what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 101 - 125 of 287 RSS Feed

Files

Toko Lite CMS 1.5.2 Cross Site Scripting
Posted Sep 19, 2011
Authored by LiquidWorm | Site zeroscience.mk

Toko Lite CMS version 15.2 suffers from multiple cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | 1e375defb0b70ff576bb4ab30105128e41f023f56c06f5adc032a0786038ed7c
Aspgwy Access 1.0.0 Cross Site Scripting
Posted Sep 19, 2011
Authored by kurdish hackers team | Site kurdteam.org

Aspgwy Access version 1.0.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 78db463e58965c529a5c4a6614d17333f3c19ce080b1a06db7603e8385da93ae
WordPress Filedownload 0.1 File Disclosure
Posted Sep 19, 2011
Authored by Septemb0x

WordPress Filedownload plugin version 0.1 suffers from a file disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | 7caf8797e03a291467364c0a1cd9e428d63613b9a7870a60ea2e99e43d1090f5
KnFTP 1.0.0 Buffer Overflow
Posted Sep 19, 2011
Authored by loneferret

KnFTP version 1.0.0 buffer overflow denial of service proof of concept exploit.

tags | exploit, denial of service, overflow, proof of concept
SHA-256 | c8dbba0550733b7b64cb6fcc1db09bc11f418b3fbd9cb4822b7d529e0ff3a3f3
WordPress Count Per Day 2.17 SQL Injection
Posted Sep 19, 2011
Authored by Miroslav Stampar

WordPress Count Per Day plugin versions 2.17 and below suffer from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 13411fc482f31ec413a312166f4d200c9694acd983163be252b527555f7f53be
Crea Boutique Pack Pro SQL Injection
Posted Sep 19, 2011
Authored by J.O

Crea Boutie Pack Pro suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | be2883477e9a10271cfb2d27b81464e931af4d547ee874ceef536539c10cf9b4
Car Portal 2.0 SQL Injection
Posted Sep 19, 2011
Authored by m3rciL3Ss

Car Portal version 2.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass. This is the same vulnerability that affected version 1.0.

tags | exploit, remote, sql injection, bypass
SHA-256 | b81d1ba1dfa5f5b4abef4f68cf9938f66968aba574bf0980b51df453711c74a0
Gocommerced SQL Injection
Posted Sep 19, 2011
Authored by J.O

Gocommerced suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | ac58034dc5ee533d56b1631792312f1f176fe4948b30ab27b8d3264bc6b93913
Asp Basit Haber Script 1.0 SQL Injection
Posted Sep 19, 2011
Authored by m3rciL3Ss

Asp Basit Haber Script version 1.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection, asp
SHA-256 | 281f3148cd8070695b7c5c5173f62525cc90b0bbe3c9488308af102fbf0ec75e
Evidalia Web SL SQL Injection
Posted Sep 19, 2011
Authored by ruben_linux

Evidalia Web SL suffers from a remote SQL injection vulnerability.

tags | exploit, remote, web, sql injection
SHA-256 | 728d0e460ebe21bf1be2fa6456a0431f31ee1417520e8d755510f9bdd5e12f59
Gap Infotech Team SQL Injection
Posted Sep 19, 2011
Authored by nGa Sa Lu

Gap Infotech Team suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 0c533653c8f4f325211b46563d50b92350ac07b7c88efca7e10fddc4159ddb74
Ayco Resim Galeri SQL Injection
Posted Sep 19, 2011
Authored by m3rciL3Ss

Ayco Resim Galeri suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 2a43eb8a26e24822918c2d627e91acf86d45a50fb539d8fba37894531a9d7c03
Ayco Emlak SQL Injection
Posted Sep 19, 2011
Authored by m3rciL3Ss

Ayco Emlak suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | f8bce656a88e6f072ea08c8693bc9c35408a509bd88b81b3c2a079ff6b47e6c9
Ayco Shop SQL Injection
Posted Sep 19, 2011
Authored by m3rciL3Ss

Ayco Shop version 1 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 4201607e8da71b96f886977104a9a7448011c0dc9aff47e895ced50a3ca620ad
JlWeb SQL Injection
Posted Sep 19, 2011
Authored by 3spi0n

JlWeb suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 38b0b10c7ef3e1a4d29db9ba17f815ab72c315e078fa5c1e9cd493adde76faf5
KnFTP 1.0.0 USER Buffer Overflow
Posted Sep 19, 2011
Authored by mr.pr0n

KnFTP server version 1.0.0 remote buffer overflow exploit that leverages the USER command.

tags | exploit, remote, overflow
SHA-256 | ad1af12d60d187a995b54043229d49d25f922fbb2e08bf4d92ad939e4049bace
iGallery Plugin 1.0.0 Cross Site Scripting
Posted Sep 18, 2011
Authored by LiquidWorm | Site zeroscience.mk

iGallery plugin version 1.0.0 suffers from a cross site scripting vulnerability when parsing user input to the 'dir' parameter via GET method in '/scripts/pthumb/demo/phpThumb.demo.random.php'. Attackers can exploit this weakness to execute arbitrary HTML and script code in a user's browser session.

tags | exploit, arbitrary, php, xss
SHA-256 | 649c0e5f670adcc02d2f48ac41bb3b9dbf1473ba6e21da4a9bebd40f9b3f7896
iManager Plugin 1.2.8 Cross Site Scripting
Posted Sep 18, 2011
Authored by LiquidWorm | Site zeroscience.mk

iManager plugin versions 1.2.8 build 02012008 and below suffer from a cross site scripting vulnerability when parsing user input to the 'dir' parameter via GET method in 'random.php' and 'phpThumb.demo.random.php'. Attackers can exploit this weakness to execute arbitrary HTML and script code in a user's browser session.

tags | exploit, arbitrary, php, xss
SHA-256 | 4c4c2b763221737d36a6acfffd6dbb477bc08d64d63061a263200f70c4504d7a
iBrowser Plugin 1.4.1 Cross Site Scripting
Posted Sep 18, 2011
Authored by LiquidWorm | Site zeroscience.mk

iBrowser plugin versions 1.4.1 and below suffer from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 2107ed08679b3cadf3a5612f0068b8a88d9524b1ecc47a00f4761fae255d7405
iManager Plugin 1.2.8 Arbitrary File Deletion
Posted Sep 18, 2011
Authored by LiquidWorm | Site zeroscience.mk

iManager plugin version 1.2.8 suffers from an arbitrary file deletion vulnerability.

tags | exploit, arbitrary
SHA-256 | 63d8ec3f4d364c44e15e1df3ae54eb79901968d0e854a24fdc9ff42dc237090b
PunBB PHP Forum 1.3.5 Cross Site Scripting
Posted Sep 18, 2011
Authored by @drk1wi

PunBB PHP Forum suffers from cross site scripting vulnerabilities.

tags | exploit, php, vulnerability, xss
SHA-256 | d8d3793a6fcf75cc7f7df0ecb723320bdd09dc088958cdb60f390cfd39f87be9
Measuresoft ScadaPro 4.0.0 Remote Command Execution
Posted Sep 17, 2011
Authored by Luigi Auriemma, mr_me, TecR0c | Site metasploit.com

This Metasploit module allows remote attackers to execute arbitrary commands on the affected system by abusing a directory traversal attack when using the 'xf' command (execute function). An attacker can execute system() from msvcrt.dll to upload a backdoor and gain remote code execution.

tags | exploit, remote, arbitrary, code execution
SHA-256 | 802baf0283f3035901e556177c67bc14ff8b62fa5e4ccd9e691b0fd5740792be
RealNetworks Realplayer QCP Parsing Heap Overflow
Posted Sep 17, 2011
Authored by Sean de Regge, juan vazquez | Site metasploit.com

This Metasploit module exploits a heap overflow in Realplayer when handling a .QCP file. The specific flaw exists within qcpfformat.dll. A static 256 byte buffer is allocated on the heap and user-supplied data from the file is copied within a memory copy loop. This allows a remote attacker to execute arbitrary code running in the context of the web browser via a .QCP file with a specially crafted "fmt" chunk. At this moment this module exploits the flaw on Windows XP IE6, IE7.

tags | exploit, remote, web, overflow, arbitrary
systems | windows
advisories | CVE-2011-2950, OSVDB-74549
SHA-256 | cce2bc3fede3c402a04087782f79fa183476cf2dbb4148275dc851a1d3272199
ScadaTEC ScadaPhone 5.3.11.1230 Buffer Overflow
Posted Sep 17, 2011
Authored by mr_me | Site metasploit.com

This Metasploit module exploits a stack-based buffer overflow vulnerability in version 5.3.11.1230 of scadaTEC's ScadaPhone. In order for the command to be executed, an attacker must convince someone to load a specially crafted project zip file with ScadaPhone. By doing so, an attacker can execute arbitrary code as the victim user.

tags | exploit, overflow, arbitrary
advisories | OSVDB-75375
SHA-256 | e57c5d7bb2afa78df530127adc494c09c01ecf0da39129aaa47ac10c126368d3
iManager Plugin 1.2.8 Local File Inclusion
Posted Sep 17, 2011
Authored by LiquidWorm | Site zeroscience.mk

iManager plugin version 1.2.8 suffers from a local file inclusion vulnerability / file disclosure vulnerability when input passed thru the 'lang' parameter to imanager.php, rfiles.php, symbols.php, colorpicker.php, loadmsg.php, ov_rfiles.php and examples.php is not properly verified before being used to include files. This can be exploited to include files from local resources with directory traversal attacks and URL encoded NULL bytes.

tags | exploit, local, php, file inclusion
SHA-256 | d0cf4e6a0566ee44420d01dd97fde3f21f7a6d484e9d9448f4b1f6a0c32cc43c
Page 5 of 12
Back34567Next

Top Authors In Last 30 Days

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close