المساعد الشخصي الرقمي

مشاهدة النسخة كاملة : exploit database


الصفحات : 1 2 3 [4] 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67

  1. [webapps] Car Rental Management System 1.0 - 'id' SQL Injection (Authenticated)
  2. [local] Logitech Solar Keyboard Service - 'L4301_Solar' Unquoted Service Path
  3. [local] Advanced System Care Service 13 - 'AdvancedSystemCareService13' Unquoted Serv
  4. [webapps] Water Billing System 1.0 - 'id' SQL Injection (Authenticated)
  5. [webapps] Pandora FMS 7.0 NG 749 - 'CG Items' SQL Injection (Authenticated)
  6. [local] KiteService 1.2020.1113.1 - 'KiteService.exe' Unquoted Service Path
  7. [local] SAntivirus IC 10.0.21.61 - 'SAntivirusIC' Unquoted Service Path
  8. [local] IDT PC Audio 1.0.6425.0 - 'STacSV' Unquoted Service Path
  9. [webapps] OpenCart Theme Journal 3.1.0 - Sensitive Data Exposure
  10. [webapps] October CMS Build 465 - Arbitrary File Read Exploit (Authenticated)
  11. [local] DigitalPersona 5.1.0.656 'DpHostW' - Unquoted Service Path
  12. [webapps] Touchbase.io 1.10 - Stored Cross Site Scripting
  13. [webapps] Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit)
  14. [webapps] Citrix ADC NetScaler - Local File Inclusion (Metasploit)
  15. [webapps] Bludit 3.9.2 - Authentication Bruteforce Bypass (Metasploit)
  16. [webapps] ASUS TM-AC1900 - Arbitrary Command Execution (Metasploit)
  17. [local] Nidesoft 3GP Video Converter 2.6.18 - Local Stack Buffer Overflow
  18. [webapps] Wordpress Plugin Good LMS 2.1.4 - 'id' Unauthenticated SQL Injection
  19. [webapps] Water Billing System 1.0 - 'username' and 'password' parameters SQL Injecti
  20. [webapps] Customer Support System 1.0 - 'username' Authentication Bypass
  21. [webapps] CMSUno 1.6.2 - 'user' Remote Code Execution (Authenticated)
  22. [webapps] Customer Support System 1.0 - 'description' Stored XSS in The Admin Panel
  23. [webapps] Customer Support System 1.0 - Cross-Site Request Forgery
  24. [webapps] Anuko Time Tracker 1.19.23.5325 - CSV/Formula Injection
  25. [webapps] ShoreTel Conferencing 19.46.1802.0 - Reflected Cross-Site Scripting
  26. [webapps] Car Rental Management System 1.0 - SQL injection + Arbitrary File Upload
  27. [webapps] Joplin 1.2.6 - 'link' Cross Site Scripting
  28. [local] Privacy Drive v3.17.0 - 'pdsvc.exe' Unquoted Service Path
  29. [local] DiskBoss v11.7.28 - Multiple Services Unquoted Service Path
  30. [local] RealTimes Desktop Service 18.1.4 - 'rpdsvc.exe' Unquoted Service Path
  31. [local] Deep Instinct Windows Agent 1.2.24.0 - 'DeepNetworkService' Unquoted Service
  32. [local] Canon Inkjet Extended Survey Program 5.1.0.8 - 'IJPLMSVC.EXE' - Unquoted Ser
  33. [local] iDeskService 3.0.2.1 - 'iDeskService' Unquoted Service Path
  34. [local] Magic Mouse 2 utilities 2.20 - 'magicmouse2service' Unquoted Service Path
  35. [local] MEMU PLAY 3.7.0 - 'MEmusvc' Unquoted Service Path
  36. [local] Realtek Andrea RT Filters 1.0.64.10 - 'AERTSr64.EXE' Unquoted Service Path
  37. [local] Genexus Protection Server 9.6.4.2 - 'protsrvservice' Unquoted Service Path
  38. [local] DigitalPersona 4.5.0.2213 - 'DpHostW' Unquoted Service Path
  39. [local] Syncplify.me Server! 5.0.37 - 'SMWebRestServicev5' Unquoted Service Path
  40. [local] HP WMI Service 1.4.8.0 - 'HPWMISVC.exe' Unquoted Service Path
  41. [local] Motorola Device Manager 2.4.5 - 'ForwardDaemon.exe ' Unquoted Service Path
  42. [local] Motorola Device Manager 2.5.4 - 'MotoHelperService.exe' Unquoted Service Path
  43. [local] Motorola Device Manager 2.5.4 - 'ForwardDaemon.exe ' Unquoted Service Path
  44. [local] IPTInstaller 4.0.9 - 'PassThru Service' Unquoted Service Path
  45. [local] OKI sPSV Port Manager 1.0.41 - 'sPSVOpLclSrv' Unquoted Service Path
  46. [local] Winstep 18.06.0096 - 'Xtreme Service' Unquoted Service Path
  47. [webapps] SuiteCRM 7.11.15 - 'last_name' Remote Code Execution (Authenticated)
  48. [local] KMSpico 17.1.0.0 - 'Service KMSELDI' Unquoted Service Path
  49. [local] HP Display Assistant x64 Edition 3.20 - 'DTSRVC' Unquoted Service Path
  50. [webapps] Genexis Platinum-4410 P4410-V2-1.28 - Broken Access Control and CSRF
  51. [webapps] BlogEngine 3.3.8 - 'Content' Stored XSS
  52. [webapps] SmartBlog 2.0.1 - 'id_post' Blind SQL injection
  53. [webapps] CMSUno 1.6.2 - 'lang' Remote Code Execution (Authenticated)
  54. [webapps] Sentrifugo 3.2 - 'assets' Remote Code Execution (Authenticated)
  55. [webapps] Sentrifugo Version 3.2 - 'announcements' Remote Code Execution (Authenticat
  56. [remote] TP-Link WDR4300 - Remote Code Execution (Authenticated)
  57. [webapps] iDS6 DSSPro Digital Signage System 6.2 - CAPTCHA Security Bypass
  58. [webapps] iDS6 DSSPro Digital Signage System 6.2 - Improper Access Control Privilege
  59. [local] Amarok 2.8.0 - Denial-of-Service
  60. [webapps] iDS6 DSSPro Digital Signage System 6.2 - Cross-Site Request Forgery (CSRF)
  61. [webapps] PDW File Browser < v1.3 - Remote Code Execution
  62. [webapps] School Log Management System 1.0 - 'username' SQL Injection / Remote Code E
  63. [webapps] Student Attendance Management System 1.0 - 'username' SQL Injection / Remot
  64. [webapps] Processwire CMS 2.4.0 - 'download' Local File Inclusion
  65. [webapps] Multi Restaurant Table Reservation System 1.0 - 'table_id' Unauthenticated
  66. [webapps] Exploit Title: Complaints Report Management System 1.0 - 'username' SQL Inj
  67. [webapps] WordPress Plugin Simple File List 5.4 - Arbitrary File Upload
  68. [webapps] Monitorr 1.7.6m - Remote Code Execution (Unauthenticated)
  69. [webapps] Monitorr 1.7.6m - Authorization Bypass
  70. [local] Foxit Reader 9.7.1 - Remote Command Execution (Javascript API)
  71. [local] Quick N Easy FTP Service 3.2 - Unquoted Service Path
  72. [webapps] Apache Flink 1.9.x - File Upload RCE (Unauthenticated)
  73. [webapps] Simple College Website 1.0 - 'username' SQL Injection / Remote Code Executi
  74. [webapps] Online Job Portal 1.0 - 'userid' SQL Injection
  75. [webapps] Citadel WebCit < 926 - Session Hijacking Exploit
  76. [webapps] DedeCMS v.5.8 - "keyword" Cross-Site Scripting
  77. [webapps] CSE Bookstore 1.0 - 'quantity' Persistent Cross-site Scripting
  78. [webapps] Genexis Platinum-4410 P4410-V2-1.28 - Cross Site Request Forgery to Reboot
  79. [webapps] WebLogic Server 10.3.6.0.0 / 12.1.3.0.0 / 12.2.1.3.0 / 12.2.1.4.0 / 14.1.1.
  80. [webapps] Mailman 1.x > 2.1.23 - Cross Site Scripting (XSS)
  81. [webapps] Online Examination System 1.0 - 'name' Stored Cross Site Scripting
  82. [webapps] Oracle Business Intelligence Enterprise Edition 5.5.0.0.0 / 12.2.1.3.0 / 12
  83. [local] Program Access Controller v1.2.0.0 - 'PACService.exe' Unquoted Service Path
  84. [local] Prey 1.9.6 - "CronService" Unquoted Service Path
  85. [local] IP Watcher v3.0.0.30 - 'PACService.exe' Unquoted Service Path
  86. [local] Exploit - EPSON 1.124 - 'seksmdb.exe' Unquoted Service Path
  87. [local] PackageKit < 1.1.13 - File Existence Disclosure
  88. [local] aptdaemon < 1.1.1 - File Existence Disclosure
  89. [local] Blueman < 2.1.4 - Local Privilege Escalation
  90. [webapps] Nagios XI 5.7.3 - 'mibs.php' Remote Command Injection (Authenticated)
  91. [webapps] CSE Bookstore 1.0 - Authentication Bypass
  92. [remote] GoAhead Web Server 5.1.1 - Digest Authentication Capture Replay Nonce Reuse
  93. [webapps] Sentrifugo 3.2 - File Upload Restriction Bypass (Authenticated)
  94. [webapps] Client Management System 1.0 - 'searchdata' SQL injection
  95. [webapps] Sphider Search Engine 1.3.6 - 'word_upper_bound' RCE (Authenticated)
  96. [local] TDM Digital Signage PC Player 4.1 - Insecure File Permissions
  97. [remote] Adtec Digital Multiple Products - Default Hardcoded Credentials Remote Root
  98. [webapps] ReQuest Serious Play F3 Media Server 7.0.3 - Remote Denial of Service
  99. [webapps] ReQuest Serious Play F3 Media Server 7.0.3 - Remote Code Execution (Unauthe
  100. [webapps] ReQuest Serious Play F3 Media Server 7.0.3 - Debug Log Disclosure
  101. [webapps] ReQuest Serious Play Media Player 3.0 - Directory Traversal File Disclosure
  102. [webapps] InoERP 0.7.2 - Remote Code Execution (Unauthenticated)
  103. [webapps] PDW File Browser 1.3 - 'new_filename' Cross-Site Scripting (XSS)
  104. [webapps] Genexis Platinum-4410 - 'SSID' Persistent XSS
  105. [webapps] CMS Made Simple 2.1.6 - 'cntnt01detailtemplate' Server-Side Template Inject
  106. [webapps] Online Health Care System 1.0 - Multiple Cross Site Scripting (Stored)
  107. [webapps] Bludit 3.9.2 - Auth Bruteforce Bypass
  108. [webapps] TextPattern CMS 4.8.3 - Remote Code Execution (Authenticated)
  109. [webapps] Gym Management System 1.0 - Stored Cross Site Scripting
  110. [webapps] Gym Management System 1.0 - Authentication Bypass
  111. [webapps] School Faculty Scheduling System 1.0 - 'username' SQL Injection
  112. [webapps] School Faculty Scheduling System 1.0 - 'id' SQL Injection
  113. [webapps] Lot Reservation Management System 1.0 - Authentication Bypass
  114. [webapps] Lot Reservation Management System 1.0 - Cross-Site Scripting (Stored)
  115. [webapps] Gym Management System 1.0 - 'id' SQL Injection
  116. [webapps] Point of Sales 1.0 - 'username' SQL Injection
  117. [webapps] Point of Sales 1.0 - 'id' SQL Injection
  118. [webapps] Car Rental Management System 1.0 - Arbitrary File Upload
  119. [webapps] User Registration & Login and User Management System 2.1 - SQL Injection
  120. [webapps] Stock Management System 1.0 - 'brandId and categoriesId' SQL Injection
  121. [webapps] Ajenti 2.1.36 - Remote Code Execution (Authenticated)
  122. [webapps] Online Library Management System 1.0 - Arbitrary File Upload
  123. [webapps] Stock Management System 1.0 - 'Categories Name' Persistent Cross-Site Scrip
  124. [webapps] Stock Management System 1.0 - 'Brand Name' Persistent Cross-Site Scripting
  125. [webapps] Tiki Wiki CMS Groupware 21.1 - Authentication Bypass
  126. [webapps] GOautodial 4.0 - Authenticated Shell Upload
  127. [webapps] Stock Management System 1.0 - 'Product Name' Persistent Cross-Site Scriptin
  128. [webapps] Hrsale 2.0.0 - Local File Inclusion
  129. [webapps] School Faculty Scheduling System 1.0 - Stored Cross Site Scripting POC
  130. [webapps] School Faculty Scheduling System 1.0 - Authentication Bypass POC
  131. [webapps] Mobile Shop System v1.0 - SQL Injection Authentication Bypass
  132. [webapps] Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution
  133. [webapps] WordPress Plugin Rest Google Maps < 7.11.18 - SQL Injection
  134. [webapps] WordPress Plugin Colorbox Lightbox v1.1.1 - Persistent Cross-Site Scripting
  135. [webapps] WordPress Plugin HS Brand Logo Slider 2.1 - 'logoupload' File Upload
  136. [webapps] User Registration & Login and User Management System With admin panel 2.1 -
  137. [webapps] RiteCMS 2.2.1 - Remote Code Execution (Authenticated)
  138. [webapps] Ultimate Project Manager CRM PRO Version 2.0.5 - SQLi (Authenticated)
  139. [webapps] Wordpress Plugin WP Courses < 2.0.29 - Broken Access Controls leading to Co
  140. [webapps] Visitor Management System in PHP 1.0 - SQL Injection (Authenticated)
  141. [webapps] Comtrend AR-5387un router - Persistent XSS (Authenticated)
  142. [webapps] Loan Management System 1.0 - Multiple Cross Site Scripting (Stored)
  143. [webapps] Textpattern CMS 4.6.2 - Cross-site Request Forgery
  144. [webapps] Typesetter CMS 5.1 - Arbitrary Code Execution (Authenticated)
  145. [webapps] Hostel Management System 2.1 - Cross Site Scripting (Multiple Fields)
  146. [webapps] Jenkins 2.63 - Sandbox bypass in pipeline: Groovy plug-in
  147. [webapps] HiSilicon Video Encoders - Unauthenticated file disclosure via path travers
  148. [webapps] HiSilicon Video Encoders - RCE via unauthenticated command injection
  149. [webapps] HiSilicon Video Encoders - Full admin access via backdoor password
  150. [webapps] HiSilicon Video Encoders - Unauthenticated RTSP buffer overflow (DoS)
  151. [webapps] HiSilicon video encoders - RCE via unauthenticated upload of malicious firm
  152. [webapps] Online Job Portal 1.0 - Cross Site Scripting (Stored)
  153. [webapps] Online Discussion Forum Site 1.0 - XSS in Messaging System
  154. [webapps] Online Student's Management System 1.0 - Remote Code Execution (Authenticat
  155. [webapps] Nagios XI 5.7.3 - 'Contact Templates' Persistent Cross-Site Scripting
  156. [webapps] Nagios XI 5.7.3 - 'Manage Users' Authenticated SQL Injection
  157. [webapps] Nagios XI 5.7.3 - 'SNMP Trap Interface' Authenticated SQL Injection
  158. [webapps] Tourism Management System 1.0 - Arbitrary File Upload
  159. [webapps] Seat Reservation System 1.0 - Remote Code Execution (Unauthenticated)
  160. [webapps] Hotel Management System 1.0 - Remote Code Execution (Authenticated)
  161. [webapps] Seat Reservation System 1.0 - Unauthenticated SQL Injection
  162. [webapps] CS-Cart 1.3.3 - 'classes_dir' LFI
  163. [webapps] CS-Cart 1.3.3 - authenticated RCE
  164. [webapps] aaPanel 6.6.6 - Privilege Escalation & Remote Code Execution (Authenticated
  165. [webapps] Employee Management System 1.0 - Cross Site Scripting (Stored)
  166. [webapps] Employee Management System 1.0 - Authentication Bypass
  167. [webapps] Alumni Management System 1.0 - Authentication Bypass
  168. [webapps] Company Visitor Management System (CVMS) 1.0 - Authentication Bypass
  169. [webapps] Restaurant Reservation System 1.0 - 'date' SQL Injection (Authenticated)
  170. [webapps] Simple Grocery Store Sales And Inventory System 1.0 - Authentication Bypass
  171. [webapps] Zoo Management System 1.0 - Authentication Bypass
  172. [webapps] Vehicle Parking Management System 1.0 - Authentication Bypass
  173. [webapps] rConfig 3.9.5 - Remote Code Execution (Unauthenticated)
  174. [webapps] NodeBB Forum 1.12.2-1.14.2 - Account Takeover
  175. [local] Guild Wars 2 - Insecure Folder Permissions
  176. [webapps] TimeClock Software 1.01 0 - (Authenticated) Time-Based SQL Injection
  177. [webapps] berliCRM 1.0.24 - 'src_record' SQL Injection
  178. [local] Battle.Net 1.27.1.12428 - Insecure File Permissions
  179. [webapps] Online Students Management System 1.0 - 'username' SQL Injections
  180. [webapps] Liman 0.7 - Cross-Site Request Forgery (Change Password)
  181. [webapps] Cisco ASA and FTD 9.6.4.42 - Path Traversal
  182. [webapps] Small CRM 2.0 - 'email' SQL Injection
  183. [webapps] MedDream PACS Server 6.8.3.751 - Remote Code Execution (Unauthenticated)
  184. [webapps] DynPG 4.9.1 - Persistent Cross-Site Scripting (Authenticated)
  185. [webapps] openMAINT 1.1-2.4.2 - Arbitrary File Upload
  186. [webapps] Kentico CMS 9.0-12.0.49 - Persistent Cross Site Scripting
  187. [webapps] D-Link DSR-250N 3.12 - Denial of Service (PoC)
  188. [webapps] SEO Panel 4.6.0 - Remote Code Execution
  189. [dos] BACnet Test Server 1.01 - Remote Denial of Service (PoC)
  190. [webapps] Textpattern CMS 4.6.2 - 'body' Persistent Cross-Site Scripting
  191. [webapps] EasyPMS 1.0.0 - Authentication Bypass
  192. [webapps] Karel IP Phone IP1211 Web Management Panel - Directory Traversal
  193. [webapps] MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection
  194. [webapps] SpamTitan 7.07 - Unauthenticated Remote Code Execution
  195. [webapps] MedDream PACS Server 6.8.3.751 - Remote Code Execution (Authenticated)
  196. [webapps] Photo Share Website 1.0 - Persistent Cross-Site Scripting
  197. [webapps] BrightSign Digital Signage Diagnostic Web Server 8.2.26 - Server-Side Reque
  198. [webapps] BrightSign Digital Signage Diagnostic Web Server 8.2.26 - File Delete Path
  199. [webapps] SpinetiX Fusion Digital Signage 3.4.8 - Database Backup Disclosure
  200. [webapps] SpinetiX Fusion Digital Signage 3.4.8 - Cross-Site Request Forgery (Add Adm
  201. [webapps] SpinetiX Fusion Digital Signage 3.4.8 - Username Enumeration
  202. [webapps] MonoCMS Blog 1.0 - Arbitrary File Deletion (Authenticated)
  203. [webapps] WebsiteBaker 2.12.2 - 'display_name' SQL Injection (authenticated)
  204. [webapps] GetSimple CMS 3.3.16 - Persistent Cross-Site Scripting (Authenticated)
  205. [webapps] CMS Made Simple 2.2.14 - Persistent Cross-Site Scripting (Authenticated)
  206. [webapps] Typesetter CMS 5.1 - 'Site Title' Persistent Cross-Site Scripting
  207. [remote] Sony IPELA Network Camera 1.82.01 - 'ftpclient.cgi' Remote Stack Buffer Over
  208. [webapps] WebsiteBaker 2.12.2 - Remote Code Execution
  209. [local] BearShare Lite 5.2.5 - 'Advanced Search'Buffer Overflow in (PoC)
  210. [local] CloudMe 1.11.2 - Buffer Overflow ROP (DEP,ASLR)
  211. [webapps] Joplin 1.0.245 - Arbitrary Code Execution (PoC)
  212. [webapps] Mida eFramework 2.8.9 - Remote Code Execution
  213. [local] MSI Ambient Link Driver 1.0.0.8 - Local Privilege Escalation
  214. [webapps] BigTree CMS 4.4.10 - Remote Code Execution
  215. [webapps] Anchor CMS 0.12.7 - Persistent Cross-Site Scripting (Authenticated)
  216. [webapps] B-swiss 3 Digital Signage System 3.6.5 - Cross-Site Request Forgery (Add Ma
  217. [webapps] B-swiss 3 Digital Signage System 3.6.5 - Database Disclosure
  218. [webapps] Simple Online Food Ordering System 1.0 - 'id' SQL Injection (Unauthenticate
  219. [webapps] Visitor Management System in PHP 1.0 - Persistent Cross-Site Scripting
  220. [webapps] Online Food Ordering System 1.0 - Remote Code Execution
  221. [webapps] Flatpress Add Blog 1.0.3 - Persistent Cross-Site Scripting
  222. [webapps] Comodo Unified Threat Management Web Console 2.7.0 - Remote Code Execution
  223. [webapps] Mida eFramework 2.9.0 - Back Door Access
  224. [webapps] B-swiss 3 Digital Signage System 3.6.5 - Remote Code Execution
  225. [webapps] Online Shop Project 1.0 - 'p' SQL Injection
  226. [webapps] BlackCat CMS 1.3.6 - Cross-Site Request Forgery
  227. [local] ForensiTAppxService 2.2.0.4 - 'ForensiTAppxService.exe' Unquoted Service Path
  228. [webapps] Seat Reservation System 1.0 - 'id' SQL Injection
  229. [webapps] SpamTitan 7.07 - Remote Code Execution (Authenticated)
  230. [webapps] Mantis Bug Tracker 2.3.0 - Remote Code Execution (Unauthenticated)
  231. [remote] Microsoft SQL Server Reporting Services 2016 - Remote Code Execution
  232. [local] Windows TCPIP Finger Command - C2 Channel and Bypassing Security Software
  233. [webapps] Piwigo 2.10.1 - Cross Site Scripting
  234. [webapps] Tailor MS 1.0 - Reflected Cross-Site Scripting
  235. [webapps] ThinkAdmin 6 - Arbitrarily File Read
  236. [local] Rapid7 Nexpose Installer 6.6.39 - 'nexposeengine' Unquoted Service Path
  237. [webapps] RAD SecFlow-1v SF_0290_2.3.01.26 - Cross-Site Request Forgery (Reboot)
  238. [local] Pearson Vue VTS 2.3.1911 Installer - 'VUEApplicationWrapper' Unquoted Service
  239. [webapps] Joomla! paGO Commerce 2.5.9.0 - SQL Injection (Authenticated)
  240. [webapps] RAD SecFlow-1v SF_0290_2.3.01.26 - Persistent Cross-Site Scripting
  241. [local] Gnome Fonts Viewer 3.34.0 - Heap Corruption
  242. [webapps] VTENEXT 19 CE - Remote Code Execution
  243. [webapps] Tea LaTex 1.0 - Remote Code Execution (Unauthenticated)
  244. [local] Internet Explorer 11 - Use-After-Free
  245. [webapps] CuteNews 2.1.2 - Remote Code Execution
  246. [webapps] ZTE Router F602W - Captcha Bypass
  247. [webapps] Tiandy IPC and NVR 9.12.7 - Credential Disclosure
  248. [webapps] Scopia XT Desktop 8.3.915.4 - Cross-Site Request Forgery (change admin pass
  249. [local] Input Director 1.4.3 - 'Input Director' Unquoted Service Path
  250. [local] Audio Playback Recorder 3.2.2 - Local Buffer Overflow (SEH)