exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 101 - 125 of 135 RSS Feed

Files

Trustix Secure Linux Security Advisory 2005.23
Posted Jan 9, 2006
Authored by yorn

The CMS system from brainsquad-team suffers from a cross site scripting vulnerability in the user profile section and also may be susceptible to SQL injection attacks.

tags | exploit, xss, sql injection
SHA-256 | d05089085e8f207a1ee537c3b1cb920f972155981b8f275b8b6fab95ebd32e62
ms05-055.c
Posted Jan 8, 2006
Authored by SoBeIt

Microsoft Windows Kernel APC Data-Free local privilege escalation vulnerability exploit.

tags | exploit, kernel, local
systems | windows
SHA-256 | 43bc5bb31b73cc77b6818dad4290654a2d4f93a03c0f6e4f0757671e7109db41
ihs_winrar.c
Posted Jan 8, 2006
Authored by c0d3r

WinRAR local buffer overflow exploit for versions 3.3.0 and below.

tags | exploit, overflow, local
SHA-256 | 74b04fbbeb8322c1240670f0d444c12756eb79f8d215e2ac599f516d07215d52
EV0019.txt
Posted Jan 8, 2006
Authored by Aliaksandr Hartsuyeu

NavBoard BBcode version 16 Stable (2.6.0) is susceptible to cross site scripting attacks. Exploitation details provided.

tags | exploit, xss
SHA-256 | a9bfc24fea36040757fc7e73d54276a13d72f20e2cff57584ea10ae7dc9dbf30
EV0017.txt
Posted Jan 8, 2006
Authored by Aliaksandr Hartsuyeu

TheWebForum version 1.2.1 is susceptible to cross site scripting and SQL injection attacks. Exploitation details provided.

tags | exploit, xss, sql injection
SHA-256 | 7433cfc2456901c6fde3b48113b54eb1cf1af326eff0490c1dda45b5c96a230d
EV0016.txt
Posted Jan 8, 2006
Authored by Aliaksandr Hartsuyeu

Proyecto Domus version 2.10 is susceptible to a cross site scripting vulnerability. Exploitation details provided.

tags | exploit, xss
SHA-256 | 9abf7f2bddccf5403b40e1ff62a0ef381ccccfdb010020ef64f6c34b62fb0504
EV0015.txt
Posted Jan 8, 2006
Authored by Aliaksandr Hartsuyeu

ADNForum version 1.0b is susceptible to SQL injection and cross site scripting vulnerabilities. Exploitation details provided.

tags | exploit, vulnerability, xss, sql injection
SHA-256 | 2a12355a12abebd0831bb41c80516a4e976ebc037d357e708a1d3278258d5fe2
cybershopSQL.txt
Posted Jan 8, 2006
Authored by Night_Warrior

CyberShop is susceptible to SQL injection attacks via the login sequence.

tags | exploit, sql injection
SHA-256 | 100fe015380b7511cd7556102561cdcacf7cb6edb13cf01f7a1db46d86881ce6
EV0014.txt
Posted Jan 8, 2006
Authored by Aliaksandr Hartsuyeu

TinyPHPForum versions 3.6 and below suffer from directory traversal, cross site scripting, and information disclosure flaws. Exploitation details provided.

tags | exploit, xss, info disclosure
SHA-256 | c2b40e95d689d6b11d4e31d7ff926505f8e034eacd9e0aae6ee22f2684b94675
webftpInclude.txt
Posted Jan 8, 2006
Authored by Thomas Henlich

A file inclusion vulnerability exists in WebFTP version 1.2.6 in webftp.php.

tags | exploit, php, file inclusion
SHA-256 | 5be93b7e1c3861a44e8fd2e42aaf49adbbcf18c9cfd4ded89e929284fa6939f2
phpflaw.php.zip
Posted Jan 6, 2006
Authored by mercenary

PHP 4.3.10 and 4.4.0 Windows remote stack overflow exploit which works on certain systems by overflowing the mysql_connect function. Includes an advisory and workaround information.

tags | exploit, remote, overflow, php
systems | windows
SHA-256 | 41491759f49a7ccda8c1083bd67b32078d239237138d5edb185670bedfc7ff7d
MS05-055Exp.rar
Posted Jan 6, 2006
Authored by SoBeIt

MS05-055 local privilege escalation exploit tested on Windows2000 pro sp4 with and without rollup 1 - Chinese and English versions. Takes advantage of a vulnerability in the Windows Kernel APC Data-Free. Includes C source.

tags | exploit, kernel, local
systems | windows
SHA-256 | 420fb67743576a9332e2c185e1b549ead375c1397b4ee4674307ed70dfd50548
LizardCart.txt
Posted Jan 5, 2006
Authored by Aliaksandr Hartsuyeu | Site evuln.com

The Lizard Cart CMS version 1.04 suffers from an SQL injection vulnerability in the "id" variable.

tags | exploit, sql injection
SHA-256 | d868491ffcff74085c4a3ab4d1c959a1a654c565b2d45b9ab8ce2a47543a2a2a
20051228.ie_xp_pfv_metafile.pm
Posted Jan 4, 2006
Authored by H D Moore | Site metasploit.com

Perl module which exploits the WMF SetAbortProc in the Windows Picture and Fax Viewer found in Windows XP and 2003. This vulnerability uses a corrupt Windows Metafile to execute arbitrary code and was reported to the Bugtraq mailing list after being discovered in the wild at the following URL: http://unionseek[DOT]com/d/t1/wmf_exp.htm. Unofficial patch here.

tags | exploit, web, arbitrary, perl
systems | windows
SHA-256 | 5bce51d9c67bc4ff25072cff79bdbc9d236fe8bb95c51f54208ac06e31d1bddb
20051231.ie_xp_pfv_metafile.pm
Posted Jan 4, 2006
Authored by H D Moore, san, O600KO78RUS | Site metasploit.com

Microsoft Windows Metafile (WMF) SetAbortProc remote code execution exploit which takes advantage of a vulnerability in the GDI library by using the 'Escape' metafile function to execute arbitrary code through the SetAbortProc procedure. Tested against Windows XP and 2003.

tags | exploit, remote, arbitrary, code execution
systems | windows
SHA-256 | bdfd116bc6a03d8c1124c067854578e4ef5e1ef88b7c3bd05c6e6f83179f797c
winrar330.c
Posted Jan 4, 2006
Authored by Alpha_Programmer

WinRAR version 3.30 suffers from a buffer overflow vulnerability when processing a long file name. Proof of concept exploit provided.

tags | exploit, overflow, proof of concept
SHA-256 | 15e8264363d5f7bd7a12704f3585a6269bf2946347c178acf4a069b9e9a7ae1d
cijfer-vsczpl.pl.txt
Posted Jan 4, 2006
Authored by cijfer

Valdersoft Shopping Cart versions 3.0 and below remote command execution exploit.

tags | exploit, remote
SHA-256 | e527deb3eb987e4baffbf7c1b7aac78abf9f89afd9bfeee77d9319631e61a158
termsh.c
Posted Jan 4, 2006
Authored by rod hedor

SCO Openserver 5.0.7 termsh local privilege escalation exploit.

tags | exploit, local
advisories | CVE-2005-0351
SHA-256 | f7a3d4a66d5029784ec01e7c244577689ed677bf1011df6147694236519b212b
EV0011.txt
Posted Jan 4, 2006
Authored by Aliaksandr Hartsuyeu

ScozBook version BETA 1.1 is susceptible to SQL injection attacks. Exploitation details provided.

tags | exploit, sql injection
SHA-256 | da4d1cc5a46c5dff385f4e303beef21af5adba50bd95bfe1a007467af6052325
EV0010.txt
Posted Jan 4, 2006
Authored by Aliaksandr Hartsuyeu

B-net Software version 1.0 is susceptible to cross site scripting attacks. Exploitation details provided.

tags | exploit, xss
SHA-256 | 6d7eb3dceb4488c5b449d29c7e3abe86b8194505b213bda8b02274f513dd2b1b
EV0009.txt
Posted Jan 4, 2006
Authored by Aliaksandr Hartsuyeu

PHPjournaler version 1.0 is susceptible to SQL injection attacks via index.php. Exploitation details provided.

tags | exploit, php, sql injection
SHA-256 | 2cccf720985f175be9d2914db2d99db3e3b524cd8ab172a0e627b8c53853893c
EV0008.txt
Posted Jan 4, 2006
Authored by Aliaksandr Hartsuyeu

inTouch 0.5.1 Alpha is susceptible to SQL injection attacks via the login page. Exploitation details provided.

tags | exploit, sql injection
SHA-256 | 00a20dd1ba146e1a3514736c9781175d9171f70e743290e75fb31387999227a3
EV0007.txt
Posted Jan 4, 2006
Authored by Aliaksandr Hartsuyeu

Chimera Web Portal System version 0.2 is susceptible to SQL injection and cross site scripting attacks. Exploitation details provided.

tags | exploit, web, xss, sql injection
SHA-256 | bd7eda5945d7337e9d512eede3391f5de72d052a3c66eb165a201bb6fb6ee70e
EV0006.txt
Posted Jan 4, 2006
Authored by Aliaksandr Hartsuyeu

phpBook versions 1.3.2 and below suffer from a php code execution flaw due to an unsanitized variable. Exploitation details provided.

tags | exploit, php, code execution
SHA-256 | 1daf972e33787535cdb4cd688f01d75a897c28e9d064ad6dc6bd2bc284106bd2
EV0005.txt
Posted Jan 4, 2006
Authored by Aliaksandr Hartsuyeu

PHPenpals version 310704 suffers from a SQL injection flaw in profile.php. Exploitation details provided.

tags | exploit, php, sql injection
SHA-256 | 537f9cb86f0fdfc27350b8cea6da3791eb77f39ca43febcd407c5798f822d1c2
Page 5 of 6
Back23456Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
Google Patches Critical Chrome Vulnerability
Posted Apr 24, 2024

tags | headline, flaw, google, patch, chrome
Hackers Are Using Developing Countries For Ransomware Practice
Posted Apr 24, 2024

tags | headline, hacker, malware, cybercrime, fraud, cryptography
Authorities Investigate LabHost Users After Phishing Service Shutdown
Posted Apr 23, 2024

tags | headline, cybercrime, fraud, phish
Windows Vulnerability Reported By The NSA Exploited To Install Russian Malware
Posted Apr 23, 2024

tags | headline, government, microsoft, usa, russia, flaw, cyberwar, spyware, nsa
UnitedHealth Admits Breach Could Cover Substantial Proportion Of People In America
Posted Apr 23, 2024

tags | headline, hacker, privacy, data loss
Microsoft DRM Hack Could Allow Movie Downloads From Streaming
Posted Apr 23, 2024

tags | headline, microsoft, flaw, pirate
Over A Million Neighbourhood Watch Members Exposed
Posted Apr 23, 2024

tags | headline, privacy, britain, data loss
MITRE Hacked By State Sponsored Group Via Ivanti Zero Days
Posted Apr 23, 2024

tags | headline, hacker, government
Russia's Sandworm APT Linked To Attack On Texas Water Plant
Posted Apr 18, 2024

tags | headline, malware, usa, russia, cyberwar, scada
EU Tells Meta It Can't Paywall Privacy
Posted Apr 18, 2024

tags | headline, government, privacy, facebook, social
View More News →
packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close