Section: .. / 0611-exploits /
| /// File Name: |
blogtorrent092xss.txt |
Description:
|
BlogTorrent-preview versions 0.92 and below suffer from a cross site scripting flaw.
| | Author: | the_Edit0r | | File Size: | 1109 | | Last Modified: | Nov 17 19:40:59 2006 |
| MD5 Checksum: | 15bc8394acbb73fcfa99f285c5beaf61 |
|
| /// File Name: |
bloo100-rfi.txt |
Description:
|
Bloo versions 1.00 and below suffer from a remote file inclusion vulnerability.
| | Author: | the_Edit0r | | File Size: | 1134 | | Last Modified: | Nov 17 19:45:24 2006 |
| MD5 Checksum: | c3d21f2da432a1da7c98efb7ef9955f2 |
|
| /// File Name: |
bloo100.txt |
Description:
|
Bloo versions 1.00 and below suffer from a cross site scripting flaw.
| | Author: | the_Edit0r | | File Size: | 1120 | | Last Modified: | Nov 17 19:43:00 2006 |
| MD5 Checksum: | 15eb5f4985a2cef966e8388226b54ff2 |
|
| /// File Name: |
bpg.txt |
Description:
|
The BPG Content Management System suffers from a SQL injection vulnerability.
| | Homepage: | http://aria-security.net/ | | File Size: | 464 | | Last Modified: | Nov 16 10:20:37 2006 |
| MD5 Checksum: | f1ea5ef9d217d4aa19c30dd0328e25d1 |
|
| /// File Name: |
broadcom_wifi_ssid.rb.txt |
Description:
|
This Metasploit module exploits a stack overflow in the Broadcom Wireless driver that allows remote code execution in kernel mode by sending a 802.11 probe response that contains a long SSID. The target MAC address must be provided to use this exploit. The two cards tested fell into the 00:14:a5:06:XX:XX and 00:14:a4:2a:XX:XX ranges.
| | Author: | Chris Eagle, Johnny Cache, skape, H D Moore | | Homepage: | http://projects.info-pull.com/mokb/ | | File Size: | 5063 | | Last Modified: | Nov 14 02:59:18 2006 |
| MD5 Checksum: | 8e29a33ce3fa0dea0811bce89496dec2 |
|
| /// File Name: |
BytesFall-exp.txt |
Description:
|
BytesFall Explorer suffers from an input sanitization vulnerability in login/doLogin.php which can lead to SQL injection. POC included that resets the admin password.
| | Author: | RedTeam Pentesting | | Homepage: | http://www.redteam-pentesting.de | | File Size: | 3438 | | Last Modified: | Nov 1 17:45:19 2006 |
| MD5 Checksum: | 3a4ad2fdc37704e9a590d3cdb1f816ed |
|
| /// File Name: |
calsnails106.txt |
Description:
|
mxBB calsnails module version 1.06 remote file inclusion exploit.
| | Author: | the_Edit0r | | File Size: | 3158 | | Last Modified: | Nov 21 01:38:46 2006 |
| MD5 Checksum: | a90f6e486864a60f10b13055ee0b535c |
|
| /// File Name: |
carsite.txt |
Description:
|
Car Site Manager suffers from SQL injection and cross site scripting vulnerabilities.
| | Author: | laurent gaffi, benjamin moss | | Homepage: | http://s-a-p.ca/ | | File Size: | 555 | | Last Modified: | Nov 16 10:45:20 2006 |
| MD5 Checksum: | 12a4433760c57a35806538d5dc666656 |
|
| /// File Name: |
cidstats.txt |
Description:
|
@cid stats version 2.3 suffers from a remote file inclusion vulnerability.
| | Author: | Mahmood_ali | | File Size: | 1003 | | Last Modified: | Nov 7 00:31:10 2006 |
| MD5 Checksum: | e634e8a4c567507e82b84620ae011a5c |
|
| /// File Name: |
classsys.txt |
Description:
|
The Classified System suffers from cross site scripting and SQL injection vulnerabilities.
| | Author: | laurent gaffi, benjamin moss | | Homepage: | http://s-a-p.ca/ | | File Size: | 789 | | Last Modified: | Nov 21 04:52:02 2006 |
| MD5 Checksum: | 581ec3bead4bcf37690b4f8420730a64 |
|
| /// File Name: |
comdev41.txt |
Description:
|
Comdev One Admin Pro version 4.1 is susceptible to a remote file inclusion vulnerability.
| | Author: | AG-Spider | | File Size: | 1336 | | Last Modified: | Nov 17 19:06:28 2006 |
| MD5 Checksum: | ee11b7721121c94f7774e09003d084a8 |
|
| /// File Name: |
contentnow-130-2.txt |
Description:
|
ContentNow version 1.30 suffers from directory traversal and cross site scripting vulnerabilities.
| | Author: | Timq | | Homepage: | http://securitydb.org/ | | File Size: | 910 | | Last Modified: | Nov 14 01:59:02 2006 |
| MD5 Checksum: | bfd4b266567da6fe861d2b11f9dbc6c7 |
|
| /// File Name: |
contentnow-130.txt |
Description:
|
ContentNow version 1.30 suffers from local file inclusion, file upload and command execution vulnerabilities.
| | Author: | r0ut3r | | File Size: | 3711 | | Last Modified: | Nov 14 01:57:36 2006 |
| MD5 Checksum: | 794cdef9f3f1d363b50f92e9eb4517da |
|
| /// File Name: |
cpanel10-xss.txt |
Description:
|
CPanel version 10 is susceptible to cross site scripting attacks via the file manager.
| | Homepage: | http://aria-security.net/ | | File Size: | 756 | | Last Modified: | Nov 14 01:26:41 2006 |
| MD5 Checksum: | feeb6ec6b27206ac9a279075e921fa0d |
|
| /// File Name: |
cpanel10-xss2.txt |
Description:
|
CPanel version 10 is susceptible to cross site scripting attacks via the network tools.
| | Homepage: | http://aria-security.net/ | | File Size: | 450 | | Last Modified: | Nov 18 20:42:36 2006 |
| MD5 Checksum: | 5848cd1ff3a63917cefc418b82e9355a |
|
| /// File Name: |
cra.pl.txt |
Description:
|
PHP-Nuke Mermaid module version 1.2 remote file inclusion exploit that makes use of formdisp.php.
| | Author: | Crackers_Child | | File Size: | 3094 | | Last Modified: | Nov 29 10:23:56 2006 |
| MD5 Checksum: | 7bcc1b4093a59a3640bb2084e33eb419 |
|
| /// File Name: |
daringphucball.rb |
Description:
|
The Apple Airport driver provided with Orinoco-based Airport cards (1999-2003 PowerBooks, iMacs) is vulnerable to a remote memory corruption flaw. When the driver is placed into active scanning mode, a malformed probe response frame can be used to corrupt internal kernel structures, leading to arbitrary code execution. This vulnerability is triggered when a probe response frame is received that does not contain valid information element (IE) fields after the fixed-length header. The data following the fixed-length header is copied over internal kernel structures, resulting in memory operations being performed on attacker-controlled pointer values. This is the Metasploit module for this vulnerability.
| | Author: | H D Moore | | Homepage: | http://metasploit.com/ | | File Size: | 6172 | | Last Modified: | Nov 2 21:08:16 2006 |
| MD5 Checksum: | b3bece5770fb6b8baf288b1f5e1f6148 |
|
| /// File Name: |
datingbypass.txt |
Description:
|
Dating Site suffers from a login bypass vulnerability via SQL injection and also suffers from a cross site scripting flaw.
| | Author: | laurent gaffi, benjamin moss | | Homepage: | http://s-a-p.ca/ | | File Size: | 282 | | Last Modified: | Nov 17 19:02:25 2006 |
| MD5 Checksum: | 2877189d8b1fa443a5c94394ef9f5054 |
|
|
|
|
|