what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 101 - 125 of 54,266 RSS Feed

Exploit Files

Passion Responsive Blogging 1.0 Cross Site Scripting
Posted Sep 11, 2024
Authored by indoushka

Passion Responsive Blogging version 1.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | d018857c74fe94b61772f381b1c65cf98c7545a26d4e10a537baa1ba622950b2
Online Survey System 1.0 Cross Site Scripting / Remote File Inclusion
Posted Sep 11, 2024
Authored by indoushka

Online Survey System version 1.0 suffers from cross site scripting and remote file inclusion vulnerabilities.

tags | exploit, remote, vulnerability, xss, file inclusion
SHA-256 | 0573d4aa4fad74ba21dfae8c95d8a0ef8922ce6bbbf5c65fcd1a8b98424e3d9e
Online Birth Certificate System 1.0 Insecure Settings
Posted Sep 11, 2024
Authored by indoushka

Online Birth Certificate System version 1.0 suffers from an ignored default credential vulnerability.

tags | exploit
SHA-256 | c7135c363265f519cec4fb4469d88770d47f7406243e7711a2ef7aca6159b30a
Medical Card Generations System 1.0 Insecure Settings
Posted Sep 11, 2024
Authored by indoushka

Medical Card Generations System version 1.0 suffers from an ignored default credential vulnerability.

tags | exploit
SHA-256 | 548b7135e2e243d5d128158ec4a8510b49b16082fb38de180bdb2e26aeaff932
Emergency Ambulance Hiring Portal 1.0 WYSIWYG Code Injection
Posted Sep 11, 2024
Authored by indoushka

Emergency Ambulance Hiring Portal version 1.0 suffer from a WYSIWYG code injection vulnerability.

tags | exploit
SHA-256 | 7b43b9d23f12307ed0da163a4b20cc1867ad452d0156731cd3972715a734a359
Printable Staff ID Card Creator System 1.0 Insecure Direct Object Reference
Posted Sep 11, 2024
Authored by indoushka

Printable Staff ID Card Creator System version 1.0 suffers from an insecure direct object reference vulnerability.

tags | exploit
SHA-256 | 1f76023e1ce2b532a638fe37cd83cacdb3aa9015435641c743140013ed4ffc9f
GitHub sqlpad/sqlpad Template Injection / Remote Code Execution
Posted Sep 10, 2024
Authored by Philip-Otter | Site github.com

Proof of concept automation code to exploit a template injection vulnerability in GitHub repository sqlpad/sqlpad version prior to 6.10.1 that can result in remote code execution.

tags | exploit, remote, code execution, proof of concept
advisories | CVE-2022-0944
SHA-256 | 79a6a3c0f0cc3437faa5b70a9c94c21f376448987379d2b3ee42300f9a2f5271
Spring Cloud Data Flow Remote Code Execution
Posted Sep 10, 2024
Authored by Kayiyan | Site github.com

Proof of concept exploit for Spring Cloud Data Flow versions prior to 2.11.4 that achieves remote code execution through a malicious upload.

tags | exploit, remote, code execution, proof of concept
advisories | CVE-2024-37084
SHA-256 | 0ee38b6a8cf494539040a02c4712511aeac366dfde03820937e77f9441253ed3
PowerVR DEVMEMXINT_RESERVATION::ppsPMR Use-After-Free
Posted Sep 10, 2024
Authored by Jann Horn, Google Security Research

The array ppsPMR in DEVMEMXINT_RESERVATION holds references to PMR structures (using PMRRefPMR2()), intending to prevent the PMRs' physical memory from being released. However, PMRs with PVRSRV_MEMALLOCFLAG_NO_OSPAGES_ON_ALLOC (which for OSMem PMRs internally translates to FLAG_ONDEMAND) can release their backing physical pages while references to the PMR still exist; PMRLockSysPhysAddresses() must be used to prevent a PMR's backing pages from disappearing, like in DevmemIntMapPMR2(). Therefore, it is currently possible to free a PMR's backing pages while the PMR is mapped into a DEVMEMXINT_RESERVATION, leading to physical page use-after-free.

tags | exploit
advisories | CVE-2024-34747
SHA-256 | cc6e11ae0dee934a94a29ebded0e52e70690ca998d7efe6c5f0ffe85ffda4eba
Prison Management System 1.0 Add Administrator
Posted Sep 10, 2024
Authored by indoushka

Prison Management System version 1.0 suffers from an add administrator vulnerability.

tags | exploit, add administrator
SHA-256 | a25a824e97167db71e31b2009a9c44afedb55532be1b9ffa63f063ebf5479933
Online Survey System 1.0 Remote File Inclusion
Posted Sep 10, 2024
Authored by indoushka

Online Survey System version 1.0 suffers from a remote file inclusion vulnerability.

tags | exploit, remote, code execution, file inclusion
SHA-256 | 9ac49e540003cc98bbab6ed47333ffe2f4616bc3a383f48fe3a342e9a7dd83cc
Online Student Grading System 1.0 SQL Injection
Posted Sep 10, 2024
Authored by indoushka

Online Student Grading System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection, bypass
SHA-256 | 6572f3f9bad83df66bb8f42e5fa49921e0511eab96c98361242df9209e7eb2d1
Online Marriage Registration System 1.0 Shell Upload
Posted Sep 10, 2024
Authored by indoushka

Online Marriage Registration System version 1.0 suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell
SHA-256 | 990ace207073f604556500939f13df158bf2dfab39adaff554b8e9d0500f40f9
Dairy Farm Shop Management System 1.2 SQL Injection / Code Execution
Posted Sep 10, 2024
Authored by indoushka

Dairy Farm Shop Management System version 1.2 suffers from a remote SQL injection vulnerability that allows for a backdoor to be inserted for code execution.

tags | exploit, remote, code execution, sql injection
SHA-256 | f0a55905dd74350644935386e7b408242f816011a8331a2ff6ea98c8aaa3d8b4
Beauty Parlour Management System 1.0 SQL Injection / Code Execution
Posted Sep 10, 2024
Authored by indoushka

Beauty Parlour Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for a backdoor to be inserted for code execution.

tags | exploit, remote, code execution, sql injection
SHA-256 | b0286b70ee31536cfdb4ed8e4228e76f2063f3a36f78315a2281b5a491ef8140
Apartment Visitor Management System 1.0 SQL Injection / Code Execution
Posted Sep 10, 2024
Authored by indoushka

Apartment Visitor Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for a backdoor to be inserted for code execution.

tags | exploit, remote, code execution, sql injection
SHA-256 | 987ce5e26137f8bdddbb51bcae57cd30034894c8600689ffa818695de55f9f63
Passion Responsive Blogging 1.0 SQL Injection
Posted Sep 10, 2024
Authored by indoushka

Passion Responsive Blogging version 1.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | e5c501fb2cc5591e80691d788822914442c49c70c0cef043c7a782a2ac61afd5
Microsoft Windows DWM Core Library Privilege Escalation
Posted Sep 9, 2024
Authored by ricnar456 | Site github.com

Proof of concept code for the Microsoft Windows DWM Core library elevation of privilege vulnerability. The researcher shows how they reversed the patch, how the heap overflow is produced, and overall gives a complete walk through of their process.

tags | exploit, overflow, proof of concept
systems | windows
advisories | CVE-2024-30051
SHA-256 | ae21b7b798fa9141cefb1411db92e94dfef6796823599323e49ec4cfcc3f7c0d
Breaking Oracle Database VPD Through DDL Permissions In 19c
Posted Sep 9, 2024
Authored by Emad Al-Mousa

By having specific DDL permissions set in Oracle 19c, you can bypass access restrictions normally in place for VPD (virtual private database).

tags | exploit
SHA-256 | ff60854406414096e014384dc484cf5d2a0ecd59484b16d36d5fb5dd40a2a5f3
PPDB 2.4-update 6118-1 SQL Injection
Posted Sep 9, 2024
Authored by indoushka

PPDB version 2.4-update 6118-1 suffers from a remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 9d523a1c4c7a1e4958bb28bea2acec5647cfe8b259c7789ee6c3b10177fbb4d5
POMS 1.0 Insecure Settings
Posted Sep 9, 2024
Authored by indoushka

POMS version 1.0 suffers from an ignored default credential vulnerability.

tags | exploit
SHA-256 | e96b4926531826f22ee72eeb7f339d7761192178a35f69af5d5141abbc8b63c1
Pharmacy Management System version 1.0 Insecure Settings
Posted Sep 9, 2024
Authored by indoushka

Pharmacy Management System version version 1.0 suffers from an ignored default credential vulnerability.

tags | exploit
SHA-256 | 6c367c1c4b085e72851f370194180a14f132217419dbc26645d989d1f50bd05c
PDF Generator Web Application 1.0 Insecure Settings
Posted Sep 9, 2024
Authored by indoushka

PDF Generator Web Application version 1.0 suffers from an ignored default credential vulnerability.

tags | exploit, web
SHA-256 | ea0edf3e01f27c48e18ff7db4471b92d0d058e7c65718cf02003efd67a75fb49
Park Ticketing Project 1.0 SQL Injection
Posted Sep 9, 2024
Authored by indoushka

Park Ticketing Project version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection, bypass
SHA-256 | 1273e992f54e38d81032650942cf05f0d1f6d8b4728541c4e226b2c694587317
Online Travel Agency System 1.0 Insecure Settings
Posted Sep 9, 2024
Authored by indoushka

Online Travel Agency System version 1.0 suffers from an ignored default credential vulnerability.

tags | exploit
SHA-256 | 33fc5279701fd33248284f756fca51419cb1e797d0158e5bc05d6612e87f5c60
Page 5 of 2,171
Back34567Next

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close