Exploits & CVE's

Exploits Database – Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, CVEs and more.

Electrolink FM/DAB/TV Transmitter (controlloLogin.js) Credential Disclosure

0
Authored by LiquidWorm | Site zeroscience.mk Electrolink FM/DAB/TV Transmitter suffers from a disclosure of clear-text credentials in controlloLogin.js that can allow security bypass and system access. Change Mirror Download Electrolink FM/DAB/TV Transmitter...

Electrolink FM/DAB/TV Transmitter (Login Cookie) Authentication Bypass

0
Authored by LiquidWorm | Site zeroscience.mk Electrolink FM/DAB/TV Transmitter suffers from an authentication bypass vulnerability affecting the Login Cookie. An attacker can set an arbitrary value except NO to the...

Electrolink FM/DAB/TV Transmitter Remote Authentication Removal

0
Authored by LiquidWorm | Site zeroscience.mk Electrolink FM/DAB/TV Transmitter suffers from an unauthenticated parameter manipulation that allows an attacker to set the credentials to blank giving her access to the...

TOTOLINK Wireless Routers Remote Command Execution

0
Authored by h00die-gr3y, Kazamayc | Site metasploit.com Multiple TOTOLINK network products contain a command injection vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the command...

Taskhub 2.8.8 Cross Site Scripting

0
Authored by nu11secur1ty Taskhub version 2.8.8 suffers from a cross site scripting vulnerability. Change Mirror Download ## Title: TASKHUB-2.8.8-XSS-Reflected## Author: nu11secur1ty## Date: 09/22/2023## Vendor: https://codecanyon.net/user/infinitietech## Software: https://codecanyon.net/item/taskhub-project-management-finance-crm-tool/25685874## Reference: https://portswigger.net/web-security/cross-site-scripting## Description:The value of...

Elasticsearch 8.5.3 Stack Overflow

0
Authored by Touhami Kasbaoui Elasticsearch version 8.5.3 stack overflow proof of concept exploit. advisories | CVE-2023-31419 Change Mirror Download # Exploit Author: TOUHAMI KASBAOUI# Vendor Homepage: https://elastic.co/# Version: 8.5.3 / OpenSearch# Tested on:...

Lamano LMS 0.1 Insecure Settings

0
Authored by indoushka Lamano LMS version 0.1 suffers from an ignored default credential vulnerability. Change Mirror Download ====================================================================================================================================| # Title : Lamano LMS v0.1 Insecure Settings Vulnerability ...

LogoBee CMS 0.2 Cross Site Scripting

0
Authored by indoushka LogoBee CMS version 0.2 suffers from a cross site scripting vulnerability. Change Mirror Download ====================================================================================================================================| # Title : LogoBee CMS v0.2 XSS Vulnerability ...

OPNsense 23.1.11_1 / 23.7.3 / 23.7.4 Cross Site Scripting / Privilege Escalation

0
Authored by Yasar Klawohn, JM | Site x41-dsec.de OPNsense versions 23.1.11_1, 23.7.3, and 23.7.4 suffer from cross site scripting vulnerabilities that can allow for privilege escalation. Change Mirror Download Advisory X41-2023-001: Two...

RoyalTSX 6.0.1 RTSZ File Handling Heap Memory Corruption

0
Authored by LiquidWorm | Site zeroscience.mk RoyalTSX version 6.0.1 suffers from an RTSZ file handling heap memory corruption vulnerability. The application receives SIGABRT after the RAPortCheck.createNWConnection() function is handling the...