Exploits & CVE's

Exploits Database – Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, CVEs and more.

Joomla SIGE 3.4.1-FREE / 3.5.3-PRO RFI / Cross Site Scripting

0
Authored by h4shur Joomla Simple Image Gallery Extended (SIGE) extension versions 3.4.1-FREE and 3.5.3-PRO suffer from cross site scripting and remote file inclusion vulnerabilities. Change Mirror Download # Title: SIGE - Simple...

Customer Support System 1.0 Cross Site Request Forgery

0
Authored by Ahmed Abbas Customer Support System version 1.0 suffers from a cross site request forgery vulnerability. Change Mirror Download # Exploit Title: Customer Support System 1.0 - Cross-Site Request Forgery...

Microsoft Windows Local Spooler Bypass

0
Authored by James Forshaw, Google Security Research Microsoft Windows suffers from a local spooler bypass vulnerability. advisories | CVE-2020-1337, CVE-2020-17001 Change Mirror Download Windows: Local Spooler CVE-2020-1337 BypassOne way of exploiting this on...

ShoreTel Conferencing 19.46.1802.0 Cross Site Scripting

0
Authored by Joe Helle ShoreTel Conferencing version 19.46.1802.0 suffers from a cross site scripting vulnerability. advisories | CVE-2020-28351 Change Mirror Download # Exploit Title: ShoreTel Conferencing 19.46.1802.0 - Reflected Cross-Site Scripting# Date: 11/8/2020#...

Anuko Time Tracker 1.19.23.5325 CSV Injection

0
Authored by Mufaddal Masalawala Anuko Time Tracker version 1.19.23.5325 suffers from a CSV formula injection vulnerability. advisories | CVE-2020-15255 Change Mirror Download # Exploit Title: Anuko Time Tracker 1.19.23.5325 - CSV/Formula Injection# Date:...

WordPress File Manager 6.8 Remote Code Execution

0
Authored by Imran E. Dawoodjee, Alex Souza | Site metasploit.com The WordPress File Manager (wp-file-manager) plugin versions 6.0 through 6.8 allows remote attackers to upload and execute arbitrary PHP code...

Deep Instinct Windows Agent 1.2.24.0 Unquoted Service Path

0
Authored by Paulina Giron Deep Instinct Windows Agent version 1.2.24.0 suffers from an unquoted service path vulnerability. Change Mirror Download # Exploit Title: Deep Instinct Windows Agent 1.2.24.0 - 'DeepNetworkService' Unquoted Service...

Privacy Drive 3.17.0 Unquoted Service Path

0
Authored by Mohammed Alshehri Privacy Drive version 3.17.0 suffers from an unquoted service path vulnerability. Change Mirror Download # Exploit Title: Privacy Drive v3.17.0 - 'pdsvc.exe' Unquoted Service Path# Date: 2020-8-20# Exploit...

Joplin 1.2.6 Cross Site Scripting

0
Authored by Philip Holbrook Joplin version 1.2.6 suffers from a cross site scripting vulnerability. Change Mirror Download # Exploit Title: Joplin 1.2.6 - 'link' Cross Site Scripting# Date: 2020-09-21# Exploit Author: Philip...

Chrome V8 Turbofan Type Confusion

0
Authored by saelo, Google Security Research Turbofan fails to deoptimize code after map deprecation, leading to a type confusion vulnerability. advisories | CVE-2020-16009 Change Mirror Download V8: Turbofan fails to deoptimize code after...