WordPress Olimometer 2.56 SQL Injection

WordPress Olimometer plugin versions 2.56 and below suffer from a remote SQL injection vulnerability.

Linux Kernel Dirty COW PTRACE_POKEDATA Privilege Escalation

Linux kernel versions 2.6.22 and below 3.9 Dirty COW PTRACE_POKEDATA race condition privilege escalation exploit that provides write access.

Burden TMA 2.1.1 Cross Site Scripting

Burden TMA version 2.1.1 suffers from a cross site scripting vulnerability.

Atbox.io Open Redirect

Atbox.io suffers from an open redirection vulnerability.

AOMEI Backupper Standard 3.5 DLL Hijacking

AOMEI Backupper Standard version 3.5 suffers from a dll hijacking vulnerability.

Core FTP LE 2.2 Build 1883 Buffer Overflow

Core FTP LE version 2.2 build 1883 suffers from a buffer overflow vulnerability.

ChatNow 1.1 SQL Injection

ChatNow version 1.1 suffers from a remote SQL injection vulnerability.

Microsoft Windows Kernel NtSetWindowLongPtr Privilege Escalation

Microsoft Windows Kernel win32k.sys NtSetWindowLongPtr privilege escalation proof of concept exploit. Leverages the issue as noted in MS16-135.

Disk Pulse Enterprise 9.1.16 Buffer Overflow

Disk Pulse Enterprise version 9.1.16 suffers from a buffer overflow vulnerability.

Linux Kernel Dirty COW PTRACE_POKEDATA Privilege Escalation

This exploit uses the pokemon exploit as a base and automatically generates a new passwd line. The original /etc/passwd is then backed up to /tmp/passwd.bak and overwritten with the new line. The user will be prompted for the new password when the binary is run. After running the exploit you should be able to login […]