IPCop 2.1.9 Remote Code Execution
Authored by Mucahit Saratar
IPCop version 2.1.9 authenticated remote code execution exploit.
Change Mirror Download
# Exploit Title: IPCop 2.1.9 - Remote Code Execution (RCE) (Authenticated)# Date: 02/08/2021# Exploit Author: Mücahit Saratar#...
Facebook For Android Friend Acceptance
Authored by Sivanesh Ashok
Facebook for Android is vulnerable to a permission issue which allows anyone with physical access to the Android device, to accept friend requests without unlocking the...
WordPress Picture Gallery 1.4.2 Cross Site Scripting
Authored by Aryan Chehreghani
WordPress Picture Gallery plugin version 1.4.2 suffers from a persistent cross site scripting vulnerability.
Change Mirror Download
# Exploit Title: WordPress Plugin Picture Gallery 1.4.2 - 'Edit Content...
Simple Library Management System 1.0 SQL Injection
Authored by Halit Akaydin
Simple Library Management System version 1.0 suffers from a remote SQL injection vulnerability.
Change Mirror Download
# Exploit Title: Simple Library Management System 1.0 - 'rollno' SQL Injection#...
Backdoor.Win32.Zaratustra Remote File Write / Code Execution
Authored by malvuln | Site malvuln.com
Backdoor.Win32.Zaratustra malware suffers from an unauthenticated remote file write that can be leveraged to execute arbitrary code.
Change Mirror Download
Discovery / credits: Malvuln - malvuln.com...
OneNav Beta 0.9.12 Cross Site Scripting
Authored by nu11secur1ty
OneNav Beta version 0.9.12 suffers from a persistent cross site scripting vulnerability.
advisories | CVE-2021-38138
Change Mirror Download
# Exploit Title: XSS-Stored - Brutal PWNED on OneNav beta 0.9.12 add_link...
Microsoft Windows Malicious Software Removal Tool Privilege Escalation
Authored by James Forshaw, Google Security Research
Microsoft Windows suffers from unsafe temporary directory use with the Malicious Software Removal Tool that can lead to elevation of privilege.
advisories | CVE-2007-0843,...
Cockpit CMS 0.11.1 NoSQL Injection
Authored by Brian Ombongi
Cockpit CMS version 0.11.1 username enumeration and password reset NoSQL injection exploit.
advisories | CVE-2020-35847, CVE-2020-35848
Change Mirror Download
# Exploit Title: Cockpit CMS 0.11.1 - 'Username Enumeration &...
Moodle 3.9 Remote Code Execution
Authored by lanz
Moodle version 3.9 authenticated remote code execution exploit.
Change Mirror Download
# Exploit Title: Moodle 3.9 - Remote Code Execution (RCE) (Authenticated)# Date: 12-05-2021# Exploit Author: lanz# Vendor Homepage:...
GFI Mail Archiver 15.1 Arbitrary File Upload
Authored by Paul Taylor, Amin Bohio
GFI Mail Archiver versions 15.1 and below Telerik UI component unauthenticated arbitrary file upload exploit.
Change Mirror Download
# Exploit Title: GFI Mail Archiver <= 15.1...





