Section: .. / 0902-exploits /
| /// File Name: |
openxclient-xss.rar |
Description:
|
OpenX version 2.6.3 clientid parameter cross site scripting vulnerability details with screen shots.
| | Author: | Vinod Sharma | | File Size: | 455332 | | Last Modified: | Feb 16 16:19:59 2009 |
| MD5 Checksum: | f50403eabd97f35a33805cfcce0572b4 |
|
| /// File Name: |
openxorderdir-xss.rar |
Description:
|
OpenX version 2.6.3 orderdirection and listorder parameter cross site scripting vulnerability details with screen shots.
| | Author: | Vinod Sharma | | File Size: | 334935 | | Last Modified: | Feb 16 16:20:00 2009 |
| MD5 Checksum: | 89954169073bd957c07d216727cddee7 |
|
| /// File Name: |
optus-xss.txt |
Description:
|
The Optus/Huawei E960 HSDPA router suffers from a cross site scripting vulnerability.
| | Author: | Rizki Wicaksono | | Homepage: | http://www.ilmuhacking.com/ | | File Size: | 2086 | | Last Modified: | Feb 23 16:56:02 2009 |
| MD5 Checksum: | afc81cc200669890f9fab15d8857e232 |
|
| /// File Name: |
oracle10-sql.txt |
Description:
|
This Metasploit module will escalate a Oracle DB user to MDSYS by exploiting a SQL injection bug in the MDSYS.SDO_TOPO_DROP_FTBL trigger. After that, the exploit escalates the user to DBA using "CREATE ANY TRIGGER" privilege given to the MDSYS user by creating an evil trigger in system scheme (2-stage attack).
| | Author: | Sh2kerr | | Homepage: | http://www.dsec.ru/ | | File Size: | 4169 | | Last Modified: | Feb 18 17:07:38 2009 |
| MD5 Checksum: | 25ef4210f8f699c598c6d20415cbdbdf |
|
| /// File Name: |
orbit-overflow.txt |
Description:
|
Orbit versions 2.4 and below long hostname remote buffer overflow exploit.
| | Author: | JavaGuru | | File Size: | 2427 | | Last Modified: | Feb 27 13:47:48 2009 |
| MD5 Checksum: | 8cd2bd5c505262190be95e7ebac9be8d |
|
| /// File Name: |
orbit_expl.c |
Description:
|
Orbit Downloader version 2.8.5 malformed URL buffer overflow exploit that spawns calc.exe, can add a user, or binds a shell to port 4444.
| | Author: | fl0 fl0w | | Homepage: | http://fl0-fl0w.docspages.com/ | | File Size: | 14749 | | Last Modified: | Feb 6 15:14:38 2009 |
| MD5 Checksum: | 9976a6947102d797f095d9e2725bb481 |
|
| /// File Name: |
osmodia-disclose.txt |
Description:
|
Osmodia Bulletin Board suffers from an information disclosure vulnerability.
| | Author: | Pouya Server | | File Size: | 684 | | Last Modified: | Feb 19 23:18:44 2009 |
| MD5 Checksum: | 984debcf247694c3c62f85608495ff8d |
|
| /// File Name: |
papoocms-lfi.txt |
Description:
|
Papoo CMS version 3.6 suffers from a local file inclusion vulnerability.
| | Author: | SirGod | | Homepage: | http://www.insecurity.ro/ | | File Size: | 842 | | Last Modified: | Feb 10 14:28:37 2009 |
| MD5 Checksum: | 2dc66c80dcff27f8197b72f926163129 |
|
| /// File Name: |
passwordprotect-insecure.txt |
Description:
|
WholeHogSoftware Password Protect suffers from an insecure cookie handling vulnerability.
| | Author: | Stack | | Homepage: | http://v4-team.com/ | | File Size: | 645 | | Last Modified: | Feb 3 13:43:29 2009 |
| MD5 Checksum: | 4531892764868b5118bff08e027da992 |
|
| /// File Name: |
penpal-sql.txt |
Description:
|
PenPal version 2.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
| | Author: | ByALBAYX | | Homepage: | http://www.c4team.org/ | | File Size: | 1022 | | Last Modified: | Feb 25 14:56:27 2009 |
| MD5 Checksum: | 43ea691e4d49c79d42af6f6fe8f48e82 |
|
| /// File Name: |
phnews-disclose.txt |
Description:
|
pHNews Alpha 1 suffers from a remote database disclosure vulnerability in genbackup.php.
| | Author: | X0r | | File Size: | 736 | | Last Modified: | Feb 17 16:25:40 2009 |
| MD5 Checksum: | 41c55ecba4321f9595f2b3dd418525d4 |
|
| /// File Name: |
phnews-sql.txt |
Description:
|
pHNews Alpha 1 suffers from a remote SQL injection vulnerability in header.php.
| | Author: | X0r | | File Size: | 1134 | | Last Modified: | Feb 17 16:24:53 2009 |
| MD5 Checksum: | 8ebcfe909d4061c51652fa1366dc560a |
|
| /// File Name: |
phormerpg-insecure.txt |
Description:
|
Phormer PhotoGallery version 3.3.1 suffers from an insecure cookie handling vulnerability.
| | Author: | Hussin X | | Homepage: | http://www.tryag.cc/ | | File Size: | 649 | | Last Modified: | Feb 3 16:22:11 2009 |
| MD5 Checksum: | ea47b4ee7e4c1d8b33058ed3de302b1e |
|
| /// File Name: |
php_eval.rb.txt |
Description:
|
This Metasploit module is for OpenHelpDesk version 1.0.100 that is vulnerability to php code execution to an improper use of eval().
| | Author: | LSO | | File Size: | 2527 | | Last Modified: | Feb 2 17:01:49 2009 |
| MD5 Checksum: | d5b28363c029cd702dacb8d2c7cfcdea |
|
| /// File Name: |
phpbb3-rfi.txt |
Description:
|
phpBB 3 with the Autopost Bot module versions 0.1.3 and below suffers from a remote file inclusion vulnerability.
| | Author: | Kacper | | Homepage: | http://devilteam.pl/ | | File Size: | 2269 | | Last Modified: | Feb 20 14:27:45 2009 |
| MD5 Checksum: | 0971667243c232b9d736423bf6a0cfe9 |
|
| /// File Name: |
phpbbbook-lfi.txt |
Description:
|
PHPbbBook version 1.3 local file inclusion exploit that leverages bbcode.php.
| | Author: | Osirys | | Homepage: | http://osirys.org/ | | File Size: | 6037 | | Last Modified: | Feb 4 13:43:52 2009 |
| MD5 Checksum: | 491da8eeaad69de9e1096d41075bc276 |
|
| /// File Name: |
phpslash-exec.txt |
Description:
|
phpslash versions 0.8.1.1 and below remote code execution exploit.
| | Author: | DarkFig | | File Size: | 19708 | | Last Modified: | Feb 2 17:35:04 2009 |
| MD5 Checksum: | 5bf054f40b42907a6bb958d33389c0e6 |
|
| /// File Name: |
phpyabs-rfi.txt |
Description:
|
phpYabs version 0.1.2 suffers from a remote file inclusion vulnerability.
| | Author: | Arka69 | | Homepage: | http://exploita.altervista.org/ | | File Size: | 666 | | Last Modified: | Feb 6 17:38:54 2009 |
| MD5 Checksum: | 1377900bfacbe0f48ba4316e6961a4be |
|
| /// File Name: |
pirelli-router-xsrf.txt |
Description:
|
Alice Gate2 plus Wi-Fi arbitrary port forward cross site request forgery exploit.
| | Author: | RingZero | | Homepage: | http://www.w00tz0ne.org/ | | File Size: | 890 | | Last Modified: | Feb 15 15:01:54 2009 |
| MD5 Checksum: | a90730709143b4579cbf305d39097608 |
|
| /// File Name: |
potatonews-lfi.txt |
Description:
|
Potato News version 1.0.0 suffers from a local file inclusion vulnerability.
| | Author: | X0r | | File Size: | 1087 | | Last Modified: | Feb 10 16:46:32 2009 |
| MD5 Checksum: | 5e324d94809a23718fba8907226c4880 |
|
| /// File Name: |
powermovielist-sqlxss.txt |
Description:
|
PowerMovieList version 0.14b suffers from cross site scripting and remote SQL injection vulnerabilities.
| | Author: | brain[pillow] | | File Size: | 2041 | | Last Modified: | Feb 16 15:45:13 2009 |
| MD5 Checksum: | 91ccf6889cec563ad1241e915d4fc705 |
|
| /// File Name: |
ppim-exec.txt |
Description:
|
pPIM version 1.01 remote command execution exploit that leverages notes.php.
| | Author: | JosS | | Homepage: | http://www.spanish-hackers.com/ | | File Size: | 4813 | | Last Modified: | Feb 23 16:49:34 2009 |
| MD5 Checksum: | 0266209baed54e908eff0e4f7cfbba2a |
|
| /// File Name: |
ppim-xssexecsql.txt |
Description:
|
pPIM version 1.0 suffers from a large amount of security issues including cross site scripting, SQL injection, authentication bypass, password disclosure, and code execution vulnerabilities.
| | Author: | Justin C. Klein Keane | | File Size: | 8920 | | Last Modified: | Feb 24 20:04:36 2009 |
| MD5 Checksum: | 4d9df5cf8c5353a7a18b661ad0f7567e |
|
|
|
|
|