Section: .. / Last 50 Files /
| /// File Name: | USN-913-1.txt | Description:
| Ubuntu Security Notice 913-1 - It was discovered that libpng did not properly initialize memory when decoding certain 1-bit interlaced images. If a user or automated system were tricked into processing crafted PNG images, an attacker could possibly use this flaw to read sensitive information stored in memory. This issue only affected Ubuntu 6.06 LTS, 8.04 LTS, 8.10 and 9.04. It was discovered that libpng did not properly handle certain excessively compressed PNG images. If a user or automated system were tricked into processing a crafted PNG image, an attacker could possibly use this flaw to consume all available resources, resulting in a denial of service. | | Author: | Ubuntu | | Homepage: | http://security.ubuntu.com/ | | File Size: | 17736 | | Related CVE(s): | CVE-2009-2042, CVE-2010-0205 | | Last Modified: | Mar 16 20:04:21 2010 | | MD5 Checksum: | e34dd3abb0e2d79fb917042a37af2af6 |
|
| /// File Name: | argosoft-traversal.txt | Description:
| ArGoSoft FTP Server .NET version 1.0.2.1 suffers from a directory traversal vulnerability. | | Author: | dmnt | | File Size: | 432 | | Last Modified: | Mar 16 20:01:06 2010 | | MD5 Checksum: | bb8f51d72fd0b584647dd84d190a595a |
|
| /// File Name: | dff-0.5.0-src.tar.gz | Description:
| DFF (Digital Forensics Framework) is a simple but powerful tool with a flexible module system which will help you in your digital forensics works, including file recovery due to error or crash, evidence research and analysis, etc. DFF provides a robust architecture and some handy modules. | | Author: | Christophe M.,Solal J. | | Homepage: | http://www.digital-forensic.org/ | | Changes: | This release includes several bugfixes and a new API and graphical features: file carving with an enhanced algorithm, a complete rewrite of the hexadecimal viewer, research functions in the API, a new gallery viewer with speed improvements, a partition mapper that allows extended partitions to be added, and automation capabilities based on MIME type for improved GUI navigation. | | File Size: | 2838773 | | Last Modified: | Mar 16 19:57:44 2010 | | MD5 Checksum: | ae8674a3ec7268d1f500bb5eb5a828bc |
|
| /// File Name: | CORE-2009-0803.txt | Description:
| Core Security Technologies Advisory - A vulnerability found in the memory management of the Virtual Machine Monitor makes memory pages mapped above the 2GB available with read or read/write access to user-space programs running in a Guest operating system. | | Author: | Core Security Technologies,Diego Juarez,Nicolas A. Economou | | Homepage: | http://www.coresecurity.com/corelabs/ | | File Size: | 36508 | | Last Modified: | Mar 16 19:53:29 2010 | | MD5 Checksum: | 936c26e59571a54c68f677c92c973253 |
|
| /// File Name: | CORELAN-10-013.txt | Description:
| Windisc version 1.3 suffers from a stack buffer overflow vulnerability. Full exploit code included. | | Author: | Rick | | Homepage: | http://www.corelan.be/ | | File Size: | 11031 | | Last Modified: | Mar 16 19:51:52 2010 | | MD5 Checksum: | ae169a1b3bef09878c6b43b25193a365 |
|
| /// File Name: | fckeditor-shell.txt | Description:
| FCKEditor version 2.0 RC3 suffers from a shell upload vulnerability. | | Author: | Aodrulez | | File Size: | 935 | | Last Modified: | Mar 16 19:48:58 2010 | | MD5 Checksum: | b59c2afa640cc668f579fb57c3dac4e0 |
|
| /// File Name: | USN-912-1.txt | Description:
| Ubuntu Security Notice 912-1 - It was discovered that Audio File Library contained a heap-based buffer overflow. If a user or automated system processed a crafted WAV file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program. The default compiler options for Ubuntu should reduce this vulnerability to a denial of service. | | Author: | Ubuntu | | Homepage: | http://security.ubuntu.com/ | | File Size: | 15508 | | Related CVE(s): | CVE-2008-5824 | | Last Modified: | Mar 16 19:47:32 2010 | | MD5 Checksum: | cea5bb89800954462cbfdec1bfb278eb |
|
| /// File Name: | ZDI-10-032.txt | Description:
| Zero Day Initiative Advisory 10-032 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of SAP MaxDB. Authentication is not required to exploit this vulnerability. The specific flaw exists within the serv.exe process which listens by default on TCP port 7210. The process trusts a value from a handshake packet and uses it as a length when copying data to the stack. If provided a malicious value and packet data, this can be leveraged to execute arbitrary code under the context of the SYSTEM user. | | Author: | TippingPoint | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2648 | | Last Modified: | Mar 16 19:47:16 2010 | | MD5 Checksum: | e2375d89695fe12b1a00cc15adebefb0 |
|
| /// File Name: | clantigercms-xsrf.txt | Description:
| Clan Tiger CMS suffers from a cross site request forgery vulnerability. | | Author: | Pratul Agrawal | | File Size: | 1699 | | Last Modified: | Mar 16 19:46:20 2010 | | MD5 Checksum: | 8ac6d6d229428e13402d0a1955b048ba |
|
| /// File Name: | chillycms-xss.txt | Description:
| Chilly CMS suffers from a persistent cross site scripting vulnerability. | | Author: | Pratul Agrawal | | File Size: | 3159 | | Last Modified: | Mar 16 19:45:12 2010 | | MD5 Checksum: | e97b751f44416cb2cc09edb43df20446 |
|
| /// File Name: | chillycms-xsrf.txt | Description:
| Chilly CMS suffers from a cross site request forgery vulnerability. | | Author: | Pratul Agrawal | | File Size: | 1737 | | Last Modified: | Mar 16 19:44:18 2010 | | MD5 Checksum: | 6f5f88f67ef821bb958d06369419b319 |
|
| /// File Name: | wftpdkill.py.txt | Description:
| WFTPD version 3.3 remote unhandled exception denial of service exploit. | | Author: | dmnt | | File Size: | 1323 | | Last Modified: | Mar 16 19:43:06 2010 | | MD5 Checksum: | 8323be9aa4f257a477d0cf841e451e32 |
|
| /// File Name: | sugarcrm-xss.txt | Description:
| SugarCRM versions prior to 5.5.0a and 5.2.0l suffer from a cross site scripting vulnerability. | | Author: | Jeromie Jackson | | File Size: | 2111 | | Related CVE(s): | CVE-2010-0465 | | Last Modified: | Mar 16 19:41:43 2010 | | MD5 Checksum: | 65028fdd56e01094100a9af2f5680c25 |
|
| /// File Name: | ZDI-10-031.txt | Description:
| Zero Day Initiative Advisory 10-031 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable software utilizing Apple's WebKit library. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists due to a failure to unregister a callback pointer during the destruction of a particular type of element when embedded inside a 'blink' container. The application dereferences the original resource which can can be leveraged by an attacker to execute arbitrary code under the context of the current user. | | Author: | TippingPoint | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2910 | | Last Modified: | Mar 16 19:40:43 2010 | | MD5 Checksum: | 43ec94b162ba7d2b0766fafde3e3e294 |
|
| /// File Name: | ossim22-exec.pdf | Description:
| CYBSEC Security Advisory - OSSIM version 2.2 suffers from a remote command execution vulnerability. | | Author: | Nahuel Grisolia | | Homepage: | http://www.cybsec.com/ | | File Size: | 65714 | | Last Modified: | Mar 16 19:33:55 2010 | | MD5 Checksum: | d41bdbe4b05ef8ac976280685a559ab9 |
|
| /// File Name: | ossim22-upload.pdf | Description:
| CYBSEC Security Advisory - OSSIM version 2.2 suffers from an arbitrary file upload vulnerability. | | Author: | Nahuel Grisolia | | Homepage: | http://www.cybsec.com/ | | File Size: | 64759 | | Last Modified: | Mar 16 19:33:50 2010 | | MD5 Checksum: | 0d2575f09ecdeab1d769bcad45a27d0a |
|
| /// File Name: | ossim22-download.pdf | Description:
| CYBSEC Security Advisory - OSSIM version 2.2 suffers from an arbitrary file download vulnerability. | | Author: | Nahuel Grisolia | | Homepage: | http://www.cybsec.com/ | | File Size: | 65669 | | Last Modified: | Mar 16 19:33:44 2010 | | MD5 Checksum: | c1260392b7369292d9f6003b0d6b7963 |
|
| /// File Name: | egroupware-exec.pdf | Description:
| CYBSEC Security Advisory - EGroupware suffers from a remote command execution vulnerability. Versions 1.4.001 / 1.4.002 / 1.6.001 / 1.6.002 and Premium Line versions 9.1 and 9.2 are affected. | | Author: | Nahuel Grisolia | | Homepage: | http://www.cybsec.com/ | | File Size: | 377524 | | Last Modified: | Mar 16 19:34:21 2010 | | MD5 Checksum: | cd3392e71ec7dd6cd61ee3e6df2f1390 |
|
| /// File Name: | egroupware-xss.pdf | Description:
| CYBSEC Security Advisory - EGroupware suffers from a reflected cross site scripting vulnerability. Versions 1.4.001 / 1.4.002 / 1.6.001 / 1.6.002 and Premium Line versions 9.1 and 9.2 are affected. | | Author: | Nahuel Grisolia | | Homepage: | http://www.cybsec.com/ | | File Size: | 377386 | | Last Modified: | Mar 16 19:34:12 2010 | | MD5 Checksum: | edcf883b64ba6f5440633f8c051e01dc |
|
| /// File Name: | occms-sql.txt | Description:
| Online Community CMS By I-net suffers from a remote SQL injection vulnerability. | | Author: | Th3 RDX | | File Size: | 2999 | | Last Modified: | Mar 16 19:32:47 2010 | | MD5 Checksum: | c953d33ead51b48209a45fa2489cdd63 |
|
| /// File Name: | zigurratcms-sql.txt | Description:
| Zigurrat CMS suffers from a remote SQL injection vulnerability. | | Author: | Isfahan University of Technology | | File Size: | 1064 | | Last Modified: | Mar 16 19:29:34 2010 | | MD5 Checksum: | ea2d6bbeac33bd7357d32c710bc3362e |
|
| /// File Name: | parscms-sql.txt | Description:
| Pars CMS suffers from a remote SQL injection vulnerability. | | Author: | Isfahan University of Technology | | File Size: | 1160 | | Last Modified: | Mar 16 19:28:49 2010 | | MD5 Checksum: | c91edb7d57a0243b3445a51147e8cc9a |
|
| /// File Name: | dsa-2017-1.txt | Description:
| Debian Linux Security Advisory 2017-1 - Dan Rosenberg discovered that the PulseAudio sound server creates a temporary directory with a predictable name. This allows a local attacker to create a Denial of Service condition or possibly disclose sensitive information to unprivileged users. | | Author: | Debian | | Homepage: | http://www.debian.org/security | | File Size: | 59070 | | Related CVE(s): | CVE-2009-1299 | | Last Modified: | Mar 16 19:28:16 2010 | | MD5 Checksum: | c7940506ee2f24afcaa65332c6a54d6b |
|
| /// File Name: | cutenews-insecure.txt | Description:
| CuteNews version 1.4.6 suffers from an insecure cookie handling vulnerability. | | Author: | indoushka | | File Size: | 2098 | | Last Modified: | Mar 16 19:26:53 2010 | | MD5 Checksum: | 04d570d583a36d524fbe3d82c01d26b1 |
|
| /// File Name: | familyconnections22-sql.txt | Description:
| Family Connections version 2.2 suffers from multiple remote SQL injection vulnerabilities. | | Author: | Blake | | File Size: | 3114 | | Last Modified: | Mar 16 19:25:29 2010 | | MD5 Checksum: | 7c8b7a5bc42c222e570cfc4490d6510d |
|
| /// File Name: | ZDI-10-030.txt | Description:
| Zero Day Initiative Advisory 10-030 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Safari and other WebKit based browsers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists in the handling of the run-in value for display CSS styles. A specially crafted web page can cause a use after free() condition in WebKit's WebCore::RenderBlock() method. This can be further leveraged by attackers to execute arbitrary code under the context of the current user. | | Author: | TippingPoint | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2745 | | Last Modified: | Mar 16 19:23:46 2010 | | MD5 Checksum: | 01f4bf61bb7cbb5256b0ad70e2ff46d0 |
|
| /// File Name: | frecf-lfi.txt | Description:
| Free Real Estate Contact Form version 1.09 suffers from a local file inclusion vulnerability. | | Author: | Pouya Daneshmand | | File Size: | 846 | | Last Modified: | Mar 16 18:05:32 2010 | | MD5 Checksum: | b240e39bf6abbb836cbabe60252fbc52 |
|
| /// File Name: | shorturl-lfi.txt | Description:
| Short URL version 1.01 suffers from a local file inclusion vulnerability. | | Author: | Pouya Daneshmand | | File Size: | 815 | | Last Modified: | Mar 16 18:04:49 2010 | | MD5 Checksum: | 69a2e15252eb4b91243a8b8e9b14282d |
|
| /// File Name: | oscmax-shell.txt | Description:
| osCMax version 2.0 using blacklisting instead of whitelisting and due to this suffers from a shell upload vulnerability. | | Author: | Itsecteam | | File Size: | 1947 | | Last Modified: | Mar 16 18:03:50 2010 | | MD5 Checksum: | cde1c450c31235324a15d6ccb746ff45 |
|
| /// File Name: | adobe_libtiff.rb.txt | Description:
| This Metasploit module exploits an integer overflow vulnerability in Adobe Reader and Adobe Acrobat Professional versions 8.0 through 8.2 and 9.0 through 9.3. | | Author: | Microsoft,jduck,villy | | Homepage: | http://www.metasploit.com | | File Size: | 11578 | | Related OSVDB(s): | 62526 | | Related CVE(s): | CVE-2010-0188 | | Last Modified: | Mar 16 17:51:38 2010 | | MD5 Checksum: | 7e3d29c6e1a62c31e6d005a4c6c26424 |
|
| /// File Name: | httpdx-break.txt | Description:
| Httpdx version 1.5.3 remote break services exploit. | | Author: | Jonathan Salwan | | File Size: | 1513 | | Last Modified: | Mar 16 00:48:54 2010 | | MD5 Checksum: | 5dc4a8f716291ef5f6ee472c61c54e83 |
|
| /// File Name: | dojo-xss.txt | Description:
| Dojo Toolkit SDK versions 1.4.1 and below suffer from a cross site scripting vulnerability. | | Author: | Adam Bixby | | Homepage: | http://www.gdssecurity.com/ | | File Size: | 4343 | | Last Modified: | Mar 16 00:46:57 2010 | | MD5 Checksum: | 35c74e69700d51106381fc918fded8e4 |
|
| /// File Name: | plumbercon10-cfp.txt | Description:
| PlumberCon 10 Call For Papers - This convention will be taking place in Austria from July 9th through the 11th, 2010. | | Homepage: | http://plumbercon.org/ | | File Size: | 5213 | | Last Modified: | Mar 16 00:45:57 2010 | | MD5 Checksum: | 0e4053ecbfbfdb5f785a0768c3121f79 |
|
| /// File Name: | csice-xssxsrf.txt | Description:
| CSICE suffers from cross site request forgery and cross site scripting vulnerabilities. | | Author: | FB1H2S | | File Size: | 2046 | | Last Modified: | Mar 16 00:39:32 2010 | | MD5 Checksum: | 9cff76f6a49ec0dea4b4b1024a864414 |
|
| /// File Name: | buck-security_0.4.zip | Description:
| Buck-Security is a security scanner for Debian and Ubuntu Linux. It helps you to harden your system by running some important security checks. For example, it finds world-writable files and directories, setuid and setgid programs, superuser accounts, and installed attack tool packages. It also checks your umask and checks if the sticky bit is set for /tmp, among other checks. | | Homepage: | http://buck-security.sourceforge.net/ | | File Size: | 35181 | | Last Modified: | Mar 16 00:35:57 2010 | | MD5 Checksum: | d10b3410df616cea9b60b44a182debf2 |
|
| /// File Name: | iexploder-1.5.tgz | Description:
| iExploder is like a fire hydrant full of bad HTML and CSS code to test the stability and security of web browsers. Available as a standalone webserver or CGI script, it continuously feeds browsers bad data in the hope that they will eventually crash. It is designed to run for hours, or even days until the browser crashes. namebench was initially written as a QA tool for the Mozilla Project to test the Firefox 1.0 release, and is now included and used by Apple's Webkit project. | | Author: | Thomas Stromberg | | Homepage: | http://code.google.com/p/iexploder/ | | File Size: | 344463 | | Last Modified: | Mar 16 00:32:10 2010 | | MD5 Checksum: | a9f13caef6e05e60c287cb32bf4e5084 |
|
| /// File Name: | joomlaas-sql.txt | Description:
| The Joomla As component suffers from a remote SQL injection vulnerability. | | Author: | N2n-Hacker | | File Size: | 1177 | | Last Modified: | Mar 16 00:28:05 2010 | | MD5 Checksum: | 09707a55a39a42123137cd9512d4bc93 |
|
| /// File Name: | iphone_crash_2.py.txt | Description:
| iPhone Springboard crash proof of concept exploit. | | Author: | Chase Higgins | | File Size: | 1326 | | Last Modified: | Mar 16 00:26:32 2010 | | MD5 Checksum: | fe7fc2c53b3770143815e56cc0b9cd39 |
|
| /// File Name: | whatweb-0.4.tar.gz | Description:
| WhatWeb next generation web scanner identifies what websites are running. Released at the Kiwicon conference (kiwicon.org) in Wellington, New Zealand. Written in Ruby for Linux. Flexible plugin architecture with over 70 plugins so far. Passive plugins use information in the headers, cookies, HTML body and URL. Aggressive plugins can identify versions of Joomla, phpBB, etc by making extra requests to the webserver. Screenshots on the homepage. | | Author: | Andrew Horton (urbanadventurer) | | Homepage: | http://www.morningstarsecurity.com/research/whatweb | | Changes: | Added HTTPS support. Improved documentation. Various additions and updates. | | File Size: | 170740 | | Last Modified: | Mar 15 23:14:59 2010 | | MD5 Checksum: | e1e415bb7cb2c76ff4489232fff5a668 |
|
| /// File Name: | swingette-dos.txt | Description:
| Swingette version 1.1 buffer overflow denial of service exploit that creates a malicious .mp3 file. | | Author: | cr4wl3r | | File Size: | 3102 | | Last Modified: | Mar 16 00:22:33 2010 | | MD5 Checksum: | 1eef33283d881afdf0885f51df41ca63 |
|
| /// File Name: | embedthis-dos.txt | Description:
| Embedthis Appweb version 3.1.2 remote denial of service exploit. | | Author: | chr1x | | File Size: | 4192 | | Last Modified: | Mar 16 00:21:05 2010 | | MD5 Checksum: | 21b1af26a52d6bc36668e826d80f52a0 |
|
| /// File Name: | httpdx153b-crash.txt | Description:
| httpdx version 1.5.3b remote pre-authentication denial of service proof of concept exploit. | | Author: | loneferret | | File Size: | 3898 | | Last Modified: | Mar 16 00:19:41 2010 | | MD5 Checksum: | cd6eaf143dd7d6978809b8f9990e2645 |
|
| /// File Name: | mediaplayer-dos.txt | Description:
| Media Player version 6.4.9.1 with K-Lite Codec Pack denial of service exploit that creates a malicious .avi file. | | Author: | Enigma7 | | File Size: | 886 | | Last Modified: | Mar 16 00:17:06 2010 | | MD5 Checksum: | 0dfc40bacc39b136497d4969c1427b4d |
|
| /// File Name: | gomplayeravi-dos.txt | Description:
| GOM Player version 2.1.21 denial of service exploit that creates a malicious .avi file. | | Author: | Enigma7 | | File Size: | 550 | | Last Modified: | Mar 16 00:15:35 2010 | | MD5 Checksum: | e5fc437366d97e8499cadf910f1dcf1d |
|
| /// File Name: | quickzip_xpsp3.pl.txt | Description:
| QuickZip version 4.60.019 stack buffer overflow exploit for XP SP3. | | Author: | corelanc0d3r | | File Size: | 4363 | | Last Modified: | Mar 16 00:13:48 2010 | | MD5 Checksum: | 115495832ffe27ef0c37a2dfa4d3d799 |
|
| /// File Name: | sipwitch-0.7.3.tar.gz | Description:
| GNU SIP Witch is a pure SIP-based office telephone call server that supports generic phone system features like call forwarding, hunt groups and call distribution, call coverage and ring groups, holding, and call transfer, as well as offering SIP rver, or an IP-PBX, and does not try to emulate Asterisk, FreeSWITCH, or Yate. | | Author: | David Sugar | | Homepage: | http://www.gnutelephony.org/ | | Changes: | Additional server management commands were added. Proper installation of the sipwitch CGI Web service is done to support introduction of a separately installable sipwitch-cgi package in Debian and RPM packaging. | | File Size: | 491035 | | Last Modified: | Mar 15 23:22:18 2010 | | MD5 Checksum: | 9ff32a00a623b77e65bb1c0f04dd6d08 |
|
| /// File Name: | ocftpd-overflow.rb.txt | Description:
| This Metasploit module exploits a stack overflow in the USER verb in Open & Compact FTPd version 1.2. The program will crash once the payload is sent, so bind shell payloads are not effective. | | Author: | Blake | | Homepage: | http://www.metasploit.com | | File Size: | 2154 | | Last Modified: | Mar 15 23:20:20 2010 | | MD5 Checksum: | 4a8214de5df6870ce41b4ddd3218d4f4 |
|
| /// File Name: | ads-xss.txt | Description:
| phpAdsNew, OpenAds and OpenX suffer from a cross site scripting vulnerability in banner.swf. | | Author: | MustLive | | File Size: | 2273 | | Last Modified: | Mar 15 23:18:33 2010 | | MD5 Checksum: | 147a3787722d88ea4263a8c894cecc5d |
|
| /// File Name: | sqlmap-0.8.tar.gz | Description:
| sqlmap is an open source command-line automatic SQL injection tool. Its goal is to detect and take advantage of SQL injection vulnerabilities in web applications. Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user's specified DBMS tables/columns, run his own SQL statement, read or write either text or binary files on the file system, execute arbitrary commands on the operating system, establish an out-of-band stateful connection between the attacker box and the database server via Metasploit payload stager, database stored procedure buffer overflow exploitation or SMB relay attack and more. | | Author: | Bernardo Damele | | Homepage: | http://sqlmap.sourceforge.net | | Changes: | Support to enumerate and dump all database tables. Support to parse -C when fetching columns of a table. Support for takeover features on PostgreSQL 8.4. Various other improvements and tweaks. | | File Size: | 3811238 | | Last Modified: | Mar 15 23:12:07 2010 | | MD5 Checksum: | 1005e55af73b4368c4f70de54bea4d24 |
|
|
|
|
|