Warehouse Inventory System version 1.0 suffers from a cross site request forgery vulnerability.
This exploit is an all-in-one tool that leverages vulnerabilities described in CVE-2020-16139, CVE-2020-16138, and CVE-2020-16137 against Cisco 7937G devices versions SIP-1-4-5-7 and below.
Cisco 7947G versions SIP-1-4-5-7 and below privilege escalation exploit.
Two denial of service exploits for Cisco 7937G versions SIP-1-4-5-7 and below.
ManageEngine ADSelfService Plus 6000 unauthenticated remote code execution exploit.
vBulletin version 5.x pre-authentication widget_tabbedcontainer_tab_panel remote code execution exploit. This exploit demonstrates that the patch for CVE-2019-16759 was not sufficient. Written in bash.
vBulletin version 5.x pre-authentication widget_tabbedcontainer_tab_panel remote code execution exploit. This exploit demonstrates that the patch for CVE-2019-16759 was not sufficient. Written in python.
Travel Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Travel Management System version 1.0 unauthenticated remote code execution exploit.
CMS Made Simple 2.2.14 – Authenticated Arbitrary File Upload