CVE Certified

The Exploit Database

The Exploit Database (EDB) – an ultimate archive of exploits and vulnerable software. A great resource for penetration testers, vulnerability researchers, and security addicts alike. Our aim is to collect exploits from submittals and mailing lists and concentrate them in one, easy to navigate database.


Remote Exploits

Date D A V   Description Plat. Author
2012-02-17 - Waiting verification   HP VSA Remote Command Execution Exploit 365 hardware Nicolas Gregoire
2012-05-13 - Verified   Firefox 8/9 AttributeChildRemoved() Use-After-Free 2723 windows metasploit
2012-05-12 - Verified   Distinct TFTP 3.01 Writable Directory Traversal Execution 1063 windows metasploit
2012-05-09 - Verified   Firefox 7/8 (<= 8.0.1) nsSVGValue Out-of-Bounds Access Vulnerability 3369 windows metasploit
2012-05-05 - Verified   PHP CGI Argument Injection Exploit 9109 php rayh4c
2012-05-04 - Verified   PHP CGI Argument Injection 5251 php metasploit
2012-05-04 - Verified   Solarwinds Storage Manager 5.1.0 SQL Injection 1782 windows metasploit

Local Exploits

Date D A V   Description Plat. Author
2012-05-11 - Waiting verification   PHP 5.4 (5.4.3) Code Execution (Win32) 2521 windows 0in
2012-05-12 - Waiting verification   AnvSoft Any Video Converter 4.3.6 Unicode Buffer Overflow 523 windows h1ch4m
2012-05-11 - Verified   Adobe Photoshop CS5.1 U3D.8BI Collada Asset Elements Stack Overflow 1099 windows rgod
2012-05-03 - Waiting verification   AnvSoft Any Video Converter 4.3.6 Stack Overflow Exploit 987 windows cikumel
2012-05-02 - Waiting verification   Symantec pcAnywhere Insecure File Permissions Local Privilege Escalation 1034 windows Edward Torkington
2012-05-01 - Waiting verification   SAMSUNG NET-i Viewer 1.37 SEH Overwrite 762 windows Blake

Web Applications

Date D A V   Description Plat. Author
2012-05-16 Download Vulnerable Application Verified   Artiphp CMS 5.5.0 Database Backup Disclosure Exploit 986 php LiquidWorm
2012-01-03 - Verified   OpenKM Document Management System 5.1.7 Command Execution 497 jsp Cyrill Brunschwil.
2012-05-16 Download Vulnerable Application Verified   Axous 1.1.1 Multiple Vulnerabilities (CSRF - Persistent XSS) 549 php Ivano Binetti
2012-05-08 Download Vulnerable Application Verified   Serendipity 1.6 Backend XSS And SQLi Vulnerability 788 php Stefan Schurtz
2012-05-13 - Waiting verification   Liferay Portal 6.1 - 6.0.x Privilege Escalation 516 java Jelmer Kuperus
2012-05-15 Download Vulnerable Application Verified   b2ePMS 1.0 Authentication Bypass Vulnerability 761 php Jean Pascal Perei.
2012-05-13 - Verified   Galette (picture.php) SQL Injection Vulnerability 2112 php sbz

DoS/PoC

Date D A V   Description Plat. Author
2012-05-16 - Waiting verification   Trigerring Java Code from a SVG Image 863 multiple Nicolas Gregoire
2012-05-15 - Verified   Multimedia Builder 4.9.8 Malicious mef Crash 438 windows Ahmed Elhady Moha.
2012-05-14 - Verified   FlexNet License Server Manager Stack Overflow In lmgrd 672 multiple Luigi Auriemma
2012-05-14 - Verified   Pro-face Pro-Server EX WinGP PC Runtime Multiple Vulnerabilities 446 windows Luigi Auriemma
2012-05-11 - Verified   QNX phrelay/phindows/phditto Multiple Vulnerabilities 556 windows Luigi Auriemma
2012-03-15 - Waiting verification   Asterisk 'ast_parse_digest()' Stack Buffer Overflow Vulnerability 728 linux Russell Bryant
2012-05-09 - Verified   SAP Netweaver Dispatcher Multiple Vulnerabilities 750 windows Core Security

Shellcode

Date D   Description Plat. Author
2009-06-18   netbsd/x86 kill all processes shellcode 23 bytes 3802 netbsd/x86 Anonymous
2009-12-14   win xp sp2 PEB ISbeingdebugged shellcode 3450 windows Anonymous
2010-04-02   linux x86 nc -lvve/bin/sh -p13377 shellcode 3159 linux Anonymous
2012-03-12   Linux x86_64 - add user with passwd (189 bytes) 4150 lin/x86-64 0_o
2012-01-17   Linux/x86 Search For php,html Writable Files and Add Your Code 5220 lin/x86 rigan
2011-12-31   Linux/x86 Polymorphic ShellCode - setuid(0)+setgid(0)+add user 'iph' without password to /etc/passwd 7341 lin/x86 pentesters.ir
2011-12-10   Linux/MIPS - reboot() - 32 bytes. 5805 linux/mips rigan

Papers

Date D   Description Author
2012-05-09 Hyperion: Implementation of a PE Crypter belial
2012-05-06 [Hebrew] Digital Whisper Security Magazine #31 cp77fk4r and Unde.
2012-05-01 Reverse Engineering Malware Part 1 Arunpreet Singh
2012-05-04 iOS Application (In)Security dmc
2012-05-01 [French] Pas Pas Vers L'Assembleur Notewothy Lord
2012-04-17 JavaScript Deobfuscation - A Manual Approach Sudeep Singh