Offensive Security
|
7b87f30fbc
|
DB: 2020-04-25
5 changes to exploits/shellcodes
Popcorn Time 6.2 - 'Update service' Unquoted Service Path
EspoCRM 5.8.5 - Privilege Escalation
Edimax EW-7438RPn 1.13 - Remote Code Execution
Furukawa Electric ConsciusMAP 2.8.1 - Remote Code Execution
Linux/x64 - Password Protected Bindshell + Null-free Shellcode (272 Bytes)
|
2020-04-25 05:01:51 +00:00 |
|
Offensive Security
|
cae82bb178
|
DB: 2020-04-24
8 changes to exploits/shellcodes
User Management System 2.0 - Persistent Cross-Site Scripting
User Management System 2.0 - Authentication Bypass
Complaint Management System 4.2 - Persistent Cross-Site Scripting
Complaint Management System 4.2 - Authentication Bypass
Complaint Management System 4.2 - Cross-Site Request Forgery (Delete User)
Zen Load Balancer 3.10.1 - Directory Traversal (Metasploit)
Sky File 2.1.0 iOS - Directory Traversal
|
2020-04-24 05:01:50 +00:00 |
|
Offensive Security
|
7b676133d3
|
DB: 2020-04-23
5 changes to exploits/shellcodes
Vesta Control Panel 0.9.8-16 - Local Privilege Escalation
RM Downloader 3.1.3.2.2010.06.13 - 'Load' Buffer Overflow (SEH)
Edimax EW-7438RPn - Information Disclosure (WiFi Password)
Edimax EW-7438RPn - Cross-Site Request Forgery (MAC Filtering)
Mahara 19.10.2 CMS - Persistent Cross-Site Scripting
|
2020-04-23 05:01:50 +00:00 |
|
Offensive Security
|
1c5c38825d
|
DB: 2020-04-22
10 changes to exploits/shellcodes
Oracle Solaris Common Desktop Environment 1.6 - Local Privilege Escalation
WordPress 2.0.2 - 'cache' Remote Shell Injection
Neowise CarbonFTP 1.4 - Insecure Proprietary Password Encryption
WordPress Core 2.0.2 - 'cache' Remote Shell Injection
CSZ CMS 1.2.7 - Persistent Cross-Site Scripting
PMB 5.6 - 'logid' SQL Injection
CSZ CMS 1.2.7 - 'title' HTML Injection
IQrouter 3.3.1 Firmware - Remote Code Execution
NSClient++ 0.5.2.35 - Authenticated Remote Code Execution
jizhi CMS 1.6.7 - Arbitrary File Download
P5 FNIP-8x16A FNIP-4xSH 1.0.20 - Cross-Site Request Forgery (Add Admin)
Windows/x86 - MSVCRT System + Dynamic Null-free + Add RDP Admin + Disable Firewall + Enable RDP Shellcode (644 Bytes)
|
2020-04-22 05:01:47 +00:00 |
|
Offensive Security
|
01900f216d
|
DB: 2020-04-21
7 changes to exploits/shellcodes
Atomic Alarm Clock 6.3 - Stack Overflow (Unicode+SEH)
Nsauditor 3.2.1.0 - Buffer Overflow (SEH+ASLR bypass (3 bytes overwrite))
Rubo DICOM Viewer 2.0 - Buffer Overflow (SEH)
Atomic Alarm Clock x86 6.3 - 'AtomicAlarmClock' Unquoted Service Path
Unraid 6.8.0 - Auth Bypass PHP Code Execution (Metasploit)
Centreon 19.10.5 - 'id' SQL Injection
Fork CMS 5.8.0 - Persistent Cross-Site Scripting
|
2020-04-21 05:01:47 +00:00 |
|
Offensive Security
|
189c8b52c9
|
DB: 2020-04-18
6 changes to exploits/shellcodes
Easy MPEG to DVD Burner 1.7.11 - Buffer Overflow (SEH + DEP)
Code Blocks 16.01 - Buffer Overflow (SEH) UNICODE
Nexus Repository Manager - Java EL Injection RCE (Metasploit)
Playable 9.18 iOS - Persistent Cross-Site Scripting
TAO Open Source Assessment Platform 3.3.0 RC02 - HTML Injection
Cisco IP Phone 11.7 - Denial of service (PoC)
|
2020-04-18 05:01:49 +00:00 |
|
Offensive Security
|
c3e827f657
|
DB: 2020-04-17
8 changes to exploits/shellcodes
VMware Fusion - USB Arbitrator Setuid Privilege Escalation (Metasploit)
TP-Link Archer A7/C7 - Unauthenticated LAN Remote Code Execution (Metasploit)
Liferay Portal - Java Unmarshalling via JSONWS RCE (Metasploit)
ThinkPHP - Multiple PHP Injection RCEs (Metasploit)
Pandora FMS - Ping Authenticated Remote Code Execution (Metasploit)
PlaySMS - index.php Unauthenticated Template Injection Code Execution (Metasploit)
DotNetNuke - Cookie Deserialization Remote Code Execution (Metasploit)
Apache Solr - Remote Code Execution via Velocity Template (Metasploit)
|
2020-04-17 05:01:48 +00:00 |
|
Offensive Security
|
decb2a46ee
|
DB: 2020-04-16
9 changes to exploits/shellcodes
BlazeDVD 7.0.2 - Buffer Overflow (SEH)
AirDisk Pro 5.5.3 for iOS - Persistent Cross-Site Scripting
SuperBackup 2.0.5 for iOS - Persistent Cross-Site Scripting
Pinger 1.0 - Remote Code Execution
SeedDMS 5.1.18 - Persistent Cross-Site Scripting
Macs Framework 1.14f CMS - Persistent Cross-Site Scripting
DedeCMS 7.5 SP2 - Persistent Cross-Site Scripting
File Transfer iFamily 2.1 - Directory Traversal
Xeroneit Library Management System 3.0 - 'category' SQL Injection
|
2020-04-16 05:01:47 +00:00 |
|
Offensive Security
|
0137126a8e
|
DB: 2020-04-15
4 changes to exploits/shellcodes
B64dec 1.1.2 - Buffer Overflow (SEH Overflow + Egg Hunter)
Edimax Technology EW-7438RPn-v3 Mini 1.27 - Remote Code Execution
WSO2 3.1.0 - Persistent Cross-Site Scripting
Oracle WebLogic Server 12.2.1.4.0 - Remote Code Execution
|
2020-04-15 05:01:49 +00:00 |
|
Offensive Security
|
be2aa5d840
|
DB: 2020-04-14
7 changes to exploits/shellcodes
Free Desktop Clock x86 Venetian Blinds Zipper 3.0 - Unicode Stack Overflow (SEH)
Huawei HG630 2 Router - Authentication Bypass
TVT NVMS 1000 - Directory Traversal
Webtateas 2.0 - Arbitrary File Read
WSO2 3.1.0 - Arbitrary File Delete
Wordpress Plugin Media Library Assistant 2.81 - Local File Inclusion
MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection
|
2020-04-14 05:01:51 +00:00 |
|
Offensive Security
|
4ee0ce31e7
|
DB: 2020-04-11
3 changes to exploits/shellcodes
AbsoluteTelnet 11.12 - 'SSH1/username' Denial of Service (PoC)
Windscribe 1.83 - 'WindscribeService' Unquoted Service Path
Zen Load Balancer 3.10.1 - 'index.cgi' Directory Traversal
|
2020-04-11 05:01:50 +00:00 |
|
Offensive Security
|
6d55b45cdf
|
DB: 2020-04-09
2 changes to exploits/shellcodes
Django 3.0 - Cross-Site Request Forgery Token Bypass
Amcrest Dahua NVR Camera IP2M-841 - Denial of Service (PoC)
|
2020-04-09 05:01:51 +00:00 |
|
Offensive Security
|
36c65f8dd4
|
DB: 2020-04-08
2 changes to exploits/shellcodes
dnsmasq-utils 2.79-1 - 'dhcp_release' Denial of Service (PoC)
ZOC Terminal 7.25.5 - 'Script' Denial of Service (PoC)
|
2020-04-08 05:01:50 +00:00 |
|
Offensive Security
|
85bef6929f
|
DB: 2020-04-07
17 changes to exploits/shellcodes
Product Key Explorer 4.2.2.0 - 'Key' Denial of Service (PoC)
SpotAuditor 5.3.4 - 'Name' Denial of Service (PoC)
Nsauditor 3.2.0.0 - 'Name' Denial of Service (PoC)
Frigate 3.36 - Denial of Service (PoC)
UltraVNC Launcher 1.2.4.0 - 'RepeaterHost' Denial of Service (PoC)
UltraVNC Launcher 1.2.4.0 - 'Password' Denial of Service (PoC)
UltraVNC Viewer 1.2.4.0 - 'VNCServer' Denial of Service (PoC)
ZOC Terminal v7.25.5 - 'Private key file' Denial of Service (PoC)
Memu Play 7.1.3 - Insecure Folder Permissions
Triologic Media Player 8 - '.m3l' Buffer Overflow (Unicode) (SEH)
Microsoft NET USE win10 - Insufficient Authentication Logic
LimeSurvey 4.1.11 - 'Survey Groups' Persistent Cross-Site Scripting
Vesta Control Panel 0.9.8-26 - Authenticated Remote Code Execution (Metasploit)
WhatsApp Desktop 0.3.9308 - Persistent Cross-Site Scripting
Bolt CMS 3.7.0 - Authenticated Remote Code Execution
LimeSurvey 4.1.11 - 'File Manager' Path Traversal
pfSense 2.4.4-P3 - 'User Manager' Persistent Cross-Site Scripting
|
2020-04-07 05:02:01 +00:00 |
|
Offensive Security
|
9cbe99271d
|
DB: 2020-04-04
2 changes to exploits/shellcodes
AIDA64 Engineer 6.20.5300 - 'Report File' filename Buffer Overflow (SEH)
Pandora FMS 7.0NG - 'net_tools.php' Remote Code Execution
|
2020-04-04 05:01:48 +00:00 |
|
Offensive Security
|
6f90e88040
|
DB: 2020-04-03
1 changes to exploits/shellcodes
DiskBoss 7.7.14 - 'Input Directory' Local Buffer Overflow (PoC)
|
2020-04-03 05:01:50 +00:00 |
|
Offensive Security
|
c4e0c06fd9
|
DB: 2020-04-02
2 changes to exploits/shellcodes
DiskBoss 7.7.14 - Denial of Service (PoC)
10Strike LANState 9.32 - 'Force Check' Buffer Overflow (SEH)
|
2020-04-02 05:01:49 +00:00 |
|
Offensive Security
|
19615ff704
|
DB: 2020-04-01
7 changes to exploits/shellcodes
FlashFXP 4.2.0 Build 1730 - Denial of Service (PoC)
Redis - Replication Code Execution (Metasploit)
IBM TM1 / Planning Analytics - Unauthenticated Remote Code Execution (Metasploit)
DLINK DWL-2600 - Authenticated Remote Command Injection (Metasploit)
SharePoint Workflows - XOML Injection (Metasploit)
Grandstream UCM6200 Series CTI Interface - 'user_password' SQL Injection
Grandstream UCM6200 Series WebSocket 1.0.20.20 - 'user_password' SQL Injection
|
2020-04-01 05:01:47 +00:00 |
|
Offensive Security
|
169b528eaa
|
DB: 2020-03-31
6 changes to exploits/shellcodes
Odin Secure FTP Expert 7.6.3 - 'Site Info' Denial of Service (PoC)
10-Strike Network Inventory Explorer 9.03 - 'Read from File' Buffer Overflow (SEH)(ROP)
Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Local Privilege Escalation
Multiple DrayTek Products - Pre-authentication Remote Root Code Execution
ECK Hotel 1.0 - Cross-Site Request Forgery (Add Admin)
Joomla! com_fabrik 3.9.11 - Directory Traversal
Zen Load Balancer 3.10.1 - Remote Code Execution
|
2020-03-31 05:01:48 +00:00 |
|
Offensive Security
|
284325fbf5
|
DB: 2020-03-28
5 changes to exploits/shellcodes
Everest 5.50.2100 - 'Open File' Denial of Service (PoC)
Easy RM to MP3 Converter 2.7.3.700 - 'Input' Local Buffer Overflow (SEH)
ECK Hotel 1.0 - Cross-Site Request Forgery (Add Admin)
Jinfornet Jreport 15.6 - Unauthenticated Directory Traversal
rConfig 3.9.4 - 'searchField' Unauthenticated Root Remote Code Execution
|
2020-03-28 05:01:48 +00:00 |
|
Offensive Security
|
4b289033f4
|
DB: 2020-03-27
3 changes to exploits/shellcodes
TP-Link Archer C50 3 - Denial of Service (PoC)
Centreo 19.10.8 - 'DisplayServiceStatus' Remote Code Execution
|
2020-03-27 05:01:46 +00:00 |
|
Offensive Security
|
606ad946d3
|
DB: 2020-03-26
7 changes to exploits/shellcodes
AVAST SecureLine 5.5.522.0 - 'SecureLine' Unquoted Service Path
10-Strike Network Inventory Explorer - 'srvInventoryWebServer' Unquoted Service Path
10-Strike Network Inventory Explorer 8.54 - 'Add' Local Buffer Overflow (SEH)
Wordpress Plugin WPForms 1.5.9 - Persistent Cross-Site Scripting
Wordpress Plugin WPForms 1.5.8.2 - Persistent Cross-Site Scripting
Joomla! Component GMapFP 3.30 - Arbitrary File Upload
LeptonCMS 4.5.0 - Persistent Cross-Site Scripting
Windows/x64 - WinExec Add-Admin Dynamic Null-Free Shellcode (210 Bytes)
|
2020-03-26 05:01:48 +00:00 |
|
Offensive Security
|
52df09d89e
|
DB: 2020-03-25
4 changes to exploits/shellcodes
Veyon 4.3.4 - 'VeyonService' Unquoted Service Path
UliCMS 2020.1 - Persistent Cross-Site Scripting
Wordpress Plugin WPForms 1.5.9 - Persistent Cross-Site Scripting
UCM6202 1.0.18.13 - Remote Command Injection
|
2020-03-25 05:01:47 +00:00 |
|
Offensive Security
|
b84d953124
|
DB: 2020-03-24
10 changes to exploits/shellcodes
ProficySCADA for iOS 5.0.25920 - 'Password' Denial of Service (PoC)
Google Chrome 80.0.3987.87 - Heap-Corruption Remote Denial of Service (PoC)
CyberArk PSMP 10.9.1 - Policy Restriction Bypass
PHPMailer < 5.2.18 - Remote Code Execution (Bash)
FIBARO System Home Center 5.021 - Remote File Include
rConfig 3.9.4 - 'search.crud.php' Remote Command Injection
Joomla! com_hdwplayer 4.2 - 'search.php' SQL Injection
Windows\x86 - Null-Free WinExec Calc.exe Shellcode (195 bytes)
Windows\x64 - Dynamic MessageBoxA or MessageBoxW PEB & Import Table Method Shellcode (232 bytes)
Windows/x86 - Null-Free WinExec Calc.exe Shellcode (195 bytes)
Windows/x64 - Dynamic MessageBoxA or MessageBoxW PEB & Import Table Method Shellcode (232 bytes)
Linux\x86 - 'reboot' polymorphic Shellcode (26 bytes)
|
2020-03-24 05:01:50 +00:00 |
|
Offensive Security
|
d3992973f1
|
DB: 2020-03-21
2 changes to exploits/shellcodes
VMware Fusion 11.5.2 - Privilege Escalation
Exagate Sysguard 6001 - Cross-Site Request Forgery (Add Admin)
|
2020-03-21 05:01:49 +00:00 |
|
Offensive Security
|
26b38131c0
|
DB: 2020-03-20
1 changes to exploits/shellcodes
Broadcom Wi-Fi Devices - 'KR00K Information Disclosure
|
2020-03-20 05:01:50 +00:00 |
|
Offensive Security
|
85cdf30cea
|
DB: 2020-03-19
7 changes to exploits/shellcodes
NetBackup 7.0 - 'NetBackup INET Daemon' Unquoted Service Path
Microsoft VSCode Python Extension - Code Execution
VMWare Fusion - Local Privilege Escalation
Microtik SSH Daemon 6.44.3 - Denial of Service (PoC)
Netlink GPON Router 1.0.11 - Remote Code Execution
Windows\x64 - Dynamic MessageBoxA or MessageBoxW PEB & Import Table Method Shellcode (232 bytes)
|
2020-03-19 05:01:49 +00:00 |
|
Offensive Security
|
20e5ee2e94
|
DB: 2020-03-18
2 changes to exploits/shellcodes
Rconfig 3.x - Chained Remote Code Execution (Metasploit)
ManageEngine Desktop Central - Java Deserialization (Metasploit)
|
2020-03-18 05:01:50 +00:00 |
|
Offensive Security
|
72f1d24f1a
|
DB: 2020-03-17
5 changes to exploits/shellcodes
Enhanced Multimedia Router 3.0.4.27 - Cross-Site Request Forgery (Add Admin)
MiladWorkShop VIP System 1.0 - 'lang' SQL Injection
PHPKB Multi-Language 9 - Authenticated Remote Code Execution
PHPKB Multi-Language 9 - Authenticated Directory Traversal
PHPKB Multi-Language 9 - 'image-upload.php' Authenticated Remote Code Execution
|
2020-03-17 05:01:49 +00:00 |
|
Offensive Security
|
9bacc6784a
|
DB: 2020-03-15
2 changes to exploits/shellcodes
Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Buffer Overflow (PoC)
Horde Groupware Webmail Edition 5.2.22 - Remote Code Execution
|
2020-03-15 05:01:47 +00:00 |
|
Offensive Security
|
79fee2e601
|
DB: 2020-03-14
4 changes to exploits/shellcodes
AnyBurn 4.8 - Buffer Overflow (SEH)
Drobo 5N2 4.1.1 - Remote Command Injection
Centos WebPanel 7 - 'term' SQL Injection
|
2020-03-14 05:01:46 +00:00 |
|
Offensive Security
|
153c392dd9
|
DB: 2020-03-13
9 changes to exploits/shellcodes
ASUS AAHM 1.00.22 - 'asHmComSvc' Unquoted Service Path
Joomla! Component com_newsfeeds 1.0 - 'feedid' SQL Injection
WatchGuard Fireware AD Helper Component 5.8.5.10317 - Credential Disclosure
Wordpress Plugin Appointment Booking Calendar 1.3.34 - CSV Injection
HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin)
rConfig 3.93 - 'ajaxAddTemplate.php' Authenticated Remote Code Execution
rConfig 3.9 - 'searchColumn' SQL Injection
Horde Groupware Webmail Edition 5.2.22 - PHP File Inclusion
Horde Groupware Webmail Edition 5.2.22 - PHAR Loading
|
2020-03-13 05:01:50 +00:00 |
|
Offensive Security
|
3c74040d79
|
DB: 2020-03-12
2 changes to exploits/shellcodes
ASUS AXSP 1.02.00 - 'asComSvc' Unquoted Service Path
Wordpress Plugin Search Meter 2.13.2 - CSV injection
|
2020-03-12 05:01:49 +00:00 |
|
Offensive Security
|
0a0ad49d15
|
DB: 2020-03-11
7 changes to exploits/shellcodes
Counter Strike: GO - '.bsp' Memory Control (PoC)
Nagios XI - Authenticated Remote Command Execution (Metasploit)
PHPStudy - Backdoor Remote Code execution (Metasploit)
Sysaid 20.1.11 b26 - Remote Command Execution
YzmCMS 5.5 - 'url' Persistent Cross-Site Scripting
Persian VIP Download Script 1.0 - 'active' SQL Injection
|
2020-03-11 05:01:47 +00:00 |
|
Offensive Security
|
4df22c7404
|
DB: 2020-03-10
13 changes to exploits/shellcodes
Microsoft Windows - 'WizardOpium' Local Privilege Escalation
OpenSMTPD - OOB Read Local Privilege Escalation (Metasploit)
Apache ActiveMQ 5.x-5.11.1 - Directory Traversal Shell Upload (Metasploit)
PHP-FPM - Underflow Remote Code Execution (Metasploit)
Google Chrome 72 and 73 - Array.map Out-of-Bounds Write (Metasploit)
Google Chrome 67_ 68 and 69 - Object.create Type Confusion (Metasploit)
Google Chrome 80 - JSCreate Side-effect Type Confusion (Metasploit)
ManageEngine ServiceDesk Plus 9.3 - User Enumeration
60CycleCMS - 'news.php' SQL Injection
Sahi pro 8.x - Directory Traversal
Sentrifugo HRMS 3.2 - 'id' SQL Injection
|
2020-03-10 05:01:44 +00:00 |
|
Offensive Security
|
04881134cd
|
DB: 2020-03-07
5 changes to exploits/shellcodes
Iskysoft Application Framework Service 2.4.3.241 - 'IsAppService' Unquoted Service Path
SpyHunter 4 - 'SpyHunter 4 Service' Unquoted Service Path
ASUS GiftBox Desktop 1.1.1.127 - 'ASUSGiftBoxDesktop' Unquoted Service Path
Deep Instinct Windows Agent 1.2.29.0 - 'DeepMgmtService' Unquoted Service Path
ManageEngine Desktop Central - 'FileStorage getChartImage' Deserialization / Unauthenticated Remote Code Execution
|
2020-03-07 05:01:49 +00:00 |
|
Offensive Security
|
7531fa6a21
|
DB: 2020-03-06
3 changes to exploits/shellcodes
Exchange Control Panel - Viewstate Deserialization (Metasploit)
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
netkit-telnet-0.17 telnetd (Fedora 31) - 'BraveStarr' Remote Code Execution
|
2020-03-06 05:01:47 +00:00 |
|
Offensive Security
|
fce46f25ae
|
DB: 2020-03-05
1 changes to exploits/shellcodes
UniSharp Laravel File Manager 2.0.0 - Arbitrary File Read
|
2020-03-05 05:01:47 +00:00 |
|
Offensive Security
|
d85ad29bbc
|
DB: 2020-03-04
4 changes to exploits/shellcodes
RICOH Aficio SP 5200S Printer - 'entryNameIn' HTML Injection
Alfresco 5.2.4 - Persistent Cross-Site Scripting
GUnet OpenEclass 1.7.3 E-learning platform - 'month' SQL Injection
RICOH Aficio SP 5210SF Printer - 'entryNameIn' HTML Injection
|
2020-03-04 05:01:50 +00:00 |
|
Offensive Security
|
afe5797b88
|
DB: 2020-03-03
12 changes to exploits/shellcodes
Cyberoam Authentication Client 2.1.2.7 - Buffer Overflow (SEH)
Wing FTP Server 6.2.3 - Privilege Escalation
Microsoft Exchange 2019 15.2.221.12 - Authenticated Remote Code Execution
CA Unified Infrastructure Management Nimsoft 7.80 - Remote Buffer Overflow
Joplin Desktop 1.0.184 - Cross-Site Scripting
Netis WF2419 2.2.36123 - Remote Code Execution
Wordpress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery (Add User)
TL-WR849N 0.9.1 4.16 - Authentication Bypass (Upload Firmware)
Wing FTP Server 6.2.5 - Privilege Escalation
TP LINK TL-WR849N - Remote Code Execution
Intelbras Wireless N 150Mbps WRN240 - Authentication Bypass (Config Upload)
Cacti v1.2.8 - Unauthenticated Remote Code Execution (Metasploit)
|
2020-03-03 05:01:48 +00:00 |
|
Offensive Security
|
016ad02a70
|
DB: 2020-02-29
1 changes to exploits/shellcodes
qdPM < 9.1 - Remote Code Execution
|
2020-02-29 05:01:46 +00:00 |
|
Offensive Security
|
02aee6c80e
|
DB: 2020-02-28
5 changes to exploits/shellcodes
Business Live Chat Software 1.0 - Cross-Site Request Forgery (Add Admin)
Comtrend VR-3033 - Command Injection
Apache Tomcat - AJP 'Ghostcat File Read/Inclusion
Cacti 1.2.8 - Authenticated Remote Code Execution
Cacti 1.2.8 - Unauthenticated Remote Code Execution
|
2020-02-28 05:01:52 +00:00 |
|
Offensive Security
|
2d45ff4f39
|
DB: 2020-02-27
5 changes to exploits/shellcodes
Core FTP LE 2.2 - Denial of Service (PoC)
OpenSMTPD 6.6.3 - Arbitrary File Read
OpenSMTPD < 6.6.3p1 - Local Privilege Escalation + Remote Code Execution
GUnet OpenEclass E-learning platform 1.7.3 - 'uname' SQL Injection
PhpIX 2012 Professional - 'id' SQL Injection
|
2020-02-27 05:02:27 +00:00 |
|
Offensive Security
|
17bb415ff8
|
DB: 2020-02-26
5 changes to exploits/shellcodes
SpotFTP-FTP Password Recover 2.4.8 - Denial of Service (PoC)
aSc TimeTables 2020.11.4 - Denial of Service (PoC)
Odin Secure FTP Expert 7.6.3 - Denial of Service (PoC)
WordPress Plugin WooCommerce CardGate Payment Gateway 3.1.15 - Payment Process Bypass
Magento WooCommerce CardGate Payment Gateway 2.0.30 - Payment Process Bypass
|
2020-02-26 05:01:51 +00:00 |
|
Offensive Security
|
cf92ea269e
|
DB: 2020-02-25
22 changes to exploits/shellcodes
Quick N Easy Web Server 3.3.8 - Denial of Service (PoC)
Go SSH servers 0.0.2 - Denial of Service (PoC)
Android Binder - Use-After-Free (Metasploit)
Diamorphine Rootkit - Signal Privilege Escalation (Metasploit)
Apache James Server 2.3.2 - Insecure User Creation Arbitrary File Write (Metasploit)
Avaya IP Office Application Server 11.0.0.0 - Reflective Cross-Site Scripting
ESCAM QD-900 WIFI HD Camera - Remote Configuration Disclosure
Real Web Pentesting Tutorial Step by Step - [Persian]
AMSS++ v 4.31 - 'id' SQL Injection
SecuSTATION IPCAM-130 HD Camera - Remote Configuration Disclosure
CandidATS 2.1.0 - Cross-Site Request Forgery (Add Admin)
AMSS++ 4.7 - Backdoor Admin Account
SecuSTATION SC-831 HD Camera - Remote Configuration Disclosure
ATutor 2.2.4 - 'id' SQL Injection
I6032B-P POE 2.0MP Outdoor Camera - Remote Configuration Disclosure
ManageEngine EventLog Analyzer 10.0 - Information Disclosure
eLection 2.0 - 'id' SQL Injection
DotNetNuke 9.5 - Persistent Cross-Site Scripting
DotNetNuke 9.5 - File Upload Restrictions Bypass
Aptina AR0130 960P 1.3MP Camera - Remote Configuration Disclosure
Cacti 1.2.8 - Remote Code Execution
Windows\x86 - Null-Free WinExec Calc.exe Shellcode (195 bytes)
|
2020-02-25 05:01:52 +00:00 |
|
Offensive Security
|
ed6caf0837
|
DB: 2020-02-21
2 changes to exploits/shellcodes
Core FTP Lite 1.3 - Denial of Service (PoC)
Easy2Pilot 7 - Cross-Site Request Forgery (Add User)
|
2020-02-21 05:01:53 +00:00 |
|
Offensive Security
|
16b45536b7
|
DB: 2020-02-20
5 changes to exploits/shellcodes
WordPress Plugin WP Sitemap Page 1.6.2 - Persistent Cross-Site Scripting
Virtual Freer 1.58 - Remote Command Execution
DBPower C300 HD Camera - Remote Configuration Disclosure
Nanometrics Centaur 4.3.23 - Unauthenticated Remote Memory Leak
|
2020-02-20 05:01:53 +00:00 |
|
Offensive Security
|
e28fa0b839
|
DB: 2020-02-19
1 changes to exploits/shellcodes
WordPress Theme Fruitful 3.8 - Persistent Cross-Site Scripting
WordPress Plugin WP Sitemap Page 1.6.2 - Persistent Cross-Site Scripting
|
2020-02-19 05:01:54 +00:00 |
|
Offensive Security
|
228a37da9c
|
DB: 2020-02-18
15 changes to exploits/shellcodes
HP System Event 1.2.9.0 - 'HPWMISVC' Unquoted Service Path
BOOTP Turbo 2.0.1214 - 'BOOTP Turbo' Unquoted Service Path
MSI Packages Symbolic Links Processing - Windows 10 Privilege Escalation
DHCP Turbo 4.61298 - 'DHCP Turbo 4' Unquoted Service Path
TFTP Turbo 4.6.1273 - 'TFTP Turbo 4' Unquoted Service Path
Cuckoo Clock v5.0 - Buffer Overflow
Anviz CrossChex - Buffer Overflow (Metasploit)
SOPlanning 1.45 - 'by' SQL Injection
Wordpress Plugin Strong Testimonials 2.40.1 - Persistent Cross-Site Scripting
Avaya Aura Communication Manager 5.2 - Remote Code Execution
Ice HRM 26.2.0 - Cross-Site Request Forgery (Add User)
WordPress Theme Fruitful 3.8 - Persistent Cross-Site Scripting
SOPlanning 1.45 - Cross-Site Request Forgery (Add User)
SOPlanning 1.45 - 'users' SQL Injection
LabVantage 8.3 - Information Disclosure
|
2020-02-18 05:01:54 +00:00 |
|
Offensive Security
|
53517327e7
|
DB: 2020-02-15
21 changes to exploits/shellcodes
PHP 5.2.3 Win32std - 'win_shell_execute' Safe Mode / Disable Functions Bypass
PHP 5.2.3 Win32std - 'win_shell_execute' Safe Mode / disable_functions Bypass
PHP 5.2.4 ionCube - 'ioncube_read_file' Safe Mode / Disable Functions Bypass
PHP 5.2.4 ionCube - 'ioncube_read_file' Safe Mode / disable_functions Bypass
PHP 5.x COM - Safe Mode / Disable Functions Bypass
PHP 5.x COM - Safe Mode / disable_functions Bypass
PHP 5.2.3 imap (Debian Based) - 'imap_open' Disable Functions Bypass
PHP 5.2.3 imap (Debian Based) - 'imap_open' disable_functions Bypass
HomeGuard Pro 9.3.1 - Insecure Folder Permissions
EPSON EasyMP Network Projection 2.81 - 'EMP_NSWLSV' Unquoted Service Path
SprintWork 2.3.1 - Local Privilege Escalation
Windows Kernel - Information Disclosure
PHP 7.0 < 7.4 (Unix) - 'debug_backtrace' disable_functions Bypass
OpenSMTPD 6.4.0 < 6.6.1 - Local Privilege Escalation + Remote Code Execution
PHP < 5.6.2 - 'Shellshock' Safe Mode / Disable Functions Bypass / Command Injection
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
PHP 5.5.9 - 'zend_executor_globals' 'CGIMode FPM WriteProcMemFile' Disable Functions Bypass / Load Dynamic Library
PHP 5.5.9 - 'zend_executor_globals' 'CGIMode FPM WriteProcMemFile' disable_functions Bypass / Load Dynamic Library
Imagick 3.3.0 (PHP 5.4) - Disable Functions Bypass
Imagick 3.3.0 (PHP 5.4) - disable_functions Bypass
PHP 7.1 < 7.3 - 'json serializer' Disable Functions Bypass
PHP 7.1 < 7.3 - 'json serializer' disable_functions Bypass
PHP 7.0 < 7.3 (Unix) - 'gc' Disable Functions Bypass
PHP 7.0 < 7.3 (Unix) - 'gc' disable_functions Bypass
VehicleWorkshop 1.0 - 'bookingid' SQL Injection
Wordpress Plugin tutor.1.5.3 - Local File Inclusion
Wordpress Plugin tutor.1.5.3 - Persistent Cross-Site Scripting
Wordpress Plugin wordfence.7.4.5 - Local File Disclosure
Wordpress Plugin contact-form-7 5.1.6 - Remote File Upload
phpMyChat Plus 1.98 - 'pmc_username' SQL Injection
WordPress Plugin ultimate-member 2.1.3 - Local File Inclusion
|
2020-02-15 05:01:54 +00:00 |
|