exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 51 - 75 of 207 RSS Feed

Files

ManageEngine Service Desk Plus 8.0 Directory Traversal
Posted Jun 24, 2011
Authored by Keith Lee

ManageEngine Service Desk Plus version 8 suffers from a directory traversal vulnerability.

tags | exploit, file inclusion
SHA-256 | 4f147a402469540bda70a2d4460e60ce17cdd395e97084b88ed6877689a53c33
Kofax 2.5.0.933 File Overwrite
Posted Jun 24, 2011
Authored by High-Tech Bridge SA | Site htbridge.com

Kofax version 2.5.0.933 suffers from an arbitrary file overwrite vulnerability.

tags | exploit, arbitrary
SHA-256 | 3281c8b5dece97ac0a85e385b7de5c6f12504838d5c29db6be1e5e33f9c43352
FanUpdate 3.0 Cross Site Scripting
Posted Jun 24, 2011
Authored by High-Tech Bridge SA | Site htbridge.com

FanUpdate version 3.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 8aa6260c4a3817754f9c4fb660d63880ee97da901ced7c5af5b923f779758630
iSupport 1.8 SQL Injection
Posted Jun 24, 2011
Authored by Brendan Coles

iSupport version 1.8 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 2b710744b5d40ea4085cc2528feab9d2b8211d10b452dac2c9cbbb977f110275
BrewBlogger 2.8.2 Cross Site Scripting / SQL Injection
Posted Jun 24, 2011
Authored by Brendan Coles

BrewBlogger version 2.3.2 suffers from cross site scripting, path disclosure, and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection, info disclosure
SHA-256 | 9e5309251f26557177e8598963e20674f5b3b572bee9a84c821b9eea97682ff6
RealWin SCADA Server DATAC Login Buffer Overflow
Posted Jun 23, 2011
Authored by Luigi Auriemma, MC | Site metasploit.com

This Metasploit module exploits a stack buffer overflow in DATAC Control International RealWin SCADA Server 2.1 (Build 6.0.10.10) or earlier. By sending a specially crafted On_FC_CONNECT_FCS_LOGIN packet containing a long username, an attacker may be able to execute arbitrary code.

tags | exploit, overflow, arbitrary
SHA-256 | eefc2e2dd1a8e6e3d6bbd51968ba293d8582140300ddd65d9a563690a5bf114b
Sielco Sistemi Winlog Buffer Overflow
Posted Jun 23, 2011
Authored by Luigi Auriemma, MC | Site metasploit.com

This Metasploit module exploits a buffer overflow in Sielco Sistem Winlog <= 2.07.00. When sending a specially formatted packet to the Runtime.exe service, an attacker may be able to execute arbitrary code.

tags | exploit, overflow, arbitrary
advisories | CVE-2011-0517, OSVDB-70418
SHA-256 | ad560ed7c2b5c2b085b3af27e95252ee83dd229a20d5349ee20068a8929d360f
Sitemagic CMS Directory Traversal
Posted Jun 23, 2011
Authored by Andrea Bocchetti

Sitemagic CMS suffers from a directory traversal vulnerability.

tags | exploit, file inclusion
SHA-256 | 6b480a073a294ad63da8d569a12e8ffa57a5e07c8a301358a24e317656464735
IBM Web Application Firewall Bypass
Posted Jun 21, 2011
Authored by Trustwave | Site trustwave.com

The IBM Web Application Firewall can be evaded, allowing an attacker to exploit web vulnerabilities that the product intends to protect. The issue occurs when an attacker submits repeated occurrences of the same parameter.

tags | exploit, web, vulnerability
SHA-256 | dd1e9c94795aba4ffecf00c4d23acf69a25e54a0a279d3b90a3b780c202eb617
Sitemagic CMS 2010.04.17 Cross Site Scripting
Posted Jun 21, 2011
Authored by LiquidWorm | Site zeroscience.mk

Sitemagic CMS suffers from a XSS vulnerability when parsing user input to the 'SMExt' parameter via GET method in 'index.php'. Attackers can exploit this weakness to execute arbitrary HTML and script code in a user's browser session.

tags | exploit, arbitrary, php
SHA-256 | 8e9bd0f1156742f2d83faa0606fca5304a8e3b055624c9077f24c1a8e274c310
FactoryLink vrn.exe Opcode 9 Buffer Overflow
Posted Jun 21, 2011
Authored by Luigi Auriemma, hal | Site metasploit.com

This Metasploit module exploits a stack buffer overflow in FactoryLink 7.5, 7.5 SP2, and 8.0.1.703. By sending a specially crafted packet, an attacker may be able to execute arbitrary code. Originally found and posted by Luigi Auriemma.

tags | exploit, overflow, arbitrary
advisories | OSVDB-72815
SHA-256 | 180a8907d61d69a4ded59759afdcd03ea9f1757008b99fd69ef2a1c78f4f6f23
Black Ice Cover Page ActiveX Control Arbitrary File Download
Posted Jun 21, 2011
Authored by shinnai, mr_me, sinn3r | Site metasploit.com

This Metasploit module allows remote attackers to place arbitrary files on a users file system by abusing the "DownloadImageFileURL" method in the Black Ice BIImgFrm.ocx ActiveX Control (BIImgFrm.ocx 12.0.0.0). Code execution can be achieved by first uploading the payload to the remote machine, and then upload another mof file, which enables Windows Management Instrumentation service to execute the binary. Please note that this module currently only works for Windows before Vista. Also, a similar issue is reported in BIDIB.ocx (10.9.3.0) within the Barcode SDK.

tags | exploit, remote, arbitrary, code execution, activex
systems | windows
advisories | CVE-2008-2683, OSVDB-46007
SHA-256 | c654011b0b3147d7a6b19b80df3e17b7fd597bafa54d127293006bedf2615b9d
Blue Bison Script SQL Injection
Posted Jun 21, 2011
Authored by HeRoTuRK

Blue Bison Script suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 7880a3ca3557c50dac2f14276792af3c24e1534ae07085756946b9256c400508
EA Sports Cross Site Scripting
Posted Jun 21, 2011
Authored by Juan Sacco

EA Sports aka ea.com suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 2de1463eb99e58c2c78410d7068ed00f86ce8bc9e7e49e6c254af72e509df958
If-CMS 2.07 Local File Inclusion
Posted Jun 21, 2011
Authored by TecR0c

If-CMS version 2.07 pre-authentication local file inclusion exploit that leverages the newlang parameter.

tags | exploit, local, file inclusion
SHA-256 | 54e0d5a2b5475f09684e3d5e161e928ef2258de0b02c152c7f1fffea225f343d
DreamBox DM800 Arbitrary File Download
Posted Jun 21, 2011
Authored by ShellVision

DreamBox DM800 versions 1.6rc3 and below suffer from a remote arbitrary file download vulnerability.

tags | exploit, remote, arbitrary, info disclosure
SHA-256 | 9903b5996d825cd58d3ca550b02438e32094e98f800883c5f8767a40223d9173
XnView 1.98 Denial Of Service Proof Of Concept
Posted Jun 20, 2011
Authored by BraniX

XnView version 1.98 proof of concept denial of service exploit.

tags | exploit, denial of service, proof of concept
SHA-256 | fa100ee8b79f5fb0993035b6b1c6a7e65a6470c5a1875b1e5858ec2c67f26a4c
WordPress WPTouch 1.9.27 URL Redirection
Posted Jun 20, 2011
Authored by MaKyOtOx

WordPress WPtouch plugin version 1.9.27 suffers from a URL redirection vulnerability.

tags | exploit
SHA-256 | f8562a4052d763ce8f06be98cb6f666931c4d1ca5979a972efdf6d7356ddd647
Netclues Script SQL Injection
Posted Jun 20, 2011
Authored by HeRoTuRK

Netclues Script suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 7466898a8173b4a6fb7bde676af273b9ffb156a034decea427209d212c0f256a
Black Ice Cover Page ActiveX Control Arbitrary File Download
Posted Jun 20, 2011
Authored by mr_me | Site metasploit.com

This Metasploit module allows remote attackers to place arbitrary files on a users file system by abusing the "DownloadImageFileURL" method in the Black Ice BIImgFrm.ocx ActiveX Control (BIImgFrm.ocx 12.0.0.0).

tags | exploit, remote, arbitrary, activex
SHA-256 | 865b5dfcca02d2a6aa7a695fab5ecd9bed1fd762899a653cfbd3f158ed37c831
Black Ice Fax Voice SDK 12.6 Code Execution
Posted Jun 20, 2011
Authored by mr_me

Black Ice Fax Voice SDK version 12.6 remote code execution exploit.

tags | exploit, remote, code execution
SHA-256 | b74e8d9fa16afc7c5be868647ea87134dbc15594a5e17358904cc7728f7d2012
Websitesforless SQL Injection
Posted Jun 20, 2011
Authored by N[-m0]

Sites design and developed by Websitesforless suffer from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 704b2ff619fb0ca688b25b26b38ee4879707069293e87386769068946eea8a6c
KievShina Designs SQL Injection
Posted Jun 20, 2011
Authored by Xecuti0N3r

KievShina Designs suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 25451833c3581be1ba00d7a08b2a6337c53b0df11201d10314d6f5a2b6323977
Time Warner SQL Injection
Posted Jun 20, 2011
Authored by Xecuti0N3r

It seems that sites owned by Time Warner all seem to suffer from the same remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 7d0cd865ece7e4f89ead8ca54d236b8177481b0c9e9babfeb8374961805c5119
EssentialSoft Sales Force Automation SQL Injection
Posted Jun 20, 2011
Authored by Xecuti0N3r

EssentialSoft Sales Force Automation Systems suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection
SHA-256 | 27ce6d8c26ec03e95b0df00e1d7092bc44217f3c5d9e27a494d26594ab3df74b
Page 3 of 9
Back12345Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
Social Media Users Lack Control Over Data Used By AI, US FTC Says
Posted Sep 19, 2024

tags | headline, government, privacy, usa, data loss, botnet
Hackers Demand $6 Million From Seattle Airport Operators
Posted Sep 19, 2024

tags | headline, hacker, cybercrime, data loss, fraud, cryptography
Recent WhatsUp Gold Vulnerabilities Possibly Exploited In Ransomware Attacks
Posted Sep 19, 2024

tags | headline, malware, cybercrime, flaw, cryptography
14 Dead As Hezbollah Walkie Talkies Explode In Second, Deadlier Attack
Posted Sep 19, 2024

tags | headline, cyberwar, israel, terror, backdoor
UK Activists Targeted With Pegasus Spyware Ask Police To Charge NSO Group
Posted Sep 19, 2024

tags | headline, government, privacy, britain, israel, spyware
Pip Dreams And Security Schemes: Chaos In Your Configuration Files
Posted Sep 18, 2024

tags | headline, backdoor
Apple Suddenly Drops NSO Group Spyware Lawsuit
Posted Sep 18, 2024

tags | headline, privacy, phone, flaw, israel, spyware, apple
11 Dead, Thousands Injured In Explosive Supply Chain Attack On Hezbollah Pagers
Posted Sep 18, 2024

tags | headline, wireless, cyberwar, israel, terror, backdoor
CloudImposer Attack Targets Google Cloud Services
Posted Sep 18, 2024

tags | headline, hacker, google
AT&T Fined $13 Million For Data Breach
Posted Sep 18, 2024

tags | headline, privacy, phone, data loss
View More News →
packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close