OpenPLC WebServer 3 Remote Code Execution
Authored by Fellipe Oliveira
OpenPLC WebServer version 3 authentication remote code execution exploit.
Change Mirror Download
# Exploit Title: OpenPLC WebServer v3 - Authenticated Remote Code Execution# Google Dork: N/A# Date: 25/04/2021#...
ScadaBR 1.0 / 1.1CE Linux Shell Upload
Authored by Fellipe Oliveira
ScadaBR versions 1.0 and 1.1CE authenticated shell upload exploit written for Linux targets.
advisories | CVE-2021-26828
Change Mirror Download
#!/usr/bin/python# Exploit Title: Authenticated Arbitrary File Upload (Remote Code Execution)#...
Microsoft Internet Explorer 8/11 Use-After-Free
Authored by deadlock
Microsoft Internet Explorer 8/11 and WPAD service Jscript.dll use-after-free exploit.
advisories | CVE-2020-0674
Change Mirror Download
# Exploit Title: Microsoft Internet Explorer 8/11 and WPAD service 'Jscript.dll' - Use-After-Free# Date:...
ScadaBR 1.0 / 1.1CE Windows Shell Upload
Authored by Fellipe Oliveira
ScadaBR versions 1.0 and 1.1CE authenticated shell upload exploit written for Windows targets.
advisories | CVE-2021-26828
Change Mirror Download
#!/usr/bin/python# Exploit Title: Authenticated Arbitrary File Upload (Remote Code Execution)#...
Firefox 72 IonMonkey JIT Type Confusion
Authored by deadlock
Firefox 72 IonMonkey JIT type confusion exploit.
advisories | CVE-2019-17026
Change Mirror Download
# Exploit Title: Firefox 72 IonMonkey - JIT Type Confusion# Date: 2021-05-10# Exploit Author: deadlock (Forrest Orr)#...
Chamilo LMS 1.11.14 Remote Code Execution
Authored by M. Cory Billington
Chamilo LMS version 1.11.14 authenticated remote code execution exploit.
advisories | CVE-2021-31933
Change Mirror Download
# Exploit Title: Chamilo LMS 1.11.14 - Remote Code Execution (Authenticated)# Date: 13/05/2021#...
Podcast Generator 3.1 Cross Site Scripting
Authored by Aysenur Karaaslan
Podcast Generator version 3.1 suffers from a persistent cross site scripting vulnerability.
Change Mirror Download
# Exploit Title: Podcast Generator 3.1 - 'Long Description' Persistent Cross-Site Scripting (XSS)#...
Student Management System 1.0 Cross Site Scripting
Authored by Mohsen Khashei
Student Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
Change Mirror Download
# Exploit Title: Student Management System 1.0 - 'message' Persistent Cross-Site Scripting...
Chrome Array Transfer Bypass
Authored by Google Security Research, Glazvunov
The fix for CVE-2021-21148 has added a check in |ValueSerializer::WriteJSArrayBuffer| to make sure non-detachable array buffers cannot be transferred. The check can be bypassed...
ExifTool DjVu ANT Perl Injection
Authored by Justin Steven, William Bowling | Site metasploit.com
This Metasploit module exploits a Perl injection vulnerability in the DjVu ANT parsing code of ExifTool versions 7.44 through 12.23 inclusive....





