Section: .. / 0712-exploits /
| /// File Name: |
hc-multi.txt |
Description:
|
Hosting Controller versions 6.1 Hot fix through 3.3 suffer from multiple vulnerabilities including administrative takeover and SQL injection.
| | Author: | AmnPardaz Security Research Team | | Homepage: | http://www.bugreport.ir/ | | File Size: | 20789 | | Last Modified: | Dec 13 17:56:02 2007 |
| MD5 Checksum: | 2d44d806bd7d909749d5246b551ee1a2 |
|
| /// File Name: |
hpopen-overflow.txt |
Description:
|
HP OpenView Network Node Manager version 07.50 CGI remote buffer overflow exploit that spawns a shell on tcp/4444.
| | Author: | Muts | | Homepage: | http://www.offensive-security.com/ | | File Size: | 4492 | | Last Modified: | Dec 12 17:47:12 2007 |
| MD5 Checksum: | b951951b30d381eef1be4d2ef5fcb558 |
|
| /// File Name: |
viart-rfi.txt |
Description:
|
ViArt CMS version 3.3.2 suffers from a remote file inclusion vulnerability.
| | Author: | RoMaNcYxHaCkEr | | File Size: | 778 | | Last Modified: | Dec 12 17:45:49 2007 |
| MD5 Checksum: | 9d1b60b4b11d87b8ca3f41b9ff7e7d59 |
|
| /// File Name: |
fastpub-rfi.txt |
Description:
|
Fastpublish CMS version 1.9999 suffers from a remote file inclusion vulnerability.
| | Author: | RoMaNcYxHaCkEr | | File Size: | 1761 | | Last Modified: | Dec 12 17:44:56 2007 |
| MD5 Checksum: | 906b08f5d6c0ad9d7e1b09adab9a22b9 |
|
| /// File Name: |
xnu-superblob-dos.c |
Description:
|
Apple Mac OS X xnu versions 1228.0 and below local kernel denial of service proof of concept exploit.
| | Author: | mu-b | | File Size: | 4429 | | Last Modified: | Dec 12 17:43:21 2007 |
| MD5 Checksum: | 10a647463477175d18b997a41f947014 |
|
| /// File Name: |
hpcompaq-exec.txt |
Description:
|
Multiple Hewlett-Packard notebook series are prone to a remote code execution attack. The manufacturer's preinstalled software contains a critical flaw within the software built to support one-touch button quick feature access. This exploit takes advantage of this issue.
| | Author: | porkythepig | | File Size: | 10396 | | Last Modified: | Dec 11 22:21:41 2007 |
| MD5 Checksum: | 9391f4d9db579653c77665250f2e00bf |
|
| /// File Name: |
mcmseasy-lfi.txt |
Description:
|
MCMS Easy Web Make suffers from a local file inclusion vulnerability in index.php.
| | Author: | MhZ91 | | Homepage: | http://www.inj3ct-it.org/ | | File Size: | 1179 | | Last Modified: | Dec 11 22:19:25 2007 |
| MD5 Checksum: | 1aa180fbd7c87e067821c3498956775e |
|
| /// File Name: |
squirrel-inject.txt |
Description:
|
SquirrelMail G/PGP Plugin deletekey() command injection exploit.
| | Homepage: | http://backdoored.net/ | | File Size: | 1302 | | Last Modified: | Dec 11 22:18:03 2007 |
| MD5 Checksum: | bdcdcbf4669f1324020ff2f4f185a0b8 |
|
| /// File Name: |
simple-py.txt |
Description:
|
Simple HTTPD version 1.3 /aux remote denial of service exploit.
| | Author: | shinnai | | Homepage: | http://shinnai.altervista.org/ | | File Size: | 684 | | Last Modified: | Dec 11 22:16:36 2007 |
| MD5 Checksum: | dc603d793628d0a7afc91ceeba96cae9 |
|
| /// File Name: |
omt-bofpoc.txt |
Description:
|
Online Media Technologies remote buffer overflow proof of concept exploit that makes use of AVSMJPEGFILE.DLL version 1.1.
| | Author: | shinnai | | Homepage: | http://shinnai.altervista.org/ | | File Size: | 3339 | | Last Modified: | Dec 11 22:15:36 2007 |
| MD5 Checksum: | 607e92729c5e1b9c1712e24a81c68631 |
|
| /// File Name: |
dosboxxx.zip |
Description:
|
Proof of concept exploit for DOSBox versions 0.72 and below which suffer from a full filesystem access vulnerability.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related File: | dosboxxx.txt | | File Size: | 7644 | | Last Modified: | Dec 10 20:11:29 2007 |
| MD5 Checksum: | eb79708fbc974a763631865111a510bd |
|
| /// File Name: |
badbluebof.zip |
Description:
|
BadBlue versions 2.72b and below suffer from buffer overflow and directory traversal vulnerabilities.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | File Size: | 1056 | | Last Modified: | Dec 10 20:09:05 2007 |
| MD5 Checksum: | ad6db2314b5c6395cb8d00c9da290da9 |
|
| /// File Name: |
barracuda-multi.txt |
Description:
|
The BarracudaDrive Web Server versions 3.7.2 and below suffer from directory traversal, arbitrary file deletion, and multiple other vulnerabilities.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | File Size: | 4176 | | Last Modified: | Dec 10 20:07:12 2007 |
| MD5 Checksum: | 113bb500b222f40b5ac4215124d35eca |
|
| /// File Name: |
wordpresscharset-sql.txt |
Description:
|
WordPress suffers from a charset remote SQL injection vulnerability.
| | Author: | Abel Cheung | | File Size: | 1743 | | Last Modified: | Dec 10 19:45:28 2007 |
| MD5 Checksum: | 4831cb66e7db19c807d8a93c811947d4 |
|
| /// File Name: |
serendipity-xss.txt |
Description:
|
The Serendipity blog system contains a plugin to display the content of feeds in the sidebar (serendipity_plugin_remoterss). If an attacker can modify the RSS feed, it is possible to inject javascript code in the link part, because it is not correctly escaped. Versions below 1.2.1 are affected.
| | Author: | Hanno Boeck | | Homepage: | http://www.hboeck.de/ | | File Size: | 1316 | | Related CVE(s): | CVE-2007-6205 | | Last Modified: | Dec 10 19:43:37 2007 |
| MD5 Checksum: | b821d6ea55e23f0392f1f8a833a17acd |
|
| /// File Name: |
bitweaver-sqlxss.txt |
Description:
|
Bitweaver is susceptible to multiple cross site scripting and SQL injection vulnerabilities.
| | Author: | Doz | | Homepage: | http://www.hackerscenter.com/ | | File Size: | 1591 | | Last Modified: | Dec 10 17:39:58 2007 |
| MD5 Checksum: | 7f9af4f3f67335d9330af7c7ad7bce00 |
|
| /// File Name: |
exoops-sql.txt |
Description:
|
E-XOOPS suffers from multiple SQL injection vulnerabilities. Versions 1.05 Revisions 1 through 3 and version 1.08 are affected.
| | Author: | Lostmon | | Homepage: | http://lostmon.blogspot.com/ | | File Size: | 2788 | | Last Modified: | Dec 10 17:39:05 2007 |
| MD5 Checksum: | aa8294995f10ef90cc1c4a04239506de |
|
| /// File Name: |
gestdown-sql.txt |
Description:
|
GestDown version 1.00Beta suffers from possible SQL injection vulnerabilities.
| | Author: | bebe | | File Size: | 327 | | Last Modified: | Dec 10 17:25:55 2007 |
| MD5 Checksum: | 4085ed51691cd050bdc26113e5c225d1 |
|
| /// File Name: |
bttlxe-sqlxss.txt |
Description:
|
bttlxeForum suffers from multiple SQL injection and cross site scripting vulnerabilities.
| | Author: | Mormoroth | | Homepage: | http://aria-security.net/ | | File Size: | 843 | | Last Modified: | Dec 10 17:24:59 2007 |
| MD5 Checksum: | 406f659bf95def181152ce694388d44a |
|
| /// File Name: |
webspell-xss.txt |
Description:
|
webSPELL version 4.01.02 suffers from cross site scripting vulnerabilities in calendar.php and usergallery.php.
| | Author: | Brainhead | | File Size: | 843 | | Last Modified: | Dec 10 17:21:03 2007 |
| MD5 Checksum: | 26608ba1192411b0a18e03c73d70341f |
|
| /// File Name: |
falconcms-rfixss.txt |
Description:
|
Falcon CMS version 1.4.3 suffers from cross site scripting and remote file inclusion vulnerabilities.
| | Author: | KiNgOfThEwOrLd | | Homepage: | http://www.inj3ct-it.org/ | | File Size: | 2010 | | Last Modified: | Dec 10 17:15:08 2007 |
| MD5 Checksum: | 9587e82349f91fe3ea608573fcd93749 |
|
| /// File Name: |
falt4cms-multi.txt |
Description:
|
The Falt4 CMS version RC4 10.9.2007 suffers from multiple vulnerabilities including blind SQL injection and cross site scripting issues.
| | Author: | H-Security Labs | | Homepage: | http://h-labs.org/ | | File Size: | 2492 | | Last Modified: | Dec 10 17:13:51 2007 |
| MD5 Checksum: | 76288e991a270509d3010625c1fa5e0a |
|
| /// File Name: |
lotfiandb-sql.txt |
Description:
|
The Lotfian.com Database Driven Travel Site suffers from a SQL injection vulnerability.
| | Homepage: | http://aria-security.net/ | | File Size: | 379 | | Last Modified: | Dec 10 17:12:19 2007 |
| MD5 Checksum: | 52d89810c96acfc4569f7a964cbffd93 |
|
|
|
|
|