المساعد الشخصي الرقمي

مشاهدة النسخة كاملة : exploit database


الصفحات : 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 [19] 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61

  1. [webapps] Joomla! Component User Bench 1.0 - 'userid' SQL Injection
  2. [remote] Western Digital MyCloud - 'multi_uploadify' File Upload (Metasploit)
  3. [dos] Zoom Linux Client 2.0.106600.0904 - Stack-Based Buffer Overflow
  4. [dos] Zoom Linux Client 2.0.106600.0904 - Command Injection
  5. [remote] Outlook for Android - Attachment Download Directory Traversal
  6. [dos] CDex 1.96 - Buffer Overflow
  7. [local] Linux kernel < 4.10.15 - Race Condition Privilege Escalation
  8. [webapps] Joomla! Component Guru Pro - 'promocode' SQL Injection
  9. [webapps] Joomla! Component JB Visa 1.0 - 'visatype' SQL Injection
  10. [webapps] Monstra CMS 3.0.4 - Arbitrary File Upload / Remote Code Execution
  11. [webapps] Movie Guide 2.0 - SQL Injection
  12. [dos] Sync Breeze 10.2.12 - Denial of Service
  13. [webapps] ITGuard-Manager 0.0.0.1 - Remote Code Execution
  14. [remote] pfSense 2.4.1 - CSRF Error Page Clickjacking (Metasploit)
  15. [remote] Palo Alto Networks Firewalls - Remote root Code Execution
  16. [webapps] Advantech WebAccess 8.2-2017.03.31 - Webvrpcs Service Opcode 80061 Stack Bu
  17. [remote] Dup Scout Enterprise - Login Buffer Overflow (Metasploit)
  18. [remote] Microsoft Office - DDE Payload Delivery (Metasploit)
  19. [webapps] Joomla! Component JEXTN Question And Answer 3.1.0 - SQL Injection
  20. [webapps] Paid To Read Script 2.0.5 - 'uid' / 'fnum' / 'fn' SQL Injection
  21. [webapps] Readymade Video Sharing Script 3.2 - HTML Injection
  22. [webapps] FS Lynda Clone 1.0 - SQL Injection
  23. [webapps] Piwigo 2.9.1 - 'cat_true' / 'cat_false' SQL Injection
  24. [webapps] Bus Booking Script 1.0 - 'txtname' SQL Injection
  25. [webapps] Joomla! Component JEXTN Video Gallery 3.0.5 - 'id' SQL Injection
  26. [local] glibc ld.so - Memory Leak / Buffer Overflow
  27. [webapps] Meinberg LANTIME Web Configuration Utility 6.16.008 - Arbitrary File Read
  28. [dos] Apple XNU Kernel - Memory Corruption due to Integer Overflow in __offsetof Usag
  29. [dos] macOS/iOS - Multiple Kernel Use-After-Frees due to Incorrect IOKit Object Lifet
  30. [dos] macOS - Kernel Code Execution due to Lack of Bounds Checking in AppleIntelCapri
  31. [dos] macOS/iOS - Kernel Double Free due to Incorrect API Usage in Flow Divert Socket
  32. [webapps] Joomla! Component JBuildozer 1.4.1 - 'appid' SQL Injection
  33. [webapps] Accesspress Anonymous Post Pro < 3.2.0 - Unauthenticated Arbitrary File Upl
  34. [dos] iOS/macOS - Kernel Double Free due to IOSurfaceRootUserClient not Respecting MI
  35. [dos] macOS XNU Kernel - Memory Disclosure due to bug in Kernel API for Detecting Ker
  36. [dos] LibTIFF pal2rgb 4.0.9 - Heap Buffer Overflow
  37. [dos] macOS - 'necp_get_socket_attributes' so_pcb Type Confusion
  38. [dos] macOS - 'getrusage' Stack Leak Through struct Padding
  39. [dos] MikroTik 6.40.5 ICMP - Denial of Service
  40. [webapps] Vanguard 1.4 - SQL Injection
  41. [webapps] Resume Clone Script 2.0.5 - SQL Injection
  42. [webapps] Advanced World Database 2.0.5 - SQL Injection
  43. [webapps] Vanguard 1.4 - Arbitrary File Upload
  44. [webapps] Basic Job Site Script 2.0.5 - SQL Injection
  45. [webapps] Car Rental Script 2.0.4 - 'val' SQL Injection
  46. [webapps] Groupon Clone Script 3.01 - 'state_id' / 'search' SQL Injection
  47. [webapps] MLM Forced Matrix 2.0.9 - 'newid' SQL Injection
  48. [webapps] Muslim Matrimonial Script 3.02 - 'succid' SQL Injection
  49. [webapps] MLM Forex Market Plan Script 2.0.4 - 'newid' / 'eventid' SQL Injection
  50. [webapps] Entrepreneur Bus Booking Script 3.0.4 - 'sourcebus' SQL Injection
  51. [webapps] Advanced Real Estate Script 4.0.7 - SQL Injection
  52. [webapps] Single Theater Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
  53. [webapps] Multiplex Movie Theater Booking Script 3.1.5 - 'moid' / 'eid' SQL Injection
  54. [webapps] Responsive Events & Movie Ticket Booking Script 3.2.1 - 'findcity.php?q' SQ
  55. [webapps] Multireligion Responsive Matrimonial 4.7.2 - 'succid' SQL Injection
  56. [webapps] Entrepreneur Dating Script 2.0.1 - 'marital' / 'gender' / 'country' / 'prof
  57. [webapps] PHP Multivendor Ecommerce 1.0 - 'sid' / 'searchcat' / 'chid1' SQL Injection
  58. [webapps] Professional Service Script 1.0 - 'service-list?city' SQL Injection
  59. [webapps] Readymade PHP Classified Script 3.3 - 'subctid' / 'mctid' SQL Injection
  60. [webapps] Readymade Video Sharing Script 3.2 - SQL Injection
  61. [webapps] Responsive Realestate Script 3.2 - 'property-list?tbud' SQL Injection
  62. [webapps] Multivendor Penny Auction Clone Script 1.0 - SQL Injection
  63. [webapps] Online Exam Test Application Script 1.6 - 'exams.php?sort' SQL Injection
  64. [webapps] Opensource Classified Ads Script 3.2 - SQL Injection
  65. [webapps] Secure E-commerce Script 2.0.1 - 'searchcat' / 'searchmain' SQL Injection
  66. [webapps] Lawyer Search Script 1.1 - 'lawyer-list?city' SQL Injection
  67. [webapps] Laundry Booking Script 1.0 - 'list?city' SQL Injection
  68. [webapps] Foodspotting Clone Script 1.0 - 'quicksearch.php?q' SQL Injection
  69. [webapps] Kickstarter Clone Acript 2.0 - 'projid' SQL Injection
  70. [webapps] Hot Scripts Clone 3.1 - 'subctid' / 'mctid' SQL Injection
  71. [webapps] Facebook Clone Script 1.0 - 'id' / 'send' SQL Injection
  72. [webapps] Food Order Script 1.0 - 'list?city' SQL Injection
  73. [webapps] Yoga Class Script 1.0 - 'list?city' SQL Injection
  74. [webapps] Freelance Website Script 2.0.6 - 'pr_id' / 'catid' SQL Injection
  75. [webapps] Entrepreneur Job Portal Script 2.0.6 - 'jobsearch_all.php?rid1' SQL Injecti
  76. [webapps] Consumer Complaints Clone Script 1.0 - 'id' SQL Injection
  77. [webapps] Doctor Search Script 1.0 - 'city' SQL Injection
  78. [webapps] E-commerce MLM Software 1.0 - SQL Injection
  79. [webapps] Event Calendar Category Script 1.0 - 'city' SQL Injection
  80. [webapps] CMS Auditor Website 1.0 - SQL Injection
  81. [webapps] Co-work Space Search Script 1.0 - 'city' SQL Injection
  82. [webapps] Chartered Accountant Booking Script 1.0 - 'city' SQL Injection
  83. [webapps] Child Care Script 1.0 - 'city' SQL Injection
  84. [webapps] Cab Booking Script 1.0 - 'city' SQL Injection
  85. [webapps] Nearbuy Clone Script 3.2 - 'search' SQL Injection
  86. [webapps] FS Foodpanda Clone 1.0 - SQL Injection
  87. [webapps] Advance B2B Script 2.1.3 - 'show_id' / 'pid' SQL Injection
  88. [webapps] Advance Online Learning Management Script 3.1 - 'subcatid' / 'popcourseid'
  89. [webapps] Affiliate MLM Script 1.0 - 'product-category.php?key' SQL Injection
  90. [webapps] Basic B2B Script 2.0.8 - 'product_details.php?id' SQL Injection
  91. [webapps] Beauty Parlour Booking Script 1.0 - 'gender' / 'city' SQL Injection
  92. [webapps] FS Expedia Clone 1.0 - 'fl_orig' / 'fl_dest' / 'id' SQL Injection
  93. [webapps] FS Gigs Script 1.0 - 'cat' / 'sc' SQL Injection
  94. [webapps] FS Freelancer Clone 1.0 - 'profile.php?u' SQL Injection
  95. [webapps] FS Ebay Clone 1.0 - 'id' / 'sub_category_id' / 'category_id' SQL Injection
  96. [webapps] FS Crowdfunding Script 1.0 - 'latest_news_details.php?id' SQL Injection
  97. [webapps] FS Care Clone 1.0 - 'jobFrequency' / 'jobType' SQL Injection
  98. [webapps] FS Amazon Clone 1.0 - SQL Injection
  99. [webapps] FS Trademe Clone 1.0 - 'search' / 'id' SQL Injection
  100. [webapps] FS Indiamart Clone 1.0 - 'token' / 'id' / 'c' SQL Injection
  101. [webapps] FS IMDB Clone 1.0 - 'f' / 's' / 'id' SQL Injection
  102. [webapps] FS Linkedin Clone 1.0 - 'grid' / 'fid' / 'id' SQL Injection
  103. [webapps] FS Grubhub Clone 1.0 - 'keywords' SQL Injection
  104. [webapps] FS Groupon Clone 1.0 - 'id' SQL Injection
  105. [webapps] FS Makemytrip Clone 1.0 - 'fl_orig' / 'fl_dest' SQL Injection
  106. [local] Apple macOS 10.13.1 (High Sierra) - 'Blank Root' Local Privilege Escalation
  107. [local] Apple macOS 10.13.1 (High Sierra) - Insecure Cron System Local Privilege Esca
  108. [webapps] FS Quibids Clone 1.0 - SQL Injection
  109. [webapps] FS Olx Clone 1.0 - 'scat' / 'pid' SQL Injection
  110. [webapps] FS Monster Clone 1.0 - 'Employer_Details.php?id' SQL Injection
  111. [webapps] Realestate Crowdfunding Script 2.7.2 - 'pid' SQL Injection
  112. [webapps] FS Thumbtack Clone 1.0 - 'cat' / 'sc' SQL Injection
  113. [webapps] FS Stackoverflow Clone 1.0 - 'keywords' SQL Injection
  114. [webapps] FS Shutterstock Clone 1.0 - 'keywords' SQL Injection
  115. [webapps] Simple Chatting System 1.0.0 - Arbitrary File Upload
  116. [webapps] Website Auction Marketplace 2.0.5 - 'cat_id' SQL Injection
  117. [webapps] DomainSale PHP Script 1.0 - 'id' SQL Injection
  118. [remote] LabF nfsAxe FTP Client 3.7 - Buffer Overflow (DEP Bypass)
  119. [dos] Wireshark 2.4.0 - 2.4.2 / 2.2.0 - 2.2.10 - CIP Safety Dissector Crash
  120. [dos] Linux Kernel - DCCP Socket Use-After-Free
  121. [remote] Polycom Shell HDX Series - Traceroute Command Execution (Metasploit)
  122. [remote] Claymore Dual ETH + DCR/SC/LBC/PASC GPU Miner - Stack Buffer Overflow / Path
  123. [webapps] OpenEMR 5.0.0 - OS Command Injection / Cross-Site Scripting
  124. [remote] LaCie 5big Network 2.2.8 - Command Injection
  125. [webapps] FS IMDB Clone - 'id' SQL Injection
  126. [webapps] FS Facebook Clone - 'token' SQL Injection
  127. [dos] Microsoft Windows Defender - Controlled Folder Bypass Through UNC Path
  128. [local] Hashicorp vagrant-vmware-fusion 5.0.0 - Local root Privilege Escalation
  129. [local] Hashicorp vagrant-vmware-fusion 4.0.24 - Local root Privilege Escalation
  130. [local] Hashicorp vagrant-vmware-fusion 4.0.23 - Local root Privilege Escalation
  131. [local] Proxifier for Mac 2.19 - Local root Privilege Escalation
  132. [local] Arq 5.9.7 - Local root Privilege Escalation
  133. [local] Murus 1.4.11 - Local root Privilege Escalation
  134. [local] Arq 5.9.6 - Local root Privilege Escalation
  135. [local] Hashicorp vagrant-vmware-fusion 5.0.3 - Local root Privilege Escalation
  136. [local] Sera 1.2 - Local root Privilege Escalation / Password Disclosure
  137. [local] Hashicorp vagrant-vmware-fusion 5.0.1 - Local root Privilege Escalation
  138. [webapps] FS Makemytrip Clone - 'id' SQL Injection
  139. [webapps] WinduCMS 3.1 - Local File Disclosure
  140. [webapps] FS Shaadi Clone - 'token' SQL Injection
  141. [webapps] Readymade Classifieds Script 1.0 - SQL Injection
  142. [webapps] Techno Portfolio Management Panel - 'id' SQL Injection
  143. [remote] VX Search 10.2.14 - 'command_name' Buffer Overflow
  144. [local] Perspective ICM Investigation & Case 5.1.1.16 - Privilege Escalation
  145. [dos] Abyss Web Server < 2.11.6 - Heap Memory Corruption
  146. [remote] HP iMC Plat 7.2 - Remote Code Execution (2)
  147. [webapps] Jobs2Careers / Coroflot Clone - SQL Injection
  148. [papers] [Hebrew] Digital Whisper Security Magazine #89
  149. [webapps] Artica Web Proxy 3.06 - Remote Code Execution
  150. [webapps] MistServer 2.12 - Cross-Site Scripting
  151. [remote] HP iMC Plat 7.2 - Remote Code Execution
  152. [local] macOS High Sierra - Root Privilege Escalation (Metasploit)
  153. [dos] Asterisk 13.17.2 - Memory Corruption
  154. [dos] Linux Kernel - 'The Huge Dirty Cow' Overwriting The Huge Zero Page
  155. [webapps] WordPress Plugin WooCommerce 2.0/3.0 - Directory Traversal
  156. [dos] QEMU - Stack Buffer Overflow in NBD Server Triggered via Long Export Name
  157. [remote] pfSense - Authenticated Group Member RCE (Metasploit)
  158. [local] Microsoft Windows 10 Creators Update (version 1703) (x86) - 'WARBIRD' 'NtQuer
  159. [webapps] osCommerce 2.3.4.1 - Arbitrary File Upload
  160. [webapps] Synology StorageManager 5.2 - Remote Root Command Execution
  161. [dos] Android Gmail < 7.11.5.176568039 - Directory Traversal in Attachment Download
  162. [webapps] ZTE ZXDSL 831CII - Improper Access Restrictions
  163. [local] Diving Log 6.0 - XML External Entity Injection
  164. [dos] KMPlayer 4.2.2.4 - Denial of Service
  165. [dos] Winamp Pro 5.66.Build.3512 - Denial of Service
  166. [dos] Exim 4.89 - 'BDAT' Denial of Service
  167. [dos] Microsoft Edge Chakra JIT - 'BailOutOnTaggedValue' Bailouts Type Confusion
  168. [dos] Microsoft Edge Chakra JIT - 'Inline::InlineCallApplyTarget_Shared' does not Ret
  169. [dos] Microsoft Edge Chakra JIT - Incorrect Function Declaration Scope
  170. [dos] Microsoft Edge Chakra JIT - 'GlobOpt::OptTagChecks' Must Consider IsLoopPrePass
  171. [webapps] CommuniGatePro 6.1.16 - Cross-Site Scripting
  172. [local] ALLPlayer 7.5 - Local Buffer Overflow (SEH Unicode)
  173. [dos] Linux - 'mincore()' Uninitialized Kernel Heap Page Disclosure
  174. [dos] WebKit - 'WebCore::AXObjectCache::performDeferredCacheUpdat e' Use-After-Free
  175. [dos] WebKit - 'WebCore::RenderObject::previousSibling' Use-After-Free
  176. [dos] WebKit - 'WebCore::DocumentLoader::frameLoader' Use-After-Free
  177. [dos] WebKit - 'WebCore::FormSubmission::create' Use-After-Free
  178. [dos] WebKit - 'WebCore::SimpleLineLayout::RunResolver::runForPoi nt' Out-of-Bounds Re
  179. [dos] WebKit - 'WebCore::Style::TreeResolver::styleForElement' Use-After-Free
  180. [dos] WebKit - 'WebCore::SVGPatternElement::collectPatternAttribu tes' Out-of-Bounds R
  181. [dos] WebKit - 'WebCore::RenderText::localCaretRect' Out-of-Bounds Read
  182. [dos] WebKit - 'WebCore::PositionIterator::decrement' Use-After-Free
  183. [dos] WebKit - 'WebCore::InputType::element' Use-After-Free
  184. [dos] WebKit - 'WebCore::TreeScope::documentScope' Use-After-Free
  185. [webapps] Icon Time Systems RTC-1000 Firmware 2.5.7458 - Cross-Site Scripting
  186. [dos] Vonage VDV-23 - Denial of Service
  187. [dos] Microsoft Windows 10 - 'nt!NtQueryDirectoryFile (luafv!LuafvCopyDirectoryEntry)
  188. [remote] Microsoft Office - OLE Remote Code Execution
  189. [local] Microsoft Windows 10 - CiSetFileCache TOCTOU Security Feature Bypass
  190. [dos] iOS < 11.1 / tvOS < 11.1 / watchOS < 4.1 - Denial of Service
  191. [papers] Reversing and Exploiting IoT devices
  192. [papers] [Hebrew] Digital Whisper Security Magazine #88
  193. [webapps] MyBB 1.8.13 - Remote Code Execution
  194. [webapps] MyBB 1.8.13 - Cross-Site Scripting
  195. [local] VX Search 10.2.14 - 'Proxy' Buffer Overflow (SEH)
  196. [webapps] Zeta Components Mail 1.8.1 - Remote Code Execution
  197. [dos] Microsoft Edge Chakra JIT - Type Confusion with switch Statements
  198. [dos] Microsoft Edge Chakra: JIT - 'Lowerer::LowerBoundCheck' Incorrect Integer Overf
  199. [dos] Microsoft Edge Chakra: JIT - 'OP_Memset' Type Confusion
  200. [dos] Microsoft Edge - 'Object.setPrototypeOf' Memory Corruption
  201. [webapps] Vonage VDV23 - Cross-Site Scripting
  202. [webapps] TP-Link TL-WR740N - Cross-Site Scripting
  203. [webapps] LanSweeper 6.0.100.75 - Cross-Site Scripting
  204. [dos] D-Link DIR605L - Denial of Service
  205. [webapps] D-Link DCS-936L Network Camera - Cross-Site Request Forgery
  206. [remote] Dup Scout Enterprise 10.0.18 - 'Login' Buffer Overflow
  207. [dos] Microsoft Internet Explorer 11 - 'jscript!JsErrorToString' Use-After-Free
  208. [remote] Mako Server 2.5 - OS Command Injection Remote Command Execution (Metasploit)
  209. [dos] PHP 7.1.8 - Heap-Based Buffer Overflow
  210. [remote] D-Link DIR-850L - Unauthenticated OS Command Execution (Metasploit)
  211. [dos] PSFTPd Windows FTP Server 10.0.4 Build 729 - Log Injection / Use-After-Free
  212. [remote] Wireless IP Camera (P2P) WIFICAM - Unauthenticated Remote Code Execution
  213. [remote] Ulterius Server < 1.9.5.0 - Directory Traversal
  214. [webapps] Kirby CMS < 2.5.7 - Cross-Site Scripting
  215. [local] IKARUS anti.virus 2.16.7 - 'ntguard_x64' Privilege Escalation
  216. [webapps] Web Viewer 1.0.0.193 (Samsung SRN-1670D) - Unrestricted File Upload
  217. [dos] Xlight FTP Server 3.8.8.5 - Buffer Overflow (PoC)
  218. [webapps] ManageEngine Applications Manager 13 - SQL Injection
  219. [local] Vir.IT eXplorer Anti-Virus 8.5.39 - 'VIAGLT64.SYS' Privilege Escalation
  220. [webapps] Ingenious School Management System 2.3.0 - 'friend_index' SQL injection
  221. [dos] WhatsApp 2.17.52 - Memory Corruption
  222. [webapps] WordPress Plugin JTRT Responsive Tables 4.1 - SQL Injection
  223. [webapps] OctoberCMS 1.0.426 (Build 426) - Cross-Site Request Forgery
  224. [local] Easy MPEG/AVI/DIVX/WMV/RM to DVD - 'Enter User Name' Buffer Overflow (SEH)
  225. [dos] GraphicsMagick - Memory Disclosure / Heap Overflow
  226. [remote] tnftp - 'savefile' Arbitrary Command Execution (Metasploit)
  227. [webapps] Ladon Framework for Python 0.9.40 - XML External Entity Expansion
  228. [webapps] Oracle PeopleSoft Enterprise PeopleTools < 8.55 - Remote Code Execution Via
  229. [dos] Ipswitch WS_FTP Professional < 12.6.0.3 - Local Buffer Overflow (SEH)
  230. [webapps] WordPress Plugin Userpro < 4.9.17.1 - Authentication Bypass
  231. [remote] Actiontec C1000A Modem - Backdoor Account
  232. [dos] Debut Embedded httpd 1.20 - Denial of Service
  233. [dos] Avaya OfficeScan (IPO) < 10.1 - ActiveX Buffer Overflow
  234. [remote] Avaya OfficeScan (IPO) < 10.1 - 'SoftConsole' Buffer Overflow (SEH)
  235. [webapps] Logitech Media Server 7.9.0 - 'favorites' Cross-Site Scripting
  236. [webapps] Logitech Media Server 7.9.0 - 'Radio URL' Cross-Site Scripting
  237. [dos] SMPlayer 17.11.0 - '.m3u' Buffer Overflow (PoC)
  238. [papers] PoC || GTFO 0x16
  239. [local] Linux Kernel 4.13 (Ubuntu 17.10) - 'waitid()' SMEP/SMAP/Chrome Sandbox Privil
  240. [webapps] pfSense 2.3.1_1 - Command Execution
  241. [webapps] Oracle Java SE - Web Start jnlp XML External Entity Processing Information
  242. [remote] ZyXEL PK5001Z Modem - Backdoor Account
  243. [webapps] pfSense 2.3.1_1 - Command Execution
  244. [webapps] ManageEngine Applications Manager 13 - SQL Injection
  245. [local] Linux Kernel 4.13 - 'waitid()' SMEP/SMAP Privilege Escalation
  246. [papers] PoC || GTFO 0x16
  247. [dos] SMPlayer 17.11.0 - '.m3u' Buffer Overflow (PoC)
  248. [webapps] Logitech Media Server 7.9.0 - 'favorites' Cross-Site Scripting
  249. [webapps] Logitech Media Server 7.9.0 - 'Radio URL' Cross-Site Scripting
  250. [remote] Avaya OfficeScan (IPO) < 10.1 - 'SoftConsole' Buffer Overflow (SEH)