Результаты поиска

  1. Exploiter

    Exploit Google Android - 'cfp_ropp_new_key_reenc' / 'cfp_ropp_new_key' RKP Memory Corruption

    Google Android - 'cfp_ropp_new_key_reenc' / 'cfp_ropp_new_key' RKP Memory Corruption Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=979 As part of Samsung KNOX, Samsung phones include a security hypervisor called RKP (Real-time Kernel Protection), running in EL2. This...
  2. Exploiter

    Exploit Dokany 1.2.0.1000 - Stack-Based Buffer Overflow Privilege Escalation

    Dokany 1.2.0.1000 - Stack-Based Buffer Overflow Privilege Escalation /* Exploit Title - Dokany Stack-based Buffer Overflow Privilege Escalation Date - 14th January 2019 Discovered by - Parvez Anwar (@parvezghh) Vendor Homepage - http://dokan-dev.github.io Tested Version -...
  3. Exploiter

    Exploit Netgear Routers - Password Disclosure

    Netgear Routers - Password Disclosure Trustwave SpiderLabs Security Advisory TWSL2017-003: Multiple Vulnerabilities in NETGEAR Routers Published: 01/30/2017 Version: 1.0 Vendor: NETGEAR (http://www.netgear.com/) Product: Multiple products Finding 1: Remote and Local Password Disclosure...
  4. Exploiter

    Exploit Real Estate Custom Script 2.0 - SQL Injection

    Real Estate Custom Script 2.0 - SQL Injection # Exploit Title: Real Estate Custom Script 2.0 - SQL Injection # Dork: N/A # Date: 2019-01-14 # Exploit Author: Ihsan Sencan # Vendor Homepage: http://ocsolutions.co.in/ # Software Link...
  5. Exploiter

    Exploit Job Portal Platform 1.0 - SQL Injection

    Job Portal Platform 1.0 - SQL Injection # Exploit Title: Job Portal 1.0 - SQL Injection # Dork: N/A # Date: 2019-01-14 # Exploit Author: Ihsan Sencan # Vendor Homepage: http://ocsolutions.co.in/ # Software Link...
  6. Exploiter

    Exploit HelpDeskZ < 1.0.2 - (Authenticated) SQL Injection / Unauthorized File Download

    HelpDeskZ < 1.0.2 - (Authenticated) SQL Injection / Unauthorized File Download ''' # Exploit Title: HelpDeskZ <= v1.0.2 - Authenticated SQL Injection / Unauthorized file download # Google Dork: intext:"Help Desk Software by HelpDeskZ", inurl:?v=submit_ticket # Date: 2017-01-30 # Exploit...
  7. Exploiter

    Exploit Find a Place CMS Directory 1.5 - SQL Injection

    Find a Place CMS Directory 1.5 - SQL Injection # Exploit Title: Locations CMS 1.5 - SQL Injection # Dork: N/A # Date: 2019-01-13 # Exploit Author: Ihsan Sencan # Vendor Homepage: https://themerig.com/ # Software Link...
  8. Exploiter

    Exploit HealthNode Hospital Management System 1.0 - SQL Injection

    HealthNode Hospital Management System 1.0 - SQL Injection # Exploit Title: HealthNode Hospital Management System 1.0 - SQL Injection # Dork: N/A # Date: 2019-01-13 # Exploit Author: Ihsan Sencan # Vendor Homepage: http://sunriseservices.biz/ # Software Link...
  9. Exploiter

    Exploit Modern POS 1.3 - Arbitrary File Download

    Modern POS 1.3 - Arbitrary File Download # Exploit Title: Modern POS 1.3 - Arbitrary File Download # Dork: N/A # Date: 2019-01-13 # Exploit Author: Ihsan Sencan # Vendor Homepage: http://itsolution24.com/ # Software Link...
  10. Exploiter

    Exploit Modern POS 1.3 - SQL Injection

    Modern POS 1.3 - SQL Injection # Exploit Title: Modern POS 1.3 - SQL Injection # Dork: N/A # Date: 2019-01-13 # Exploit Author: Ihsan Sencan # Vendor Homepage: http://itsolution24.com/ # Software Link: https://codecanyon.net/item/modern-pos-point-of-sale-with-stock-management-system/22702683 #...
  11. Exploiter

    Exploit Live Call Support Widget 1.5 - Remote Code Execution / SQL Injection

    Live Call Support Widget 1.5 - Remote Code Execution / SQL Injection # Exploit Title: Live Call Support 1.5 - Remote Code Execution / SQL Injection # Dork: N/A # Date: 2019-01-13 # Exploit Author: Ihsan Sencan # Vendor Homepage: http://ranksol.com/ # Software Link...
  12. Exploiter

    Exploit Craigs Classified Ads CMS Theme 1.0.2 - SQL Injection

    Craigs Classified Ads CMS Theme 1.0.2 - SQL Injection # Exploit Title: Craigs CMS 1.0.2 - SQL Injection # Dork: N/A # Date: 2019-01-13 # Exploit Author: Ihsan Sencan # Vendor Homepage: https://themerig.com/ # Software Link...
  13. Exploiter

    Exploit Palo Alto Networks Terminal Services Agent 7.0.3-13 - Integer Overflow

    Palo Alto Networks Terminal Services Agent 7.0.3-13 - Integer Overflow /* Exploit Title - Palo Alto Networks Terminal Services Agent Integer Overflow Date - 26th January 2017 Discovered by - Parvez Anwar (@parvezghh) Vendor Homepage - https://www.paloaltonetworks.com/...
  14. Exploiter

    Exploit Joomla! Component JoomProject 1.1.3.2 - Information Disclosure

    Joomla! Component JoomProject 1.1.3.2 - Information Disclosure # Exploit Title: Joomla! Component JoomProject 1.1.3.2 - Information Disclosure # Dork: N/A # Date: 2019-01-11 # Exploit Author: Ihsan Sencan # Vendor Homepage: http://joomboost.com/ # Software Link...
  15. Exploiter

    Exploit Joomla! Component JoomCRM 1.1.1 - SQL Injection

    Joomla! Component JoomCRM 1.1.1 - SQL Injection # Exploit Title: Joomla! Component JoomCRM 1.1.1 - SQL Injection # Dork: N/A # Date: 2019-01-11 # Exploit Author: Ihsan Sencan # Vendor Homepage: http://joomboost.com/ # Software Link...
  16. Exploiter

    Exploit Matrix MLM Script 1.0 - Information Disclosure

    Matrix MLM Script 1.0 - Information Disclosure # Exploit Title: Matrix MLM Script 1.0 - Information Leakage # Dork: N/A # Date: 2019-01-10 # Exploit Author: Ihsan Sencan # Vendor Homepage: https://royallifefoundation.org/ # Software Link...
  17. Exploiter

    Exploit doitX 1.0 - 'search' SQL Injection

    doitX 1.0 - 'search' SQL Injection # Exploit Title: doitX 1.0 - SQL Injection # Dork: N/A # Date: 2019-01-10 # Exploit Author: Ihsan Sencan # Vendor Homepage: http://mybizcms.com/ # Software Link: https://codecanyon.net/item/doitx/23041037 # Version: 1.0 # Category: Webapps # Tested on...
  18. Exploiter

    Exploit Event Calendar 3.7.4 - 'id' SQL Injection

    Event Calendar 3.7.4 - 'id' SQL Injection # Exploit Title: Event Calendar 3.7.4 - SQL Injection # Dork: N/A # Date: 2019-01-10 # Exploit Author: Ihsan Sencan # Vendor Homepage: http://ezcode.pt/ # Software Link: https://codecanyon.net/item/event-calendar-phpmysql-plugin/19246267 # Version...
  19. Exploiter

    Exploit Event Locations 1.0.1 - 'id' SQL Injection

    Event Locations 1.0.1 - 'id' SQL Injection # Exploit Title: Event Locations 1.0.1 - SQL Injection # Dork: N/A # Date: 2019-01-10 # Exploit Author: Ihsan Sencan # Vendor Homepage: http://ezcode.pt/ # Software Link: https://codecanyon.net/item/event-locations-phpmysql-plugin/22100679 # Version...
  20. Exploiter

    Exploit Apple macOS 10.12.1 / iOS Kernel - 'IOService::matchPassive' Use-After-Free

    Apple macOS 10.12.1 / iOS Kernel - 'IOService::matchPassive' Use-After-Free /* Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=973 IOService::matchPassive is called when trying to match a request dictionary against a candidate IOService. We can call this function on a...
  21. Exploiter

    Exploit Apple macOS 10.12.1 / iOS Kernel - 'host_self_trap' Use-After-Free

    Apple macOS 10.12.1 / iOS Kernel - 'host_self_trap' Use-After-Free /* Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1034 The task struct has a lock (itk_lock_data, taken via the itk_lock macros) which is supposed to protect the task->itk_* ports. The host_self_trap mach...
  22. Exploiter

    Exploit KB Affiliate Referral Script 1.0 - Authentication Bypass

    KB Affiliate Referral Script 1.0 - Authentication Bypass # # # # # # Exploit Title: KB Affiliate Referral PHP Script V1.0 - Authentication Bypass # Google Dork: N/A # Date: 26.01.2017 # Vendor Homepage: http://kunals.com/ # Software Download...
  23. Exploiter

    Exploit polkit - Temporary auth Hijacking via PID Reuse and Non-atomic Fork

    polkit - Temporary auth Hijacking via PID Reuse and Non-atomic Fork /* When a (non-root) user attempts to e.g. control systemd units in the system instance from an active session over DBus, the access is gated by a polkit policy that requires "auth_admin_keep" auth. This results in an auth...
  24. Exploiter

    Exploit Haraka < 2.8.9 - Remote Command Execution

    Haraka < 2.8.9 - Remote Command Execution #!/usr/bin/python # Exploit Title: Harakiri # ShortDescription: Haraka comes with a plugin for processing attachments. Versions before 2.8.9 can be vulnerable to command injection # Exploit Author: xychix [xychix at hotmail.com] / [mark at outflank.nl]...
  25. Exploiter

    Exploit Apple macOS 10.12.1 / iOS 10.2 - Kernel Userspace Pointer Memory Corruption

    Apple macOS 10.12.1 / iOS 10.2 - Kernel Userspace Pointer Memory Corruption Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1004 mach_voucher_extract_attr_recipe_trap is a mach trap which can be called from any context Here's the code: kern_return_t...