Exploit-DB
|
6bc7a6f9b0
|
DB: 2023-03-29
25 changes to exploits/shellcodes/ghdb
ReQlogic v11.3 - Reflected Cross-Site Scripting (XSS)
Tapo C310 RTSP server v1.3.0 - Unauthorised Video Stream Access
ZKTeco ZEM/ZMM 8.88 - Missing Authentication
Hashicorp Consul v1.0 - Remote Command Execution (RCE)
X-Skipper-Proxy v0.13.237 - Server Side Request Forgery (SSRF)
OPSWAT Metadefender Core - Privilege Escalation
Pega Platform 8.1.0 - Remote Code Execution (RCE)
Beauty-salon v1.0 - Remote Code Execution (RCE)
BoxBilling<=4.22.1.5 - Remote Code Execution (RCE)
iBooking v1.0.8 - Arbitrary File Upload
Jetpack 11.4 - Cross Site Scripting (XSS)
Moodle LMS 4.0 - Cross-Site Scripting (XSS)
Online shopping system advanced 1.0 - Multiple Vulnerabilities
rukovoditel 3.2.1 - Cross-Site Scripting (XSS)
Senayan Library Management System v9.5.0 - SQL Injection
Social-Share-Buttons v2.2.3 - SQL Injection
Subrion CMS 4.2.1 - Stored Cross-Site Scripting (XSS)
YouPHPTube<= 7.8 - Multiple Vulnerabilities
Label Studio 1.5.0 - Authenticated Server Side Request Forgery (SSRF)
SuperMailer v11.20 - Buffer overflow DoS
Tunnel Interface Driver - Denial of Service
VMware Workstation 15 Pro - Denial of Service
HDD Health 4.2.0.112 - 'HDDHealth' Unquoted Service Path
SugarSync 4.1.3 - 'SugarSync Service' Unquoted Service Path
|
2023-03-29 00:16:31 +00:00 |
|
Exploit-DB
|
b137003172
|
DB: 2023-03-28
36 changes to exploits/shellcodes/ghdb
MiniDVBLinux 5.4 - Change Root Password
MiniDVBLinux 5.4 - Remote Root Command Injection
MiniDVBLinux 5.4 - Arbitrary File Read
MiniDVBLinux 5.4 - Unauthenticated Stream Disclosure
MiniDVBLinux 5.4 Simple VideoDiskRecorder Protocol SVDRP - Remote Code Execution (RCE)
MiniDVBLinux <=5.4 - Config Download Exploit
Desktop Central 9.1.0 - Multiple Vulnerabilities
FortiOS_ FortiProxy_ FortiSwitchManager v7.2.1 - Authentication Bypass
Aero CMS v0.0.1 - PHP Code Injection (auth)
Aero CMS v0.0.1 - SQL Injection (no auth)
Atom CMS v2.0 - SQL Injection (no auth)
Canteen-Management v1.0 - SQL Injection
Canteen-Management v1.0 - XSS-Reflected
Clansphere CMS 2011.4 - Stored Cross-Site Scripting (XSS)
eXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE)
FlatCore CMS 2.1.1 - Stored Cross-Site Scripting (XSS)
Webgrind 1.1 - Reflected Cross-Site Scripting (XSS) & Remote Command Execution (RCE)
WebTareas 2.4 - RCE (Authorized)
WebTareas 2.4 - Reflected XSS (Unauthorised)
WebTareas 2.4 - SQL Injection (Unauthorised)
WPN-XM Serverstack for Windows 0.8.6 - Multiple Vulnerabilities
Zentao Project Management System 17.0 - Authenticated Remote Code Execution (RCE)
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
Grafana <=6.2.4 - HTML Injection
Hex Workshop v6.7 - Buffer overflow DoS
Scdbg 1.0 - Buffer overflow DoS
Sysax Multi Server 6.95 - 'Password' Denial of Service (PoC)
AVS Audio Converter 10.3 - Stack Overflow (SEH)
Explorer32++ v1.3.5.531 - Buffer overflow
Frhed (Free hex editor) v1.6.0 - Buffer overflow
Gestionale Open 12.00.00 - 'DB_GO_80' Unquoted Service Path
Mediconta 3.7.27 - 'servermedicontservice' Unquoted Service Path
Resource Hacker v3.6.0.92 - Buffer overflow
Tftpd32_SE 4.60 - 'Tftpd32_svc' Unquoted Service Path
WiFi Mouse 1.8.3.2 - Remote Code Execution (RCE)
|
2023-03-28 00:16:27 +00:00 |
|
Exploit-DB
|
79023d1f9c
|
DB: 2023-03-26
22 changes to exploits/shellcodes/ghdb
Password Manager for IIS v2.0 - XSS
DLink DIR 819 A1 - Denial of Service
D-Link DNR-322L <=2.60B15 - Authenticated Remote Code Execution
Abantecart v1.3.2 - Authenticated Remote Code Execution
Bus Pass Management System 1.0 - Cross-Site Scripting (XSS)
Composr-CMS Version <=10.0.39 - Authenticated Remote Code Execution
Employee Performance Evaluation System v1.0 - File Inclusion and RCE
GuppY CMS v6.00.10 - Remote Code Execution
Human Resources Management System v1.0 - Multiple SQLi
ImpressCMS v1.4.3 - Authenticated SQL Injection
Lavalite v9.0.0 - XSRF-TOKEN cookie File path traversal
MODX Revolution v2.8.3-pl - Authenticated Remote Code Execution
NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi
Online Diagnostic Lab Management System v1.0 - Remote Code Execution (RCE) (Unauthenticated)
PHPGurukul Online Birth Certificate System V 1.2 - Blind XSS
SimpleMachinesForum v2.1.1 - Authenticated Remote Code Execution
Translatepress Multilinugal WordPress plugin < 2.3.3 - Authenticated SQL Injection
Yoga Class Registration System v1.0 - Multiple SQLi
NVFLARE < 2.1.4 - Unsafe Deserialization due to Pickle
_camp_ Raspberry Pi camera server 1.0 - Authentication Bypass
System Mechanic v15.5.0.61 - Arbitrary Read/Write
|
2023-03-26 00:16:30 +00:00 |
|
Exploit-DB
|
3be88e5f7b
|
DB: 2023-03-25
1 changes to exploits/shellcodes/ghdb
|
2023-03-25 00:16:18 +00:00 |
|
Exploit-DB
|
a1ff73f948
|
DB: 2023-03-24
6 changes to exploits/shellcodes/ghdb
wkhtmltopdf 0.12.6 - Server Side Request Forgery
Owlfiles File Manager 12.0.1 - Multiple Vulnerabilities
WorkOrder CMS 0.1.0 - SQL Injection
Bitbucket v7.0.0 - RCE
MAN-EAM-0003 V3.2.4 - XXE
|
2023-03-24 00:16:21 +00:00 |
|
Exploit-DB
|
6206f4f208
|
DB: 2023-03-23
4 changes to exploits/shellcodes/ghdb
SoX 14.4.2 - Denial Of Service
Linksys AX3200 V1.1.00 - Command Injection
VIAVIWEB Wallpaper Admin 1.0 - Multiple Vulnerabilities
|
2023-03-23 00:16:30 +00:00 |
|
Exploit-DB
|
7d85ccf96b
|
DB: 2023-03-22
1 changes to exploits/shellcodes/ghdb
|
2023-03-22 00:16:24 +00:00 |
|
Exploit-DB
|
14407a5441
|
DB: 2023-03-17
1 changes to exploits/shellcodes/ghdb
|
2023-03-17 00:16:29 +00:00 |
|
Exploit-DB
|
ac21e95253
|
DB: 2023-03-15
1 changes to exploits/shellcodes/ghdb
|
2023-03-15 00:16:22 +00:00 |
|
Exploit-DB
|
d27b4d0886
|
DB: 2023-03-14
1 changes to exploits/shellcodes/ghdb
|
2023-03-14 00:16:20 +00:00 |
|
Exploit-DB
|
c14829d011
|
DB: 2023-03-10
1 changes to exploits/shellcodes/ghdb
|
2023-03-10 00:16:27 +00:00 |
|
Exploit-DB
|
197b08386b
|
DB: 2023-03-09
1 changes to exploits/shellcodes/ghdb
|
2023-03-09 00:16:28 +00:00 |
|
Exploit-DB
|
0f1d8f7d93
|
DB: 2023-03-08
1 changes to exploits/shellcodes/ghdb
|
2023-03-08 00:16:47 +00:00 |
|
Exploit-DB
|
7a27aa4d46
|
DB: 2023-03-06
1 changes to exploits/shellcodes/ghdb
|
2023-03-06 00:16:16 +00:00 |
|
Exploit-DB
|
84fbe09591
|
DB: 2023-03-01
1 changes to exploits/shellcodes/ghdb
|
2023-03-01 00:16:29 +00:00 |
|
Exploit-DB
|
ac0d21c865
|
DB: 2023-02-28
1 changes to exploits/shellcodes/ghdb
|
2023-02-28 00:16:46 +00:00 |
|
Exploit-DB
|
fecff07390
|
DB: 2023-02-25
1 changes to exploits/shellcodes/ghdb
|
2023-02-25 00:16:24 +00:00 |
|
Exploit-DB
|
e476fd5d0d
|
DB: 2023-02-23
1 changes to exploits/shellcodes/ghdb
|
2023-02-23 00:16:31 +00:00 |
|
Exploit-DB
|
c884c53913
|
DB: 2023-02-22
1 changes to exploits/shellcodes/ghdb
|
2023-02-22 00:16:31 +00:00 |
|
Exploit-DB
|
e194129791
|
DB: 2023-02-21
2 changes to exploits/shellcodes/ghdb
pfBlockerNG 2.1.4_26 - Remote Code Execution (RCE)
|
2023-02-21 00:16:32 +00:00 |
|
Exploit-DB
|
df343ad7ef
|
DB: 2023-02-16
1 changes to exploits/shellcodes/ghdb
|
2023-02-16 00:16:26 +00:00 |
|
Exploit-DB
|
80ff1acba5
|
DB: 2023-02-14
1 changes to exploits/shellcodes/ghdb
|
2023-02-14 00:16:31 +00:00 |
|
Exploit-DB
|
4c211fe127
|
DB: 2023-02-10
1 changes to exploits/shellcodes/ghdb
|
2023-02-10 00:16:22 +00:00 |
|
Exploit-DB
|
4925dbd7d7
|
DB: 2023-02-09
1 changes to exploits/shellcodes/ghdb
|
2023-02-09 00:16:25 +00:00 |
|
Exploit-DB
|
be22559ab8
|
DB: 2023-02-08
1 changes to exploits/shellcodes/ghdb
|
2023-02-08 00:16:25 +00:00 |
|
Exploit-DB
|
78ed00ec08
|
DB: 2023-02-07
1 changes to exploits/shellcodes/ghdb
|
2023-02-07 00:16:24 +00:00 |
|
Exploit-DB
|
a363293afc
|
DB: 2023-02-03
1 changes to exploits/shellcodes/ghdb
|
2023-02-03 00:16:31 +00:00 |
|
Exploit-DB
|
24da8dd701
|
DB: 2023-02-02
1 changes to exploits/shellcodes/ghdb
|
2023-02-02 00:16:27 +00:00 |
|
Exploit-DB
|
218bb6c6f7
|
DB: 2023-02-01
1 changes to exploits/shellcodes/ghdb
|
2023-02-01 00:16:33 +00:00 |
|
Exploit-DB
|
225f9878ca
|
DB: 2022-11-22
1 changes to exploits/shellcodes/ghdb
Feehi CMS 2.1.1 - Remote Code Execution (RCE) (Authenticated)
Feehi CMS 2.1.1 - Remote Code Execution (Authenticated)
|
2022-11-22 13:04:39 +00:00 |
|
Offensive Security
|
ec8ac60c13
|
DB: 2022-11-22
93 changes to exploits/shellcodes/ghdb
|
2022-11-22 11:08:59 +00:00 |
|
Offensive Security
|
03db452e11
|
DB: 2022-11-22
1 changes to exploits/shellcodes/ghdb
SmartRG Router SR510n 2.6.13 - RCE (Remote Code Execution)
SmartRG Router SR510n 2.6.13 - Remote Code Execution
|
2022-11-22 00:16:31 +00:00 |
|
Offensive Security
|
b275a646e0
|
DB: 2022-11-21
1 changes to exploits/shellcodes/ghdb
QNAP NVR/NAS Devices - Buffer Overflow (PoC)
|
2022-11-21 21:29:53 +00:00 |
|
g0tmi1k
|
aa06ea8fec
|
Fix URL
|
2022-11-21 14:55:48 +00:00 |
|
Offensive Security
|
842fcc5901
|
DB: 2022-11-19
1 changes to exploits/shellcodes/ghdb
MSNSwitch Firmware MNT.2408 - Remote Code Exectuion (RCE)
MSNSwitch Firmware MNT.2408 - Remote Code Execution
Open Web Analytics 1.7.3 - Remote Code Execution (RCE)
Open Web Analytics 1.7.3 - Remote Code Execution
CVAT 2.0 - SSRF (Server Side Request Forgery)
CVAT 2.0 - Server Side Request Forgery
|
2022-11-19 00:16:40 +00:00 |
|
Offensive Security
|
d77965c440
|
DB: 2022-11-17
1 changes to exploits/shellcodes/ghdb
qdPM 9.1 - Remote Code Execution (RCE) (Authenticated)
qdPM 9.1 - Remote Code Execution (Authenticated)
|
2022-11-17 07:08:08 +00:00 |
|
Offensive Security
|
c9e53fa57b
|
DB: 2022-11-12
7 changes to exploits/shellcodes/ghdb
AVEVA InTouch Access Anywhere Secure Gateway 2020 R2 - Path Traversal
MSNSwitch Firmware MNT.2408 - Remote Code Exectuion (RCE)
SmartRG Router SR510n 2.6.13 - RCE (Remote Code Execution)
Open Web Analytics 1.7.3 - Remote Code Execution (RCE)
CVAT 2.0 - SSRF (Server Side Request Forgery)
IOTransfer V4 - Unquoted Service Path
NetTransport 2.96L - Remote Buffer Overflow (DEP Bypass)
Linux/MIPS (Little Endian) - system(telnetd -l /bin/sh) Shellcode (80 bytes)
Linux/MIPS - reboot() Shellcode (32 bytes)
Linux/x86 - execve(/bin/sh) + Socket Re-Use Shellcode (50 bytes)
Linux/x86 - setuid(0) + setgid(0) + execve(/bin/sh_ [/bin/sh_ NULL]) Shellcode (37 bytes)
Windows/x86 - Write-to-file ('pwned' ./f.txt) + Null-Free Shellcode (278 bytes)
|
2022-11-12 09:02:02 +00:00 |
|
g0tmi1k
|
871af74158
|
GitHub -> GitLab
|
2022-11-11 01:27:50 +00:00 |
|
g0tmi1k
|
653b3893e6
|
Version bump
|
2022-11-11 01:24:01 +00:00 |
|
g0tmi1k
|
7f3e900967
|
json_pp -> jq
|
2022-11-11 00:38:26 +00:00 |
|
g0tmi1k
|
8ff1798f71
|
Nicer formatting
|
2022-11-11 00:38:26 +00:00 |
|
g0tmi1k
|
3ae6e956a2
|
Split code output
|
2022-11-11 00:38:26 +00:00 |
|
g0tmi1k
|
033af0c325
|
File may not be installed
|
2022-11-11 00:38:26 +00:00 |
|
g0tmi1k
|
73e22c7346
|
Remove new line
|
2022-11-11 00:38:26 +00:00 |
|
g0tmi1k
|
8cb55f5f95
|
Update comments
|
2022-11-11 00:38:26 +00:00 |
|
g0tmi1k
|
142f38c279
|
Fix Incorrect processing of -t (GitHub 190)
https://github.com/offensive-security/exploitdb/issues/190
|
2022-11-11 00:38:26 +00:00 |
|
Offensive Security
|
b6e780c138
|
DB: 2022-11-10
20 changes to exploits/shellcodes/ghdb
0 new exploits/shellcodes
Too many to list!
|
2022-11-10 23:30:40 +00:00 |
|
Offensive Security
|
033a8167fc
|
Merge branch 'main' of gitlab.com:exploit-database/exploitdb into main
|
2022-11-10 19:58:04 +00:00 |
|
g0tmi1k
|
7dc06078b3
|
SearchSploit v4.2.0
Various fixes
|
2022-11-10 18:01:01 +00:00 |
|
Offensive Security
|
8bf3aee631
|
DB: 2022-11-10
2 changes to exploits/shellcodes/ghdb
|
2022-11-10 17:10:37 +00:00 |
|