exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 50 of 54 RSS Feed

Files

apc_9606_backdoor.txt
Posted Feb 16, 2004
Authored by Dave Tarbatt | Site null.sniffing.net

APC SmartSwitch and UPS products use an HTTP/SNMP management card that have backdoor passwords in them. Tested vulnerable: SmartUPS 3000RM with AP9606 AOS v3.2.1 and SmartUPS App v3.2.6, MasterSwitch AP9212 with AP9606 AOS v3.0.3 and MasterSwitch App v2.2.0.

tags | exploit, web
SHA-256 | 0989efe070b1c7429abb7289c478d608124cb94c6c330d1264d2dceb29eed5c1
robotFTP.txt
Posted Feb 16, 2004
Authored by gsicht

Robot FTP server versions 1.0 and 2.0 beta 1 have a buffer overflow vulnerability when taking in a username.

tags | exploit, overflow
SHA-256 | 9a44aad3f8e6c0db56451fda95fc12fc8be929e688de14d3ff9a4383aea86d72
AllMyGuests.txt
Posted Feb 14, 2004
Authored by bnfx, Mad_Skater

AllMyGuests suffers from a PHP code injection vulnerability that allows a remote attacker to execute arbitrary commands on the server.

tags | exploit, remote, arbitrary, php
SHA-256 | 942969a79939e95cfeb0e66489b2a7bb67da8d59077abece9d3530faf4dd8620
AllMyLinks.txt
Posted Feb 14, 2004
Authored by bnfx, Mad_Skater

AllMyLinks suffers from a PHP code injection vulnerability that allows a remote attacker to execute arbitrary commands on the server.

tags | exploit, remote, arbitrary, php
SHA-256 | 455fe13e78ca8b714120c34b21cfa370f26b8f7c2c0cfce088dba787c7fc699b
AllMyVisitors.txt
Posted Feb 14, 2004
Authored by bnfx, Mad_Skater

AllMyVisitors suffers from a PHP code injection vulnerability that allows a remote attacker to execute arbitrary commands on the server.

tags | exploit, remote, arbitrary, php
SHA-256 | df8aa30a5295614238725f5082a8277bb929aac6924ee98fb15d32f55b2aeb85
ASPportal.txt
Posted Feb 13, 2004
Authored by Manuel Lopez

ASP Portal suffers from multiple vulnerabilities that can lead to disclosure of authentication information, disclosure of user information, execution of arbitrary code remotely, modification of user information, and identity spoofing. Cookie hijacking exploit enclosed.

tags | exploit, arbitrary, spoof, vulnerability, asp
SHA-256 | e8e1d8a121e11e0a9246f324ce6326b2f6d53ab92eace97fe8e0cd1214ba9a81
MS04-007-dos.c
Posted Feb 13, 2004
Authored by Christophe Devine | Site linuxfromscratch.org

Remote denial of service exploit that causes a windows machine to reboot by manipulating the ASN.1 vulnerabilities mentioned here.

tags | exploit, remote, denial of service, vulnerability
systems | windows
SHA-256 | 4b1303246713d534c4f2ba06e4601987ac52ec41c2f9c015ca77017cf870ed60
crobftp.txt
Posted Feb 13, 2004
Authored by gsicht

Crob FTP version 2.5.2 is vulnerable to a denial of service attack.

tags | exploit, denial of service
SHA-256 | d203607240612684c7152609c705dc92cf03ee5e54cb90b79d49814973d234f4
X11.fontalias.c
Posted Feb 11, 2004
Authored by Bender

Local root exploit for the XFree86 font.alias vulnerability discussed in the advisory here. Tested on various versions of RedHat Linux.

tags | exploit, local, root
systems | linux, redhat
SHA-256 | ed1c569efa3e325a52a9440160ee982d9cf1d8e3c61594c37edad149d60c1e3a
ZH2004-05SA.txt
Posted Feb 11, 2004
Authored by G00db0y | Site zone-h.org

BosDates lacks sufficient sanitization of user-supplied data. Inadvertantly, it allows a remote attacker to influence SQL query logic to disclose sensitive information that can be used to gain unauthorized access.

tags | exploit, remote
SHA-256 | 99f16a5fc0fa02d0ef6ab68973a1477d5cc41f825bce692666aeaceb13a1ba27
The_First_Cut_Is_The_Deepest.txt
Posted Feb 10, 2004
Authored by Pokleyzz

PHPNuke versions 6.x and greater remote php-based exploit that extracts the administrator hash using a SQL injection attack.

tags | exploit, remote, php, sql injection
SHA-256 | 791d39105cfc044976d705a568eb8942b33b8ffcca0d90a5ec35d5163bb96b29
trackmania.c
Posted Feb 9, 2004
Authored by Arnaud Jacques | Site securiteinfo.com

The TrackMania game server that listens on TCP port 2350 can be crashed when garbage data is sent resulting in a denial of service.

tags | exploit, denial of service, tcp
SHA-256 | 679bdbc58dd5a64c64906445a5ca1bcb61f1c3b41fd72b74a16e4ead64037f83
PalmOShttpd.txt
Posted Feb 9, 2004
Authored by Shaun Colley

A bug exists in the PalmOS httpd that causes a crash with a "Fatal Error". Full exploit included.

tags | exploit
systems | palmos
SHA-256 | 5b285308b063e2d59eb136e0072c9ab4a49538d664eb748f4491f7dabcadc37a
openjournal2.5.txt
Posted Feb 7, 2004
Authored by Tri Huynh

Open Journal Blog versions 2.5 and below lack proper user authentication prior to attempting to add a new user to the system.

tags | exploit
SHA-256 | 401cc728745468c6c5fefe43aac710a09eb1b0b3e23eec037542fd5593ae1b60
vserver_chroot.txt
Posted Feb 6, 2004
Authored by Markus Mueller

Local exploit that breaks out of a vserver, even if it is secured with chmod 000 /vservers. Modified version of the chroot-again exploit. Tested with linux 2.4.24 and vserver 1.24. Fixed in release 1.25.

tags | exploit, local
systems | linux
SHA-256 | ecb32af70153e79f3accdcb8ad729fc7c190f6447576c9716239b96b27b6bad2
discuz.txt
Posted Feb 5, 2004
Authored by Cheng Peng Su

A cross site scripting vulnerability exists in Discuz! Board versions 2.x and 3.x.

tags | exploit, xss
SHA-256 | 37321841d97c7b320b61a7e918a129093b97db3a73d154e774707b7d1f4519c5
ZH2004-04SA.txt
Posted Feb 4, 2004
Authored by G00db0y | Site zone-h.org

Multiple SQL Injection vulnerabilities live in ReviewPost PHP Pro due to insufficient sanitization of user-supplied data.

tags | exploit, php, vulnerability, sql injection
SHA-256 | ebc67630c35361eae82fca9970ac250ef2e0cde6a6c9ca3b39f3c9f8e8441843
JSinject.txt
Posted Feb 3, 2004
Authored by Andreas Sandblad

There lies a way to inject a javascript url in the history list of Microsoft Internet Explorer causing a cross site/zone scripting attack when the user presses the backbutton. An attacker may use this to read arbitrary cookies/local files and execute programs leading to total system compromise if IE is run as administrator.

tags | exploit, arbitrary, local, javascript
SHA-256 | e01b9463a639085838e90199fac938b440e307d2558b62b00d81aa347385b6ed
chasercrash.zip
Posted Feb 3, 2004
Authored by Luigi Auriemma | Site aluigi.altervista.org

Test exploit for the server of Chaser versions 1.50 and below.

tags | exploit
SHA-256 | 5db8a2952d0d3502c0d77bedd136b57adbcd6b86f01c70c113c3ededd395d65b
chaser-client.zip
Posted Feb 3, 2004
Authored by Luigi Auriemma | Site aluigi.altervista.org

Test exploit for the client of Chaser versions 1.50 and below.

tags | exploit
SHA-256 | 94f8a2af34c9faacbd305b4a981f59d043e979b2eac32d0782cae09ca7532000
webxdos.txt
Posted Feb 3, 2004
Authored by Peter Winter-Smith | Site elitehaven.net

Web Crossing versions 4.x and 5.x have a denial of service vulnerability. When an HTTP POST request is made to the built-in server, if the 'Content-Length' header supplied with the request is an extremely large or negative number, the server will encounter a set of instructions which lead to an integer-divide-by-zero problem, immediately crashing the server and denying any further service.

tags | exploit, web, denial of service
SHA-256 | a4cb26465dde1aa7db4e37e9bae87f085ad4ccdeb6c14a77fa125516a33bbbd6
phpscripts.txt
Posted Feb 3, 2004
Site security-challenge.com

PHPscripts suffer from a file include vulnerability.

tags | exploit
SHA-256 | f7531beaf196d3efafda379976dbdb9162fcf36480cb7dff573a5603c34728e7
phpMyAdmin255pl1.txt
Posted Feb 3, 2004
Authored by Cedric Cochin | Site netvigilance.com

phpMyAdmin versions 2.5.5-pl1 and below do not properly sanitize variables resulting in them being susceptible to a directory traversal attack.

tags | exploit
SHA-256 | 81168b522d27c42876217622e1f8214fcf0c77dfd436e34b4b0aedbe9e03a637
xcart343.txt
Posted Feb 3, 2004
Authored by Philip

X-Cart version 3.4.3 fails to sanitize various input variables leaving itself open to directory traversal and remote command execution attacks.

tags | exploit, remote
SHA-256 | 310f9a8cac8979d8671622dad1d75561c158e182b0a88454b82adc760eb65407
smbmountDoS.txt
Posted Feb 3, 2004
Authored by Steve Ladjabi, Daniel Kabs

smbmount can cause a denial of service attack on Microsoft Windows. The attack induces a memory shortage on the Windows system by creating directories in a special way.

tags | exploit, denial of service
systems | windows
SHA-256 | 8ccb97f425f4922eeaaacb2ffe330c9f9fa5c7bdf43159239648210620c8916a
Page 2 of 3
Back123Next

Top Authors In Last 30 Days

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close