header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

File disclosure via XEE in SharePoint and DotNetNuke

This exploit allows an attacker to disclose files on SharePoint 2007/2010 and DotNetNuke versions lower than 6. By exploiting an XML External Entity (XEE) vulnerability, the attacker can read arbitrary files on the system. The proof of concept (POC) files xee.xml and xee.xsl are provided.

MY MP3 Player DEP Bypass

This exploit is designed to bypass the OptIn/OptOut DEP (Data Execution Prevention) policy on Windows XP SP3. It was written by Blake and has been tested on a virtual machine running Windows XP SP3. The exploit uses a combination of shellcode and return-oriented programming (ROP) techniques to bypass DEP and execute arbitrary code.

ScadaTEC ModbusTagServer & ScadaPhone (.zip) buffer overflow exploit (0day)

This exploit targets ScadaTEC ModbusTagServer and ScadaPhone software. It triggers a buffer overflow vulnerability when loading a project from a zip file. The ScadaPhone exploit bypasses DEP on Windows XP SP3, while the ModbusTagServer exploit does not. The vulnerability affects ScadaPhone versions up to 5.3.11.1230 and ModbusTagServer versions up to 4.1.1.81. The exploit has been tested on Windows XP SP3 with NX enabled.

Recent Exploits: