exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Recent Files

Files RSS Feed
TinyDir 1.2.5 Buffer Overflow
Posted Dec 4, 2023
Authored by Marco Ivaldi | Site security.humanativaspa.it

TinyDir versions 1.2.5 and below suffer from a buffer overflow vulnerability with long path names.

tags | exploit, overflow
Debian Security Advisory 5572-1
Posted Dec 4, 2023
Authored by Debian | Site debian.org

Debian Linux Security Advisory 5572-1 - Rene Rehme discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, did not properly set headers when handling attachments. This would allow an attacker to load arbitrary JavaScript code.

tags | advisory, arbitrary, javascript, imap
systems | linux, debian
PHPJabbers Appointment Scheduler 3.0 CSV Injection
Posted Dec 4, 2023
Authored by Rahad Chowdhury, BugsBD Limited

PHPJabbers Appointment Scheduler version 3.0 suffers from a CSV injection vulnerability.

tags | exploit
Nikto Web Scanner 2.5.0
Posted Dec 4, 2023
Authored by Sullo | Site cirt.net

Nikto is an Open Source web server scanner which performs comprehensive tests against web servers for multiple items, including over 3500 potentially dangerous files/CGIs, versions on over 900 servers, and version specific problems on over 250 servers.

Changes: Breaking changes to JSON and XML output may have occurred. IPv6 support added. Updated db_checks format uses multiple reference. Hundreds of OSVDB and BID references replaced. Removal of some very old and false-positive prone tests. Decodes Netscaler cookies. Added -usecookies flag to send received cookies with subsequent requests. Added -followredirects flag to signal 3xx responses should be fetched and tested. Added -noslash to remove trailing slash from directories. Check for indexing on redirect paths. Alert on alt-svc header. Hundreds of bug fixes, test updates and enhancements, and other optimization changes.
tags | tool, web, cgi
systems | unix
PHPJabbers Appointment Scheduler 3.0 Missing Rate Limiting
Posted Dec 4, 2023
Authored by Rahad Chowdhury, BugsBD Limited

PHPJabbers Appointment Scheduler version 3.0 suffers from a missing rate limiting control that can allow for resource exhaustion.

tags | exploit
PHPJabbers Appointment Scheduler 3.0 Cross Site Scripting
Posted Dec 4, 2023
Authored by Rahad Chowdhury, BugsBD Limited

PHPJabbers Appointment Scheduler version 3.0 suffers from multiple persistent cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
PHPJabbers Appointment Scheduler 3.0 HTML Injection
Posted Dec 4, 2023
Authored by Rahad Chowdhury, BugsBD Limited

PHPJabbers Appointment Scheduler version 3.0 suffers from multiple html injection vulnerabilities.

tags | exploit, vulnerability
October CMS 3.4.0 Wiki Article Cross Site Scripting
Posted Dec 4, 2023
Authored by Nazli Soysal Kuran | Site zeroscience.mk

October CMS version 3.4.0 suffers from a persistent cross site scripting vulnerability when a user has article posting capabilities.

tags | exploit, xss
October CMS 3.4.0 Category Cross Site Scripting
Posted Dec 4, 2023
Authored by Nazli Soysal Kuran | Site zeroscience.mk

October CMS version 3.4.0 suffers from a persistent cross site scripting vulnerability when a user has category-creating capabilities.

tags | exploit, xss
October CMS 3.4.0 Blog Cross Site Scripting
Posted Dec 4, 2023
Authored by Nazli Soysal Kuran | Site zeroscience.mk

October CMS version 3.4.0 suffers from a persistent cross site scripting vulnerability when a user has blog-creating capabilities.

tags | exploit, xss
October CMS 3.4.0 Author Cross Site Scripting
Posted Dec 4, 2023
Authored by Nazli Soysal Kuran | Site zeroscience.mk

October CMS version 3.4.0 suffers from a persistent cross site scripting vulnerability when a user has author posting capabilities.

tags | exploit, xss
October CMS 3.4.0 About Cross Site Scripting
Posted Dec 4, 2023
Authored by Nazli Soysal Kuran | Site zeroscience.mk

October CMS version 3.4.0 suffers from a persistent cross site scripting vulnerability where a user has the ability to edit the landing/about page.

tags | exploit, xss
PHPJabbers Car Rental 3.0 HTML Injection
Posted Dec 4, 2023
Authored by Rahad Chowdhury, BugsBD Limited

PHPJabbers Car Rental version 3.0 suffers from an html injection vulnerability.

tags | exploit
Ubuntu Security Notice USN-6509-2
Posted Dec 4, 2023
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 6509-2 - USN-6509-1 fixed vulnerabilities in Firefox. The update introduced several minor regressions. This update fixes the problem. Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information across domains, or execute arbitrary code. It was discovered that Firefox did not properly manage memory when images were created on the canvas element. An attacker could potentially exploit this issue to obtain sensitive information. It discovered that Firefox incorrectly handled certain memory when using a MessagePort. An attacker could potentially exploit this issue to cause a denial of service. It discovered that Firefox incorrectly did not properly manage ownership in ReadableByteStreams. An attacker could potentially exploit this issue to cause a denial of service. It discovered that Firefox incorrectly did not properly manage copy operations when using Selection API in X11. An attacker could potentially exploit this issue to obtain sensitive information. Rachmat Abdul Rokhim discovered incorrectly handled parsing of relative URLS starting with "///". An attacker could potentially exploit this issue to cause a denial of service.

tags | advisory, denial of service, arbitrary, vulnerability
systems | linux, ubuntu
PHPJabbers Car Rental 3.0 Cross Site Scripting
Posted Dec 4, 2023
Authored by Rahad Chowdhury, BugsBD Limited

PHPJabbers Car Rental version 3.0 suffers from multiple persistent cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
PHPJabbers Car Rental 3.0 CSV Injection
Posted Dec 4, 2023
Authored by Rahad Chowdhury, BugsBD Limited

PHPJabbers Car Rental version 3.0 suffers from a CSV injection vulnerability.

tags | exploit
R Radio Network FM Transmitter 1.07 system.cgi Password Disclosure
Posted Dec 4, 2023
Authored by LiquidWorm | Site zeroscience.mk

R Radio Network FM Transmitter version 1.07 suffers from an improper access control that allows an unauthenticated actor to directly reference the system.cgi endpoint and disclose the clear-text password of the admin user allowing authentication bypass and FM station setup access.

tags | exploit, cgi
PHPJabbers Car Rental 3.0 Missing Rate Limit
Posted Dec 4, 2023
Authored by Rahad Chowdhury, BugsBD Limited

PHPJabbers Car Rental version 3.0 suffers from a missing rate limiting control that can allow for resource exhaustion.

tags | exploit
PHPJabbers Time Slots Booking Calendar 4.0 Missing Rate Limiting
Posted Dec 4, 2023
Authored by Rahad Chowdhury, BugsBD Limited

PHPJabbers Time Slots Booking Calendar version 4.0 suffers from a missing rate limiting control that can allow for resource exhaustion.

tags | exploit
Red Hat Security Advisory 2023-7633-01
Posted Dec 4, 2023
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2023-7633-01 - An update for rh-mariadb105-galera and rh-mariadb105-mariadb is now available for Red Hat Software Collections. Issues addressed include a null pointer vulnerability.

tags | advisory
systems | linux, redhat
Debian Security Advisory 5571-1
Posted Dec 4, 2023
Authored by Debian | Site debian.org

Debian Linux Security Advisory 5571-1 - It was discovered that missing input sanitising in the HTTP API endpoint of RabbitMQ, an implementation of the AMQP protocol, could result in denial of service.

tags | advisory, web, denial of service, protocol
systems | linux, debian
PHPJabbers Availability Booking Calendar 5.0 Missing Rate Limiting
Posted Dec 4, 2023
Authored by Rahad Chowdhury, BugsBD Limited

PHPJabbers Availability Booking Calendar version 5.0 suffers from a missing rate limiting control that can allow for resource exhaustion.

tags | exploit
PHPJabbers Shuttle Booking Software 2.0 CSV Injection
Posted Dec 4, 2023
Authored by Rahad Chowdhury, BugsBD Limited

PHPJabbers Shuttle Booking Software version 2.0 suffers from a CSV injection vulnerability.

tags | exploit
PHPJabbers Time Slots Booking Calendar 4.0 Cross Site Scripting
Posted Dec 4, 2023
Authored by Rahad Chowdhury, BugsBD Limited

PHPJabbers Time Slots Booking Calendar version 4.0 suffers from multiple persistent cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
PHPJabbers Time Slots Booking Calendar 4.0 HTML Injection
Posted Dec 4, 2023
Authored by Rahad Chowdhury, BugsBD Limited

PHPJabbers Time Slots Booking Calendar version 4.0 suffers from an html injection vulnerability.

tags | exploit
View Older Files →

Recent News

News RSS Feed
New Relic Says Hackers Accessed Internal Environment Using Stolen Credentials
Posted Dec 4, 2023

tags | headline, hacker, privacy, data loss, password
Qlik Sense Vulnerabilities Exploited In Ransomware Attacks
Posted Dec 1, 2023

tags | headline, hacker, malware, cybercrime, flaw, cryptography
Black Basta's Ransom Haul Tops $100M In Less Than 2 Years
Posted Dec 1, 2023

tags | headline, hacker, malware, cybercrime, data loss, cryptography
Zoom Flaw Enabled Hijacking Of Accounts With Access To Meetings, Team Chat
Posted Dec 1, 2023

tags | headline, hacker, privacy, flaw
Apple Patches WebKit Flaws Exploited On Older iPhones
Posted Dec 1, 2023

tags | headline, phone, flaw, patch, apple
Interpol Makes First Border Arrest Using Biometric Hub To ID Suspect
Posted Dec 1, 2023

tags | headline, government, spyware, science
Google 0-Day Browser Bug Under Attack, Patch Available
Posted Dec 1, 2023

tags | headline, flaw, google, patch, zero day, chrome
Critical ownCloud Bug Actively Exploited After Disclosure
Posted Nov 30, 2023

tags | headline, hacker, flaw
US Lawmakers Have Chinese LiDAR On Their Threat Detection Radar
Posted Nov 30, 2023

tags | headline, government, usa, china, cyberwar, spyware
Dollar Tree Impacted By Data Breach Affecting 2 Million
Posted Nov 30, 2023

tags | headline, hacker, privacy, data loss
View More News →

File Archive:

December 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    11 Files
  • 2
    Dec 2nd
    0 Files
  • 3
    Dec 3rd
    0 Files
  • 4
    Dec 4th
    32 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

News Tags

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close