Offensive Security
1569af9b59
DB: 2020-10-06
...
2 changes to exploits/shellcodes
MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection
SpamTitan 7.07 - Unauthenticated Remote Code Execution
2020-10-06 05:02:05 +00:00
Offensive Security
9772f1e7c0
DB: 2020-10-03
...
2 changes to exploits/shellcodes
MedDream PACS Server 6.8.3.751 - Remote Code Execution (Authenticated)
Photo Share Website 1.0 - Persistent Cross-Site Scripting
2020-10-03 05:02:10 +00:00
Offensive Security
f697a81a18
DB: 2020-10-02
...
12 changes to exploits/shellcodes
Sony IPELA Network Camera 1.82.01 - 'ftpclient.cgi' Remote Stack Buffer Overflow
BrightSign Digital Signage Diagnostic Web Server 8.2.26 - Server-Side Request Forgery (Unauthenticated)
BrightSign Digital Signage Diagnostic Web Server 8.2.26 - File Delete Path Traversal
SpinetiX Fusion Digital Signage 3.4.8 - Database Backup Disclosure
SpinetiX Fusion Digital Signage 3.4.8 - Cross-Site Request Forgery (Add Admin)
SpinetiX Fusion Digital Signage 3.4.8 - Username Enumeration
MonoCMS Blog 1.0 - Arbitrary File Deletion (Authenticated)
WebsiteBaker 2.12.2 - 'display_name' SQL Injection (authenticated)
GetSimple CMS 3.3.16 - Persistent Cross-Site Scripting (Authenticated)
CMS Made Simple 2.2.14 - Persistent Cross-Site Scripting (Authenticated)
Typesetter CMS 5.1 - 'Site Title' Persistent Cross-Site Scripting
Exhibitor Web UI 1.7.1 - Remote Code Execution
2020-10-02 05:02:08 +00:00
Offensive Security
fdab02c0ff
DB: 2020-09-30
...
3 changes to exploits/shellcodes
BearShare Lite 5.2.5 - 'Advanced Search'Buffer Overflow in (PoC)
CloudMe 1.11.2 - Buffer Overflow ROP (DEP_ASLR)
WebsiteBaker 2.12.2 - Remote Code Execution
2020-09-30 05:02:05 +00:00
Offensive Security
18829b7a22
DB: 2020-09-26
...
4 changes to exploits/shellcodes
BigTree CMS 4.4.10 - Remote Code Execution
Anchor CMS 0.12.7 - Persistent Cross-Site Scripting (Authenticated)
B-swiss 3 Digital Signage System 3.6.5 - Cross-Site Request Forgery (Add Maintenance Admin)
B-swiss 3 Digital Signage System 3.6.5 - Database Disclosure
2020-09-26 05:02:04 +00:00
Offensive Security
72506f63c2
DB: 2020-09-25
...
2 changes to exploits/shellcodes
Simple Online Food Ordering System 1.0 - 'id' SQL Injection (Unauthenticated)
Visitor Management System in PHP 1.0 - Persistent Cross-Site Scripting
2020-09-25 05:02:10 +00:00
Offensive Security
00b27610c8
DB: 2020-09-24
...
2 changes to exploits/shellcodes
Online Food Ordering System 1.0 - Remote Code Execution
2020-09-24 05:02:05 +00:00
Offensive Security
1a8b74a305
DB: 2020-09-23
...
2 changes to exploits/shellcodes
Comodo Unified Threat Management Web Console 2.7.0 - Remote Code Execution
Flatpress Add Blog 1.0.3 - Persistent Cross-Site Scripting
2020-09-23 05:02:05 +00:00
Offensive Security
87f49d4427
DB: 2020-09-22
...
6 changes to exploits/shellcodes
ForensiTAppxService 2.2.0.4 - 'ForensiTAppxService.exe' Unquoted Service Path
Online Shop Project 1.0 - 'p' SQL Injection
BlackCat CMS 1.3.6 - Cross-Site Request Forgery
Seat Reservation System 1.0 - 'id' SQL Injection
Mida eFramework 2.9.0 - Back Door Access
B-swiss 3 Digital Signage System 3.6.5 - Remote Code Execution
2020-09-22 05:02:05 +00:00
Offensive Security
0d8101f1a1
DB: 2020-09-19
...
2 changes to exploits/shellcodes
SpamTitan 7.07 - Remote Code Execution (Authenticated)
Mantis Bug Tracker 2.3.0 - Remote Code Execution (Unauthenticated)
2020-09-19 05:02:05 +00:00
Offensive Security
3080c3ca18
DB: 2020-09-17
...
2 changes to exploits/shellcodes
Windows TCPIP Finger Command - C2 Channel and Bypassing Security Software
Piwigo 2.10.1 - Cross Site Scripting
2020-09-17 05:02:05 +00:00
Offensive Security
e23028b045
DB: 2020-09-16
...
2 changes to exploits/shellcodes
ThinkAdmin 6 - Arbitrarily File Read
Tailor MS 1.0 - Reflected Cross-Site Scripting
2020-09-16 05:02:06 +00:00
Offensive Security
903280c17b
DB: 2020-09-15
...
6 changes to exploits/shellcodes
Rapid7 Nexpose Installer 6.6.39 - 'nexposeengine' Unquoted Service Path
Pearson Vue VTS 2.3.1911 Installer - 'VUEApplicationWrapper' Unquoted Service Path
RAD SecFlow-1v SF_0290_2.3.01.26 - Persistent Cross-Site Scripting
RAD SecFlow-1v SF_0290_2.3.01.26 - Cross-Site Request Forgery (Reboot)
Joomla! paGO Commerce 2.5.9.0 - SQL Injection (Authenticated)
2020-09-15 05:02:06 +00:00
Offensive Security
421c99f9e3
DB: 2020-09-11
...
3 changes to exploits/shellcodes
Tiandy IPC and NVR 9.12.7 - Credential Disclosure
CuteNews 2.1.2 - Remote Code Execution
ZTE Router F602W - Captcha Bypass
2020-09-11 05:02:04 +00:00
Offensive Security
73dd822b51
DB: 2020-09-10
...
4 changes to exploits/shellcodes
Input Director 1.4.3 - 'Input Director' Unquoted Service Path
Audio Playback Recorder 3.2.2 - Local Buffer Overflow (SEH)
Tailor Management System - 'id' SQL Injection
Scopia XT Desktop 8.3.915.4 - Cross-Site Request Forgery (change admin password)
2020-09-10 05:02:04 +00:00
Offensive Security
f288c52ef9
DB: 2020-09-08
...
3 changes to exploits/shellcodes
Cabot 0.11.12 - Persistent Cross-Site Scripting
grocy 2.7.1 - Persistent Cross-Site Scripting
ManageEngine Applications Manager 14700 - Remote Code Execution (Authenticated)
2020-09-08 05:02:07 +00:00
Offensive Security
0d540768a4
DB: 2020-09-04
...
5 changes to exploits/shellcodes
BarracudaDrive v6.5 - Insecure Folder Permissions
Savsoft Quiz Enterprise Version 5.5 - Persistent Cross-Site Scripting
BloodX CMS 1.0 - Authentication Bypass
Daily Tracker System 1.0 - Authentication Bypass
SiteMagic CMS 4.4.2 - Arbitrary File Upload (Authenticated)
2020-09-04 05:02:06 +00:00
Offensive Security
4784c1aeb4
DB: 2020-09-03
...
1 changes to exploits/shellcodes
Stock Management System 1.0 - Cross-Site Request Forgery (Change Username)
2020-09-03 05:02:09 +00:00
Offensive Security
38929aaab6
DB: 2020-09-02
...
2 changes to exploits/shellcodes
Mara CMS 7.5 - Remote Code Execution (Authenticated)
moziloCMS 2.0 - Persistent Cross-Site Scripting (Authenticated)
2020-09-02 05:02:05 +00:00
Offensive Security
d6bcc3b093
DB: 2020-09-01
...
5 changes to exploits/shellcodes
BlazeDVD 7.0 Professional - '.plf' Local Buffer Overflow (SEH_ASLR_DEP)
Online Book Store 1.0 - 'id' SQL Injection
Mara CMS 7.5 - Reflective Cross-Site Scripting
Fuel CMS 1.4.8 - 'fuel_replace_id' SQL Injection (Authenticated)
CMS Made Simple 2.2.14 - Arbitrary File Upload (Authenticated)
2020-09-01 05:02:09 +00:00
Offensive Security
abfd379775
DB: 2020-08-29
...
4 changes to exploits/shellcodes
Online Shopping Alphaware 1.0 - 'id' SQL Injection
Nagios Log Server 2.1.6 - Persistent Cross-Site Scripting
SymphonyCMS 3.0.0 - Persistent Cross-Site Scripting
Eibiz i-Media Server Digital Signage 3.8.0 - Privilege Escalation
2020-08-29 05:01:59 +00:00
Offensive Security
2621b3c52e
DB: 2020-08-28
...
3 changes to exploits/shellcodes
ASX to MP3 converter 3.1.3.7.2010.11.05 - '.wax' Local Buffer Overflow (DEP_ASLR Bypass) (PoC)
Mida eFramework 2.9.0 - Remote Code Execution
Wordpress Plugin Autoptimize 2.7.6 - Arbitrary File Upload (Authenticated)
2020-08-28 05:01:55 +00:00
Offensive Security
8bf2002f51
DB: 2020-08-27
...
3 changes to exploits/shellcodes
Ericom Access Server x64 9.2.0 - Server-Side Request Forgery
Eibiz i-Media Server Digital Signage 3.8.0 - Directory Traversal
2020-08-27 05:01:55 +00:00
Offensive Security
1567b7af86
DB: 2020-08-25
...
3 changes to exploits/shellcodes
LimeSurvey 4.3.10 - 'Survey Menu' Persistent Cross-Site Scripting
Eibiz i-Media Server Digital Signage 3.8.0 - Authentication Bypass
Eibiz i-Media Server Digital Signage 3.8.0 - Configuration Disclosure
2020-08-25 05:01:52 +00:00
Offensive Security
3b08fb4f1e
DB: 2020-08-22
...
3 changes to exploits/shellcodes
Complaint Management System 1.0 - 'cid' SQL Injection
Seowon SlC 130 Router - Remote Code Execution
vBulletin 5.1.2 < 5.1.9 - Unserialize Code Execution (Metasploit)
2020-08-22 05:01:52 +00:00
Offensive Security
caf6833937
DB: 2020-08-21
...
2 changes to exploits/shellcodes
ElkarBackup 1.3.3 - Persistent Cross-Site Scripting
PNPSCADA 2.200816204020 - 'interf' SQL Injection (Authenticated)
2020-08-21 05:01:48 +00:00
Offensive Security
ec071bef5f
DB: 2020-08-19
...
2 changes to exploits/shellcodes
Pharmacy Medical Store and Sale Point 1.0 - 'catid' SQL Injection
Savsoft Quiz 5 - Stored Cross-Site Scripting
2020-08-19 05:01:49 +00:00
Offensive Security
81f468c9ee
DB: 2020-08-18
...
6 changes to exploits/shellcodes
Bludit 3.9.2 - Authentication Bruteforce Mitigation Bypass
Microsoft SharePoint Server 2019 - Remote Code Execution
QiHang Media Web Digital Signage 3.0.9 - Cleartext Credential Disclosure
QiHang Media Web Digital Signage 3.0.9 - Unauthenticated Arbitrary File Deletion
QiHang Media Web Digital Signage 3.0.9 - Unauthenticated Arbitrary File Disclosure
QiHang Media Web Digital Signage 3.0.9 - Remote Code Execution (Unauthenticated)
2020-08-18 05:01:50 +00:00
Offensive Security
e3b25a25ca
DB: 2020-08-14
...
2 changes to exploits/shellcodes
Artica Proxy 4.3.0 - Authentication Bypass
GetSimple CMS Plugin Multi User 1.8.2 - Cross-Site Request Forgery (Add Admin)
2020-08-14 05:01:50 +00:00
Offensive Security
a999edcbb6
DB: 2020-08-13
...
2 changes to exploits/shellcodes
CMS Made Simple 2.2.14 - Authenticated Arbitrary File Upload
vBulletin 5.6.2 - 'widget_tabbedContainer_tab_panel' Remote Code Execution
2020-08-13 05:01:49 +00:00
Offensive Security
eea08c4481
DB: 2020-08-12
...
1 changes to exploits/shellcodes
Fuel CMS 1.4.7 - 'col' SQL Injection (Authenticated)
2020-08-12 05:01:48 +00:00
Offensive Security
ba30f5e257
DB: 2020-08-11
...
3 changes to exploits/shellcodes
BarcodeOCR 19.3.6 - 'BarcodeOCR' Unquoted Service Path
Warehouse Inventory System 1.0 - Cross-Site Request Forgery (Change Admin Password)
ManageEngine ADSelfService Build prior to 6003 - Remote Code Execution (Unauthenticated)
2020-08-11 05:01:48 +00:00
Offensive Security
a52cf4598f
DB: 2020-08-08
...
2 changes to exploits/shellcodes
All-Dynamics Digital Signage System 2.0.2 - Cross-Site Request Forgery (Add Admin)
Daily Expenses Management System 1.0 - 'item' SQL Injection
2020-08-08 05:01:49 +00:00
Offensive Security
0d0e6419f1
DB: 2020-08-07
...
2 changes to exploits/shellcodes
CodeMeter 6.60 - 'CodeMeter.exe' Unquoted Service Path
Victor CMS 1.0 - 'Search' SQL Injection
2020-08-07 05:01:51 +00:00
Offensive Security
b4336a2935
DB: 2020-08-06
...
3 changes to exploits/shellcodes
ACTi NVR3 Standard or Professional Server 3.0.12.42 - Denial of Service (PoC)
QlikView 12.50.20000.0 - 'FTP Server Address' Denial of Service (PoC)
Stock Management System 1.0 - Authentication Bypass
2020-08-06 05:01:49 +00:00
Offensive Security
9384c59418
DB: 2020-08-05
...
4 changes to exploits/shellcodes
Mocha Telnet Lite for iOS 4.2 - 'User' Denial of Service (PoC)
RTSP for iOS 1.0 - 'IP Address' Denial of Service (PoC)
Pi-hole 4.3.2 - Remote Code Execution (Authenticated)
Daily Expenses Management System 1.0 - 'username' SQL Injection
2020-08-05 05:01:47 +00:00
Offensive Security
3e56299335
DB: 2020-07-31
...
1 changes to exploits/shellcodes
Online Shopping Alphaware 1.0 - Authentication Bypass
2020-07-31 05:02:04 +00:00
Offensive Security
8a30306a81
DB: 2020-07-30
...
2 changes to exploits/shellcodes
Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary File Deletion
Wordpress Plugin Maintenance Mode by SeedProd 5.1.1 - Persistent Cross-Site Scripting
2020-07-30 05:02:03 +00:00
Offensive Security
720fabd066
DB: 2020-07-28
...
114 changes to exploits/shellcodes
Notepad++ < 7.7 (x64) - Denial of Service
winrar 5.80 64bit - Denial of Service
WinRAR 5.80 (x64) - Denial of Service
Linux Kernel 4.4.0-21 (Ubuntu 16.04 x64) - Netfilter target_offset Out-of-Bounds Privilege Escalation
Linux Kernel 4.4.0-21 (Ubuntu 16.04 x64) - Netfilter 'target_offset' Out-of-Bounds Privilege Escalation
TeamViewer 11 < 13 (Windows 10 x86) - Inline Hooking / Direct Memory Modification Permission Change
Microsoft Windows 7 SP1 x86 - GDI Palette Objects Local Privilege Escalation (MS17-017)
Microsoft Windows 7 SP1 (x86) - GDI Palette Objects Local Privilege Escalation (MS17-017)
Microsoft Word 2007 (x86) - Information Disclosure
IKARUS anti.virus 2.16.7 - 'ntguard_x64' Local Privilege Escalation
ASX to MP3 Converter 1.82.50 (Windows 2003 x86) - '.asx' Local Stack Overflow
Linux Kernel < 3.5.0-23 (Ubuntu 12.04.2 x64) - 'SOCK_DIAG' SMEP Bypass Local Privilege Escalation
Linux Kernel < 4.4.0-21 (Ubuntu 16.04 x64) - 'netfilter target_offset' Local Privilege Escalation
Linux Kernel < 3.16.39 (Debian 8 x64) - 'inotfiy' Local Privilege Escalation
Linux Kernel < 3.5.0-23 (Ubuntu 12.04.2 x64) - 'SOCK_DIAG' SMEP Bypass Local Privilege Escalation
Linux Kernel < 4.4.0-21 (Ubuntu 16.04 x64) - 'netfilter target_offset' Local Privilege Escalation
Linux Kernel < 3.16.39 (Debian 8 x64) - 'inotfiy' Local Privilege Escalation
Microsoft Internet Explorer 11 (Windows 7 x64/x86) - vbscript Code Execution
Microsoft Internet Explorer 11 (Windows 7 x86/x64) - vbscript Code Execution
Linux Kernel 2.6.x / 3.10.x / 4.14.x (RedHat / Debian / CentOS) (x64) - 'Mutagen Astronomy' Local Privilege Escalation
R 3.4.4 (Windows 10 x64) - Buffer Overflow (DEP/ASLR Bypass)
MySQL User-Defined (Linux) (x32/x86_64) - 'sys_exec' Local Privilege Escalation
MySQL User-Defined (Linux) (x86) - 'sys_exec' Local Privilege Escalation
Anyburn 4.3 x86 - 'Copy disc to image file' Buffer Overflow (Unicode) (SEH)
Microsoft Windows (x84/x64) - 'Error Reporting' Discretionary Access Control List / Local Privilege Escalation
Microsoft Windows (x86/x64) - 'Error Reporting' Discretionary Access Control List / Local Privilege Escalation
Microsoft Windows (x86) - Task Scheduler' .job' Import Arbitrary Discretionary Access Control List Write / Local Privilege Escalation
R 3.4.4 (Windows 10 x64) - Buffer Overflow SEH (DEP/ASLR Bypass)
Linux Kernel 4.4.0-21 < 4.4.0-51 (Ubuntu 14.04/16.04 x86-64) - 'AF_PACKET' Race Condition Privilege Escalation
Linux Kernel 4.4.0-21 < 4.4.0-51 (Ubuntu 14.04/16.04 x64) - 'AF_PACKET' Race Condition Privilege Escalation
Microsoft Windows 7 build 7601 (x86) - Local Privilege Escalation
Free Desktop Clock x86 Venetian Blinds Zipper 3.0 - Unicode Stack Overflow (SEH)
Atomic Alarm Clock x86 6.3 - 'AtomicAlarmClock' Unquoted Service Path
DEWESoft X3 SP1 (64-bit) - Remote Command Execution
DEWESoft X3 SP1 (x64) - Remote Command Execution
CompleteFTP Professional 12.1.3 - Remote Code Execution
TeamCity Agent XML-RPC 10.0 - Remote Code Execution
eGroupWare 1.14 - 'spellchecker.php' Remote Command Execution
FreeBSD x86 / x64 - execve(/bin/sh) Anti-Debugging Shellcode (140 bytes)
FreeBSD x86/x64 - execve(/bin/sh) Anti-Debugging Shellcode (140 bytes)
Linux/x86 - /usr/bin/head -n99 cat etc/passwd Shellcode (61 Bytes)
Linux/x86 - Kill All Processes Shellcode (14 bytes)
Linux/x86 - Add User to /etc/passwd Shellcode (59 bytes)
Linux/x86 - adduser (User) to /etc/passwd Shellcode (74 bytes)
Linux/x86 - execve /bin/sh Shellcode (25 bytes)
Linux/x86 - Reverse Shell NULL free 127.0.0.1:4444 Shellcode (91 bytes)
Linux/x86 - execve(/bin/sh) socket reuse Shellcode (42 bytes)
Linux/x86 - (NOT|ROT+8 Encoded) execve(/bin/sh) null-free Shellcode (47 bytes)
Linux/x86 - Add User to /etc/passwd Shellcode (59 bytes)
Linux/x86 - adduser (User) to /etc/passwd Shellcode (74 bytes)
Linux/x86 - execve /bin/sh Shellcode (25 bytes)
Linux/x86 - Reverse Shell NULL free 127.0.0.1:4444 Shellcode (91 bytes)
Linux/x86 - execve(/bin/sh) socket reuse Shellcode (42 bytes)
Linux/x86 - (NOT|ROT+8 Encoded) execve(/bin/sh) null-free Shellcode (47 bytes)
Linux/x86 - Execve() Alphanumeric Shellcode (66 bytes)
Linux/x86 - Random Bytes Encoder + XOR/SUB/NOT/ROR execve(/bin/sh) Shellcode (114 bytes)
Linux/x86 - Execve() Alphanumeric Shellcode (66 bytes)
Linux/x86 - Random Bytes Encoder + XOR/SUB/NOT/ROR execve(/bin/sh) Shellcode (114 bytes)
Windows/x86 - Dynamic Bind Shell + Null-Free Shellcode (571 Bytes)
Linux/x86 - Bind Shell Generator Shellcode (114 bytes)
Windows/x86 - Dynamic Bind Shell + Null-Free Shellcode (571 Bytes)
Linux/x86 - Bind Shell Generator Shellcode (114 bytes)
Windows/x64 - Dynamic MessageBoxA or MessageBoxW PEB & Import Table Method Shellcode (232 bytes)
Linux\x86 - 'reboot' polymorphic Shellcode (26 bytes)
Windows/x64 - Dynamic MessageBoxA or MessageBoxW PEB & Import Table Method Shellcode (232 bytes)
Linux/x86 - 'reboot' polymorphic Shellcode (26 bytes)
Windows/x86 - MSVCRT System + Dynamic Null-free + Add RDP Admin + Disable Firewall + Enable RDP Shellcode (644 Bytes)
Linux/x64 - Password (P3WP3Wl4ZerZ) + Bind (0.0.0.0:4444/TCP) Shell (/bin/bash) + Null-free Shellcode (272 Bytes)
Windows/x86 - MSVCRT System + Dynamic Null-free + Add RDP Admin + Disable Firewall + Enable RDP Shellcode (644 Bytes)
Linux/x64 - Password (P3WP3Wl4ZerZ) + Bind (0.0.0.0:4444/TCP) Shell (/bin/bash) + Null-free Shellcode (272 Bytes)
2020-07-28 05:01:59 +00:00
Offensive Security
e46d9f65ff
DB: 2020-07-27
...
32 changes to exploits/shellcodes
Calavera UpLoader 3.5 - 'FTP Logi' Denial of Service (PoC + SEH Overwrite)
Nidesoft DVD Ripper 5.2.18 - Local Buffer Overflow (SEH)
Frigate Professional 3.36.0.9 - 'Pack File' Buffer Overflow (SEH Egghunter)
DiskBoss 7.7.14 - 'Reports and Data Directory' Buffer Overflow (SEH Egghunter)
Socusoft Photo to Video Converter Professional 8.07 - 'Output Folder' Buffer Overflow (SEH Egghunter)
Port Forwarding Wizard 4.8.0 - Buffer Overflow (SEH)
Free MP3 CD Ripper 2.8 - Stack Buffer Overflow (SEH + Egghunter)
docPrint Pro 8.0 - 'Add URL' Buffer Overflow (SEH Egghunter)
GOautodial 4.0 - Persistent Cross-Site Scripting (Authenticated)
ManageEngine Applications Manager 13 - 'MenuHandlerServlet' SQL Injection
INNEO Startup TOOLS 2018 M040 13.0.70.3804 - Remote Code Execution
UBICOD Medivision Digital Signage 1.5.1 - Cross-Site Request Forgery (Add Admin)
WordPress Plugin Email Subscribers & Newsletters 4.2.2 - Unauthenticated File Download
WordPress Plugin Email Subscribers & Newsletters 4.2.2 - 'hash' SQL Injection (Unauthenticated)
Bludit 3.9.2 - Directory Traversal
LibreHealth 2.0.0 - Authenticated Remote Code Execution
Online Course Registration 1.0 - Unauthenticated Remote Code Execution
elaniin CMS - Authentication Bypass
Koken CMS 0.22.24 - Arbitrary File Upload (Authenticated)
PandoraFMS 7.0 NG 746 - Persistent Cross-Site Scripting
Bio Star 2.8.2 - Local File Inclusion
Webtareas 2.1p - Arbitrary File Upload (Authenticated)
F5 Big-IP 13.1.3 Build 0.0.6 - Local File Inclusion
Sickbeard 0.1 - Cross-Site Request Forgery (Disable Authentication)
Socket.io-file 2.0.31 - Arbitrary File Upload
pfSense 2.4.4-p3 - Cross-Site Request Forgery
Virtual Airlines Manager 2.6.2 - Persistent Cross-Site Scripting
Rails 5.0.1 - Remote Code Execution
Linux/x86 - ASLR deactivation polymorphic Shellcode (124 bytes)
Linux/x86 - Egghunter(0x50905090) + sigaction + execve(/bin/sh) Shellcode (35 bytes)
Windows/x86 - Download using mshta.exe Shellcode (100 bytes)
2020-07-27 05:02:04 +00:00
Offensive Security
67c1f99f41
DB: 2020-07-23
...
4 changes to exploits/shellcodes
NetPCLinker 1.0.0.0 - Buffer Overflow (SEH Egghunter)
Docsify.js 4.11.4 - Reflective Cross-Site Scripting
WordPress Theme NexosReal Estate 1.7 - 'search_order' SQL Injection
Sophos VPN Web Panel 2020 - Denial of Service (Poc)
2020-07-23 05:02:04 +00:00
Offensive Security
bd3d5964fc
DB: 2020-07-18
...
5 changes to exploits/shellcodes
Sonar Qube 8.3.1 - 'SonarQube Service' Unquoted Service Path
Simple Startup Manager 1.17 - 'File' Local Buffer Overflow (PoC)
RiteCMS 2.2.1 - Remote Code Execution
CMSUno 1.6 - Cross-Site Request Forgery (Change Admin Password)
2020-07-18 05:02:04 +00:00
Offensive Security
da1d7301af
DB: 2020-07-17
...
2 changes to exploits/shellcodes
RiteCMS 2.2.1 - Remote Code Execution
Wing FTP Server 6.3.8 - Remote Code Execution (Authenticated)
2020-07-17 05:02:11 +00:00
Offensive Security
8bb6bd8fb0
DB: 2020-07-16
...
8 changes to exploits/shellcodes
SuperMicro IPMI WebInterface 03.40 - Cross-Site Request Forgery (Add Admin)
Zyxel Armor X1 WAP6806 - Directory Traversal
Joomla! J2 JOBS 1.3.0 - 'sortby' Authenticated SQL Injection
Online Polling System 1.0 - Authentication Bypass
Web Based Online Hotel Booking System 0.1.0 - Authentication Bypass
Online Farm Management System 0.1.0 - Persistent Cross-Site Scripting
Infor Storefront B2B 1.0 - 'usr_name' SQL Injection
2020-07-16 05:02:11 +00:00
Offensive Security
ec0cd21b16
DB: 2020-07-14
...
2 changes to exploits/shellcodes
Park Ticketing Management System 1.0 - 'viewid' SQL Injection
Park Ticketing Management System 1.0 - Authentication Bypass
2020-07-14 05:02:07 +00:00
Offensive Security
c0e7247938
DB: 2020-07-11
...
5 changes to exploits/shellcodes
FrootVPN 4.8 - 'frootvpn' Unquoted Service Path
Aruba ClearPass Policy Manager 6.7.0 - Unauthenticated Remote Command Execution
HelloWeb 2.0 - Arbitrary File Download
Barangay Management System 1.0 - Authentication Bypass
2020-07-11 05:02:09 +00:00
Offensive Security
3847f7e468
DB: 2020-07-10
...
4 changes to exploits/shellcodes
FrootVPN 4.8 - 'frootvpn' Unquoted Service Path
PHP 7.4 FFI - 'disable_functions' Bypass
Wordpress Plugin Powie's WHOIS Domain Check 0.9.31 - Persistent Cross-Site Scripting
Savsoft Quiz 5 - Persistent Cross-Site Scripting
2020-07-10 05:02:06 +00:00
Offensive Security
8f6367cf98
DB: 2020-07-08
...
8 changes to exploits/shellcodes
Sony Playstation 4 (PS4) < 7.02 / FreeBSD 9 / FreeBSD 12 - 'ip6_setpktopt' Kernel Local Privilege Escalation (PoC)
Microsoft Windows mshta.exe 2019 - XML External Entity Injection
BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 < 12.1.5.1 / 11.6.1 < 11.6.5.1 - Traffic Management User Interface 'TMUI' Remote Code Execution
BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 < 12.1.5.1 / 11.6.1 < 11.6.5.1 - Traffic Management User Interface 'TMUI' Remote Code Execution (PoC)
Sickbeard 0.1 - Remote Command Injection
Online Shopping Portal 3.1 - 'email' SQL Injection
Joomla! J2 JOBS 1.3.0 - 'sortby' Authenticated SQL Injection
BSA Radar 1.6.7234.24750 - Authenticated Privilege Escalation
2020-07-08 05:01:58 +00:00
Offensive Security
1bc852d2af
DB: 2020-07-07
...
7 changes to exploits/shellcodes
Frigate 2.02 - Denial Of Service (PoC)
Fire Web Server 0.1 - Remote Denial of Service (PoC)
Grafana 7.0.1 - Denial of Service (PoC)
File Management System 1.1 - Persistent Cross-Site Scripting
RiteCMS 2.2.1 - Authenticated Remote Code Execution
RSA IG&L Aveksa 7.1.1 - Remote Code Execution
Nagios XI 5.6.12 - 'export-rrd.php' Remote Code Execution
2020-07-07 05:01:57 +00:00
Offensive Security
d6a1f63996
DB: 2020-07-03
...
3 changes to exploits/shellcodes
WhatsApp Remote Code Execution - Paper
ZenTao Pro 8.8.2 - Command Injection
OCS Inventory NG 2.7 - Remote Code Execution
2020-07-03 05:01:59 +00:00