Exploits & CVE's

Exploits Database – Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, CVEs and more.

Geutebruck instantrec Remote Command Execution

0
Authored by Titouan Lazard, Ibrahim Ayadhi | Site metasploit.com This Metasploit module exploits a buffer overflow within the 'action' parameter of the /uapi-cgi/instantrec.cgi page of Geutebruck G-Cam EEC-2xxx and G-Code...

Maxpatrol 8 / Xspider Denial Of Service

0
Authored by AsCiI Positive Technologies Maxpatrol 8 and Xspider appears to suffer from a denial of service vulnerability. Change Mirror Download # Exploit Title: Positive Technologies Maxpatrol 8 & Xspider Remote DoS...

WordPress 5.7 Media Library XML Injection

0
Authored by David Uton WordPress version 5.7 suffers from a Media Library XML external entity injection vulnerability. advisories | CVE-2021-29447 Change Mirror Download # Exploit Title: WordPress 5.7 - 'Media Library' XML External...

Church Management System 1.0 Shell Upload

0
Authored by Abdullah Khawaja Church Management System version 1.0 remote shell upload exploit. Change Mirror Download # Exploit Title: Church Management System (CMS-Website) - Unauthenticated RCE# Exploit Author: Abdullah Khawaja# Date: 2021-09-17#...

Budget And Expense Tracker System 1.0 SQL Injection

0
Authored by Prunier Charles-Yves Budget and Expense Tracker System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass. Change Mirror Download # Exploit Title: Budget and Expense...

Church Management System 1.0 SQL Injection

0
Authored by Erwin Krazek Church Management System version 1.0 suffers from a remote SQL injection vulnerability. Original discovery of SQL injection in this version is attributed to Murat Demirci in...

T-Soft E-Commerce 4 Cross Site Request Forgery

0
Authored by Alperen Ergel T-Soft E-Commerce version 4 suffers from a cross site request forgery vulnerability. Change Mirror Download # Exploit Title: T-Soft E-Commerce 4 - change 'admin credentials' Cross-Site Request Forgery...

Support Board 3.3.3 SQL Injection

0
Authored by John Jefferson Li Support Board version 3.3.3 suffers from a remote SQL injection vulnerability. Change Mirror Download # Exploit Title: Support Board 3.3.3 - 'Multiple' SQL Injection (Unauthenticated)# Date: 29.08.2021#...

elFinder Archive Command Injection

0
Authored by Shelby Pace, Thomas Chauchefoin | Site metasploit.com elFinder versions below 2.1.59 are vulnerable to a command injection vulnerability via its archive functionality. When creating a new zip archive,...

Impress CMS 1.4.2 Remote Code Execution

0
Authored by Halit Akaydin Impress CMS version 1.4.2 suffers from a remote code execution vulnerability. Change Mirror Download # Exploit Title: ImpressCMS 1.4.2 - Remote Code Execution (RCE) (Authenticated)# Date: 15-09-2021# Exploit...