Trend Micro IWSVA CSRF / XSS / Bypass / SSRF / Code Execution
Authored by Wolfgang Ettlinger | Site sec-consult.com
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) versions below 6.5 SP2 EN Patch 4 Build 1919 suffers from bypass, command execution, cross...
Nxlog Community Edition 2.10.2150 Denial Of Service
Authored by Guillaume Petit
Nxlog Community Edition version 2.10.2150 denial of service proof of concept exploit.
Change Mirror Download
# Exploit Title: Nxlog Community Edition 2.10.2150 - DoS (Poc)# Date: 15/12/2020# Exploit...
Flexmonster Pivot Table And Charts 2.7.17 Cross Site Scripting
Authored by Marco Nappi
Flexmonster Pivot Table and Charts version 2.7.17 suffers from multiple cross site scripting vulnerabilities.
advisories | CVE-2020-20138, CVE-2020-20139, CVE-2020-20140, CVE-2020-20141, CVE-2020-20142
Change Mirror Download
# Exploit Title: CVE-2020-20140 :...
Oracle Solaris SunSSH PAM parse_user_name() Buffer Overflow
Authored by wvu, Hacker Fantastic, Jeffrey Martin, Aaron Carreras, Jacob Thompson | Site metasploit.com
This Metasploit module exploits a stack-based buffer overflow in the Solaris PAM library's username parsing code,...
Alumni Management System 1.0 Shell Upload
Authored by Valerio Alessandroni
Alumni Management System version 1.0 suffers from a remote shell upload vulnerability.
advisories | CVE-2020-28072
Change Mirror Download
# Exploit Title: Remote Code Execution on Alumni Management System #...
Solaris SunSSH 11.0 x86 libpam Remote Root
Authored by Hacker Fantastic
Solaris SunSSH versions 10 through 11.0 on x86 libpam remote root exploit.
advisories | CVE-2020-14871
Change Mirror Download
# Exploit Title: Solaris SunSSH 11.0 x86 - libpam Remote Root...
Qualcomm Adreno GPU PID Reuse Mapping Leak
Authored by Google Security Research, hawkes
Qualcomm Adreno GPU PID reuse can lead to a shared mapping leak vulnerability.
advisories | CVE-2020-11311
Microsoft Windows DrawIconEx Local Privilege Escalation
Authored by timwr, bee13oy, Yoav Alon, Netanel Ben-Simon | Site metasploit.com
This Metasploit module exploits CVE-2020-1054, an out of bounds write reachable from DrawIconEx within win32k. The out of bounds...
Grav CMS 1.6.30 Cross Site Scripting
Authored by Sagar Banwa
Grav CMS version 1.6.30 with Admin plugin version 1.9.18 suffers from a persistent cross site scripting vulnerability.
Change Mirror Download
# Exploit Title: Grav CMS 1.6.30 Admin Plugin...
Raysync 3.3.3.8 Remote Code Execution
Authored by XiaoLong Zhu
Raysync version 3.3.3.8 suffers form a remote code execution vulnerability.
Change Mirror Download
# Exploit Title: Raysync 3.3.3.8 - RCE# Date: 04/10/2020# Exploit Author: XiaoLong Zhu# Vendor Homepage:...





