Exploits & CVE's

Exploits Database – Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, CVEs and more.

Trojan.Win32.Pluder.o Insecure Permissions

0
Authored by malvuln | Site malvuln.com Trojan.Win32.Pluder.o malware suffers from an insecure permissions vulnerability. Change Mirror Download Discovery / credits: Malvuln - malvuln.com (c) 2021Original source: https://malvuln.com/advisory/ee22eea131c0e00162e4ba370f396a00.txtContact: [email protected]: twitter.com/malvulnThreat: Trojan.Win32.Pluder.oVulnerability: Insecure Permissions...

eChat 1.0 SQL Injection

0
Authored by sML eChat version 1.0 suffers from a remote SQL injection vulnerability. Change Mirror Download # Exploit Title: eChat | Time-Based Blind SQL Injection# Exploit Author: [email protected]# Date: 2021-02-21# Vendor Homepage:...

Monica 2.19.1 Cross Site Scripting

0
Authored by BouSalman Monica version 2.19.1 suffers from a cross site scripting vulnerability. advisories | CVE-2021-27370 Change Mirror Download # Exploit Title: Monica 2.19.1 - 'last_name' Stored XSS# Date: 22-02-2021# Exploit Author: BouSalman#...

HFS (HTTP File Server) 2.3.x Remote Code Execution

0
Authored by Pergyz HFS (HTTP File Server) version 2.3.x remote code execution exploit. advisories | CVE-2014-6287 Change Mirror Download # Exploit Title: HFS (HTTP File Server) 2.3.x - Remote Command Execution (3)# Google...

Batflat CMS 1.3.6 Cross Site Scripting

0
Authored by Tadjmen Batflat CMS version 1.3.6 suffers from multiple persistent cross site scripting vulnerabilities. Change Mirror Download # Exploit Title: Batflat CMS 1.3.6 - 'multiple' Stored XSS# Date: 22/02/2021# Exploit Author:...

Apache Flink JAR Upload Java Code Execution

0
Authored by Brendan Coles, bigger.wing, Henry Chen | Site metasploit.com This Metasploit module uses job functionality in the Apache Flink dashboard web interface to upload and execute a JAR file,...

Online Exam System With Timer 1.0 SQL Injection

0
Authored by Suresh Kumar Online Exam System With Timer version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass. Change Mirror Download # Exploit Title: Online Exam System...

dataSIMS Avionics ARINC 664-1 4.5.3 Buffer Overflow

0
Authored by Kagan Capar dataSIMS Avionics ARINC 664-1 version 4.5.3 suffers from a local buffer overflow vulnerability. Change Mirror Download # Exploit Title: dataSIMS Avionics ARINC 664-1 - Local Buffer Overflow (PoC)#...

Firejail TOCTOU Race Condition

0
Authored by Roman Fiedler | Site unparalleled.eu This program demonstrates a time-of-check-time-of-use TOCTOU vulnerability in Firejail. Winning it causes Firejail to create an insecure overlayfs layout, that is then used...

Apache MyFaces 2.x Cross Site Request Forgery

0
Authored by Wolfgang Ettlinger Apache MyFaces versions 2.2.13 and below, 2.3.7 and below, 2.3-next-M4 and below, and 2.1 and below suffer from a cross site request forgery vulnerability. advisories | CVE-2021-26296 Change...