exploit-db-mirror/shellcodes
Offensive Security 1979df6cb3 DB: 2020-06-19
51 changes to exploits/shellcodes

Tor Browser < 0.3.2.10 - Use After Free (PoC)
Notepad++ < 7.7 (x64)  - Denial of Service
SpotIE Internet Explorer Password Recovery 2.9.5 - 'Key' Denial of Service
InputMapper 1.6.10 - Denial of Service

SurfOffline Professional 2.2.0.103 - 'Project Name' Denial of Service (SEH)

XnConvert 1.82 - Denial of Service (PoC)

SpotFTP FTP Password Recovery 3.0.0.0 - 'Key' Denial of Service (PoC)

SpotDialup 1.6.7 - 'Key' Denial of Service (PoC)

Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)

FreeBSD 12.0 - 'fd' Local Privilege Escalation
iOS < 12.4.1 - 'Jailbreak' Local Privilege Escalation
Easy File Sharing Web Server 7.2 - 'New User' Local Overflow (SEH)

DeviceViewer 3.12.0.1 - Arbitrary Password Change

Winrar 5.80 - XML External Entity Injection

Microsoft Windows Media Center WMV / WMA 6.3.9600.16384 - Code Execution

Siemens TIA Portal - Remote Command Execution

Android 7 < 9 - Remote Code Execution
CoreFTP 2.0 Build 674 SIZE - Directory Traversal (Metasploit)
CoreFTP 2.0 Build 674 MDTM - Directory Traversal (Metasploit)
CTROMS Terminal OS Port Portal - 'Password Reset' Authentication Bypass (Metasploit)

MyBB < 1.8.21 - Remote Code Execution

Nagios XI 5.6.5 - Remote Code Execution / Root Privilege Escalation

Webmin < 1.920 - 'rpc.cgi' Remote Code Execution (Metasploit)

Wolters Kluwer TeamMate 3.1 - Cross-Site Request Forgery

Publisure Hybrid - Multiple Vulnerabilities

NetGain EM Plus 10.1.68 - Remote Command Execution

Pfsense 2.3.4 / 2.4.4-p3 - Remote Code Injection

WordPress Plugin ARforms 3.7.1 - Arbitrary File Deletion

DotNetNuke 9.3.2 - Cross-Site Scripting

VehicleWorkshop 1.0 - 'bookingid' SQL Injection
WordPress Plugin Tutor.1.5.3 - Local File Inclusion
WordPress Plugin tutor.1.5.3 - Persistent Cross-Site Scripting
WordPress Plugin Wordfence.7.4.5 - Local File Disclosure
WordPress Plugin contact-form-7 5.1.6 - Remote File Upload

WordPress Plugin ultimate-member 2.1.3 - Local File Inclusion

WordPress Plugin WOOF Products Filter for WooCommerce 1.2.3 - Persistent Cross-Site Scripting

WordPress Plugin WP Sitemap Page 1.6.2 - Persistent Cross-Site Scripting
Joomla! 3.9.0 < 3.9.7 - CSV Injection
PlaySMS 1.4.3 - Template Injection / Remote Code Execution
Wing FTP Server - Authenticated CSRF (Delete Admin)

WordPress Plugin Custom Searchable Data System - Unauthenticated Data M]odification

UADMIN Botnet 1.0 - 'link' SQL Injection

Joomla! Component ACYMAILING 3.9.0 - Unauthenticated Arbitrary File Upload

Wordpress Plugin PicUploader 1.0 - Remote File Upload

PHP-Fusion 9.03.50 - 'panels.php' Remote Code Execution

WordPress Plugin Helpful 2.4.11 - SQL Injection

Prestashop 1.7.6.4 - Cross-Site Request Forgery

WordPress Plugin Simple File List 5.4 - Remote Code Execution

Library CMS Powerful Book Management System 2.2.0 - Session Fixation

Joomla! J2 Store 3.3.11 - 'filter_order_Dir' SQL Injection (Authenticated)
Joomla! J2 Store 3.3.11 - 'filter_order_Dir' Authenticated SQL Injection

Beauty Parlour Management System 1.0 - Authentication Bypass

Linux/x86 - Add User to /etc/passwd Shellcode (59 bytes)

Windows/x64 - WinExec Add-Admin Dynamic Null-Free Shellcode (210 Bytes)
Windows/x64 - WinExec Add-Admin (ROOT/I@mR00T$) Dynamic Null-Free Shellcode (210 Bytes)

Linux/x64 - Password Protected Bindshell + Null-free Shellcode (272 Bytes)
Linux/x64 - Password (P3WP3Wl4ZerZ) + Bind (0.0.0.0:4444/TCP) Shell (/bin/bash) + Null-free Shellcode (272 Bytes)
2020-06-19 05:02:01 +00:00
..
aix DB: 2018-01-09 2018-01-09 05:02:30 +00:00
alpha DB: 2018-01-11 2018-01-11 05:02:24 +00:00
android DB: 2017-11-24 2017-11-24 20:56:23 +00:00
arm DB: 2020-06-16 2020-06-16 05:01:56 +00:00
bsd DB: 2018-01-12 2018-01-12 05:02:17 +00:00
bsd_ppc DB: 2017-11-24 2017-11-24 20:56:23 +00:00
bsd_x86 DB: 2018-01-17 2018-01-17 05:02:19 +00:00
bsdi_x86 DB: 2018-01-22 2018-01-22 05:01:45 +00:00
freebsd DB: 2018-01-22 2018-01-22 05:01:45 +00:00
freebsd_x86 DB: 2018-01-12 2018-01-12 05:02:17 +00:00
freebsd_x86-64 DB: 2019-03-08 2019-03-08 05:01:50 +00:00
generator DB: 2019-05-24 2019-05-24 05:02:03 +00:00
hardware DB: 2018-01-22 2018-01-22 05:01:45 +00:00
hp-ux DB: 2018-01-22 2018-01-22 05:01:45 +00:00
ios DB: 2017-11-24 2017-11-24 20:56:23 +00:00
irix DB: 2018-01-12 2018-01-12 05:02:17 +00:00
linux DB: 2020-06-19 2020-06-19 05:02:01 +00:00
linux_crisv32 DB: 2017-11-24 2017-11-24 20:56:23 +00:00
linux_mips DB: 2019-03-08 2019-03-08 05:01:50 +00:00
linux_ppc DB: 2017-11-24 2017-11-24 20:56:23 +00:00
linux_sparc DB: 2018-01-13 2018-01-13 05:02:13 +00:00
linux_x86 DB: 2019-10-05 2019-10-05 05:01:46 +00:00
linux_x86-64 DB: 2019-12-18 2019-12-18 05:02:05 +00:00
macos DB: 2019-02-19 2019-02-19 05:02:08 +00:00
multiple DB: 2017-11-24 2017-11-24 20:56:23 +00:00
netbsd_x86 DB: 2018-01-25 2018-01-25 18:22:06 +00:00
openbsd_x86 DB: 2018-01-17 2018-01-17 05:02:19 +00:00
osx DB: 2018-09-25 2018-09-25 05:01:51 +00:00
osx_ppc DB: 2018-01-17 2018-01-17 05:02:19 +00:00
sco_x86 DB: 2017-11-24 2017-11-24 20:56:23 +00:00
solaris DB: 2017-11-24 2017-11-24 20:56:23 +00:00
solaris_mips DB: 2018-01-17 2018-01-17 05:02:19 +00:00
solaris_sparc DB: 2018-01-25 2018-01-25 18:22:06 +00:00
solaris_x86 DB: 2018-01-25 2018-01-25 18:22:06 +00:00
superh_sh4 DB: 2018-01-13 2018-01-13 05:02:13 +00:00
system_z DB: 2017-11-24 2017-11-24 20:56:23 +00:00
unixware DB: 2018-01-25 2018-01-25 18:22:06 +00:00
windows DB: 2020-04-22 2020-04-22 05:01:47 +00:00
windows_x86 DB: 2020-02-25 2020-02-25 05:01:52 +00:00
windows_x86-64 DB: 2020-03-26 2020-03-26 05:01:48 +00:00