May 11, 2022Cyclos 4.14.7 Cross Site Scripting

Cyclos version 4.14.7 suffers from multiple cross site scripting vulnerabilities.

May 11, 2022ExifTool 12.23 Arbitrary Code Execution

ExifTool version 12.23 suffers from an arbitrary code execution vulnerability.

May 11, 2022Wondershare Dr.Fone 12.0.7 Privilege Escalation

Wondershare Dr.Fone version 12.0.7 suffers from a remote privilege escalation vulnerability related to ElevationService.

May 11, 2022Apache CouchDB 3.2.1 Remote Code Execution

Apache CouchDB version 3.2.1 suffers from a remote code execution vulnerability.

May 11, 2022e107 CMS 3.2.1 Arbitrary File Upload / Cross Site Scripting

e107 CMS version 3.2.1 suffers from cross site scripting and arbitrary file upload vulnerabilities that can allow for a shell upload.

May 10, 2022Spring4Shell Spring Framework Class Property Remote Code Execution

Spring Framework versions 5.3.0 to 5.3.17, 5.2.0 to 5.2.19, and older versions when running on JDK 9 or above and specifically packaged as a traditional WAR and deployed in a standalone Tomcat instance are vulnerable to remote code execution due to an uns

May 9, 2022F5 BIG-IP Remote Code Execution

F5 BIG-IP remote code execution proof of concept exploit that leverages the vulnerability identified in CVE-2022-1388.

May 9, 2022APT28 FancyBear Code Execution

FancyBear looks for and executes DLLs in its current directory. Therefore, we can potentially hijack a DLL to execute our own code and control and terminate the malware. The exploit DLL will check if the current directory is "C:\Windows\System32" and if n

May 9, 2022School Dormitory Management System 1.0 SQL Injection

School Dormitory Management System version 1.0 suffers from a remote SQL injection vulnerability.

May 9, 2022Ransom.Satana Code Execution

Satana ransomware searches for and loads a DLL named "wow64log.dll" in Windows\System32. Therefore, we can drop our own DLL to intercept and terminate the malware pre-encryption. The exploit DLL will simply display a Win32API message box and call exit().

Archives
Categories
  • All Exploits 4095
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow