 DB: 2023-09-07
1 changes to exploits/shellcodes/ghdb

Blood Donor Management System v1.0 - Stored XSS
2023-09-07 00:16:27 +00:00
Exploit-DB
4e246a01fb DB: 2023-09-05
18 changes to exploits/shellcodes/ghdb

DLINK DPH-400SE - Exposure of Sensitive Information

FileMage Gateway 1.10.9 - Local File Inclusion

Academy LMS 6.1 - Arbitrary File Upload

AdminLTE PiHole 5.18 - Broken Access Control

Blood Donor Management System v1.0 - Stored XSS

Bus Reservation System 1.1 - Multiple-SQLi

Credit Lite 1.5.4 - SQL Injection
CSZ CMS 1.3.0 - Stored Cross-Site Scripting ('Photo URL' and 'YouTube URL' )
CSZ CMS 1.3.0 - Stored Cross-Site Scripting (Plugin 'Gallery')

Hyip Rio 2.1 - Arbitrary File Upload

Member Login Script 3.3 - Client-side desync

SPA-Cart eCommerce CMS 1.9.0.3 - Reflected XSS
Webedition CMS v2.9.8.8 - Remote Code Execution (RCE)
Webedition CMS v2.9.8.8 - Stored XSS
Webedition CMS v2.9.8.8 - Remote Code Execution (RCE)
Webedition CMS v2.9.8.8 - Stored XSS

WP Statistics Plugin 13.1.5 current_page_id - Time based SQL injection (Unauthenticated)

Freefloat FTP Server 1.0 - 'PWD' Remote Buffer Overflow

Kingo ROOT 1.5.8 - Unquoted Service Path

NVClient v5.0 - Stack Buffer Overflow (DoS)

Ivanti Avalanche <v6.4.0.0 - Remote Code Execution
2023-09-05 00:16:27 +00:00
Exploit-DB
4c8ac36b6c DB: 2023-08-30
1 changes to exploits/shellcodes/ghdb

Online Clinic Management System 2.2 - HTML Injection
Online Clinic Management System 2.2 - Multiple Stored Cross-Site Scripting (XSS)
Online Clinic Management System 2.2 - HTML Injection
Online Clinic Management System 2.2 - Multiple Stored Cross-Site Scripting (XSS)
Purchase Order Management System 1.0 - Remote File Upload
Purchase Order Management-1.0 - Local File Inclusion
Purchase Order Management System 1.0 - Remote File Upload
Purchase Order Management-1.0 - Local File Inclusion

Restaurant Management System 1.0  - SQL Injection
2023-08-30 00:16:32 +00:00
Exploit-DB
fe2c42ff0e DB: 2023-08-25
4 changes to exploits/shellcodes/ghdb

User Registration & Login and User Management System v3.0 - SQL Injection (Unauthenticated)
User Registration & Login and User Management System v3.0 - Stored Cross-Site Scripting (XSS)

Uvdesk 1.1.4 - Stored XSS (Authenticated)
2023-08-25 00:16:28 +00:00
Exploit-DB
cb5ca4a416 DB: 2023-08-24
1 changes to exploits/shellcodes/ghdb

Color Prediction Game v1.0 - SQL Injection

Multi-Vendor Online Groceries Management System 1.0 - 'id' Blind SQL Injection

Online Eyewear Shop 1.0 - SQL Injection (Unauthenticated)
2023-08-24 00:16:24 +00:00
Exploit-DB
e07f33f24d DB: 2023-08-22
17 changes to exploits/shellcodes/ghdb

EuroTel ETL3100 - Transmitter Authorization Bypass (IDOR)
EuroTel ETL3100 - Transmitter Default Credentials
EuroTel ETL3100 - Transmitter Unauthenticated Config/Log Download

Color Prediction Game v1.0 - SQL Injection

Crypto Currency Tracker (CCT) 9.5 - Admin Account Creation (Unauthenticated)

Dolibarr Version 17.0.1 - Stored XSS

Global - Multi School Management System Express v1.0- SQL Injection

OVOO Movie Portal CMS v3.3.3 - SQL Injection

PHPJabbers Business Directory Script v3.2 - Multiple Vulnerabilities

Taskhub CRM Tool 2.8.6 - SQL Injection

Inosoft VisiWin 7 2022-2.1 - Insecure Folders Permissions
TSPlus 16.0.0.0 - Remote Work Insecure Credential storage
TSplus 16.0.0.0 - Remote Work Insecure Files and Folders
TSplus 16.0.2.14 - Remote Access Insecure Files and Folders Permissions

Linux/x64 - memfd_create ELF loader Shellcode (170 bytes)
2023-08-22 00:16:22 +00:00
Exploit-DB
500cf5a2e0 DB: 2023-08-20
1 changes to exploits/shellcodes/ghdb

Diafan CMS 6.0 - Reflected Cross-Site Scripting (XSS)

Online Art gallery project 1.0 - Arbitrary File Upload (Unauthenticated)

Online Shopping Cart System 1.0 - 'id' SQL Injection

Online Thesis Archiving System v1.0 - Multiple-SQLi
WebsiteBaker v2.13.3 - Cross-Site Scripting (XSS)
WebsiteBaker v2.13.3 - Directory Traversal
WebsiteBaker v2.13.3 - Stored XSS
WebsiteBaker v2.13.3 - Cross-Site Scripting (XSS)
WebsiteBaker v2.13.3 - Directory Traversal
WebsiteBaker v2.13.3 - Stored XSS
2023-08-20 00:16:58 +00:00
Exploit-DB
6da2bca764 DB: 2023-08-12
1 changes to exploits/shellcodes/ghdb

projectSend r1605 - CSV injection
projectSend r1605 - Private file download
projectSend r1605 - CSV injection
projectSend r1605 - Private file download

projectSend r1605 - Stored XSS
2023-08-12 00:16:26 +00:00
Exploit-DB
f55092b332 DB: 2023-08-11
6 changes to exploits/shellcodes/ghdb

TP-Link Archer AX21 - Unauthenticated Command Injection

systemd 246 - Local Privilege Escalation

Maltrail v0.53 - Unauthenticated Remote Code Execution (RCE)

Request-Baskets v1.2.1 - Server-side request forgery (SSRF)

OutSystems Service Studio 11.53.30 - DLL Hijacking
2023-08-11 00:16:25 +00:00
Exploit-DB
69f3ee7722 DB: 2023-08-09
8 changes to exploits/shellcodes/ghdb

Lucee 5.4.2.17 - Authenticated Reflected XSS

Adlisting Classified Ads 2.14.0 - WebPage Content Information Disclosure

Emagic Data Center Management Suite v6.0 - OS Command Injection

mooSocial 3.1.8 - Reflected XSS

PHPJabbers Vacation Rental Script 4.0 - CSRF

Social-Commerce 3.1.6 - Reflected XSS

Pyro CMS 3.9 - Server-Side Template Injection (SSTI) (Authenticated)
2023-08-09 00:16:24 +00:00
Exploit-DB
010e679abe DB: 2023-08-05
25 changes to exploits/shellcodes/ghdb

ReyeeOS 1.204.1614 - MITM Remote Code Execution (RCE)

Shelly PRO 4PM v0.11.0 - Authentication Bypass

Ozeki SMS Gateway 10.3.208 - Arbitrary File Read (Unauthenticated)

Academy LMS 6.0 - Reflected XSS

Adiscon LogAnalyzer v.4.1.13 - Cross Site Scripting

Campcodes Online Matrimonial Website System v3.3 - Code Execution via malicious SVG file upload

JLex GuestBook 1.6.4 - Reflected XSS

Joomla JLex Review 6.0.1 - Reflected XSS

News Portal v4.0 - SQL Injection (Unauthorized)

PHPJabbers Cleaning Business 1.0 - Reflected XSS

PHPJabbers Night Club Booking 1.0 - Reflected XSS
PHPJabbers Rental Property Booking 2.0 - Reflected XSS
PHPJabbers Service Booking Script 1.0 - Reflected XSS
PHPJabbers Shuttle Booking Software 1.0 - Reflected XSS

PHPJabbers Taxi Booking 2.0 - Reflected XSS
Webedition CMS v2.9.8.8 - Remote Code Execution (RCE)
Webedition CMS v2.9.8.8 - Stored XSS

Webutler v3.2 - Remote Code Execution (RCE)
WordPress adivaha Travel Plugin 2.3 - Reflected XSS
WordPress adivaha Travel Plugin 2.3 - SQL Injection
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Event Access
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Post Access via IDOR

WordPress Plugin Forminator 1.24.6 - Unauthenticated Remote Command Execution

WordPress Plugin Ninja Forms 3.6.25 - Reflected XSS

Xlight FTP Server 3.9.3.6 - 'Stack Buffer Overflow' (DOS)
2023-08-05 00:16:32 +00:00
Exploit-DB
9229ea6f66 DB: 2023-08-03
1 changes to exploits/shellcodes/ghdb

Bookwyrm v0.4.3 - Authentication Bypass

Gitea 1.16.6 - Remote Code Execution (RCE) (Metasploit)

Uvdesk v1.1.3 - File Upload Remote Code Execution (RCE) (Authenticated)

WordPress Plugin Duplicator 1.4.7 - Information Disclosure

Wordpress Plugin WP-UserOnline 2.88.0 - Stored Cross Site Scripting (XSS)
2023-08-03 00:16:49 +00:00
Exploit-DB
5eb89a2046 DB: 2023-08-01
5 changes to exploits/shellcodes/ghdb

Joomla iProperty Real Estate 4.1.1 - Reflected XSS

Joomla Solidres 2.13.3 - Reflected XSS

RosarioSIS 10.8.4 - CSV Injection

Uvdesk v1.1.3 - File Upload Remote Code Execution (RCE) (Authenticated)

WordPress Plugin AN_Gradebook 5.0.1 - SQLi

General Device Manager 2.5.2.2 - Buffer Overflow (SEH)
2023-08-01 00:16:36 +00:00
Exploit-DB
c18d9953a2 DB: 2023-07-29
22 changes to exploits/shellcodes/ghdb

Keeper Security desktop 16.10.2 & Browser Extension 16.5.4 - Password Dumping

Active Super Shop CMS v2.5 - HTML Injection Vulnerabilities

Availability Booking Calendar v1.0 - Multiple Cross-site scripting (XSS)

Dooblou WiFi File Explorer 1.13.3 - Multiple Vulnerabilities

Joomla HikaShop 4.7.4 - Reflected XSS

Joomla VirtueMart Shopping Cart 4.0.12 - Reflected XSS

mooDating 1.2 - Reflected Cross-site scripting (XSS)

October CMS v3.4.4 - Stored Cross-Site Scripting (XSS) (Authenticated)

PaulPrinting CMS - (Search Delivery) Cross Site Scripting

Perch v3.2 - Persistent Cross Site Scripting (XSS)

RosarioSIS 10.8.4 - CSV Injection

WordPress Plugin AN_Gradebook 5.0.1 - SQLi

Zomplog 3.9 - Cross-site scripting (XSS)

zomplog 3.9 - Remote Code Execution (RCE)
copyparty 1.8.2 - Directory Traversal
copyparty v1.8.6 - Reflected Cross Site Scripting (XSS)

GreenShot  1.2.10 - Insecure Deserialization Arbitrary Code Execution

mRemoteNG v1.77.3.1784-NB - Cleartext Storage of Sensitive Information in Memory

Windows/x64 - PIC Null-Free Calc.exe Shellcode (169 Bytes)
2023-07-29 00:16:43 +00:00
Exploit-DB
033e7ba3e0 DB: 2023-07-22
3 changes to exploits/shellcodes/ghdb

Online Piggery Management System v1.0 - unauthenticated file upload vulnerability
Perch v3.2 - Remote Code Execution (RCE)
Perch v3.2 - Stored XSS

Wordpress Plugin Zephyr Project Manager 3.2.42 - Multiple SQLi
2023-07-22 00:16:25 +00:00
Exploit-DB
98cdb05106 DB: 2023-07-21
10 changes to exploits/shellcodes/ghdb

Microsoft Office 365 Version 18.2305.1222.0 - Elevation of Privilege + RCE.

RWS WorldServer 11.7.3 - Session Token Enumeration

Aures Booking & POS Terminal - Local Privilege Escalation

Boom CMS v8.0.7 - Cross Site Scripting

PaulPrinting CMS - Multiple Cross Site Web Vulnerabilities

pfSense v2.7.0 - OS Command Injection

Webile v1.0.1 - Multiple Cross Site Scripting

Wifi Soft Unibox Administration 3.0 & 3.1 - SQL Injection

RaidenFTPD 2.4.4005 - Buffer Overflow (SEH)
2023-07-21 00:16:29 +00:00
Exploit-DB
3a3c03321c DB: 2023-07-20
18 changes to exploits/shellcodes/ghdb

Hikvision Hybrid SAN Ds-a71024 Firmware - Multiple Remote Code Execution

ABB FlowX v4.00 - Exposure of Sensitive Information

TP-Link TL-WR740N - Authenticated Directory Transversal

Microsoft Edge 114.0.1823.67 (64-bit) - Information Disclosure

Backdrop Cms v1.25.1 - Stored Cross-Site Scripting (XSS)
Blackcat Cms v1.4 - Remote Code Execution (RCE)
Blackcat Cms v1.4 - Stored XSS
CmsMadeSimple v2.2.17 - Remote Code Execution (RCE)
CmsMadeSimple v2.2.17 - session hijacking via Server-Side Template Injection (SSTI)
CmsMadeSimple v2.2.17 - Stored Cross-Site Scripting (XSS)

Joomla! com_booking component 2.4.9 - Information Leak (Account enumeration)

Online Piggery Management System v1.0 - unauthenticated file upload vulnerability

phpfm v1.7.9 - Authentication type juggling

PimpMyLog v1.7.14 - Improper access control

PMB 7.4.6 - SQL Injection

Statamic 4.7.0 - File-Inclusion

Vaidya-Mitra 1.0 - Multiple SQLi
2023-07-20 00:16:46 +00:00
Exploit-DB
20fe50e6db DB: 2023-07-18
1 changes to exploits/shellcodes/ghdb
2023-07-18 00:16:21 +00:00
Exploit-DB
fd788a92e3 DB: 2023-07-16
9 changes to exploits/shellcodes/ghdb

Cisco UCS-IMC Supervisor 2.2.0.0 - Authentication Bypass

Netlify CMS 2.10.192 - Stored Cross-Site Scripting (XSS)

Admidio v4.2.10 - Remote Code Execution (RCE)
Bus Pass Management System 1.0 - 'viewid' Insecure direct object references (IDOR)
Bus Pass Management System 1.0 - 'viewid' SQL Injection
Bus Pass Management System 1.0 - 'viewid' Insecure direct object references (IDOR)
Bus Pass Management System 1.0 - 'viewid' SQL Injection

Icinga Web 2.10 - Authenticated Remote Code Execution

News Portal v4.0 - SQL Injection (Unauthorized)

Pluck v4.7.18 - Remote Code Execution (RCE)

ProjeQtOr Project Management System v10.4.1 - Multiple XSS

WinterCMS < 1.2.3 - Persistent Cross-Site Scripting

XAMPP 8.2.4 - Unquoted Path
2023-07-16 00:16:39 +00:00
Exploit-DB
00f5021452 DB: 2023-07-12
10 changes to exploits/shellcodes/ghdb

Ateme TITAN File 3.9 - SSRF File Enumeration

Netlify CMS 2.10.192 - Stored Cross-Site Scripting (XSS)

Spring Cloud 3.2.2 - Remote Command Execution (RCE)

BuildaGate5library v5 - Reflected Cross-Site Scripting (XSS)

Park Ticketing Management System 1.0  - 'viewid' SQL Injection

Park Ticketing Management System 1.0 - 'viewid' SQL Injection

Frappe Framework (ERPNext) 13.4.0 - Remote Code Execution (Authenticated)

AVG Anti Spyware 7.5 - Unquoted Service Path _AVG Anti-Spyware Guard_

Game Jackal Server v5 - Unquoted Service Path _GJServiceV5_
MiniTool Partition Wizard ShadowMaker v.12.7 - Unquoted Service Path _MTAgentService_
MiniTool Partition Wizard ShadowMaker v.12.7 - Unquoted Service Path _MTSchedulerService_
2023-07-12 00:16:54 +00:00
Exploit-DB
743db0e747 DB: 2023-07-08
4 changes to exploits/shellcodes/ghdb

Microsoft Outlook Microsoft 365 MSO (Version 2306 Build 16.0.16529.20100) 32-bit - Remote Code Execution
Bus Pass Management System 1.0 - 'adminname' Stored Cross-Site Scripting (XSS)
Bus Pass Management System 1.0 - 'Search' SQL injection
Bus Pass Management System 1.0 - 'adminname' Stored Cross-Site Scripting (XSS)
Bus Pass Management System 1.0 - 'Search' SQL injection

Faculty Evaluation System v1.0 - SQL Injection

Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution
2023-07-08 00:16:23 +00:00
Exploit-DB
e2ea5c0412 DB: 2023-07-07
4 changes to exploits/shellcodes/ghdb

Gila CMS 1.10.9 - Remote Code Execution (RCE) (Authenticated)

Lost and Found Information System v1.0 - SQL Injection

Piwigo v13.7.0 - Stored Cross-Site Scripting (XSS) (Authenticated)
2023-07-07 00:16:26 +00:00
Exploit-DB
9461677d02 DB: 2023-07-05
4 changes to exploits/shellcodes/ghdb

Beauty Salon Management System v1.0 - SQLi

Bus Pass Management System 1.0  - Stored Cross-Site Scripting (XSS)

Car Rental Script 1.8 - Stored Cross-site scripting (XSS)

NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi
2023-07-05 00:16:21 +00:00
Exploit-DB
ef9b4e5962 DB: 2023-07-04
20 changes to exploits/shellcodes/ghdb

TP-Link TL-WR940N V4 - Buffer OverFlow

D-Link DAP-1325 - Broken Access Control

Alkacon OpenCMS 15.0 - Multiple Cross-Site Scripting (XSS)
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 32-bit - Remote Code Execution (RCE)
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 64-bit - Remote Code Execution (RCE)

FuguHub 8.1 - Remote Code Execution

GZ Forum Script 1.8 - Stored Cross-Site Scripting (XSS)

PodcastGenerator 3.2.9 - Blind SSRF via XML Injection

POS Codekop v2.0 - Authenticated Remote Code Execution (RCE)

Prestashop 8.0.4 - Cross-Site Scripting (XSS)

Rukovoditel 3.4.1 - Multiple Stored XSS

Sales of Cashier Goods v1.0 - Cross Site Scripting (XSS)

spip v4.1.10 - Spoofing Admin account

Time Slot Booking Calendar 1.8 - Stored Cross-Site Scripting (XSS)

Vacation Rental 1.8 - Stored Cross-Site Scripting (XSS)

WBCE CMS 1.6.1 - Open Redirect & CSRF
WebsiteBaker v2.13.3 - Directory Traversal
WebsiteBaker v2.13.3 - Stored XSS

WP AutoComplete 1.0.4 - Unauthenticated SQLi
2023-07-04 00:16:26 +00:00
Exploit-DB
7807e6f266 DB: 2023-06-27
7 changes to exploits/shellcodes/ghdb

Azure Apache Ambari 2302250400 - Spoofing

Microsoft SharePoint Enterprise Server 2016 - Spoofing

Bus Pass Management System 1.0 - Cross-Site Scripting (XSS)

NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi

PrestaShop Winbiz Payment module - Improper Limitation of a Pathname to a Restricted Directory

Translatepress Multilinugal WordPress plugin < 2.3.3 - Authenticated SQL Injection

Xenforo Version 2.2.13 - Authenticated Stored XSS

Windows 11 22h2 - Kernel Privilege Elevation
2023-06-27 00:17:09 +00:00
Exploit-DB
c79c4813de DB: 2023-06-24
4 changes to exploits/shellcodes/ghdb

MCL-Net 4.3.5.8788 - Information Disclosure

Abantecart v1.3.2 - Authenticated Remote Code Execution

Bludit < 3.13.1 Backup Plugin - Arbitrary File Download (Authenticated)

SimpleMachinesForum v2.1.1 - Authenticated Remote Code Execution

NCH Express Invoice - Clear Text Password Storage and Account Takeover
2023-06-24 00:16:23 +00:00
Exploit-DB
ea194c414f DB: 2023-06-23
3 changes to exploits/shellcodes/ghdb

Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)

Microsoft OneNote (Version 2305 Build 16.0.16501.20074) 64-bit - Spoofing

MODX Revolution v2.8.3-pl - Authenticated Remote Code Execution

Super Socializer 7.13.52 - Reflected XSS
2023-06-23 00:16:26 +00:00
Exploit-DB
00f6b3e7ed DB: 2023-06-22
2 changes to exploits/shellcodes/ghdb

HiSecOS 04.0.01 - Privilege Escalation

SPIP v4.2.1 - Remote Code Execution (Unauthenticated)
SPIP v4.2.0 - Remote Code Execution (Unauthenticated)
2023-06-22 00:16:26 +00:00
Exploit-DB
cc495bca11 DB: 2023-06-21
8 changes to exploits/shellcodes/ghdb

Nokia ASIKA 7.13.52 - Hard-coded private key disclosure

SPIP v4.2.1 - Remote Code Execution (Unauthenticated)

Student Study Center Management System v1.0 - Stored Cross-Site Scripting (XSS)

Super Socializer 7.13.52 - Reflected XSS

WP Sticky Social 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting (XSS)

PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)
2023-06-21 00:16:34 +00:00
Exploit-DB
147824bdba DB: 2023-06-20
8 changes to exploits/shellcodes/ghdb

Symantec SiteMinder WebAgent v12.52 - Cross-site scripting (XSS)

BoxBilling<=4.22.1.5 - Remote Code Execution (RCE)

Diafan CMS 6.0 - Reflected Cross-Site Scripting (XSS)

Groomify v1.0 - SQL Injection

Jobpilot v2.61 - SQL Injection

Sales Tracker Management System v1.0 - Multiple Vulnerabilities

Student Study Center Management System v1.0 - Stored Cross-Site Scripting (XSS)

The Shop v2.5 - SQL Injection

WordPress Theme Medic v1.0.0 - Weak Password Recovery Mechanism for Forgotten Password

Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
2023-06-20 00:16:29 +00:00