Section: .. / 0707-exploits /
| /// File Name: |
fujitsu-primergy-disclose.txt |
Description:
|
RedTeam Pentesting discovered an information disclosure in the Fujitsu-Siemens BX300 Switch Blade during a penetration test. By accessing URLs of the web interface directly and aborting the authentication dialog, one is able to access the restricted management interface without proper authentication, having read-only access.
| | Homepage: | http://www.redteam-pentesting.de/ | | File Size: | 5139 | | Related CVE(s): | CVE-2007-3012 | | Last Modified: | Jul 7 00:23:27 2007 |
| MD5 Checksum: | 272d316eed89893d1a54824e03924143 |
|
| /// File Name: |
jblog-xss.txt |
Description:
|
JBlog version 1.0 suffers from cross site scripting and administrator creation vulnerabilities.
| | Author: | S4mi | | File Size: | 5101 | | Last Modified: | Jul 23 00:07:14 2007 |
| MD5 Checksum: | bfe1ce303743a1f329f3675b8d47b6aa |
|
| /// File Name: |
NETRAGARD-20070628.txt |
Description:
|
Unavailable.
| | File Size: | 4838 | | Last Modified: | Jul 7 01:14:49 2007 |
| MD5 Checksum: | cdd22c008a037e3a7a37aa85034d5fa4 |
|
| /// File Name: |
AstKilla.c |
Description:
|
Asterisk versions below 1.2.22 / 1.4.8 / 2.2.1 chan_skinny remote denial of service exploit.
| | Author: | fbffff | | File Size: | 4639 | | Last Modified: | Jul 19 00:12:56 2007 |
| MD5 Checksum: | 56fafab58ecdf3198e8233e4305ffae7 |
|
| /// File Name: |
NETRAGARD-20070628-MAILGUARD.txt |
Description:
|
Netragard, L.L.C Advisory - Maia Mailguard versions 1.0.2 and below suffers from file read and directory traversal vulnerabilities that allow for remote code execution. Details provided.
| | Author: | Adriel T. Desautels | | Homepage: | http://www.netragard.com/html/recent_research.html | | File Size: | 4606 | | Last Modified: | Jul 7 01:15:29 2007 |
| MD5 Checksum: | cbc28d85857abefcbb502c8048638724 |
|
| /// File Name: |
argo-exec.txt |
Description:
|
m1srvx.dll version 1.8.9.1 ArGoSoft mail server arbitrary data write and remote code execution exploit.
| | Author: | callAX | | Homepage: | http://goodfellas.shellcode.com.ar/ | | File Size: | 4578 | | Last Modified: | Jul 27 21:23:32 2007 |
| MD5 Checksum: | f549fe232b8efe69551a8e58808431a4 |
|
| /// File Name: |
virc-oday.txt |
Description:
|
ViRC version 2.0 JOIN response remote SEH overwrite exploit. Tested on Visual IRC 2.0 / 2k SP4 Polish. Executes calc.exe.
| | Author: | h07 | | File Size: | 4538 | | Last Modified: | Jul 7 01:04:06 2007 |
| MD5 Checksum: | b26dd20ab595662cbb7691eab7316754 |
|
| /// File Name: |
webyapar-sql.txt |
Description:
|
Webyapar version 2.0 suffers from multiple SQL injection vulnerabilities.
| | Author: | bypass | | File Size: | 4412 | | Last Modified: | Jul 26 01:01:02 2007 |
| MD5 Checksum: | fc12350375a471bbfb4b1974bdf1aa4d |
|
| /// File Name: |
SA-20070722-0.txt |
Description:
|
SEC Consult Security Advisory - SEC Consult has discovered an arbitrary code execution flaw in Joomla! version 1.5 beta 2.
| | Author: | Johannes Greil | | Homepage: | http://www.sec-consult.com/ | | File Size: | 4225 | | Last Modified: | Jul 23 00:30:52 2007 |
| MD5 Checksum: | 0eaa4db5b506cf61eee2ea96becdde66 |
|
| /// File Name: |
scip-sitescape.txt |
Description:
|
SiteScape Forum versions prior to 7.3 suffer from an input validation flaw that allows for arbitrary javascript insertion.
| | Author: | Marc Ruef | | Homepage: | http://www.scip.ch/ | | File Size: | 4040 | | Last Modified: | Jul 13 05:24:04 2007 |
| MD5 Checksum: | 8f91255d47204d82c9642d4331c95b49 |
|
| /// File Name: |
avts10-passwd.txt |
Description:
|
AV Tutorial Script version 1.0 remote user password change exploit.
| | Author: | Dj7xpl | | Homepage: | http://Dj7xpl.2600.ir/ | | File Size: | 3975 | | Last Modified: | Jul 9 23:43:32 2007 |
| MD5 Checksum: | 65dacbac8665d793af03be7e0c83b08f |
|
| /// File Name: |
securityreporter-traverse.txt |
Description:
|
SecurityReporter version 4.6.3 from Secure Computing suffers from an authentication bypass and directory traversal vulnerability.
| | Author: | Oliver Karow | | Homepage: | http://www.oliverkarow.de | | File Size: | 3844 | | Last Modified: | Jul 23 22:27:21 2007 |
| MD5 Checksum: | 0502e8ab3d839c1214e86e3cc7ba9943 |
|
| /// File Name: |
aix53-capture.txt |
Description:
|
IBM AIX versions 5.3 sp6 and below capture Terminal Sequence local root exploit.
| | Author: | qaaz | | File Size: | 3832 | | Last Modified: | Jul 27 21:17:21 2007 |
| MD5 Checksum: | bc7b85cb47e06a823f693d7d932a215e |
|
| /// File Name: |
ecms-exec.txt |
Description:
|
Entertainment CMS remote command execution exploit that makes use of a local file inclusion vulnerability.
| | Author: | Kw3rLN | | Homepage: | http://rstzone.net/ | | File Size: | 3697 | | Last Modified: | Jul 25 00:14:33 2007 |
| MD5 Checksum: | 5c3246421fa04afc82d952cdd8c384e9 |
|
| /// File Name: |
apachemodjk-overflow.txt |
Description:
|
Apache mod_jk versions 1.2.19 and 1.2.20 remote buffer overflow exploit that binds a shell to TCP port 5555. Written for SUSE Enterprise Linux and FreeBSD.
| | Author: | eliteboy | | File Size: | 3681 | | Last Modified: | Jul 9 20:55:16 2007 |
| MD5 Checksum: | 95ff9da192f618c2f9f7b549029f03e8 |
|
| /// File Name: |
joomlaexpose-rfu.txt |
Description:
|
The Joomla component Expose versions RC35 and below suffer from a remote permission bypass and file upload vulnerability.
| | Author: | Cold z3ro | | Homepage: | http://www.hack-teach.com/ | | File Size: | 3562 | | Last Modified: | Jul 19 00:18:21 2007 |
| MD5 Checksum: | 06baad934f99d9743d1b9e55d3233198 |
|
| /// File Name: |
aix53-ftp.txt |
Description:
|
IBM AIX versions 5.3 sp6 and below ftp gets() local root exploit.
| | Author: | qaaz | | File Size: | 3447 | | Last Modified: | Jul 27 21:19:57 2007 |
| MD5 Checksum: | fe602c478e3e43a6fa609caf13e687d7 |
|
| /// File Name: |
CAL-20070730-1.txt |
Description:
|
The BlueSkyCat ActiveX control suffers from a remote heap overflow vulnerability. Versions 8.1.2.0 and below of v2.ocx are affected.
| | Author: | Code Audit Labs | | Homepage: | http://www.vulnhunt.com/ | | File Size: | 3444 | | Last Modified: | Jul 31 02:24:37 2007 |
| MD5 Checksum: | fb1f1924ce376325a941c89d2ee1da1d |
|
| /// File Name: |
jgaa-sql.txt |
Description:
|
jgaa remote SQL injection exploit that allows administrator password hash retrieval.
| | Author: | fl0 fl0w | | File Size: | 3336 | | Last Modified: | Jul 25 00:01:19 2007 |
| MD5 Checksum: | 95488946d13db8bdf40d635e71aeaba0 |
|
| /// File Name: |
sasatldll.txt |
Description:
|
The sasatl.dll version 1.5.0.531 Program Checker javascript heap spraying exploit.
| | Author: | callAX | | Homepage: | http://goodfellas.shellcode.com.ar/ | | File Size: | 3283 | | Last Modified: | Jul 11 04:48:09 2007 |
| MD5 Checksum: | 4bd82617876b15c6501fd1ecd3a58bca |
|
|
|
|
|