Section: .. / 0607-exploits /
| /// File Name: |
geoauctionsSQL.txt |
Description:
|
GeoAuctions Premier version 2.0.3 and GeoClassifieds Basic version 2.0.3 suffer from blind SQL injection flaws.
| | Author: | LBDT | | Homepage: | http://newangels-team.eu/ | | File Size: | 5144 | | Last Modified: | Jul 20 05:20:51 2006 |
| MD5 Checksum: | 5d544f67aacc10f37fe5825e9e1ec576 |
|
| /// File Name: |
papoo3rc3.php.txt |
Description:
|
PAPOO versions 3_RC3 and below remote SQL injection and administrative credential disclosure exploit.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org/ | | File Size: | 4929 | | Last Modified: | Jul 9 08:56:29 2006 |
| MD5 Checksum: | b4e86032b3aaaee9a99f853ef75cc72a |
|
| /// File Name: |
BTP00002P000ZA.zip |
Description:
|
Proof of concept denial of service exploit for ZoneAlarm that checks for the insufficient protection of a registry key. Known vulnerable versions include ZoneAlarm Internet Security Suite 6.5.722.000 and ZoneAlarm Internet Security Suite 6.1.737.000.
| | Homepage: | http://www.matousec.com/ | | File Size: | 4466 | | Last Modified: | Jul 9 05:53:38 2006 |
| MD5 Checksum: | 988ea2ceee8dd2c803ad6c93fe7e3cd6 |
|
| /// File Name: |
BTP00004P002NF.zip |
Description:
|
Proof of concept demonstration of a vulnerability in Norton that causes a system crash. Norton Personal Firewall 2006 version 9.1.0.33 is affected. Other versions of Norton software may also be affected.
| | Homepage: | http://www.matousec.com/ | | Related File: | matousec-2006-07-15.02.txt | | File Size: | 4341 | | Last Modified: | Jul 19 01:30:49 2006 |
| MD5 Checksum: | 3cdf91b2d0084058010fab01dee32d18 |
|
| /// File Name: |
eIQ-ESA.txt |
Description:
|
Remote exploit for the Syslog server by eIQnetworks that has a vulnerability when processing long strings transmitted to its TCP port.
| | Author: | kf | | Homepage: | http://www.digitalmunition.com/ | | Related File: | ZDI-06-023.txt | | File Size: | 4336 | | Related CVE(s): | CVE-2006-3838 | | Last Modified: | Jul 27 23:14:54 2006 |
| MD5 Checksum: | 653a1bb8051ce1b14857399b0dbbb5bd |
|
| /// File Name: |
cheesebof.zip |
Description:
|
Proof of concept exploit for Cheese Tracker versions 0.9.9 and below which suffer from a buffer overflow vulnerability in Loader_XM::load_instrument_internal.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org | | Related File: | cheesebof.txt | | File Size: | 4303 | | Last Modified: | Jul 26 03:10:00 2006 |
| MD5 Checksum: | e15e2f950e9ce95e2ed84ca923cf1053 |
|
| /// File Name: |
OpenCMS_multiple_vulnerabilities.tx..> |
Description:
|
OpenCMS versions 6.2.1, 6.2, 6.0.3, and 6.0.4 are vulnerable to multiple access control and input validation vulnerabilities. Other versions may be vulnerable as well. Authenticated users can perform attacks allow arbitrary file access, viewing the source of JSP files, the uploading of malicious files, and more.
| | Author: | Meder Kydyraliev | | Homepage: | http://o0o.nu/~meder | | File Size: | 4247 | | Last Modified: | Jul 27 22:27:12 2006 |
| MD5 Checksum: | cb097692e1a6cd47657ef42b2d8ef9fb |
|
| /// File Name: |
loudblog_05_sql.txt |
Description:
|
LoudBlog versions 0.5 and below 'id' SQL injection and administrative credential disclosure exploit.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org/ | | File Size: | 3952 | | Last Modified: | Jul 24 00:37:13 2006 |
| MD5 Checksum: | 6ce9ea59547d5a04adc2add35e39b616 |
|
| /// File Name: |
h00lyshit.c |
Description:
|
Linux 2.6 up to and including 2.6.17.4 is vulnerable to a race condition leading to a local root compromise if /proc is not mounted noexec. POC exploit.
| | Author: | Joanna R. | | File Size: | 3924 | | Last Modified: | Jul 14 19:21:52 2006 |
| MD5 Checksum: | 7fbcac2a32d7bf594af3fcd6cb1887e4 |
|
| /// File Name: |
rps-include.txt |
Description:
|
RPS, or Rigter Portal System, versions below 4 suffer from file inclusion and SQL injection vulnerabilities.
| | Author: | 0o_zeus_o0 | | Homepage: | http://www.elitemexico.org | | File Size: | 3872 | | Last Modified: | Jul 23 23:21:21 2006 |
| MD5 Checksum: | 6001299f342c1f6b04d64d874ac5aa73 |
|
| /// File Name: |
LinksCaffe30.txt |
Description:
|
LinksCaffe version 3.0 suffers from SQL injection and cross site scripting flaws.
| | Author: | Simo64 | | File Size: | 3778 | | Last Modified: | Jul 26 04:37:12 2006 |
| MD5 Checksum: | 785873f8c34fcc705af12d2ce7f5d97a |
|
| /// File Name: |
PBLGuestbook132.txt |
Description:
|
PBL Guestbook versions 1.32 and below suffer from cross site scripting and SQL injection vulnerabilities.
| | Author: | Paisterist | | Homepage: | http://www.neosecurityteam.net/ | | File Size: | 3759 | | Last Modified: | Jul 9 08:47:28 2006 |
| MD5 Checksum: | 3c91c793f0a79a024e910ddaffe0899f |
|
| /// File Name: |
devilzclan.txt |
Description:
|
deV!Lz Clan Portal remote SQL injection exploit for versions 1.34 and below.
| | Author: | x128 | | File Size: | 3624 | | Last Modified: | Jul 2 04:29:49 2006 |
| MD5 Checksum: | 2abf96402c0143f352b3cd72233aaa7f |
|
| /// File Name: |
ottoman-sploit.txt |
Description:
|
Ottoman CMS versions 1.1.3 and below remote file inclusion exploit.
| | Author: | Jacek Wlodarczyk | | File Size: | 3519 | | Last Modified: | Jul 12 06:03:15 2006 |
| MD5 Checksum: | 969720d9c49fc992b4cc1c04f8a2f44c |
|
| /// File Name: |
imgsvrDoS.txt |
Description:
|
Simple denial of service exploit for ImgSvr that crashes the server with a lot POST request.
| | Author: | co296, n00b | | File Size: | 3517 | | Last Modified: | Jul 9 06:06:31 2006 |
| MD5 Checksum: | e9bab146f76af5907ad97c5f0319b97a |
|
| /// File Name: |
lmmgt2ho.zip |
Description:
|
Proof of concept exploit for libmikmod versions 3.2.2 and below which suffer from a heap overflow vulnerability.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org | | Related File: | lmmgt2ho.txt | | File Size: | 3477 | | Last Modified: | Jul 26 04:07:14 2006 |
| MD5 Checksum: | f173b4ce3ff567ea121774441363f3be |
|
| /// File Name: |
adv37-matdhule-2006.txt |
Description:
|
pc_cookbook Mambo/Joomla Component versions 0.3 and below suffer from a remote file inclusion flaw.
| | Author: | Ahmad Maulana | | File Size: | 3410 | | Last Modified: | Jul 12 04:25:15 2006 |
| MD5 Checksum: | 468a0ca2e43207285216caa416985737 |
|
| /// File Name: |
ms06-035-coco.txt |
Description:
|
Microsoft SRV.SYS Mailslot Ring0 memory corruption denial of service exploit. Takes advantage of the vulnerability discussed in MS06-035.
| | Author: | cocoruder | | Homepage: | http://ruder.cdut.net | | File Size: | 3380 | | Last Modified: | Jul 24 03:05:06 2006 |
| MD5 Checksum: | 24b309a91c00f8dc687b5de5e3313706 |
|
| /// File Name: |
sipXtapi.txt |
Description:
|
SIPfoundry sipXtapi (C Seq) remote buffer overflow exploit written in Perl.
| | Author: | acaro | | Related File: | ERNW-02-2006.txt | | File Size: | 3137 | | Last Modified: | Jul 26 02:53:22 2006 |
| MD5 Checksum: | 03c989c05f5845604d9bf4b8074c476c |
|
| /// File Name: |
trionPWN.pl.txt |
Description:
|
Triton version 1.0.4 remote exploit for the sipxtapi vulnerability.
| | Author: | c0rrupt | | File Size: | 3080 | | Last Modified: | Jul 27 22:55:30 2006 |
| MD5 Checksum: | c58da24cf8218d09d5499f3d36f0a635 |
|
| /// File Name: |
01-iFX-2006-AuraCMS-v1.62-XSS-Bug.t..> |
Description:
|
CMS Aura version 1.62 suffers from cross site scripting flaws.
| | Author: | inversFX | | File Size: | 3001 | | Last Modified: | Jul 9 07:55:34 2006 |
| MD5 Checksum: | d18f07c1cb36a64890f709f37ea25505 |
|
|
|
|
|