Commit graph

2750 commits

Author SHA1 Message Date
Exploit-DB
967f9d17d6 DB: 2024-01-24
1 changes to exploits/shellcodes/ghdb
2024-01-24 00:16:25 +00:00
Exploit-DB
cb7ba0c503 DB: 2023-12-22
1 changes to exploits/shellcodes/ghdb
2023-12-22 00:16:27 +00:00
Exploit-DB
82c4f0ab51 DB: 2023-12-19
1 changes to exploits/shellcodes/ghdb
2023-12-19 00:16:22 +00:00
Exploit-DB
d6ac341475 DB: 2023-12-16
1 changes to exploits/shellcodes/ghdb
2023-12-16 00:16:30 +00:00
Exploit-DB
5ae67f58b9 DB: 2023-12-15
1 changes to exploits/shellcodes/ghdb
2023-12-15 00:16:26 +00:00
Exploit-DB
07b04761c2 DB: 2023-12-13
1 changes to exploits/shellcodes/ghdb
2023-12-13 00:16:53 +00:00
Exploit-DB
4b91641d83 DB: 2023-12-12
1 changes to exploits/shellcodes/ghdb
2023-12-12 00:16:31 +00:00
Exploit-DB
baedefe44c DB: 2023-12-07
1 changes to exploits/shellcodes/ghdb
2023-12-07 00:16:31 +00:00
Exploit-DB
3ed9fc9688 DB: 2023-12-05
1 changes to exploits/shellcodes/ghdb
2023-12-05 00:16:21 +00:00
Exploit-DB
066333e56d DB: 2023-12-02
1 changes to exploits/shellcodes/ghdb
2023-12-02 00:16:24 +00:00
Exploit-DB
7e32166ebc DB: 2023-12-01
1 changes to exploits/shellcodes/ghdb
2023-12-01 00:16:26 +00:00
Exploit-DB
057c2f886a DB: 2023-11-30
1 changes to exploits/shellcodes/ghdb
2023-11-30 00:16:31 +00:00
Exploit-DB
bde3836027 DB: 2023-11-28
1 changes to exploits/shellcodes/ghdb
2023-11-28 00:16:33 +00:00
Exploit-DB
617a6b4036 DB: 2023-11-25
1 changes to exploits/shellcodes/ghdb
2023-11-25 00:16:32 +00:00
Exploit-DB
8a972c9a3f DB: 2023-11-24
1 changes to exploits/shellcodes/ghdb
2023-11-24 00:16:42 +00:00
Exploit-DB
d66aada84d DB: 2023-11-21
1 changes to exploits/shellcodes/ghdb
2023-11-21 00:16:23 +00:00
Exploit-DB
034fa97b3e DB: 2023-11-18
1 changes to exploits/shellcodes/ghdb
2023-11-18 00:16:41 +00:00
Exploit-DB
e7b3c09fd9 DB: 2023-11-11
1 changes to exploits/shellcodes/ghdb
2023-11-11 00:16:32 +00:00
Exploit-DB
937420d384 DB: 2023-11-10
1 changes to exploits/shellcodes/ghdb
2023-11-10 00:16:27 +00:00
Exploit-DB
43a5e18260 DB: 2023-11-09
1 changes to exploits/shellcodes/ghdb
2023-11-09 00:16:27 +00:00
Exploit-DB
7b7a9c9ea4 DB: 2023-11-08
1 changes to exploits/shellcodes/ghdb
2023-11-08 00:17:10 +00:00
Exploit-DB
3711d1e88d DB: 2023-11-07
1 changes to exploits/shellcodes/ghdb
2023-11-07 00:16:47 +00:00
Exploit-DB
5b9acfe03d DB: 2023-11-03
1 changes to exploits/shellcodes/ghdb
2023-11-03 00:17:00 +00:00
Exploit-DB
ea7fd161a3 DB: 2023-11-02
1 changes to exploits/shellcodes/ghdb
2023-11-02 00:16:33 +00:00
Exploit-DB
e369c91366 DB: 2023-11-01
1 changes to exploits/shellcodes/ghdb
2023-11-01 00:16:42 +00:00
Exploit-DB
75cbb282d9 DB: 2023-10-31
12 changes to exploits/shellcodes/ghdb

systemd 246 - Local Privilege Escalation

ChurchCRM v4.5.3 - Authenticated SQL Injection

Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE) via subprocess_execute

Maltrail v0.53 - Unauthenticated Remote Code Execution (RCE)

Request-Baskets v1.2.1 - Server-side request forgery (SSRF)
2023-10-31 00:17:05 +00:00
Exploit-DB
45020d9cc3 DB: 2023-10-26
1 changes to exploits/shellcodes/ghdb
2023-10-26 00:16:49 +00:00
Exploit-DB
3c68644b7f DB: 2023-10-24
1 changes to exploits/shellcodes/ghdb
2023-10-24 00:16:26 +00:00
Exploit-DB
28233c60a9 DB: 2023-10-21
1 changes to exploits/shellcodes/ghdb
2023-10-21 00:17:11 +00:00
Exploit-DB
8e469af5e4 DB: 2023-10-20
1 changes to exploits/shellcodes/ghdb
2023-10-20 00:16:34 +00:00
Exploit-DB
d769738a1b DB: 2023-10-19
1 changes to exploits/shellcodes/ghdb
2023-10-19 00:16:34 +00:00
Exploit-DB
888e6c1d4c DB: 2023-10-17
1 changes to exploits/shellcodes/ghdb
2023-10-17 00:16:34 +00:00
Exploit-DB
53fc63f69b DB: 2023-10-14
1 changes to exploits/shellcodes/ghdb
2023-10-14 00:16:29 +00:00
Exploit-DB
f3649a641f DB: 2023-10-10
24 changes to exploits/shellcodes/ghdb

Minio 2022-07-29T19-40-48Z - Path traversal

Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Denial Of Service

Atcom 2.7.x.x - Authenticated Command Injection

Ruijie Reyee Mesh Router - MITM Remote Code Execution (RCE)
Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Admin Password Change
Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Credentials Extraction

OpenPLC WebServer 3 - Denial of Service

Splunk 9.0.5 - admin account take over

BoidCMS v2.0.0 - authenticated file upload vulnerability

Cacti 1.2.24 - Authenticated command injection when using SNMP options

Chitor-CMS v1.1.2 - Pre-Auth SQL Injection

Clcknshop 1.0.0 - SQL Injection

Coppermine Gallery 1.6.25 - RCE

Crypto Currency Tracker (CCT) 9.5 - Admin Account Creation (Unauthenticated)

GLPI GZIP(Py3) 9.4.5 - RCE

Limo Booking Software v1.0 - CORS

Media Library Assistant Wordpress Plugin - RCE and LFI

Online ID Generator 1.0 - Remote Code Execution (RCE)

Shuttle-Booking-Software v1.0 - Multiple-SQLi

Webedition CMS v2.9.8.8 - Blind SSRF

WEBIGniter v28.7.23 File Upload - Remote Code Execution

Wordpress Plugin Masterstudy LMS - 3.0.17 - Unauthenticated Instructor Account Creation

Wordpress Sonaar Music Plugin 4.7 - Stored XSS

Microsoft Windows 11 - 'apds.dll' DLL hijacking (Forced)
2023-10-10 00:16:32 +00:00
Exploit-DB
e5f7757184 DB: 2023-10-03
1 changes to exploits/shellcodes/ghdb
2023-10-03 00:16:26 +00:00
g0t mi1k
f88561adfb Merge branch 'nmap-version-parsing' into 'main'
Fix: searchsploit Nmap XML parsing loses software version data.

See merge request exploit-database/exploitdb!3
2023-09-25 16:46:54 +00:00
Michael Monsivais
8298b27c9c Fix: searchsploit Nmap parsing loses version data.
Modified searchsploit's Nmap XML parsing to correctly extract software
versions. Also, these versions are no longer split on '.'.
2023-09-15 20:29:25 -04:00
Exploit-DB
3cde8c39d6 DB: 2023-09-13
1 changes to exploits/shellcodes/ghdb
2023-09-13 00:16:29 +00:00
Exploit-DB
db6fc602bf DB: 2023-09-12
1 changes to exploits/shellcodes/ghdb
2023-09-12 00:16:26 +00:00
Exploit-DB
cbe784b087 DB: 2023-09-09
16 changes to exploits/shellcodes/ghdb

Techview LA-5570 Wireless Gateway Home Automation Controller - Multiple Vulnerabilities

Axigen < 10.3.3.47_ 10.2.3.12 - Reflected XSS

Drupal 10.1.2 - web-cache-poisoning-External-service-interaction

Jorani v1.0.3-(c)2014-2023 - XSS Reflected & Information Disclosure

soosyze 2.0.0 - File Upload

SPA-Cart eCommerce CMS 1.9.0.3 - SQL Injection

Wordpress Plugin Elementor 3.5.5 - Iframe Injection

Wp2Fac - OS Command Injection

Maltrail v0.53 - Unauthenticated Remote Code Execution (RCE)

SyncBreeze 15.2.24 - 'login' Denial of Service

GOM Player 2.3.90.5360 - Buffer Overflow (PoC)

GOM Player 2.3.90.5360 - Remote Code Execution (RCE)

Windows/x64 - PIC Null-Free TCP Reverse Shell Shellcode (476 Bytes)
2023-09-09 00:16:33 +00:00
Exploit-DB
54971d143b DB: 2023-09-08
1 changes to exploits/shellcodes/ghdb
2023-09-08 00:16:30 +00:00
Exploit-DB
fdcaa2b976 DB: 2023-09-07
1 changes to exploits/shellcodes/ghdb

Blood Donor Management System v1.0 - Stored XSS
2023-09-07 00:16:27 +00:00
Exploit-DB
4e246a01fb DB: 2023-09-05
18 changes to exploits/shellcodes/ghdb

DLINK DPH-400SE - Exposure of Sensitive Information

FileMage Gateway 1.10.9 - Local File Inclusion

Academy LMS 6.1 - Arbitrary File Upload

AdminLTE PiHole 5.18 - Broken Access Control

Blood Donor Management System v1.0 - Stored XSS

Bus Reservation System 1.1 - Multiple-SQLi

Credit Lite 1.5.4 - SQL Injection
CSZ CMS 1.3.0 - Stored Cross-Site Scripting ('Photo URL' and 'YouTube URL' )
CSZ CMS 1.3.0 - Stored Cross-Site Scripting (Plugin 'Gallery')

Hyip Rio 2.1 - Arbitrary File Upload

Member Login Script 3.3 - Client-side desync

SPA-Cart eCommerce CMS 1.9.0.3 - Reflected XSS
Webedition CMS v2.9.8.8 - Remote Code Execution (RCE)
Webedition CMS v2.9.8.8 - Stored XSS
Webedition CMS v2.9.8.8 - Remote Code Execution (RCE)
Webedition CMS v2.9.8.8 - Stored XSS

WP Statistics Plugin 13.1.5 current_page_id - Time based SQL injection (Unauthenticated)

Freefloat FTP Server 1.0 - 'PWD' Remote Buffer Overflow

Kingo ROOT 1.5.8 - Unquoted Service Path

NVClient v5.0 - Stack Buffer Overflow (DoS)

Ivanti Avalanche <v6.4.0.0 - Remote Code Execution
2023-09-05 00:16:27 +00:00
Exploit-DB
4c8ac36b6c DB: 2023-08-30
1 changes to exploits/shellcodes/ghdb

Online Clinic Management System 2.2 - HTML Injection
Online Clinic Management System 2.2 - Multiple Stored Cross-Site Scripting (XSS)
Online Clinic Management System 2.2 - HTML Injection
Online Clinic Management System 2.2 - Multiple Stored Cross-Site Scripting (XSS)
Purchase Order Management System 1.0 - Remote File Upload
Purchase Order Management-1.0 - Local File Inclusion
Purchase Order Management System 1.0 - Remote File Upload
Purchase Order Management-1.0 - Local File Inclusion

Restaurant Management System 1.0  - SQL Injection
2023-08-30 00:16:32 +00:00
Exploit-DB
fe2c42ff0e DB: 2023-08-25
4 changes to exploits/shellcodes/ghdb

User Registration & Login and User Management System v3.0 - SQL Injection (Unauthenticated)
User Registration & Login and User Management System v3.0 - Stored Cross-Site Scripting (XSS)

Uvdesk 1.1.4 - Stored XSS (Authenticated)
2023-08-25 00:16:28 +00:00
Exploit-DB
cb5ca4a416 DB: 2023-08-24
1 changes to exploits/shellcodes/ghdb

Color Prediction Game v1.0 - SQL Injection

Multi-Vendor Online Groceries Management System 1.0 - 'id' Blind SQL Injection

Online Eyewear Shop 1.0 - SQL Injection (Unauthenticated)
2023-08-24 00:16:24 +00:00
Exploit-DB
e07f33f24d DB: 2023-08-22
17 changes to exploits/shellcodes/ghdb

EuroTel ETL3100 - Transmitter Authorization Bypass (IDOR)
EuroTel ETL3100 - Transmitter Default Credentials
EuroTel ETL3100 - Transmitter Unauthenticated Config/Log Download

Color Prediction Game v1.0 - SQL Injection

Crypto Currency Tracker (CCT) 9.5 - Admin Account Creation (Unauthenticated)

Dolibarr Version 17.0.1 - Stored XSS

Global - Multi School Management System Express v1.0- SQL Injection

OVOO Movie Portal CMS v3.3.3 - SQL Injection

PHPJabbers Business Directory Script v3.2 - Multiple Vulnerabilities

Taskhub CRM Tool 2.8.6 - SQL Injection

Inosoft VisiWin 7 2022-2.1 - Insecure Folders Permissions
TSPlus 16.0.0.0 - Remote Work Insecure Credential storage
TSplus 16.0.0.0 - Remote Work Insecure Files and Folders
TSplus 16.0.2.14 - Remote Access Insecure Files and Folders Permissions

Linux/x64 - memfd_create ELF loader Shellcode (170 bytes)
2023-08-22 00:16:22 +00:00
Exploit-DB
500cf5a2e0 DB: 2023-08-20
1 changes to exploits/shellcodes/ghdb

Diafan CMS 6.0 - Reflected Cross-Site Scripting (XSS)

Online Art gallery project 1.0 - Arbitrary File Upload (Unauthenticated)

Online Shopping Cart System 1.0 - 'id' SQL Injection

Online Thesis Archiving System v1.0 - Multiple-SQLi
WebsiteBaker v2.13.3 - Cross-Site Scripting (XSS)
WebsiteBaker v2.13.3 - Directory Traversal
WebsiteBaker v2.13.3 - Stored XSS
WebsiteBaker v2.13.3 - Cross-Site Scripting (XSS)
WebsiteBaker v2.13.3 - Directory Traversal
WebsiteBaker v2.13.3 - Stored XSS
2023-08-20 00:16:58 +00:00
Exploit-DB
6da2bca764 DB: 2023-08-12
1 changes to exploits/shellcodes/ghdb

projectSend r1605 - CSV injection
projectSend r1605 - Private file download
projectSend r1605 - CSV injection
projectSend r1605 - Private file download

projectSend r1605 - Stored XSS
2023-08-12 00:16:26 +00:00
Exploit-DB
f55092b332 DB: 2023-08-11
6 changes to exploits/shellcodes/ghdb

TP-Link Archer AX21 - Unauthenticated Command Injection

systemd 246 - Local Privilege Escalation

Maltrail v0.53 - Unauthenticated Remote Code Execution (RCE)

Request-Baskets v1.2.1 - Server-side request forgery (SSRF)

OutSystems Service Studio 11.53.30 - DLL Hijacking
2023-08-11 00:16:25 +00:00