المساعد الشخصي الرقمي

مشاهدة النسخة كاملة : exploit database


الصفحات : 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 [20] 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43

  1. [webapps] Emby MediaServer 3.2.5 - Directory Traversal
  2. [webapps] Easy File Uploader - Arbitrary File Upload
  3. [webapps] Simple File Uploader - Arbitrary File Download
  4. [dos] Microsoft Internet Explorer 11.576.14393.0 - 'CStyleSheetArray::BuildListOfMatc
  5. [remote] Mercurial - Custom hg-ssh Wrapper Remote Code Exec (Metasploit)
  6. [webapps] TYPO3 News Module - SQL Injection
  7. [webapps] Revive Ad Server 4.0.1 - Cross-Site Scripting / Cross-Site Request Forgery
  8. [papers] Local File Disclosure using SQL Injection
  9. [papers] HackBack - A DIY Guide (Spanish)
  10. [papers] HackBack - A DIY Guide for those without the patience to wait for whistleblo
  11. [papers] HackBack - A DIY Guide
  12. [webapps] October CMS 1.0.412 - Multiple Vulnerabilities
  13. [local] Realtek Audio Driver 6.0.1.7898 (Windows 10) - Dolby Audio X2 Service Privile
  14. [webapps] OpenText Documentum Content Server - dm_bp_transition.ebs docbase Method Ar
  15. [remote] Microsoft Windows 2003 SP2 - SMB Remote Code Execution (ERRATICGOPHER)
  16. [dos] Apple Safari - Array concat Memory Corruption
  17. [webapps] Joomla Component Myportfolio 3.0.2 - 'pid' Parameter SQL Injection
  18. [dos] Oracle VirtualBox Guest Additions 5.1.18 - Unprivileged Windows User-Mode Gues
  19. [remote] WePresent WiPG-1000 - Command Injection (Metasploit)
  20. [remote] Microsoft Office Word - Malicious Hta Execution (Metasploit)
  21. [webapps] HPE OpenCall Media Platform (OCMP) 4.3.2 - Cross-Site Scripting / Remote Fi
  22. [webapps] FlySpray 1.0-rc4 - Cross-Site Scripting / Cross-Site Request Forgery
  23. [webapps] WordPress Plugin Car Rental System 2.5 - SQL Injection
  24. [webapps] WordPress Plugin KittyCatfish 2.2 - SQL Injection
  25. [webapps] WordPress Plugin Wow Viral Signups 2.1 - SQL Injection
  26. [webapps] Oracle E-Business Suite 12.2.3 - 'IESFOOTPRINT' SQL Injection
  27. [webapps] WordPress Plugin Wow Forms 2.1 - SQL Injection
  28. [local] Ubuntu 16.10 / 16.04 LTS - LightDM Guest Account Local Privilege Escalation
  29. [papers] nt!_SEP_TOKEN_PRIVILEGES - Single Write EoP Protect
  30. [webapps] Oracle PeopleSoft - 'PeopleSoftServiceListeningConnector' XML External Enti
  31. [dos] - PrivateTunnel Client 2.8 - Local Buffer Overflow (SEH)
  32. [local] - Dell Customer Connect 1.3.28.0 - Privilege Escalation
  33. [papers] - Flexispy
  34. [remote] - SquirrelMail < 1.4.22 - Remote Code Execution
  35. [shellcode] - Linux/x86 - Egg-hunter Shellcode (18 bytes)
  36. [local] - VirtualBox 5.0.32 r112930 x64 - Windows Process COM Injection Privilege Esc
  37. [local] - VirtualBox 5.1.14 r112924 - Unprivileged Host User to Host Kernel Privilege
  38. [dos] - VirtualBox - Environment and ioctl Unprivileged Host User to Host Kernel Priv
  39. [dos] - VirtualBox - 'virtio-net' Guest-to-Host Out-of-Bounds Write
  40. [local] - VirtualBox - Guest-to-Host Privilege Escalation via Broken Length Handling
  41. [remote] - Microsoft Windows - ManagementObject Arbitrary .NET Serialization Remote C
  42. [local] - Microsoft Windows 10 - Runtime Broker ClipboardBroker Privilege Escalation
  43. [local] - Microsoft Windows 10 10586 - IEETWCollector Arbitrary Directory/File Deleti
  44. [webapps] - Apple WebKit / Safari 10.0.2(12602.3.12.0.1) - 'operationSpreadGeneric' U
  45. [webapps] - Apple WebKit / Safari 10.0.2(12602.3.12.0.1) - 'PrototypeMap::createEmpty
  46. [papers] - [Spanish] How to Exploit ETERNALBLUE and DOUBLEPULSAR on Windows 7/2008
  47. [papers] - How to Exploit ETERNALBLUE and DOUBLEPULSAR on Windows 7/2008
  48. [remote] - Huawei HG532n - Command Injection (Metasploit)
  49. [remote] - Microsoft Word - .RTF Remote Code Execution
  50. [dos] - pinfo 0.6.9 - Local Buffer Overflow
  51. [remote] - Tenable Appliance < 4.5 - Unauthenticated Remote Root Code Execution
  52. [dos] - Microsoft Windows - Uncredentialed SMB RCE (MS17-010) (Metasploit)
  53. [dos] - WinSCP 5.9.4 - 'LIST' Denial of Service (Metasploit)
  54. [webapps] - Mantis Bug Tracker 1.3.0/2.3.0 - Password Reset
  55. [papers] - Web Services Penetration Testing
  56. [local] - VirusChaser 8.0 - Buffer Overflow (SEH)
  57. [local] - Linux Kernel 4.8.0 UDEV < 232 - Privilege Escalation
  58. [webapps] - Concrete5 8.1.0 - 'Host' Header Injection
  59. [shellcode] - Linux/x86-64 - execve("/bin/sh") Shellcode (31 bytes)
  60. [webapps] - Alienvault OSSIM/USM 5.3.4/5.3.5 - Remote Command Execution (Metasploit)
  61. [webapps] - agorum core Pro 7.8.1.4-251 - Persistent Cross-Site Scripting
  62. [webapps] - agorum core Pro 7.8.1.4-251 - Cross-Site Request Forgery
  63. [dos] - Microsoft Windows Kernel win32k.sys - Multiple Bugs in the NtGdiGetDIBitsInte
  64. [dos] - Microsoft Windows Kernel - 'win32kfull!SfnINLPUAHDRAWMENUITEM' Stack Memory D
  65. [local] - Adobe Creative Cloud Desktop Application
  66. [remote] - Cisco Catalyst 2960 IOS 12.2(55)SE1 - 'ROCEM' Remote Code Execution
  67. [local] - GNS3 Mac OS-X 1.5.2 - 'ubridge' Privilege Escalation
  68. [local] - Solaris 7 - 11 (x86 & SPARC) - 'EXTREMEPARR' dtappgather Privilege Escalati
  69. [remote] - Cisco Catalyst 2960 IOS 12.2(55)SE11 - 'ROCEM' Remote Code Execution
  70. [webapps] - MyClassifiedScript 5.1 - SQL Injection
  71. [webapps] - Social Directory Script 2.0 - SQL Injection
  72. [webapps] - FAQ Script 3.1.3 - 'category_id' Parameter SQL Injection
  73. [webapps] - WordPress Plugin Spider Event Calendar 1.5.51 - Blind SQL Injection
  74. [webapps] - MyBB smilie Module < 1.8.11 - 'pathfolder' Directory Traversal
  75. [webapps] - MyBB < 1.8.11 - 'email' MyCode Cross-Site Scripting
  76. [webapps] - Brother MFC-J6520DW - Authentication Bypass / Password Change
  77. [webapps] - Horde Groupware Webmail 3 / 4 / 5 - Multiple Remote Code Execution
  78. [local] - Proxifier for Mac 2.18 - Multiple Vulnerabilities
  79. [local] - Proxifier for Mac 2.17 / 2.18 - Privesc Escalation
  80. [remote] - Moxa MX AOPC-Server 1.5 - XML External Entity Injection
  81. [dos] - Moxa MXview 2.8 - Denial of Service
  82. [remote] - Moxa MXview 2.8 - Private Key Disclosure
  83. [webapps] - Jobscript4Web 4.5 - Authentication Bypass
  84. [webapps] - Ladder System 6.0 - 'faqid' Parameter SQL Injection
  85. [webapps] - My Gaming Ladder Combo System 7.5 - SQL Injection
  86. [webapps] - Intellinet NFC-30IR Camera - Multiple Vulnerabilities
  87. [webapps] - Survey Template 1.1 - 'masterkey1' Parameter SQL Injection
  88. [webapps] - Forum Template 1.0 - SQL Injection
  89. [webapps] - Quiz Template 1.0 - 'testid' Parameter SQL Injection
  90. [webapps] - Calendar Template 2.0 - 'editid1' Parameter SQL Injection
  91. [webapps] - Document Management Template - 'hash' Parameter SQL Injection
  92. [webapps] - Shopping Cart Template - 'item' Parameter SQL Injection
  93. [webapps] - Invoice Template - 'hash' Parameter SQL Injection
  94. [shellcode] - Windows 10 x64 - Egghunter Shellcode (45 bytes)
  95. [dos] - Cesanta Mongoose OS - Use-After-Free
  96. [webapps] - Moodle 2.x/3.x - SQL Injection
  97. [remote] - SpiceWorks 7.5 TFTP - Remote File Overwrite / Upload
  98. [webapps] - HelpDEZK 1.1.1 - Cross-Site Request Forgery / Code Execution
  99. [webapps] - Airbnb Crashpadder Clone Script - SQL Injection
  100. [webapps] - ImagePro Lazygirls Clone Script - SQL Injection
  101. [webapps] - Appointment Script - SQL Injection
  102. [webapps] - D-Link DIR-615 - Cross-Site Request Forgery
  103. [webapps] - Sweepstakes Pro Software - SQL Injection
  104. [webapps] - Premium Penny Auction Script - SQL Injection
  105. [webapps] - Apple WebKit 10.0.2(12602.3.12.0.1, r210800) - 'constructJSReadableStream
  106. [local] - macOS/iOS Kernel 10.12.3 (16D32) - Double-Free Due to Bad Locking in fseven
  107. [webapps] - Apple WebKit 10.0.2(12602.3.12.0.1) - 'disconnectSubframes' Universal Cro
  108. [webapps] - Apple Webkit - Universal Cross-Site Scripting by Accessing a Named Proper
  109. [dos] - macOS Kernel 10.12.2 (16C67) - Memory Disclosure Due to Lack of Bounds Checki
  110. [webapps] - Apple Webkit - 'JSCallbackData' Universal Cross-Site Scripting
  111. [dos] - macOS/iOS Kernel 10.12.3 (16D32) - 'bpf' Heap Overflow
  112. [webapps] - Apple WebKit 10.0.2(12602.3.12.0.1) - 'Frame::setDocument (1)' Universal
  113. [webapps] - Maian Survey 1.1 - 'survey' Parameter SQL Injection
  114. [dos] - macOS Kernel 10.12.2 (16C67) - 'AppleIntelCapriController::GetLinkConfig' Cod
  115. [dos] - macOS/iOS Kernel 10.12.3 (16D32) - Bad Locking in necp_open Use-After-Free
  116. [dos] - macOS Kernel 10.12.3 (16D32) - Use-After-Free Due to Double-Release in posix_
  117. [dos] - macOS/iOS Kernel 10.12.3 (16D32) - SIOCSIFORDER Socket ioctl Memory Corruptio
  118. [dos] - macOS/iOS Kernel 10.12.3 (16D32) - SIOCGIFORDER Socket ioctl Off-by-One Memor
  119. [webapps] - Maian Greetings 2.1 - 'cat' Parameter SQL Injection
  120. [webapps] - Maian Uploader 4.0 - 'user' Parameter SQL Injection
  121. [webapps] - Pixie 1.0.4 - Arbitrary File Upload
  122. [local] - Bluecoat ASG 6.6/CAS 1.3 - Privilege Escalation (Metasploit)
  123. [remote] - Bluecoat ASG 6.6/CAS 1.3 - OS Command Injection (Metasploit)
  124. [remote] - Apache Tomcat 6/7/8/9 - Information Disclosure
  125. [webapps] - Zyxel, EMG2926 < V1.00(AAQT.4)b8 - OS Command Injection
  126. [dos] - BackBox OS - Denial of Service
  127. [webapps] - Splunk Enterprise - Information Disclosure
  128. [webapps] - Membership Formula - 'order' Parameter SQL Injection
  129. [dos] - Apple macOS/IOS 10.12.2(16C67) - mach_msg Heap Overflow
  130. [webapps] - EyesOfNetwork (EON) 5.1 - SQL Injection
  131. [remote] - Sync Breeze Enterprise 9.5.16 - 'GET' Buffer Overflow (SEH)
  132. [local] - Disk Sorter Enterprise 9.5.12 - 'Import Command' Buffer Overflow
  133. [local] - DiskBoss Enterprise 7.8.16 - 'Import Command' Buffer Overflow
  134. [local] - Sync Breeze Enterprise 9.5.16 - 'Import Command' Buffer Overflow
  135. [shellcode] - Linux/x86 - execve(/bin/sh") Shellcode (19 bytes)
  136. [webapps] - Opensource Classified Ads Script - 'keyword' Parameter SQL Injection
  137. [dos] - MikroTik RouterBoard 6.38.5 - Denial of Service
  138. [dos] - Microsoft Outlook - HTML Email Denial of Service
  139. [local] - Intermec PM43 Industrial Printer - Privilege Escalation
  140. [dos] - VX Search Enterprise 9.5.12 - 'Verify Email' Buffer Overflow
  141. [shellcode] - Linux/x86-64 - execve("/bin/sh") Shellcode (21 Bytes)
  142. [remote] - DzSoft PHP Editor 4.2.7 - File Enumeration
  143. [remote] - Samba 4.5.2 - Symlink Race Permits Opening Files Outside Share Directory
  144. [dos] - Apple Safari - 'DateTimeFormat.format' Type Confusion
  145. [dos] - Apple Safari - Builtin JavaScript Allows Function.caller to be Used in Strict
  146. [dos] - Apple Safari - Out-of-Bounds Read when Calling Bound Function
  147. [remote] - Github Enterprise - Default Session Secret And Deserialization (Metasploit
  148. [local] - QNAP QTS < 4.2.4 - Domain Privilege Escalation
  149. [dos] - Disk Sorter Enterprise 9.5.12 - Local Buffer Overflow
  150. [remote] - Internet Information Services (IIS) 6.0 WebDAV - 'ScStoragePathFromUrl' Bu
  151. [webapps] - Professional Bus Booking Script - 'hid_Busid' Parameter SQL Injection
  152. [webapps] - CouponPHP CMS 3.1 - 'code' Parameter SQL Injection
  153. [webapps] - Just Another Video Script 1.4.3 - SQL Injection
  154. [webapps] - Alibaba Clone Script - SQL Injection
  155. [webapps] - B2B Marketplace Script 2.0 - SQL Injection
  156. [webapps] - Php Real Estate Property Script - SQL Injection
  157. [webapps] - Courier Tracking Software 6.0 - SQL Injection
  158. [webapps] - Parcel Delivery Booking Script 1.0 - SQL Injection
  159. [webapps] - Delux Same Day Delivery Script 1.0 - SQL Injection
  160. [webapps] - Hotel Booking Script 1.0 - SQL Injection
  161. [webapps] - Tour Package Booking 1.0 - SQL Injection
  162. [shellcode] - Linux/x86 - Reverse /bin/bash Shellcode (110 bytes)
  163. [local] - Forticlient 5.2.3 Windows 10 x64 (Pre Anniversary) - Privilege Escalation
  164. [local] - Forticlient 5.2.3 Windows 10 x64 (Post Anniversary) - Privilege Escalation
  165. [remote] - NETGEAR WNR2000v5 - (Un)authenticated hidden_lang_avi Stack Overflow (Meta
  166. [remote] - Logsign 4.4.2 / 4.4.137 - Remote Command Injection (Metasploit)
  167. [webapps] - Gr8 Tutorial Script - SQL Injection
  168. [webapps] - Gr8 Gallery Script - SQL Injection
  169. [remote] - Miele Professional PG 8528 - Directory Traversal
  170. [dos] - wifirxpower - Local Buffer Overflow
  171. [webapps] - Flippa Clone - SQL Injection
  172. [webapps] - Joomla! Component Modern Booking 1.0 - 'coupon' Parameter SQL Injection
  173. [webapps] - Solare Datensysteme Solar-Log Devices 2.8.4-56 / 3.5.2-85 - Multiple Vuln
  174. [remote] - SysGauge 1.5.18 - SMTP Validation Buffer Overflow (Metasploit)
  175. [dos] - SpyCamLizard 1.230 - Denial of Service
  176. [webapps] - GLink Word Link Script 1.2.3 - SQL Injection
  177. [remote] - Disk Sorter Enterprise 9.5.12 - 'GET' Buffer Overflow (SEH)
  178. [papers] - PoC || GTFO 0x14
  179. [webapps] - Joomla! Component Extra Search 2.2.8 - 'establename' Parameter SQL Inject
  180. [dos] - Google Nest Cam 5.2.1? - Buffer Overflow Conditions Over Bluetooth LE
  181. [webapps] - phplist 3.2.6 - SQL Injection
  182. [dos] - Microsoft Windows Kernel - Registry Hive Loading Crashes in nt!nt!HvpGetBinMe
  183. [dos] - Microsoft Windows - Uniscribe Font Processing Out-of-Bounds Read in usp10!otl
  184. [dos] - Microsoft Windows - 'USP10!otlList::insertAt' Uniscribe Font Processing Heap-
  185. [dos] - Microsoft Windows - Uniscribe Font Processing Heap-Based Out-of-Bounds Read/W
  186. [webapps] - Joomla! Component JooCart 2.x - 'product_id' Parameter SQL Injection
  187. [webapps] - Joomla! Component jCart for OpenCart 2.0 - 'product_id' Parameter SQL Inj
  188. [dos] - ExtraPuTTY 0.29-RC2 - Denial of Service
  189. [papers] - Art of Anti Detection - Shellcode Alchemy
  190. [dos] - FTPShell Server 6.56 - 'ChangePassword' Buffer Overflow
  191. [remote] - HttpServer 1.0 - Directory Traversal
  192. [shellcode] - Linux/x86 - File Reader Shellcode (54 Bytes)
  193. [webapps] - Secure Download Links - 'dc' Parameter SQL Injection
  194. [webapps] - iFdate Social Dating Script 2.0 - SQL Injection
  195. [webapps] - DIGISOL DG-HR1400 1.00.02 Wireless Router - Privilege Escalation
  196. [webapps] - Omegle Clone - SQL Injection
  197. [dos] - FTPShell Client 6.53 - Local Buffer Overflow
  198. [shellcode] - Linux/x86 - Encoded exceve("/bin/sh") Shellcode (44 Bytes)
  199. [shellcode] - Linux/x86 - Super Small Bind Shell Shellcode (51 bytes)
  200. [webapps] - Departmental Store Management System 1.2 - SQL Injection
  201. [dos] - Cerberus FTP Server 8.0.10.3 - 'MLST' Buffer Overflow
  202. [webapps] - Wordpress Plugin Membership Simplified 1.58 - Arbitrary File Download
  203. [webapps] - AXIS Communications - Cross-Site Scripting / Content Injection
  204. [webapps] - AXIS Multiple Products - Cross-Site Request Forgery
  205. [papers] - Attacking RDP - How to Eavesdrop on Poorly Secured RDP Connections
  206. [dos] - Microsoft Edge 38.14393.0.0 - JavaScript Engine Use-After-Free
  207. [local] - Windows DVD Maker 6.1.7 - XML External Entity Injection
  208. [webapps] - GitHub Enterprise 2.8.0 < 2.8.6 - Remote Code Execution
  209. [local] - Microsoft Windows - COM Session Moniker Privilege Escalation (MS17-012)
  210. [dos] - Adobe Flash - Metadata Parsing Out-of-Bounds Read
  211. [dos] - Adobe Flash - MovieClip Attach init Object Use-After-Free
  212. [dos] - Adobe Flash - ATF Thumbnailing Heap Overflow
  213. [dos] - Adobe Flash - ATF Planar Decompression Heap Overflow
  214. [dos] - Adobe Flash - AVC Header Slicing Heap Overflow
  215. [local] - Rawether for Windows - Privilege Escalation
  216. [local] - ASUS PCE-AC56 WLAN Card Utilities (PCAUSA Rawether Windows 10 x64) - Local
  217. [webapps] - Joomla! Component Vik Appointments 1.5 - SQL Injection
  218. [webapps] - Joomla! Component Vik Rent Items 1.3 - SQL Injection
  219. [webapps] - Joomla! Component Vik Rent Car 1.11 - SQL Injection
  220. [webapps] - Joomla! Component Simple Membership 3.3.3 - 'userId' Parameter SQL Inject
  221. [webapps] - Joomla! Component Advertisement Board 3.0.4 - 'id' Parameter SQL Injectio
  222. [local] - VirtualBox - Cooperating VMs can Escape from Shared Folder
  223. [remote] - Netgear R7000 and R6400 - cgi-bin Command Injection (Metasploit)
  224. [dos] - Cerberus FTP Server 8.0.10.1 - Denial of Service
  225. [webapps] - Car Workshop System - SQL Injection
  226. [shellcode] - Windows x86 - Hide Console Window Shellcode (182 bytes)
  227. [webapps] - Domain Marketplace Script - SQL Injection
  228. [webapps] - Global In - SQL Injection
  229. [webapps] - Global In - Arbitrary File Upload
  230. [webapps] - Vanelo - SQL Injection
  231. [webapps] - Mirage - SQL Injection
  232. [webapps] - Pet Listing Script 3.0 - SQL Injection
  233. [webapps] - Property Listing Script 3.1 - SQL Injection
  234. [webapps] - Travel Tours Script 2.0 - SQL Injection
  235. [webapps] - Yacht Listing Script 2.0 - SQL Injection
  236. [webapps] - WatchGuard XTMv 11.12 Build 516911 - User Management Cross-Site Request F
  237. [webapps] - dnaLIMS DNA Sequencing - Directory Traversal / Session Hijacking / Cross-
  238. [webapps] - Kinsey Infor/Lawson / ESBUS - SQL Injection
  239. [webapps] - Price Comparison Script 2017.1.8 - SQL Injection
  240. [webapps] - Clickbank Affiliate Marketplace Script 2017 - SQL Injection
  241. [webapps] - FTP Voyager Scheduler 16.2.0 - Cross-Site Request Forgery
  242. [webapps] - Country on Sale Script - SQL Injection
  243. [webapps] - Media Search Engine Script - 'search' Parameter SQL Injection
  244. [webapps] - Soundify 1.1 - 'tid' Parameter SQL Injection
  245. [webapps] - BistroStays 3.0 - 'guests' Parameter SQL Injection
  246. [webapps] - Nlance 2.2 - SQL Injection
  247. [webapps] - Busewe 1.2 - SQL Injection
  248. [webapps] - Fashmark 1.2 - 'category' Parameter SQL Injection
  249. [webapps] - TradeMart 1.1 - SQL Injection
  250. [webapps] - Drupal 7.x Module Services - Remote Code Execution